Privacy Policy
What the service collects, why it is used and how to exercise your rights.
Download Word documentExact version and publication record1. Controller and contact
The confirmed data controller name and service address are shown in Operator & policy status on ddns.hosti.me/policies. Until those details and this notice have been reviewed, this is a draft and new public registration remains closed. Contact technology@kai-young.co.uk about personal information, complaints or rights requests.
2. Information processed
The portal stores your email, password hash, service level, account state, accepted policy version/date, hostname allocations, origin/DNS IPs and hashed update tokens. It stores private support subjects/messages, moderation targets/reasons and audit events. Engineers can access customer information needed to operate and support the service.
Requests expose their source IP to IIS. Rate-limit records contain source IP or account/hostname identifiers for a short expiry window. IIS access/error logs, SQLite/private diagnostic logs and backups may also contain operational metadata. Diagnostic logs do not intentionally record form values, passwords, API keys or request bodies. Configure IIS to avoid Authorization or token-bearing query-string logging.
DNS hostnames and published IP records are public by design. External DDNS traffic does not pass through our web proxy. Where an internal proxy is agreed, the Hosti edge processes web requests and responses, including network metadata and content in transit; any additional hosting data handling must be addressed in that service agreement.
3. Purposes and proposed lawful bases
Account operation, hostname updates and requested support are processed to provide the service contract. Security, rate limiting, proportionate abuse investigation and audit are proposed legitimate interests, subject to an assessment of necessity, proportionality and your rights. Legal compliance or a valid disclosure requirement may rely on a legal obligation.
Support and upgrade enquiries are used to respond to you and agree requested services. We do not use portal messages as permission to send unrelated marketing. Do not include passwords, unnecessary sensitive information or illegal imagery in support messages. Lawful bases and any additional requirements must be reviewed before launch, particularly if processing criminal-offence allegations or special-category data.
4. Sharing and processors
Authorised Hosti engineers, hosting/infrastructure providers and the configured authoritative DNS provider may process information needed for the service. The included adapter uses Cloudflare for DNS record management, with its proxy disabled for these records. Email sent to the contact address is handled by the operator’s configured email provider.
We may disclose necessary information in response to a valid legal requirement, to protect rights or safety where legally justified, or with your authorisation. We do not promise that every report results in a law-enforcement referral.
The operator must document current providers, locations, processor terms and any international transfer safeguards before registration opens. Do not assume all data remains in the UK merely because the IIS server is in the UK. The operator details and provider schedule must remain current.
5. Retention and security
Accounts and hostname configuration are kept while the service is active, then reviewed on closure and retained only where necessary for unresolved disputes, security or a legal obligation. Active bans are reviewed while needed to enforce a restriction. Do not retain unnecessary personal allegations indefinitely.
The supplied maintenance defaults delete audit events after 90 days, closed support conversations after 365 days without further activity, and revoked bans after 180 days. Expired rate-limit entries are removed. Open support conversations remain while unresolved. These periods are proposed defaults and must match the configured maintenance schedule.
IIS/proxy logs, email and backups require a separately documented operator retention schedule; application cleanup cannot delete those copies. Restrict storage to authorised identities, use HTTPS, keep dependencies patched, and protect backups. Passwords are hashed and only hashes of hostname tokens persist in the server database. Windows client settings use user-scoped DPAPI; Linux/macOS settings use restrictive file permissions.
6. Cookies, rights and complaints
The portal uses a session cookie for sign-in and CSRF protection. A theme choice may be stored locally in your browser. No advertising or analytics trackers are included in this package. Public pages can be read without an account; clear browser storage to remove a stored theme choice.
Depending on the circumstances, you may have rights of access, correction, erasure, restriction, objection and portability. Contact the technology inbox from your account email where possible; we may verify identity proportionately. We respond within applicable statutory time limits and explain any lawful refusal or extension. No optional consent is used to override required service processing.
You may complain to the UK Information Commissioner at ico.org.uk or your relevant supervisory authority. Account closure does not necessarily require immediate deletion of information needed for a valid legal or security reason. This service is intended for adults, and registration is restricted to people aged 18 or older.