Data Security Policy

How we handle the security of our data systems.

Last updated: July 23, 2025

1. Scope

This policy applies to all personal data and customer information processed, stored, or transmitted by Glitch Servers. It covers systems, platforms, employees, and third-party services that interact with personal data under the control of the Company. This policy is applicable to all customer data regardless of location, with specific attention to compliance with the United Kingdom General Data Protection Regulation (UK GDPR).

2. Purpose

The purpose of this policy is to establish and communicate the practices Glitch Servers uses to safeguard customer data, ensure regulatory compliance, and protect the privacy of individuals. The policy outlines measures for secure data handling, breach notification, access controls, and data subject rights.

3. Definitions

4. Data Collection and Minimisation

Glitch Servers collects only the minimum data necessary to deliver and support its services. This includes names, email addresses, billing information, and IP addresses. Additional data collected through control panels or logs is retained only as long as required for support, compliance, or performance analysis.

5. Data Storage and Encryption

All personal data is stored securely within UK data centres. Data is encrypted in transit using TLS 1.2 or higher and stored in systems protected by industry-standard encryption methods. Payment card information is never stored; all payments are processed via Stripe, a PCI-DSS compliant provider.

6. Access Control

Access to customer data is strictly limited to authorised personnel based on the principle of least privilege. WHMCS and supporting systems enforce role-based access control (RBAC). Administrative activity is logged and reviewed weekly. Staff are required to use two-factor authentication and adhere to internal password policies.

7. Data Subject Rights

Customers have the right to access, correct, or delete their personal data. These requests can be submitted through the client area by selecting the "Data Protection" category within the support ticket system. All requests are acknowledged within 48 hours and completed within the legal timeframe of 30 days.

8. Data Retention

Customer data is retained for up to 12 months after a service is cancelled or terminated, enabling quick reinstatement if the customer returns. After this period, all associated personal data is automatically and securely deleted. Billing and invoicing data may be retained for up to 7 years to comply with UK financial regulations. Logs and analytics may be anonymised and retained indefinitely for security or operational review.

9. Breach Notification and Response

In the event of a personal data breach, Glitch Servers will notify the Information Commissioner's Office (ICO) within 72 hours, as required by law. Affected customers will be informed via email without undue delay. An internal incident response process will be initiated, including root cause analysis, remediation, and policy updates if needed.

10. Third-Party Processors

Glitch Servers only partners with third-party service providers that are GDPR-compliant and have signed appropriate Data Processing Agreements (DPAs). Third-party access to customer data is limited, controlled, and regularly reviewed.

11. Data Residency

All personal data processed by Glitch Servers is stored within the United Kingdom. No customer data is transferred internationally or to jurisdictions outside of the UK GDPR.

12. Policy Review

This policy is reviewed annually or following a major change in legal requirements, infrastructure, or data handling practices. All revisions are documented and communicated as needed.