Privacy policy
Last updated: 17 August 2026
Who is the controller
TKJ Global Media Ltd (company number 08272919), trading as TKJ Web Host, is the controller for the personal data described here. Contact us at support@tkjwebhost.com.
Two different roles
This matters, so it comes first. We are the controller for data about you as our customer — your account, your orders, your support conversations. We are a processor for personal data inside the websites, databases and mailboxes you host with us: that data is yours, we act on your instructions, and we do not use it for our own purposes.
What we collect, and why
- Account and billing data — name, email, address, company details, and payment records. Needed to perform our contract with you and to meet our tax and accounting obligations.
- Domain registrant data — passed to the relevant registry, because registries require it. This is a legal obligation of registration, not something we choose.
- Support correspondence — kept so we have the history of your account. Legitimate interests in running a supportable service.
- Server and access logs — IP addresses and request data, retained short-term for security, abuse handling and diagnostics. Legitimate interests in platform security.
Payments
Payments are taken through our checkout provider. We do not see or store your full card number — the card details go directly to the payment processor, and we receive only the result and the last four digits.
Who we share it with
- Our upstream hosting infrastructure partner, who operates the servers your account runs on.
- Domain registries and registrars, where you register or transfer a domain.
- Our payment processor, for taking payment and handling refunds and chargebacks.
- Our accountants and professional advisers, where necessary.
- Law enforcement or a regulator, where we are legally required to.
We do not sell personal data and we do not share it for advertising.
Where it is stored
Hosting infrastructure is in the UK. Some suppliers may process data outside the UK; where they do, transfers are made under the UK International Data Transfer Agreement, the UK Addendum to the EU standard contractual clauses, or an adequacy regulation.
How long we keep it
- Account records — for the life of the account, then 6 years to meet accounting and limitation requirements.
- Billing and invoices — 6 years, per HMRC requirements.
- Support correspondence — 2 years after the account closes.
- Server and access logs — typically 30 days, longer only where an active security investigation requires it.
- Your hosted content and backups — deleted 30 days after termination.
Cookies
This marketing site sets no cookies and runs no analytics. Our checkout and control panel set cookies that are strictly necessary to keep you logged in and to hold your basket — those are exempt from consent under PECR. If we ever add analytics or marketing cookies we will ask for your consent first, before they are set.
Your rights
You have the right to access your data, to have inaccurate data corrected, to erasure and to restriction in certain circumstances, to data portability, and to object to processing based on legitimate interests. Email us and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
Security
Access to customer data is limited to people who need it, accounts are protected by multi-factor authentication, and traffic is encrypted in transit. No system is perfect; if a breach occurs that is likely to risk your rights and freedoms we will tell you, and we will report to the ICO within 72 hours where required.