Privacy Policy

Privacy and Personal Data Protection Policy

Last Updated: 18 August 2026

The security of your data is of great importance to us. We therefore seek to protect and process the personal data you provide to us in accordance with applicable data protection and privacy laws.

This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected by GREENLEAFWEB LTD, a company registered in England and Wales under company number 17322783, operating under the name GreenLeafWeb.Net (“GreenLeafWeb”, “we”, “us” or “our”). It applies to the GreenLeafWeb.Net website, hosting services, customer panel and other services provided by us.

When processing personal data, we comply, where applicable, with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable UK legislation relating to electronic communications, direct marketing and cookies.

1. Data Controller

The controller responsible for your personal data is:

In this Privacy Policy, “GreenLeafWeb” refers to GREENLEAFWEB LTD and, where applicable, the services provided under the GreenLeafWeb.Net brand.

2. Personal Data We Collect

Depending on the services you use and how you interact with GreenLeafWeb, we may collect the following categories of personal data:

  • Name, surname and account information
  • Email address, telephone number and other contact information
  • Billing and payment-related information
  • IP addresses, device information and technical connection logs
  • Browser type and version, operating system and related technical information
  • Website usage, browsing and transaction information
  • Information collected through cookies and similar technologies
  • Support requests, messages and other communications you send to us
  • Information provided when applying for or entering into a business relationship with us
  • Technical and security information required to detect fraud, abuse, attacks and other security incidents

3. How We Collect Personal Data

We may collect your personal data through the following methods:

  • Forms and customer accounts on our website
  • Purchases, subscriptions, hosting services and other service transactions
  • Customer support requests and email communications
  • Cookies and similar technologies
  • Service providers and business partners
  • Security and fraud-prevention systems
  • Publicly available sources, where appropriate

4. Why We Process Your Personal Data

We may process your personal data for the following purposes:

  • To provide the products and services you request
  • To provide and manage hosting, domain, web and related services
  • To create and manage customer accounts
  • To process orders, payments and invoices
  • To provide customer support and respond to your requests
  • To enter into and perform contracts with you
  • To maintain the security, performance and availability of our services
  • To detect and prevent fraud, abuse, attacks and other security threats
  • To improve our products and services and investigate technical issues
  • To comply with legal, regulatory, accounting and tax obligations
  • To respond to lawful requests from competent authorities
  • To send important service, account and security notifications
  • To send marketing communications where permitted by applicable law
  • To protect our rights, manage legal disputes and enforce our contracts

5. Lawful Bases for Processing Personal Data

We process personal data only where a valid lawful basis exists. Depending on the nature of the processing, we may rely on one or more of the following lawful bases:

Performance of a contract: To process orders, provide hosting services, manage customer accounts and perform our contractual obligations.

Legal obligation: To comply with tax, accounting, corporate record-keeping, security and other applicable legal requirements.

Legitimate interests: To operate and improve our services, maintain network and information security, prevent fraud and abuse, and protect our legal and commercial interests.

Consent: Where applicable law requires consent, including certain optional marketing or cookie activities, we may request your consent in advance. You may withdraw your consent at any time.

6. Bank and Credit Card Security

For payment transactions, bank or credit card information may be processed by authorised payment providers and financial institutions. Depending on the payment infrastructure used, certain payment information may be securely stored by the relevant payment provider.

GreenLeafWeb does not intend to store complete bank or credit card information in plain text within its own databases. Third-party payment providers may apply their own security, privacy and data-processing policies to the information they process.

7. Disclosure of Personal Data

Where necessary to operate our services and comply with our legal obligations, your personal data may be disclosed to the following categories of recipients:

  • Hosting, server, infrastructure and technology providers
  • Payment processors and financial service providers
  • Email, communications and customer support providers
  • Analytics, security and fraud-prevention providers
  • Cloud storage and other technical service providers
  • Professional advisers, accountants and lawyers
  • Relevant parties involved in a merger, restructuring, sale or similar corporate transaction
  • Courts, law enforcement authorities, regulators and other competent public authorities

We do not intend to sell your personal data to third parties. Personal data is generally disclosed only where necessary to provide our services, comply with legal obligations or for another lawful purpose.

8. International Data Transfers and Server Infrastructure

GreenLeafWeb may use service providers and technical infrastructure located outside the United Kingdom.

Depending on our service infrastructure, your personal data may be stored on servers located in Germany (EEA) or processed through infrastructure operated by service providers located in other countries.

Where a transfer outside the United Kingdom constitutes a restricted transfer under applicable data protection law, we seek to use an adequacy decision, appropriate safeguards or another lawful transfer mechanism permitted by applicable legislation.

9. Data Retention

Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and in accordance with applicable legal requirements.

Retention periods vary depending on the type of data, the purpose of processing, whether our relationship with you remains active, legal and accounting obligations, potential disputes and security requirements.

  • Technical security, IP and device logs may be retained for security and operational purposes and are generally intended to be retained for a maximum period of one year.
  • Transaction, payment, invoice and accounting records may be retained for up to six years or longer where required by applicable legal or tax obligations.

Once personal data is no longer required, it will be securely deleted, anonymised or otherwise processed so that it is no longer identifiable as personal data, where appropriate.

10. Cookies and Similar Technologies

GreenLeafWeb may use cookies and similar technologies to operate the website, maintain security, manage sessions, measure performance and improve the user experience.

Some cookies may be strictly necessary for the operation of our services. Where applicable law requires consent for non-essential analytics, advertising or similar cookies, we will request consent before using them.

You may block or delete cookies through your browser settings. However, disabling certain cookies may cause some features of the website to function incorrectly.

Cloudflare: We may use security and infrastructure providers such as Cloudflare to protect our services against DDoS attacks, malicious traffic and other security threats. The privacy and data-processing policies of those providers may also apply.

11. Email, Notifications and Marketing Communications

We may send operational communications directly related to your services, including security alerts, account notifications, billing information and other communications necessary to provide our services.

For marketing emails, SMS messages or similar electronic marketing communications, we will comply with applicable data protection and electronic communications laws and obtain consent where required.

If you no longer wish to receive marketing communications, you may unsubscribe using the relevant link included in our emails or change your communication preferences through your customer panel, where available.

12. Data Security

We seek to implement appropriate technical and organisational security measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.

These measures may include access controls, encryption, security monitoring, logging, secure infrastructure and other appropriate technical or physical safeguards.

However, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure.

13. Children's Privacy

GreenLeafWeb services are not specifically directed at children. We do not knowingly seek to collect personal data from children under the age of 13.

If we become aware that a child has provided us with personal data, we will take reasonable steps to delete such information where appropriate and where required by applicable law.

14. Your Rights Under the UK GDPR

Under the UK GDPR, subject to applicable conditions and exemptions, you may have the following rights:

  • The right to be informed about how your personal data is processed
  • The right to request access to your personal data and obtain a copy
  • The right to request correction of inaccurate or incomplete data
  • The right to request deletion of your personal data in certain circumstances
  • The right to request restriction of processing in certain circumstances
  • The right to receive your personal data in a portable format and, where applicable, request its transfer to another service provider
  • The right to object to certain processing based on legitimate interests
  • The right to object to direct marketing
  • The right to withdraw consent at any time where processing is based on consent
  • Rights relating to certain decisions based solely on automated processing where legally applicable

15. Contact Us

For questions, requests or concerns relating to your personal data or this Privacy Policy, you can contact us through the following channels:

We will handle applicable data protection requests within the time periods required by relevant law.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, technologies, processing activities or applicable legal requirements.

Any updated version will be published on this page together with a revised "Last Updated" date.