Last reviewed: 2 August 2025
This Privacy Notice explains how Liquid Webspace Ltd (“LiquidWebSpace”, “we”, “us” or “our”) collects and uses personal information about customers, authorised users, domain registrants, reseller end-users, website visitors and people who contact us.
It applies under the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 (“PECR”) where applicable, and any UK legislation that replaces or amends them.
1. Who we are
Liquid Webspace Ltd
Company number: 15332514
Registered in England and Wales
Registered office: 44 Puttock Way, Billingshurst, West Sussex, RH14 9ZJ
Liquid Webspace Ltd is the data controller for personal information it processes for its own business purposes, including customer accounts, billing, services, support, security and this website.
For some hosting and reseller services, a customer decides why and how information about its own users is processed. The customer is normally the controller and Liquid Webspace Ltd acts as its processor. That processing is also governed by the applicable Data Processing Agreement (“DPA”). Resellers must have a lawful basis for supplying end-user information and give those users appropriate privacy information.
2. Information we collect
Identity and contact information
- Name, company name, account-holder and authorised-contact details.
- Email address, telephone number and postal or billing address.
Account information
- Customer ID, usernames, permissions, service subscriptions and account history.
- Authentication and account-security records. We do not store passwords in readable form.
Billing and transaction information
- Invoices, payments, refunds, billing addresses, transaction references and payment status.
- Payment providers may process full card or bank details directly. We generally receive a token, mandate or transaction status rather than complete payment credentials.
Domain registration information
Registrant and domain-contact name, organisation, address, email address and telephone number, plus registration, renewal and transfer records.
Hosting and technical information
IP addresses, server and service logs, login records, browser and device details, DNS and hosting-account information, security events, abuse records, API and resource usage, and diagnostics.
Support communications
Support tickets, emails, chat messages, telephone-related records where applicable, troubleshooting information and files or screenshots you provide.
Website usage information
Cookies and similar technologies, browser and device details, pages visited, referral information and consent choices. See our Cookie Policy.
3. How we collect your information
We may obtain personal information directly from you or from third parties. We collect it through registration and checkout, the customer portal, support tickets, email, telephone, domain requests, billing, logins, API use, marketing choices, and reseller or affiliate applications.
We may also receive information from payment providers, banks, domain registrars and registries, resellers, fraud-prevention services, infrastructure and security systems, and authorised customer representatives. We use indirectly obtained information only for the relevant service, legal, security or support purpose and provide privacy information as required by law.
4. How and why we use your information
| Purpose | Information used | Lawful basis |
|---|---|---|
| Create and manage accounts | Identity, contact, account and authentication information | Contract or requested pre-contract steps |
| Provide hosting, domain, DNS, email and server services | Identity, contact, account, domain and technical information | Contract |
| Process payments, refunds and invoices | Identity, contact, billing and transaction information | Contract and, where applicable, legal obligation |
| Maintain tax and accounting records | Account, invoice and transaction records | Legal obligation |
| Register, renew and transfer domains | Registrant, contact, account and transaction information | Contract and applicable registry or registrar requirements |
| Provide support and service communications | Identity, contact, account, technical and support information | Contract and legitimate interests in customer service and business relationships |
| Security, fraud prevention and abuse detection | Account, transaction, login, technical, security and abuse information | Legitimate interests in protecting us, customers, networks and third parties; legal obligation where applicable |
| Monitor reliability and improve services | Technical, service-log and usage information | Legitimate interests in reliable infrastructure and better products; consent for optional cookies where required |
| Legal and regulatory compliance | Information relevant to the requirement | Legal obligation |
| Establish or defend legal claims | Account, transaction, communications, technical, security and abuse information | Legitimate interests and applicable legal provisions |
| Relevant offers to existing customers | Name, contact details, services and preferences | Legitimate interests where PECR permits; otherwise consent |
| Marketing to prospects | Name, contact details and preferences | Consent where required by UK GDPR and PECR |
5. Lawful bases and legitimate interests
Our basis depends on the purpose. We process information to perform a contract or take requested pre-contract steps, comply with law, pursue an interest not overridden by your rights, or with consent.
Our legitimate interests include protecting systems from abuse, preventing fraud, maintaining network security and reliability, supporting customers, managing business relationships, improving products and defending legal claims. We assess and document these interests where appropriate. Consent may be withdrawn at any time without affecting earlier processing.
6. Domain registration information
Registering, renewing or transferring a domain may require disclosure to the relevant registrar, registry, registry-service provider, Nominet for applicable .UK domains, and providers involved in ICANN-governed domains. Requirements vary by extension. These organisations may retain information independently under their own rules and notices. Some domain services inherently require limited overseas transfers. We cannot provide a registration if mandatory information is not supplied.
7. Who we share information with
We share information only where there is an appropriate lawful basis and it is reasonably necessary. Recipients may include:
- Payment processors, banks and payment providers, which may independently process full payment details under their own notices.
- Domain registrars, registries, Nominet, ICANN-related providers and registry-service providers.
- Hosting infrastructure, data-centre, network, backup, security, fraud-prevention and abuse-management providers.
- Email-delivery, communications, support, customer-management and accounting providers.
- Professional advisers, auditors, insurers, courts, regulators, police and other authorities where appropriate.
- Parties and advisers involved in a proposed or completed business sale or reorganisation.
We vet suppliers as appropriate and use contractual protections when they process information for us. Suppliers may change as services develop; information about relevant sub-processors can be requested from our Privacy Contact.
8. International transfers and storage
We use UK and overseas infrastructure and suppliers as needed. We do not promise all information remains in the UK. Domain, payment, support, communications, security and infrastructure providers may process information elsewhere.
Where UK law requires a transfer safeguard, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another approved safeguard, with added technical and organisational protections where appropriate.
9. How long we keep information
We keep information only as long as reasonably necessary, considering contractual, operational, security, registry, tax, accounting and legal requirements. The criteria below apply; exact periods are reviewed in our internal retention schedule.
| Data | Typical retention |
|---|---|
| Account and service records | For the relationship and afterward as needed for queries, disputes, security and claims. We retain this information for up to 6 years. |
| Financial and invoice records | For the period required by applicable UK tax and accounting law. |
| Support communications | For support, service history and disputes. We retain this information for up to 6 years. |
| Server, access and security logs | According to operational and security needs, longer for incidents or legal duties. We retain this information for up to 6 years. |
| Fraud and abuse records | As needed to protect services, prevent repeat abuse and defend claims. We retain this information for up to 6 years. |
| Backups | Until overwritten through the documented cycle unless legally preserved. We retain this information for up to 6 years. |
| Domain records | For periods required by the registry, registrar, contract or law. |
| Marketing information | Until consent is withdrawn, you object, or it is no longer needed; minimal suppression data may remain to respect opt-outs. |
Deleting live data may not immediately remove it from immutable or rotating backups. Copies expire through the normal cycle and are not routinely searched and edited individually, unless preservation or restoration is legally required.
10. Security and data breaches
We maintain appropriate technical and organisational measures, which may include encryption, access controls, multi-factor authentication, firewalls, malware monitoring, patching, restricted administrative access, backups and network monitoring. No online system can be guaranteed completely secure.
We have procedures for suspected personal-data breaches. Where legally required, we notify the Information Commissioner’s Office (“ICO”) and affected individuals. Not every security event meets the notification threshold.
11. Cookies
We use cookies and similar technologies for security, account sessions, preferences and, where enabled, measurement. Optional technologies are managed under PECR. Read our Cookie Policy or use Cookie Settings in the footer.
12. Your data protection rights
Depending on the circumstances, you may have rights to:
- access and receive a copy;
- correct incomplete or inaccurate information;
- request erasure or restriction;
- receive or transfer certain information in a portable format;
- object to legitimate-interest processing and object at any time to direct marketing;
- withdraw consent; and
- rights concerning solely automated decisions with legal or similarly significant effects.
Rights are not absolute. We may retain information for tax, accounting, fraud prevention, domain requirements, legal claims or another lawful reason.
13. Marketing
We may send existing customers email or, where used, SMS about relevant hosting, domain and related services when UK GDPR and PECR permit. We market to prospects only with the required permission or where another lawful route applies.
You may opt out of marketing communications at any time using the unsubscribe method in a message or emailing support@liquidwebspace.com. Opting out does not stop essential invoices, renewal notices, security alerts, service notifications or support communications. Necessary service notices do not depend on marketing consent.
14. How to exercise your rights
Email our Privacy Contact at support@liquidwebspace.com. You may request a copy of information we hold about you. We may ask for proportionate identity verification before disclosure.
We do not charge a routine fee for an ordinary request. We normally respond to a valid request within one month, subject to legally permitted extensions and exemptions.
15. Automated decision-making
Automated tools may flag orders, payments, logins or activity for fraud, security or abuse and lead to delay, rejection or manual investigation. We do not currently use solely automated decisions producing legal or similarly significant effects without human involvement. Contact us if you believe an automated process materially affected you.
16. Children
LiquidWebSpace services are not directed at children. Customers must be legally capable of entering the relevant contract, and we do not intentionally collect children’s information where it is unnecessary for an authorised service.
17. Third-party links
Our websites may link to independently operated sites with their own privacy practices. We are not responsible for an independent site’s privacy notice merely because we link to it.
18. Complaints
Contact our Privacy Contact at support@liquidwebspace.com if you believe information has been mishandled. You may also complain directly to the Information Commissioner’s Office; you do not have to complain to us first.
19. Changes to this Privacy Policy
We review this notice periodically and when processing changes. We post revisions here and update the review date. Where required, we will appropriately bring a material new use of existing information to affected people’s attention before processing begins.
20. Contact us
Privacy Contact
Liquid Webspace Ltd
44 Puttock Way
Billingshurst
West Sussex
RH14 9ZJ
Email: support@liquidwebspace.com
