POWER SERVERS / Legal
GDPR Compliance
Last updated: 5 September 2026
1. What this document explains
The General Data Protection Regulation (GDPR) governs the use of personal data. The UK GDPR applies within its territorial scope; the EU GDPR may also apply depending on an organisation's activities and the people concerned. This document explains the main data-protection responsibilities relevant to POWER SERVERS hosting, domain and DNS services. It is an overview, not a certification, independent audit report or substitute for a signed data-processing agreement.
Our Privacy Policy explains the information covered by our website and service administration. For questions, contact POWER SERVERS.
2. Personal data and processing
Personal data is information about an identified or identifiable person. Examples include names, contact details, account records and IP addresses where they identify or relate to an individual. Processing includes collecting, storing, accessing, disclosing and deleting that information. Encryption and pseudonymisation can reduce risk but do not automatically make personal data anonymous.
3. Controller and processor roles
A controller decides why and how personal data is processed. A processor acts on a controller's behalf under documented instructions. POWER SERVERS' role depends on the activity: customer administration and billing are distinct from storing personal data that a customer chooses to host. Where we process hosted data on a customer's behalf, appropriate processor terms are required. A customer may itself be a controller or a processor for another organisation.
Using a hosting provider does not transfer all compliance responsibilities to that provider. Customers remain responsible for their purposes, lawful bases, notices, instructions and configuration within their control. The supplier's full legal identity and relevant processing roles must be identified in the service documentation.
4. Core principles
The main principles require processing to be lawful, fair and transparent; limited to specified purposes; limited to the data needed; accurate; kept no longer than necessary; and protected against unauthorised access, loss and damage. Accountability means being able to demonstrate compliance through suitable decisions, records and controls.
In practice, this means defining the purpose before collecting data, limiting access, keeping retention rules, correcting errors and building privacy into service design and default settings.
5. Lawful bases and consent
Each processing activity needs an appropriate legal basis. Relevant bases can include a contract with the individual, a legal obligation, a properly assessed legitimate interest or valid consent. Consent must be freely given, specific, informed and capable of withdrawal. It is not a universal substitute for every other basis. Special-category information and criminal-offence data require additional legal conditions and safeguards.
Google tags load on every visit using advanced consent mode. Analytics storage defaults to denied until consent is given; cookieless measurement requests may still be sent. Visitors can change their choice through Cookie settings. See our Cookie Policy for the current implementation.
6. Data-processing agreements and suppliers
Where a controller appoints a processor, the agreement must address the subject, duration, purpose and nature of processing, data types, people concerned, and each party's responsibilities. Required terms include documented instructions, confidentiality, security, subprocessors, assistance with rights and incidents, return or deletion of data, and information needed to demonstrate compliance.
Request the relevant data-processing terms before placing personal data into a service that requires them. Any subprocessors must be engaged under the applicable authorisation and contractual requirements. This page does not itself identify or authorise a particular subprocessor or replace an Article 28 agreement.
7. Security and incident handling
Technical and organisational measures must be proportionate to risk. Relevant measures can include access control, secure administration, patching, encryption where appropriate, recovery arrangements and testing. The agreed service scope determines which configuration, software maintenance and backup tasks belong to the customer.
A processor must notify the controller without undue delay after becoming aware of a personal-data breach. A controller must assess whether notification to the supervisory authority is required and, where required, notify without undue delay and where feasible within 72 hours of awareness. Affected individuals must be informed without undue delay where the applicable high-risk threshold is met, subject to lawful exceptions. Not every service outage is a personal-data breach.
Report a suspected incident to POWER SERVERS with the affected service, timestamps and a concise description. Do not include passwords or unnecessary personal data.
8. Individual rights
Depending on the legal basis and circumstances, people may have rights to information, access, correction, erasure, restriction, portability and objection, and safeguards concerning qualifying automated decisions. These rights have conditions and exceptions. Requests must be handled within the applicable legal timeframe; under the UK GDPR this is normally one month, with permitted extensions where justified.
Send requests about our own processing to our contact email. For data on a customer's server or website, contact that customer as the relevant controller; a hosting processor assists within its instructions and legal responsibilities. Individuals may complain to the UK ICO or another competent data-protection authority.
9. Retention and international transfers
Define retention by purpose and applicable obligations; an active hosting account is not a reason to retain every record indefinitely. Service termination, backup deletion and legal preservation need to be addressed in the relevant agreement.
Restricted international transfers require a valid transfer mechanism, such as an applicable adequacy decision or suitable contractual safeguards, together with any required assessment. A UK contact address does not imply that every supplier or server is in the UK. Request the locations and transfer terms relevant to your intended service.
10. Customer preparation and further information
Before hosting personal data, establish the parties' roles, document a lawful basis, provide notices, agree processing terms, check locations and subprocessors, and allocate security and deletion responsibilities. High-risk processing may require a data protection impact assessment. A data protection officer or representative must be appointed where the applicable legal criteria require one; this page does not claim that such an appointment or certification exists.
For official guidance, see the ICO's data-protection principles and controller and processor guidance. Contact us to discuss the service documentation relevant to your requirements.