ChainLinkHosting Privacy Policy
Effective Date: 12 March 2026 "Melbourne, Victoria, Australia, 5:00 AM AEDT"
This Privacy Policy describes how ChainLinkHosting ("we," "us," or "our") collects, uses, and protects your personal information. We are committed to protecting your privacy in compliance with applicable data protection laws, including the Australian Privacy Act 1988 (Cth) and its Australian Privacy Principles (APPs), the EU's General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and Singapore's Personal Data Protection Act (PDPA).
ChainLinkHosting acts as the data controller for personal data belonging to our direct customers. For any personal data our customers store, process, or host on our services, the customer acts as the data controller, and ChainLinkHosting acts as the data processor, processing such data solely in accordance with the customer's instructions, our Terms of Service, our Acceptable Use Policy, and this Privacy Policy.
Information We Collect
We collect information you provide directly to us, such as:
Identity & Contact Data: Name, email address, phone number, and physical address.
Financial Data: Billing details and payment information, which are processed securely by our third-party payment providers. We do not store full credit card numbers.
Account Data: Account credentials, service preferences, and support ticket communications.
Technical & Usage Data: IP addresses, browser type, server logs, and data on how you use our services.
How We Use Your Information
We use your information for the following purposes:
To provide, maintain, and manage your hosting services.
To process payments and manage billing records.
To communicate with you regarding your account, including service updates, security alerts, and billing notifications ("Service Communications").
To provide customer support and respond to your inquiries.
To improve our services, infrastructure, and website experience.
To prevent fraud, abuse, and security threats.
To comply with our legal and regulatory obligations.
To send you promotional offers and newsletters, but only with your explicit consent ("Marketing Communications"). You can opt out of marketing communications at any time.
Legal Bases for Processing (GDPR & UK GDPR)
We process your personal data based on the following lawful bases:
Contract Necessity: To fulfill our contractual obligations to you when providing our services.
Legitimate Interests: To operate our business, secure our services, and prevent fraud, provided these interests do not override your fundamental rights.
Legal Obligation: To comply with applicable laws, such as financial and tax regulations.
Consent: Where required by law, we will obtain your consent to process your personal information, for example, for marketing communications.
Our Third-Party Infrastructure Providers (Sub-processors)
ChainLinkHosting uses trusted third-party data centers and server providers to deliver its services. These providers act as sub-processors who process data on our behalf. Our relationship with them is governed by their publicly available Terms of Service, Acceptable Use Policies, and Privacy Policies, which include their commitments to data protection and security. By using these providers, we rely on their standard agreements to ensure they meet data protection standards required by applicable laws. Our primary infrastructure providers include:
ServCity
CloudExa Hosting
PebbleHost
Server.net
Traffic Processing for DDoS Mitigation
To provide network security and DDoS mitigation, we process network traffic in real time. This inspection is performed ephemerally and in memory only to detect and block malicious activity.
Traffic payloads and content are not stored, logged, or retained.
We may retain limited technical metrics for security analysis, such as source IP addresses (or a truncated/hashed version), packet counts, and attack signatures. This data is used solely for network security and abuse prevention and is never used for advertising or profiling.
Data Protection
We implement appropriate technical and organizational security measures to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include:
Encryption of data in transit (SSL/TLS).
Secure data centers with physical and logical access controls.
Regular security audits and system updates.
Access controls limiting who can view your data based on their role.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected.
Active account data is retained for the duration of your service with us.
Upon account closure, most data is deleted within 60 days.
We are required by law to retain certain financial and transactional records for specific periods. Under the Australian Corporations Act 2001, we must retain financial records for a minimum of seven years. UK law requires similar records to be kept for at least six years. Therefore, relevant data will be retained to meet these legal and tax compliance obligations.
Security-related metrics are retained for up to 30 days before being deleted or anonymized.
In cases of repeated abuse, limited identifiers (like a hashed IP) may be retained indefinitely to protect our network.
Cross-Border Data Disclosure
Our services are global, which means your personal information may be processed and stored on servers located outside of your country of residence.
Our billing and management systems (WHMCS) are hosted in the European Union (EU).
Our server infrastructure is located in the United Kingdom (UK), EU, United States (US), Singapore, and Australia, depending on the service you select.
Under Australian Privacy Principle 8 (APP 8), using infrastructure in the US, Singapore, EU, and UK constitutes a cross-border disclosure. The "reasonable steps" we take to ensure data protection consist of selecting reputable providers who have strong public commitments to privacy and security (such as GDPR compliance) as outlined in their standard Terms of Service and Privacy Policies.
By using our services, you acknowledge and consent that your data will be processed by these third-party providers in accordance with their standard legal terms.
Your Rights
You have rights over your personal data, which vary by jurisdiction:
EU & UK Users (GDPR): You have the right to access, rectify, erase, restrict processing of, and port your data. You also have the right to object to processing. Please note that the right to erasure is not absolute and is subject to legal exceptions, such as our need to retain data to comply with legal obligations.
Australian Users (APPs): You have the right to access and correct your personal information.
California Users (CCPA/CPRA): You have the right to know what data we collect, request its deletion, and correct inaccurate information. We do not sell or share your personal information. Deletion requests are subject to exceptions permitted by law, such as when the information is necessary to comply with a legal obligation.
Singapore Users (PDPA): You have rights under the PDPA to access and correct your data. Any request for deletion will be handled in accordance with the law and is subject to legal exceptions, such as our data retention obligations.
All Other Users: We will respond to all valid privacy-related requests to access, correct, or delete your personal information, regardless of your location. All requests are subject to exceptions permitted by law.
To exercise these rights, please contact us at [email protected].
IP Address Handling
We process IP addresses for security, service delivery, and abuse prevention. Under Australian, EU, and UK law, an IP address may be considered personal information. We treat it with the same level of protection as other personal data.
Cookies and Tracking Technologies
We use cookies for essential website functionality, analytics, and to improve your experience. When you visit our website, you will be presented with a cookie consent banner.
Your Consent: The banner allows you to "Allow all" or "Decline all" non-essential cookies. We use these cookies to understand user navigation patterns and improve your future visits.
Managing Cookies: In addition to our consent banner, you can manage and block cookies through your browser's settings. Please be aware that declining or blocking essential cookies may affect the functionality of our website.
Do Not Track: Our services do not currently respond to "Do Not Track" signals.
Third-Party Tracking Technologies
We use third-party analytics services, specifically Google Analytics, to help us understand how users engage with our website and services. Google Analytics uses cookies to collect information about your usage, which is used to compile reports on website activity. This information is processed in a way that does not directly identify anyone. For more information on how Google uses data, please visit Google's Privacy & Terms.
Third-Party Links & Integrations
Our website may contain links to third-party services (e.g., domain registrars, payment gateways). This Privacy Policy does not apply to those services. We encourage you to review their privacy policies before providing them with your information.
Communications and Marketing
We may send you communications related to your account and our services.
Service Communications: We will send you essential service-related emails, such as billing notices, security alerts, and critical operational updates. These communications are a required part of our services and cannot be opted out of.
Marketing Communications: We may send you marketing emails where legally permitted. You can unsubscribe from these communications at any time by using the link provided in the email or by contacting our support team.
Children's Privacy
Our services are not directed to children under the age of 16. We do not knowingly collect personal information from individuals under 16. If we become aware that we have, we will take steps to delete it.
Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authorities (such as the UK's ICO and Australia's OAIC) as required by law, typically within 72 hours.
Disclaimer Regarding Support
While we collect information during support interactions, the provision of support is offered at our discretion as outlined in our Terms of Service and is not a guaranteed contractual obligation.
Sale of Business
In the event of a merger, acquisition, or sale of all or substantially all of the assets of our business, your personal information may be transferred to a successor entity. We will ensure the new entity agrees to protect your data in accordance with the terms of this Privacy Policy.
Governing Law
This Privacy Policy is governed by the laws of Victoria and the Commonwealth of Australia.
Disclosure to Law Enforcement and Legal Compliance (Australia)
As an Australian business, we are subject to Australian laws that may require us to disclose personal information. We may be legally compelled to provide data to law enforcement or government agencies in response to a valid legal request (such as a warrant or subpoena) under legislation including, but not limited to, the Telecommunications (Interception and Access) Act 1979 (Cth). This may include obligations under the Assistance and Access Act 2018 to provide technical assistance to authorities. We will also comply with lawful notices issued under the Online Safety Act 2021 concerning the removal of illegal or harmful content.
How to Make a Complaint (Australia)
If you believe we have breached the Australian Privacy Principles, please contact us first. If you are not satisfied with our response, you have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
Contact Us
For any privacy-related questions or requests, please contact us: