Privacy Policy

The Policies and Terms listed on this page apply to your purchase and use of any services ElySpace makes available to you. To review any of our Policy/Terms please click on the corresponding name in the left-hand side menu.

Last updated: 18 September 2026

ElySpace IT Services LLP. ("ElySpace") has created this privacy statement in order to demonstrate our commitment to privacy to our customers and users of our consulting services, online services, websites, and web services ("Services"). This privacy policy governs the manner in which ElySpace uses, maintains and discloses information collected from its customers and users of our Services.

Which data protection laws apply to us

ElySpace IT Services LLP is an Indian limited liability partnership, LLP registration number AAV-5130, with its registered office at Watergam, Baramulla, Jammu and Kashmir, 193303, India. We are the controller (the Data Fiduciary, in Indian terms) of the personal data described in this policy, and we are the agency that collects and retains it.

We sell to customers in the United States, Canada, the United Kingdom, the European Union and India, we price in US Dollars, Euro and Indian Rupees, and we run servers in several countries. More than one privacy law therefore applies to us at once: the EU GDPR, the UK GDPR and the Data Protection Act 2018, India’s Digital Personal Data Protection Act 2023, and US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act.

This policy is written to cover all of them. Where a right or a rule applies only in one place, we say so. Nothing in our Service Agreement, Domain Agreement or Affiliate Terms (including the clauses that choose the law of Delaware or of Washington State) limits your rights under these laws or your right to complain where you live. Our Data Protection page gives an overview of the same ground.

Who to contact about your personal data

Write to us at [email protected], open a ticket at my.elyspace.com/submitticket.php, or write to ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India.

ElySpace has not designated a Data Protection Officer and does not use that title. The person able to answer questions about our processing is Jahangir Ahmad War, Chief Operating Officer, who can be reached at [email protected]

If you are in the EU or the UK. Contact us directly at [email protected] about anything to do with your personal data.

Grievance Officer

If you have a complaint about how we have handled your personal data, or about anything else, you can bring it to our Grievance Officer.

  • Name: Jahangir Ahmad War
  • Designation: Chief Operating Officer
  • Address: The Grievance Officer, ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India
  • Email: [email protected]
  • Telephone: +91 91038 53627
  • Hours: Monday to Saturday, 10:00 to 18:00 IST, excluding public holidays

You can also open a ticket at my.elyspace.com/submitticket.php and mark it for the Grievance Officer.

We acknowledge every complaint within 24 hours and give you a ticket number, and we resolve it within 15 days of receiving it. The full procedure, including what to include in a complaint and what you can do if you are not satisfied with our answer, is set out under Grievance Redressal in our Terms of Service.

The same person is the contact for questions about how we process your personal data. If your complaint is about your personal data and our answer does not resolve it, you may complain to the Data Protection Board of India. See India: your rights under the Digital Personal Data Protection Act 2023 below.

Privacy

ElySpace is committed to developing long-lasting relationships based on trust. As such, ElySpace will do everything in its power to ensure that your right to privacy is maintained and protected. You must be 18 or older to open an account with us, and our Services are not directed at children. See Children and age limits below.

Information We Collect

ElySpace IT Services LLP cares about your privacy. For this reason, we collect and use personal data only as it might be needed for us to deliver to you our world-class products, services and websites (collectively, our"Services"). Your personal data includes information such as:

  • Name
  • Address
  • Telephone number
  • Email address
  • Other data collected that could directly or indirectly identify you.

Our Privacy Policy is intended to describe to you how and what data we collect, and how and why we use your personal data. It also describes options we provide for you to access, update or otherwise take control of your personal data that we process.

If at any time you have questions about our practices or about any of the rights described in this policy, use the routes under Who to contact about your personal data above.

We collect information so that we can provide the best possible experience when you utilize our Services. Much of what you likely consider personal data is collected directly from you when you:

  • create an account or purchase any of our Services (eg: billing information, including name, address, payment details);
  • request assistance from our customer support team (eg: phone number, case notes);
  • complete contact forms or request newsletters or other information from us (eg: email); or
  • participate in contests and surveys, apply for a job, or otherwise participate in activities we promote that might require information about you.

However, we also collect additional information when delivering our Services to you to ensure necessary and optimal performance. These methods of collection may not be as obvious to you, so we wanted to highlight and explain below a bit more about what these might be (as they vary from time to time) and how they work:

Account related information is collected in association with your use of our Services, such as account number, purchases, when products renew or expire, information requests, support requests, and notes or details explaining what you asked for and how we responded.

Cookies and similar technologies on our websites collect information about how you use and interact with our Services, and about the device you use. What each one is, who sets it, what it does, how long it lasts and whether it needs your consent is set out in our Cookie Policy, and the summary is under Cookies, tracking and your choices below.

Data about Usage of Services is automatically collected when you use and interact with our Services, including metadata, log files, cookie/device IDs and location information. This information includes specific data about your interactions with the features, content and links (including those of third-parties, such as social media plugins) contained within the Services, IP address, browser type and settings, the date and time the Services were used, information about browser configuration and plugins, language preferences and cookie data, information about devices accessing the Services, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and error data, and some of this data collected might be capable of and be used to approximate your location.

Data from other sources. If you provide us with personal information about other people, or if other people give us your information, we will only use that information for the specific reason for which it was provided to us. Where information about you reaches us this way, we will tell you where it came from if you ask, and we will not send you marketing on the strength of it unless you have separately told us that you want to hear from us.

How we use this Information

We strongly believe in both minimising the data we collect and limiting its use and purpose to only that (1) for which we have been given permission, (2) as necessary to deliver the Services you purchase or interact with, or (3) as we might be required or permitted for legal compliance or other lawful purposes. These uses include: Delivering, improving, updating and enhancing the Services we provide to you. We collect various information relating to your purchase, use and/or interactions with our Services. We utilize this information to:

  • Improve and optimize the operation and performance of our Services (again, including our websites and mobile applications)
  • Diagnose problems with and identify any security risks, errors, or needed enhancements to the Services
  • Detect and prevent fraud and abuse of our Services and systems
  • Collecting aggregate statistics about the use of the Services
  • Understand and analyze how you use our Services and what products and services are most relevant to you

Often, much of the data collected is aggregated or statistical data about how individuals use our Services, and is not linked to any personal data, but to the extent it is itself personal data or is linked or linkable to personal data, we treat it accordingly.

Sharing with trusted third parties. We may share your personal data with third parties with which we have partnered to allow you to integrate their services into our own Services, and with trusted third party service providers as necessary for them to perform services on our behalf, such as:

  • Processing credit card payments
  • Serving advertisements
  • Conducting contests or surveys
  • Performing analysis of our Services and customers demographics
  • Communicating with you, such as by way of email or survey delivery
  • Customer relationship management

We only share your personal data as necessary for any third party to provide the services as requested or as needed on our behalf. These third parties (and any subcontractors) are subject to strict data processing terms and conditions and are prohibited from utilizing, sharing or retaining your personal data for any purpose other than as they have been specifically contracted for (or without your consent).

Communicating with you. We may contact you directly or through a third party service provider regarding products or services you have signed up to or purchased from us, such as necessary to deliver transactional or service-related communications. We may also contact you with offers for additional services we think you’ll find valuable. Where you are in India, we send you those offers only if you have given us your consent, and you can withdraw that consent at any time. See India: your rights under the Digital Personal Data Protection Act 2023. Where you are in the European Union or the United Kingdom, we send them on the basis set out under Why we use your personal data, and our legal basis. You don’t need to provide consent as a condition to purchase our goods or services. These contacts may include:

  • Email
  • Text (SMS) messages
  • Telephone calls
  • Automated phone calls or text messages

You may also update your subscription preferences with respect to receiving communications from us and/or our partners in your client area at my.elyspace.com, or by opening a ticket at my.elyspace.com/submitticket.php.

If we collect information from you in connection with a co-branded offer, it will be clear at the point of collection who is collecting the information and whose privacy policy applies. In addition, it will describe any choice options you have in regards to the use and/or sharing of your personal data with a co-branded partner, as well as how to exercise those options.

If you make use of a service that allows you to import contacts (eg. using email marketing services to send emails on your behalf), we will only use the contacts and any other personal information for the requested service. If you believe that anyone has provided us with your personal information and you would like to request that it be removed from our database, please open a ticket at my.elyspace.com/submitticket.php and we will remove it.

Transfer of personal data abroad. Your personal data will be sent to and stored in countries other than your own. How that is done and what protects it is set out under Sending your personal data to other countries below.

Compliance with legal, regulatory and law enforcement requests. We cooperate with government and law enforcement officials to enforce and comply with the law. We will disclose information about you to government or law enforcement officials where we are required to by a law that applies to us, or where it is necessary to respond to legal process such as a subpoena or a court order, to establish, exercise or defend a legal claim, or to protect the safety of the public or of any person.

To the extent we are legally permitted to do so, we will take reasonable steps to notify you in the event that we are required to provide your personal information to third parties as part of legal process. We will also share your information to the extent necessary to comply with ICANN or any ccTLD rules, regulations and policies when you register a domain name with us.

Website analytics and advertising. We use Google Tag Manager, Google Analytics, the Meta Pixel and Cloudflare Insights on our website. What each of them does, what it collects, who receives it and how to give, change or withdraw your consent is set out in our Cookie Policy and summarised under Cookies, tracking and your choices below.

Third-party websites. Our website and our mobile applications contain links to third-party websites. We are not responsible for the privacy practices or the content of third-party sites. Please read the privacy policy of any website you visit.

We have to have a lawful reason for everything we do with your personal data, and we have to tell you what it is. Here is the list, purpose by purpose. Where we name a GDPR article, the equivalent provision of the UK GDPR applies in the United Kingdom.

  • Creating and running your account, and providing hosting, domains, email and related services. Data used: name, address, email, telephone, account records, service records. Legal basis: performance of our contract with you (Article 6(1)(b)).
  • Taking payment and chasing unpaid invoices. Data used: billing details, the payment method on file, invoice and payment history. Legal basis: performance of our contract (Article 6(1)(b)); and our legitimate interest in recovering money owed to us (Article 6(1)(f)).
  • Keeping accounting and tax records. Data used: invoices and payment records. Legal basis: compliance with a legal obligation (Article 6(1)(c)), under Indian tax, GST and LLP law.
  • Answering support tickets, live chat and enquiries. Data used: your contact details, the contents of your ticket or chat, notes on your account. Legal basis: performance of our contract (Article 6(1)(b)); or, where you are not yet a customer, our legitimate interest in answering people who contact us (Article 6(1)(f)).
  • Keeping our network and our customers’ sites secure, and detecting and stopping abuse, spam and attacks. Data used: server, access and security logs, IP addresses, traffic data. Legal basis: our legitimate interest, and our customers’, in the security of the service (Article 6(1)(f)).
  • Screening orders for fraud. Data used: order data, payment data, IP address, device data. Legal basis: our legitimate interest in preventing fraud and payment abuse (Article 6(1)(f)). See Automated checks on orders below.
  • Registering and administering domain names, including publishing or disclosing what ICANN or a registry requires. Data used: registrant, administrative, technical and billing contact details. Legal basis: performance of our contract (Article 6(1)(b)); and our legitimate interest in complying with the ICANN and registry rules that bind us (Article 6(1)(f)).
  • Meeting obligations that apply to us as a hosting and server provider in India Keeping logs and subscriber records, responding to lawful orders, and reporting security incidents. Legal basis: compliance with a legal obligation (Article 6(1)(c)).
  • Analytics, advertising and measurement cookies and pixels. Data used: browsing behaviour, device and browser data, IP address. Legal basis: your consent (Article 6(1)(a)), and consent under the ePrivacy rules for storing or reading anything on your device.
  • Marketing emails and messages. Data used: name, email, telephone, marketing preferences. Legal basis: your consent (Article 6(1)(a)); or, if you are already a customer and the message is about similar services, our legitimate interest (Article 6(1)(f)), which you can stop at any time. For people in India, marketing is on consent only.
  • Running the affiliate programme and paying commission. Data used: affiliate account, referral records, payout details. Legal basis: performance of our contract with the affiliate (Article 6(1)(b)).
  • Responding to legal requests and defending claims. Data used: whatever is relevant to the request. Legal basis: compliance with a legal obligation (Article 6(1)(c)); or our legitimate interest in establishing, exercising or defending legal claims (Article 6(1)(f)).

Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and recorded that assessment. You can ask us for a summary of it, and you can object to that processing at any time. See Your rights over your personal data.

Do you have to give us your personal data? No, but we cannot open an account, take payment, register a domain name or give you support without the information marked as required when you sign up. If you do not give it to us, we cannot provide the service. Domain registries and ICANN require accurate registrant contact details; if you do not provide them, your domain registration can be suspended or cancelled.

Your rights over your personal data

If the GDPR or the UK GDPR applies to our processing of your data, you have the rights below. They are free to use and you do not have to give a reason for most of them.

  • Access Ask us to confirm whether we hold personal data about you and to give you a copy of it, with information about how we use it.
  • Rectification Ask us to correct data that is wrong, or complete data that is incomplete. You can also do most of this yourself in your client area at my.elyspace.com.
  • Erasure Ask us to delete data where we no longer need it, where you withdraw the consent we relied on, or where we have processed it unlawfully.
  • Restriction Ask us to keep your data but stop using it while a dispute about its accuracy or about our legal basis is resolved.
  • Portability Ask us for the personal data you gave us in a common machine-readable format, or ask us to send it to another provider where that is technically feasible. For hosting accounts you can do this yourself at any time with the backup and export tools in cPanel.
  • Objection Object to processing based on our legitimate interests. If you object to direct marketing we stop, immediately and always.
  • Withdraw consent Withdraw any consent you have given, at any time, as easily as you gave it. It does not affect what we did lawfully before you withdrew.

How to use them. Open a ticket at my.elyspace.com/submitticket.php (the quickest route, because you are already signed in), or email [email protected], or write to us at our registered address. Tell us which right you want to use and give us enough to find your records. If we cannot be sure who you are we will ask for proof of identity, and only for what we genuinely need. We will never ask you to post or email us a copy of a payment card.

How long we take. One month. If your request is complicated, or if you have made several, we may need up to two further months, and we will tell you inside the first month and explain why. There is no charge. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and if we refuse we will tell you why and how to complain.

When we cannot delete something. We have to keep billing, tax and accounting records for the periods Indian law sets. We have to keep some domain registration data for as long as ICANN and the registry require. Indian rules that apply to providers of servers, VPS and cloud services require us to keep certain validated subscriber records for a period after an account closes. The periods are in How long we keep your personal data. And we may need to keep data to defend a legal claim. If we cannot delete something, we will tell you which of these applies rather than simply refusing.

Automated checks on orders

When you place an order we run automated checks to detect fraud and payment abuse. They look at things like the payment method used, the billing address, the IP address and the device the order came from, and whether the order matches patterns we have seen in past fraudulent orders. If an order fails these checks we may decline it or hold it for review, and that decision can be made automatically.

If your order is declined by an automated check, you have the right to ask a member of our team to look at it, to explain your side of it, and to challenge the outcome. Open a ticket at my.elyspace.com/submitticket.php or email [email protected] and a person will review the decision.

India: your rights under the Digital Personal Data Protection Act 2023

This section applies to you if you are in India. It is our notice to you under section 5 of the Digital Personal Data Protection Act 2023, and it explains the rights that Act gives you and how to use them. The Act calls you a Data Principal and it calls us a Data Fiduciary, because we decide why and how your personal data is processed.

The rest of this Privacy Policy still applies to you. Where anything in this section says something different from another part of this policy, this section is the one that applies to people in India.

Who we are, for this purpose: ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India. The person who can answer questions about how we process your personal data is Jahangir Ahmad War, Chief Operating Officer, and you can reach them through the details under Grievance Officer above.

Where an obligation under the Digital Personal Data Protection Act 2023, or under the rules made under it, has not yet been brought into force, we follow the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 in its place, and we give you the rights set out in this section as a matter of policy in the meantime, so that nothing you can ask us for here waits on a commencement date.

What we collect and why

We process only the personal data we need, and only for the purposes listed below. Each item says what it is for, whether we rely on your consent or on a legitimate use permitted by the Act, and how long we keep it.

  • Account and billing details Your name, address, email address, telephone number, and your payment details. Used to open your account, provide the service you bought, bill you, issue a tax invoice and keep our books. You give us this voluntarily for that purpose, and we are also under legal obligations to keep some of it. Kept for the periods set out under How long we keep it below.
  • Support and correspondence Your tickets, emails, chat transcripts, call notes and the account details you give us when you ask for help. Used to answer you and to keep a record of what was asked and what we did. You give us this voluntarily for that purpose. Kept for as long as we need it to deal with your request and anything that follows from it, and then deleted. Conversations in the chat on our website are deleted automatically 12 months after they start.
  • Service and security records IP addresses, log-in times, system and server logs, and the records we keep to detect and stop fraud and abuse. Used to keep the service running, to keep it secure, and to meet the log-keeping duties Indian law places on a hosting provider. Kept as set out under How long we keep it below.
  • Subscriber records for VPS, cloud and server services Your validated name, address and contact numbers, the IP addresses we allot you, the dates of your service, the email address, IP address and timestamp you used when you signed up, the purpose for which you took the service, and the ownership pattern of the subscriber. We are required to record and keep this by directions issued by CERT-In under section 70B of the Information Technology Act 2000, and we cannot delete it early. Kept for at least five years after you leave.
  • Website usage and device data The pages you visit, how you got to us, your device, browser and settings, and the cookies and similar technologies described in our Cookie Policy. Used to run and improve the site and to measure how it is used. For visitors in India we rely on your consent for anything that is not strictly necessary to make the site work. The identifiers are stored in cookies for up to 13 months; our Cookie Policy gives the period for each. What Google and Meta keep after receiving it is governed by their own retention settings and policies.
  • Marketing preferences Whether you have asked to hear from us and by which channel. Used to send you offers and news. For people in India we rely on your consent for this, and on nothing else. Kept until you withdraw consent, and then only a record that you did.

We do not sell your personal data.

How long we keep it

We keep personal data only for as long as we need it for the purpose we collected it for, and then we delete it, unless a law requires us to keep it for longer. Where a law requires it, we keep it and we tell you why. The full schedule for all customers is under How long we keep your personal data. The Indian minimum periods are:

  • Registration information after you cancel: at least 180 days, as required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.
  • Content we remove under a court order or a government notification: 180 days, or longer if a court or an agency requires it.
  • System and server logs: for the period the CERT-In directions of 28 April 2022 require, currently at least 180 days on a rolling basis.
  • Subscriber records for VPS, cloud and server services: at least five years after the service ends, as required by the same directions.
  • Billing and tax records: for as long as Indian tax, GST and LLP law requires us to keep them.

This means that cancelling an account does not always delete everything about you straight away. Where we are required to keep a record, we keep it, we do not use it for anything else, and we delete it when the period ends.

Consent, and how to withdraw it

Where we rely on your consent, we ask for it clearly, for a specific purpose, before we process the data, and we do not bundle it with anything else. You do not have to consent to marketing in order to buy from us.

Withdrawing consent is as easy as giving it. You can withdraw at any time:

  • in your client area at my.elyspace.com, where you can change your contact preferences yourself;
  • by using the unsubscribe link in any marketing email;
  • by writing to our Grievance Officer at the address under Grievance Officer above.

When you withdraw, we stop the processing that depended on that consent within a reasonable time, and we ask anyone processing that data on our behalf to do the same. Withdrawing does not make anything we did before you withdrew unlawful.

Be aware of the consequence, because the Act requires us to tell you: if you withdraw consent for something the service actually needs, we may not be able to continue providing that service. Withdrawing consent for marketing or for analytics has no effect on your service at all.

You may also give, manage, review or withdraw your consent through a Consent Manager registered with the Data Protection Board of India. We will act on an instruction that reaches us that way in the same manner as one that comes from you directly.

We keep a record of the consents you give and withdraw. On our website, your choice and the date you made it are stored in a consent cookie on your device, and advertising and analytics tags do not load until that record says you agreed. Consent you give in your client account, such as agreeing to marketing emails, is recorded in your account.

Children and people who have a guardian

You must be 18 or older to open an account with us.

Separately from that, we do not knowingly process the personal data of anyone under 18 without the verifiable consent of a parent or lawful guardian, and we do not knowingly process the personal data of a person with a disability who has a lawful guardian without that guardian’s verifiable consent.

We do not carry out tracking or behavioural monitoring of children, and we do not direct advertising at children. The Act prohibits this outright, and consent (yours or a guardian’s) cannot make it permissible.

If you believe we hold a child’s personal data without the right consent, tell our Grievance Officer and we will look into it and delete it.

Your rights

As a Data Principal you have the following rights in relation to the personal data you have given us, or that we hold about you because of something you asked us to do.

  • The right to access information about your data. You can ask us for a summary of the personal data we process about you, of what we are doing with it, and of the other Data Fiduciaries and Data Processors we have shared it with and what we shared.
  • The right to correction, completion, updating and erasure. You can ask us to correct data that is wrong, complete data that is missing, bring data up to date, and erase data we no longer need, unless a law requires us to keep it, in which case we will tell you which law and for how long.
  • The right to withdraw consent, as described above.
  • The right to grievance redressal. You can complain to us about anything we have done or failed to do with your personal data, and we must answer you. Our Grievance Officer and the timeframes are under Grievance Officer above. The Act asks you to use this route before going to the Data Protection Board.
  • The right to nominate someone. You can nominate another individual to exercise these rights on your behalf if you die or become unable to act for yourself. Tell our Grievance Officer who you are nominating and how to reach them, and we will record it against your account. You can change or cancel a nomination at any time. Before we act on a nomination we will check the nominee’s identity and, where relevant, ask for proof of death or incapacity.

How to use your rights

  • Where to write: to our Grievance Officer, using any of the routes under Grievance Officer above. There is one route for all of these requests. You do not need to say which section of the Act you are relying on. Just tell us what you want.
  • Do it yourself: you can see and change much of your own information at any time in your client area at my.elyspace.com. That is usually faster than asking us.
  • What it costs: nothing.
  • Checking who you are: before we act, we need to be reasonably sure the request comes from you, so that we do not hand your data to somebody else. If you have an account with us, send the request from the client area at my.elyspace.com or from the email address the account is registered to, and that is normally all we need. If you have no account with us, or you no longer have the address you used, we will ask you for enough detail to match your request to the data we actually hold. We ask for the least that will do the job, we will not demand a document you have no reason to give us, and anything you send us purely to prove who you are is used for that and then deleted.
  • How long we take: within 15 days of receiving your request, the same period our Terms of Service set for grievances.
  • If we say no: we will tell you, in writing, what we are refusing and why. The commonest reason is that a law requires us to keep the data. The CERT-In five-year subscriber record and the tax records are the usual examples. If you disagree, use the escalation routes in the Terms of Service.

Your duties under the Act

The Act also places some duties on you, and we set them out here so that you know about them rather than to discourage you from complaining. You must not impersonate another person when giving personal data; you must not suppress material information when giving personal data where the law requires it; you must not register a false or frivolous grievance or complaint; and the information you give us when asking for correction or erasure must be authentic. The Act provides for a penalty of up to INR 10,000 for breaching these duties.

Complaining to the Data Protection Board of India

If you are not satisfied with how we have answered a complaint about your personal data, you may complain to the Data Protection Board of India. The Act asks you to raise the matter with us first and give us the chance to resolve it, so please use our Grievance Officer before you go to the Board.

A complaint to the Board is made in the manner, and to the address, that the Board itself publishes. Ask our Grievance Officer and we will give you the Board's current details as they stand on the day you ask. We will not ask you to withdraw a complaint, and we will not treat you any differently for having made one.

This is in addition to, and not instead of, your other rights. If you are a consumer you may also complain to a consumer commission, including the one where you live or work.

Where your data is processed

We and the providers we use process personal data both inside and outside India. Section 16 of the Act permits this, except to a country or territory that the Central Government restricts by notification, and we will comply with any such notification if one is made. Where other Indian law imposes a stricter requirement, for example on where payment data may be stored, we follow that stricter requirement.

The language of this notice

You can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India. Ask our Grievance Officer and we will provide it.

Sending your personal data to other countries

We are based in India and we run servers in several countries, so your personal data will be sent to and stored in countries other than your own. If you call us or start a chat, you may be helped from one of our locations outside your country.

Some countries have been formally recognised by the European Commission or by the UK government as giving personal data protection essentially equivalent to that in the EEA or the UK. Canada is one, for commercial organisations. Transfers to US companies are covered where the recipient is certified under the EU–US Data Privacy Framework, or its UK Extension for UK data.

India and Singapore have not been recognised in this way. Where the law of your country requires a safeguard for a transfer, we are responsible for providing one that the law recognises. Google, Meta and Cloudflare, whose services we use, build the European Commission’s Standard Contractual Clauses into their business terms or are certified under the EU–US Data Privacy Framework. You can ask us about the safeguard that applies to your data at [email protected].

Under section 16 of India’s DPDP Act 2023, personal data may be transferred outside India except to a country the Central Government restricts by notification; we will comply with any such notification. Payment data is handled in line with the Reserve Bank of India’s requirements.

How long we keep your personal data

We keep personal data only as long as we need it, and then we delete it or anonymise it. Some periods are set by laws that apply to us and we cannot go below them; where that is the case we say which law.

  • Account and contact details For as long as your account is open, then for as long as we need them to deal with questions, disputes or legal claims about the account.
  • Validated subscriber records for VPS, cloud and server customers Your validated name, address and contact numbers, the IP addresses we allotted you, the dates of your service, and the email address, IP address and timestamp used when you signed up. Indian rules that apply to data centres and to providers of VPS and cloud services require us to keep these for at least five years after your service ends. We must keep them even if you ask us to delete your account, and we cannot delete them earlier.
  • User registration information after cancellation Retained for at least 180 days, as the Indian intermediary rules require.
  • Invoices, payments and tax records For as long as Indian tax, GST and LLP law requires us to keep them.
  • Support tickets, chat transcripts and correspondence For as long as we need them to deal with your request and anything that follows from it. Conversations in the chat on our website are deleted automatically 12 months after they start.
  • Server, access and security logs Kept for the period Indian rules require, currently at least 180 days on a rolling basis.
  • Backups of your hosting account For the backup retention period of your plan, as stated on its product page (7 days on most hosting plans). Data from a closed account can remain in those backups until they are overwritten at the end of that period.
  • Domain registration records For the registration term, plus whatever ICANN and the relevant registry require of us afterwards.
  • Marketing preferences and suppression lists Until you ask us to stop, and then for as long as we need the minimum record to make sure we do not contact you again by mistake.
  • Records relating to a legal claim, investigation or takedown Until the matter ends, plus the time within which a related claim could still be brought. Content removed on a lawful order is retained for 180 days for investigation purposes, or longer if a court or agency requires it.
  • Everything else Erased once the purpose it was collected for has been served, or once you withdraw your consent, unless a law requires us to keep it.

Where we cannot delete something immediately (for example because it sits in an encrypted backup that rotates on a schedule), we isolate it from active use and delete it when that backup is next overwritten.

Our Cancellations section warns that your files and emails may be removed immediately and permanently once a cancellation request is processed. That is true of your content. It is not true of the billing records and validated subscriber records listed above, which we are required to keep. We would rather you knew that than found it out later.

Where a period above is set by law, we apply that period and we do not shorten it; where it is not, we keep the record only while the purpose it was collected for still needs it, and we go through these categories at least once a year to check that nothing is being kept out of habit. If you want to know what we still hold about you, and for how long, ask us at [email protected] and we will tell you.

If there is a personal data breach

If there is a security incident that affects personal data, we investigate immediately and contain it.

Where we are the controller and the law requires it, we report the incident to the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and if we report later than that, we say why. Where an incident is likely to put your rights or freedoms at high risk, we tell you directly and without undue delay, in plain language: what happened, what data was involved, the likely consequences, what we are doing about it, what we suggest you do, and who to contact for more.

Where the affected data is data you host with us, we are your processor and you are the controller. In that case we notify you without undue delay, with what we know about the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures we have taken or propose to take, and we keep you updated, and give you reasonable assistance, so that you can meet your own obligations.

In India we intimate affected individuals and the Data Protection Board without delay, and we report reportable cyber security incidents to CERT-In within the time its directions require. Where a US state breach notification law applies, we notify under that law as well.

We keep a record of every personal data breach we become aware of, including the ones we decide do not need to be reported, and why.

Our Grievance Officer, Jahangir Ahmad War, Chief Operating Officer, decides whether an incident has to be reported, and he, or somebody he names, makes the report to CERT-In, to the Data Protection Board of India and to the people affected. Because the CERT-In deadline is counted in hours rather than in working days, this route does not wait for office hours: whoever finds an incident escalates it to him straight away, on any day and at any hour, and if he cannot be reached the report is made without him rather than made late.

Disclosure of Information

ElySpace may also disclose aggregate, anonymous, data based on information collected from Users to investors and potential partners. In such cases, statistical information only will be disclosed and personally identifiable data will be kept strictly confidential. In case ElySpace is sold, the information collected from users may be transferred to the new owners.

ElySpace may from time to time engage third parties, including its own subsidiaries and affiliated companies, to preserve, analyze or otherwise store or manipulate data received by ElySpace from its customers. In all such cases, such third party service providers will be required to treat all such data with the same degree of care as ElySpace and they will be prohibited from disclosing such data to any other person or party, except as otherwise provided for in this Privacy Policy.

Special Offers and Updates

Our customers and users will occasionally receive information on products, services, special deals, and possibly a newsletter. Out of respect for the privacy of our users we present the option to not receive these types of communications.

Service Announcements

On rare occasions, it is necessary to send out a strictly service related announcement, if, for instance, our service is temporarily suspended for maintenance. Generally, users may not opt-out of these communications, though they can deactivate their account. However, these communications are not promotional in nature.

Though we make every effort to preserve your privacy, we may need to disclose personal information when required by law, if we have a good-faith belief that such action is necessary and required to comply with a current judicial proceeding, a court order or legal process served on ElySpace. ElySpace websites contain links to other sites. Please be aware that ElySpace is not responsible for the privacy practices of such other sites. We encourage you to read the privacy statements of each and every Web site that collect personally identifiable information. The ElySpace Privacy Policy as described herein applies solely to information collected by ElySpace.

Maintenance of Information

The information you provide to ElySpace may be stored in one or more databases directly or indirectly maintained by ElySpace, and is kept for the periods set out under How long we keep your personal data above, not indefinitely. ElySpace employs industry standard security measures to protect the confidentiality of the information.

While we cannot guarantee that loss, misuse or alteration to data will not occur; we make every effort to prevent such occurrences. Any other particularly sensitive information, such as credit card numbers collected for commercial transactions, is encrypted prior to transmission by you to ElySpace.

You can access, edit and update your personal details in your client area at my.elyspace.com at any time. If you have any difficulty doing so, open a ticket at my.elyspace.com/submitticket.php and we will help.

How we secure and store your data

We follow generally accepted standards to store and protect the personal data we collect, both during transmission and once received and stored, including utilisation of encryption where appropriate.

We retain personal data only for as long as necessary to provide the Services you have requested, and after that only where a law, a contract or the defence of a legal claim requires it. The period for each category of data is set out under How long we keep your personal data above.

If you have any questions about the security or retention of your personal data, use the routes under Who to contact about your personal data above.

Your Responsibility

You are responsible for the security of the login information, such as usernames and passwords, which give you access to your private information maintained by elyspace. Make sure you keep login information in a safe place and do not share it with others.

Note that key-loggers, viruses, or other surveillance devices can intercept login information on the computers from which you access our Services, so you should take precautions regarding such devices, especially from public computers. In addition, you should always log out from any relevant Services when you are not actively using them.

Changes in our Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we decide to change our Privacy Policy, we will post those changes to this Privacy Policy and any other places we deem appropriate, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If we make material changes to this Privacy Policy, we will notify you here, by email, or by means of a notice on our home page, at least thirty (30) days prior to the implementation of the changes.

Infrastructure and data security access and manipulation

We implement technical and organisational measures appropriate to the risk, and we keep them appropriate as risks change. Article 32 of the GDPR and section 8(5) of India’s Digital Personal Data Protection Act 2023 both require this of us, and the measures below are what we do about it.

ElySpace operates global infrastructure designed to provide state-of-the-art security through the entire information processing lifecycle. This infrastructure is built to provide secure deployment of services, secure storage of data with end-user privacy safeguards, secure communications between services, secure and private communication with customers over the Internet, and safe operation by administrators.

We designed the security of our infrastructure in layers that build upon one another, from the physical security of our upstream providers ( Amazon, DigitalOcean, IBM, etc. ), to the security protections of our hardware and software, to the processes we use to support operational security. This layered protection creates a strong security foundation for everything we do.

ElySpace uses encryption to protect data in transit and at rest. Data in transit is protected using HTTPS, which is activated by default for all users and any other type of data is stored on machines that have at least 3 layers of security with limited access for anyone in the company.

For ElySpace employees, access rights and levels are based on job function and role, using the concepts of least-privilege and need-to-know to match access privileges to defined responsibilities. Requests for additional access follow a formal process that involves a request and an approval from a data or system owner, manager, or other executives, as dictated by ElySpace's security policies.

We scan for vulnerabilities using a combination of commercially available and purpose-built in-house tools, intensive automated and manual penetration testing, quality assurance processes, software security reviews, and external audits. We also rely on the broader security research community and greatly value their help identifying vulnerabilities in all of our products. We encourage researchers to report design and implementation issues that may put customer data at risk and most of the time we reward them with credit and free ElySpace services.

Each and every customer can enable two-factor authentication (2FA) greatly reduces the risk of unauthorized access by asking users for additional proof of identity when signing in. This can be enabled for your client area at my.elyspace.com and for cPanel/WHM as well; if you are not sure how, open a ticket at my.elyspace.com/submitticket.php and we will walk you through it.

On our infrastructure we also use an in house developed firewall that watch any suspicious login attempt and helps detect suspicious logins using robust machine learning capabilities also the entire infrastructure is monitored in real time 24/7/365 by real humans that can be proactive and take care of any kind of suspicious activity at the server level.

Your US state privacy rights

This section applies if you live in a US state with a comprehensive privacy law. It is written primarily to the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the differences that apply in other states are set out at the end.

What we collect, why, and who we give it to

In the last twelve months we have collected the following categories of personal information. For each we give examples, where it comes from, why we use it, and who we disclose it to. How long we keep each category is set out in How long we keep your personal data.

  • Identifiers Name, postal address, email address, telephone number, account name, IP address, cookie and device identifiers. From you, and from your device when you use our site. Used to run your account, provide the service, take payment, give support, keep the service secure, and for analytics and advertising. Disclosed to our infrastructure, billing, payment, domain, analytics and advertising providers.
  • Customer records The categories listed in California’s customer records law, being name, address, telephone number and payment information. From you. Used to run your account, take payment and meet our tax and accounting obligations. Disclosed to our billing and payment providers and to our accountants.
  • Commercial information The services you bought, your plan, renewals and expiries, orders, and records of what you asked us for. From you and from our own systems. Used to provide and bill the service and to support you. Disclosed to our billing provider.
  • Internet or other electronic network activity information Pages viewed, links clicked, referring site, time on page, browser and device settings, and interactions with our site. From your device. Used to operate and improve the site, to keep it secure, and (with your consent) for analytics and advertising measurement. Disclosed to our analytics, advertising and security providers.
  • Geolocation data Approximate location inferred from your IP address. From your device. Used to show relevant currency and content, to screen orders for fraud, and for security. Disclosed to our analytics, security and fraud-screening providers.
  • Audio and electronic information Support chat transcripts and records of calls to our support and sales lines. From you. Used to answer your enquiry, train our staff and keep a record of what was agreed. Disclosed to our ticketing and chat providers.
  • Professional or employment-related information If you apply for a job with us, the contents of your application. From you. Used only to consider your application.
  • Sensitive personal information Your account log-in credentials. From you. Used only to let you into your account and to keep it secure. We do not use or disclose sensitive personal information for any purpose other than those permitted without a right to limit, so the right to limit its use does not arise.

Do we sell or share your personal information?

We do not sell your personal information for money, and we have not done so in the last twelve months.

We do share it, in the specific sense California law gives that word. Our site uses the Meta Pixel and Google advertising and analytics tags, and these send identifiers and information about your activity on our site to Meta and to Google for cross-context behavioural advertising and measurement. Under California law that is “sharing”, whether or not money changes hands, and you have the right to opt out of it. The categories shared are identifiers, internet or other electronic network activity information, and approximate geolocation. We do not share sensitive personal information, and we do not knowingly sell or share the personal information of anyone under 16.

How to opt out of sharing

Use the Do Not Sell or Share My Personal Information link in the footer of every page, which opens our cookie preference controls. Turning off the advertising category stops the sharing described above.

We also honour opt-out preference signals, including Global Privacy Control, as a valid opt-out request. If your browser or extension sends one, we treat it as an opt-out for that browser without you having to do anything else.

You do not need an account to opt out, and we will not ask you to create one. You can also send an opt-out through an authorised agent, in which case we may ask the agent for proof that you authorised them.

Your rights

  • Know and access Ask what personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and get a copy of it.
  • Delete Ask us to delete personal information we collected from you, subject to the exceptions the law allows and the retention periods set out above.
  • Correct Ask us to correct inaccurate personal information.
  • Opt out of sale or sharing As described above.
  • Limit the use of sensitive personal information See the note in the categories list above.
  • Non-discrimination We will not deny you service, charge you a different price, give you a lower quality of service, or suggest we will, because you used any of these rights.
  • Authorised agent You can appoint someone to make a request for you. We may ask you to verify your own identity directly and to confirm that you gave the agent permission.

We do not offer any discount, credit, free domain or other incentive in exchange for your personal information, for accepting marketing, or for agreeing to data sharing.

How to make a request, and how long we take

Open a ticket at my.elyspace.com/submitticket.php, or email [email protected]. Those are our two designated methods. We will confirm we have your request within 10 business days and respond substantively within 45 calendar days, which we may extend once by a further 45 days if we need to, telling you why. We verify your identity before we disclose or delete anything; if you have an account, signing in is the easiest way for us to do that.

If we turn your request down

You can appeal. Reply to our decision within 60 days and ask for it to be reviewed, and we will tell you the outcome and our reasons within 60 days of receiving the appeal. If we still say no, we will tell you how to complain to your state Attorney General. This appeal route is required in several states, and we offer it to everyone.

Other states

If you live in a state whose law requires opt-in consent before sensitive data is processed, we will ask for it rather than relying on an opt-out. We recognise universal opt-out mechanisms in the states that require them, using the same signal handling described above. Residents of every state with a comprehensive privacy law have, at a minimum, rights to access, correct, delete and port their personal data, to opt out of targeted advertising and sale, and to appeal a refusal.

We give these rights to residents of those states as a matter of policy, whether or not the thresholds that make a particular state's law apply to a business of our size have been met, so you do not have to work out which law covers you before you ask.

Cookies, tracking and your choices

We use cookies and similar technologies on elyspace.com and in our client area. Some are strictly necessary to make the site and your account work (keeping you signed in, remembering what is in your cart, protecting against attacks), and those are always on. Everything else, including analytics and advertising measurement, is only set if you agree to it.

Our Cookie Policy lists each cookie and technology individually: what it is, who sets it, what it does, how long it lasts and which category it is in. It also explains how to give, change or withdraw your consent, and how to control cookies in your browser.

You can change your choices at any time using the Cookie preferences link in the footer of every page. Withdrawing consent is as easy as giving it, and it takes effect straight away.

Our analytics and advertising providers are Google and Meta Platforms. Where you consent to advertising cookies, we and Meta Platforms are joint controllers for the collection of your data on our site and its transmission to Meta. We are responsible for having a lawful basis and for giving you this information, and Meta is responsible for what it does with the data afterwards. You can exercise your rights against either of us. The details are in the Cookie Policy.

Children and age limits

Our services are sold to adults, and you must be 18 or over to open an account with us. That is the same age our Service Agreement requires, so there is one answer rather than two.

We do not knowingly collect personal data from anyone under 18 without verifiable parental or guardian consent, and we do not direct behavioural tracking or targeted advertising at children. Indian law prohibits that outright for anyone under 18, and consent does not make it lawful. If you believe a child has given us personal data, contact us at [email protected] or our Grievance Officer, and we will delete it.

None of this applies to personal data that our customers hold on the sites they host with us. For that data our customer is the controller, and it is governed by their own privacy notice and by our agreement with them.

Complaining to a data protection regulator

If you are unhappy with how we have handled your personal data, tell us first (email [email protected] or open a ticket) and we will try to put it right. You do not have to, and using our process does not affect your right to go to a regulator.

  • European Union Complain to the supervisory authority where you live, where you work, or where you think the problem happened. The list is published by the European Data Protection Board at edpb.europa.eu. Because we are not established in the EU, there is no single lead authority for us; any of them can take your complaint.
  • United Kingdom The Information Commissioner’s Office, ico.org.uk/make-a-complaint, or 0303 123 1113.
  • India Our Grievance Officer first, as the DPDP Act requires, then the Data Protection Board of India. For complaints about content or about how we handled a content complaint, you may also appeal to a Grievance Appellate Committee under Rule 3A of the IT Rules 2021, within 30 days of our decision.
  • United States The Attorney General of your state, and in California also the California Privacy Protection Agency.

Questions and concerns

If you have any questions, concerns or complaints about this Privacy Policy, about our practices, or about our Services, write to us at [email protected], open a ticket at my.elyspace.com/submitticket.php, or contact our Grievance Officer using the details under Grievance Officer above. We would rather hear from you and put something right than have you go elsewhere first.

You are not obliged to come to us first, and doing so does not affect your right to complain to a regulator. See Complaining to a data protection regulator above.