General

At Ciao Host we provide web hosting, shared hosting, domain name registration, and related products and services. We focus on maintaining the safety and confidentiality of our customers and website visitors’ personal information. We place a high value on protecting this information and aim to be clear and honest regarding the data we gather, whom we share it with, and its intended purpose. Ensuring the confidentiality and safety of our Users is essential to us. So, we are dedicated to safeguarding any information you entrust. Data collected by us is usually used for providing services and content, account registration, payment processing, technical support, marketing, business communications, and more. We aim to be transparent and forthright regarding the collected data, whom we provide it to, and how it’s utilized. This information will be only shared with Members of the Ciao Host team, authorised users within your organization, and legal & regulatory authorities as required. The data we collect includes:

• Account Signup Information. (name, E-Mail, physical address, company name, phone number, geographic location, payment information, etc.)

• Login information.

• Identity Verification. Before registering a new domain name, we may collect identity verification information (such as passport images, national ID card, valid driving licence, or other documents as required or permitted by applicable laws).

• Payment Information. To access certain website features, such as registering a domain name, you may need to supply precise financial details for payment purposes.

• To streamline payments, we utilise third-party payment processors and do not keep credit card information. We only receive data on the status of payments and retain the final four digits of credit card numbers for record-keeping purposes.

• Communications, Chats, Messaging. We collect information about your communication with us and any information you choose to provide or disclose.

• To help you with your request, we may access information provided in your account, purchase history, etc. You have the option to give us information by filling out forms, searching on our website, updating, or adding details to your Ciao Host account, taking surveys, posting in community forums, participating in promotions, or using other platform features. However, we recommend refraining from sharing any private information on Ciao Host Platform. If you decide to upload any content to your account or website or provide it in any other way while using our services, you do it at your own risk.

**All personal data are processed under the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

Who we are

Our website address is: https://ciao.host.


Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your E-Mail address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service Privacy Policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.


Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.


Cookies

If you leave a comment on our site you may opt in to saving your name, E-Mail address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.


Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.


Who we share your data with

If you request a password reset, your IP address will be included in the reset E-Mail.


How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognise and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.


What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.


Where your data is sent

Visitor comments may be checked through an automated spam detection service.

 

**GDPR

 

This Data Processing Agreement (“DPA”) is an addendum to the Terms & Conditions between Inductive Concepts Limited trading as Ciao Host (“Ciao Host”) and you (the “Customer”). The DPA will be effective and replace any previously applicable data processing and security terms as from 25th May 2018 and will continue for as long as Ciao Host provides the services as set out in its Terms & Conditions.

Definitions:

  • “Customer Data” means data provided by or on behalf of Customer or Customer End Users via the Services under the account.
  • “Data Controller” means the entity that determines the purposes and means of the processing of Personal Data.
  • “Data Processor” means the entity that processes Personal Data on behalf of the Data Controller.
  • “Data Protection Laws” means all data protection and privacy laws and regulations applicable to the processing of Personal Data under the Agreement, including the GDPR.
  • “Data Subject” means the individual to whom the Personal Data relates.
  • “EEA” means the European Economic Area.
  • “GDPR” means EU General Data Protection Regulation 2016/679.
  • “Personal Data” means any Customer Data relating to an identified or identifiable natural person to the extent that such information is protected as personal data under GDPR.
  • “Processing” has the meaning given to it in the GDPR and “process”, “processes” and “processed” shall be interpreted accordingly.
  • “Sub-Processor” means any third party authorised under this DPA to have logical access to and process Customer Data to provide parts of the Services.
  • “Services” means any product or service provided to Customer and as described in Ciao Host’s Terms & Conditions.

Data Processing

Ciao Host will only act and process Customer Data in accordance with the documented instruction from Customer (the “Instruction”), unless required by law to act without such Instruction. The Instruction at the time of entering into this DPA is that Ciao Host may only process Customer Data with the purpose of delivering Services as described in its Terms & Conditions and any product-specific agreements. Subject to the terms of this DPA and with agreement of the parties, Customer may issue additional written instructions consistent with the terms of this Agreement. Customer is responsible for ensuring that all individuals who provide instructions are authorised to do so. Ciao Host will inform Customer of any instruction that it deems to be in violation of GDPR and will not execute the instructions until they have been confirmed or modified. When Customer Data is processed by Ciao Host, both parties acknowledge and agree that: – Ciao Host is a Data Processor of Customer Data under the GDPR – Customer is a Data Controller of Customer Data under GDPR.

Confidentiality

Ciao Host shall treat all Customer Data as strictly confidential information. Customer Data may not be copied, transferred or otherwise processed in conflict with the Instruction from Customer unless required by law. Ciao Host employees shall be subject to an obligation of confidentiality that ensures that the employees shall treat all Customer Data under this DPA with strict confidentiality and only process Customer Data in accordance with the Instruction.

Sub-Processing

Customer authorises Ciao Host to engage third-parties to process Customer Data (“Sub-Processors”) without obtaining any further written, specific authorisation. Ciao Host will restrict Sub-Processor access to Customer Data to what is necessary to provide the Services. Ciao Host shall complete a written agreement with any Sub-Processors. Such an agreement shall at minimum provide the same data protection obligations as the ones applicable under this DPA. It remains accountable for any Sub-Processor in the same way as for its own actions and omissions. Ciao Host will inform Customer of any new Sub-Processor engagements at least 30 days before the new Sub-Processor processes any Customer Data. Notifications of such engagements will be delivered to the account E-Mail address and/or through the control panel interface. It is Customer’s sole responsibility to ensure account information is correct and kept up-to-date. Customer has the right to object to a use of a Sub-Processor by terminating this Addendum and Services in accordance with Ciao Host’s Terms and Conditions. A list of current Sub-Processors can be found in Annex 1.

Security

Ciao Host will implement and maintain technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access as set out Annex 2 of this Addendum and in accordance with GDPR, article 32. The security measures are subject to technical progress and development and Customer acknowledges that Ciao Host may update or modify the security measures from time-to-time provided that such updates and modifications do not result in the degradation of the overall security. In addition, Ciao Host will make controls available to Customer to further secure Customer Data inside the control panel.

Data Breach Notifications

If Ciao Host becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by Ciao Host, Ciao Host agrees to notify Customer without hesitation or delay. Notifications of such incidents will be sent to the account E-Mail address as set by Customer. It is Customer’s sole responsibility to ensure this information is correct and kept up to date inside the control panel. Ciao Host will make reasonable efforts to identify the cause of any breach and take necessary steps to prevent such a breach from reoccurring. Customer agrees that Data Breach Notifications will not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.

Data Subject Rights

If Ciao Host directly receives a request from a Data Subject to exercise such rights in relation to Customer Data, it will forward the request to Customer. Customer must respond to any such request within the timeframes specified within GDPR. Ciao Host will assist Customer in fulfilling any obligation to respond to requests by data subjects, which may include providing controls via the control panel to help comply with the commitments set out under GDPR.

Data Transfers

Ciao Host stores and processes data in secure datacentres located inside the European Economic Area (“EEA”). Data may be transferred and processed outside the EEA to countries where Sub-Processors maintain their own data processing operations. Customer hereby agrees to the transfer, storing or processing of data outside the EEA. Ciao Host will take all steps reasonably necessary to ensure that Customer Data is treated securely and in accordance with the relevant Data Protection Laws.

Compliance and Audit Rights

Ciao Host agrees to maintain records of its security standards and, upon written request by Customer, Ciao Host shall make available all relevant information necessary to demonstrate compliance with this DPA. Customer agrees any audit or inspection shall be carried out with reasonable prior written notice of no less than 30 days and shall not be conducted more than once in any 12-month period. If Ciao Host declines the request, Customer is entitled to terminate this addendum and Services.

Return or Deletion of Data

Ciao Host only retains Customer Data for as long as required to fulfil the purposes for which it was initially collected. Termination of this Addendum or Services in line with Ciao Host’s Terms & Conditions will result in all Customer Data being deleted, unless otherwise required by law. For Customer Data archived on back-up systems, Ciao Host shall securely isolate and protect from any further processing.

Limitation of Liability

The total liability of each part under this addendum shall be subject to the limitation of liability as set out in Ciao Host’s Terms & Conditions. For the avoidance of doubt, in no instance will Ciao Host be liable for any losses or damages suffered by Customer where Customer is using Services in violation of its Terms & Conditions, regardless of whether it terminates or suspend an account due to such violation.

Annex 1 – Sub-Processors Company Service:

Inductive Concepts Limited: Subscription Management, Service Provisioning:

20i Limited: Servers & Data Center

PayPal: Credit/Debit Card Payments

N/A: Support & Communications

Annex 2 – Security Measures

Available upon request.