This policy explains how BPHOST handles personal information. It is written to meet the Protection of Personal Information Act 4 of 2013 (POPIA), and — where you are in the European Union or the United Kingdom — the General Data Protection Regulation (GDPR).
We sell hosting, domains and websites. That means we hold billing details, the contact details you give a domain registry, and the server logs your sites generate. We do not sell any of it, and we have never run an advertising business off the back of it.
1Who we are#
BPHOST is the responsible party (POPIA) and data controller (GDPR) for the personal information described in this policy. The contact address for privacy correspondence is at the end of this page, and you can also reach us through the client area.
Where you host a site with us and collect personal information from your own visitors, you are the responsible party for that information and we act as an operator (processor) on your behalf. You are responsible for having your own privacy policy and lawful basis for that data.
2Information we collect#
Information you give us
- Account and billing details — name, company name, email address, telephone number, billing address, and the invoices, payments and credit notes on your account.
- Domain registration details — the registrant, administrative, billing and technical contact details required by the relevant domain registry.
- Support correspondence — tickets, emails and live chat messages, including anything you choose to paste into them.
- Verification documents — only where a registry, a payment provider or a fraud check requires them, and only for as long as needed.
Information we collect automatically
- Server and access logs — IP address, timestamps, requested URLs, user agent, and error output. These are generated by the hosting platform itself and are what allow us to investigate faults, abuse and intrusion attempts.
- Authentication records — login attempts to the client area, control panel, FTP and mail, kept for security purposes.
- Website analytics and cookies — described in its own section below.
Payment card numbers. We do not store them. Card details are entered directly with our payment providers and we receive only a reference, the outcome, and the last digits needed to identify the card on an invoice.
3Why we process it#
Under POPIA and the GDPR we must have a lawful ground for each use. Ours are:
- To perform our contract with you — creating and running your services, registering and renewing domains, issuing invoices, taking payment, and providing support.
- To comply with the law — tax and accounting records, responses to lawful requests, and the contact details registries oblige us to collect and pass on.
- Our legitimate interests — keeping the platform secure, investigating abuse, preventing fraud, recovering unpaid accounts, and improving our services. We weigh this against your rights, and you can object (see Your rights).
- Your consent — for marketing email you have opted in to, and for non-essential cookies. You may withdraw consent at any time; withdrawing it does not affect what we did lawfully beforehand.
We do not use your personal information to make decisions about you by automated means alone, and we do not profile you for advertising.
4Who we share it with#
We share personal information only where it is necessary to deliver what you asked for, or where the law requires it. The categories are:
- Domain registries and registrars — the details required to register, renew or transfer a domain are passed to the registry for that extension and are governed by that registry's own rules.
- Payment providers — to take and reconcile payment, and to investigate chargebacks.
- Infrastructure and platform providers — the data centre, network, backup, email delivery, DNS and security services our platform runs on.
- Our AI assistant provider — described in its own section below.
- Professional advisers — accountants, auditors and lawyers, bound by confidentiality.
- Law enforcement and regulators — where we are legally obliged to respond, or where it is necessary to establish, exercise or defend a legal claim.
We do not sell personal information, and we do not rent or trade mailing lists. Our suppliers are permitted to use your information only to provide the service we engaged them for.
5Processing outside South Africa#
Some of the infrastructure and suppliers we use operate outside the Republic of South Africa. This means your personal information may be transferred to, stored in, or accessed from another country — as required by section 72 of POPIA, we are telling you so plainly.
Where that happens we rely on one or more of the following: the recipient is bound by binding corporate rules or an agreement that upholds standards substantially similar to POPIA; the transfer is necessary to perform our contract with you; or you have consented. For GDPR transfers we rely on adequacy decisions or standard contractual clauses where applicable.
6Cookies and analytics#
Cookies are small files a site stores in your browser. We use them for two things:
- Strictly necessary cookies — signing you in to the client area, keeping your cart and your session, and protecting forms against abuse. The site cannot work without these.
- Analytics cookies — to understand which pages are used and where people get stuck. This is aggregate, and we do not use it to identify individuals or to target advertising.
You can block or delete cookies in your browser settings. If you block the strictly necessary ones, logging in and checking out will stop working.
Some pages embed third-party content (for example video or fonts). Those providers may set their own cookies under their own policies.
7Our AI assistant#
The chat bubble on this site is an AI assistant called Kairo. So that you know exactly what happens when you use it:
- The messages you type are sent to a third-party AI provider to generate a reply. They leave our servers to do so.
- Kairo answers from our public website content and knowledgebase. It is not connected to your billing account, invoices, passwords or server data.
- We may keep a record of conversations to improve the assistant and investigate misuse.
Please do not type passwords, card numbers, ID numbers or other sensitive details into the chat. If you need to send us something confidential, open a ticket in the client area instead, where it stays within your account.
8Domain registrations and public records#
Registering a domain is not a private act. Every registry requires contact details for the registrant, and depending on the extension, some of those details may be published in a public WHOIS or RDAP lookup, or disclosed to the registry operator and its escrow agents.
What is published differs by extension and changes over time — some registries redact personal data by default, others do not. If this matters to you, ask us before you register and we will tell you what that particular extension exposes, and whether privacy protection is available for it.
Registry rules override our preferences here. We cannot withhold details a registry requires and still keep the domain registered in your name.
9How long we keep it#
- Account, billing and tax records — for as long as you are a client and then for the period required by South African tax and company law, which is generally five years from the end of the relevant tax period.
- Support tickets and correspondence — while your account is open and for a reasonable period after, so we have the history if an issue resurfaces.
- Server, access and authentication logs — for a short rolling window, long enough to investigate faults and security incidents.
- Backups — cycled on a rolling schedule and overwritten in the ordinary course. Deleted data can persist in a backup until that backup ages out.
- Terminated service data — removed on the schedule set out in our Terms of Service.
When information is no longer needed for the purpose it was collected for, and we are not required to keep it, we delete it or de-identify it.
10How we protect it#
We take reasonable technical and organisational measures to protect personal information, including encrypted connections (TLS) across the client area and our services, access controls and separation of duties, hashed credentials, firewalling and intrusion monitoring, and regular patching of the platform.
What we ask of you in return: use a strong and unique password, enable two-factor authentication on the client area where offered, keep your own applications and plugins updated, and tell us immediately if you think an account has been compromised.
If a security compromise occurs in which personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected people as required by section 22 of POPIA.
No system is perfectly secure, and we will not pretend otherwise. We cannot guarantee the security of information transmitted over the internet, and the security of the applications you install and run on your hosting remains yours to manage.
11Your rights#
Under POPIA — and, where it applies, the GDPR — you have the right to:
- Be told what personal information we hold about you, and to be given a copy of it.
- Have it corrected where it is inaccurate, irrelevant, misleading or out of date.
- Have it deleted where we no longer have grounds to keep it. Where the law requires us to retain a record, we will tell you which one and for how long.
- Object to processing based on our legitimate interests, on reasonable grounds.
- Withdraw consent at any time, where we relied on consent.
- Opt out of direct marketing — every marketing email carries an unsubscribe link, and you can also just tell us.
- Data portability (GDPR) — to receive information you gave us in a structured, commonly used, machine-readable format.
To exercise any of these, use our privacy request form, or open a ticket from inside the client area — a ticket raised while signed in is the fastest route, because it already proves who you are. We will confirm your identity before acting, because handing account data to whoever asks for it would be its own privacy failure. We aim to respond within 30 days, and we do not charge for a reasonable request.
12Complaints#
If you are unhappy with how we have handled your personal information, tell us first — most of these are misunderstandings we can fix quickly.
If we do not resolve it, you have the right to complain to the Information Regulator (South Africa), which can be reached at inforegulator.org.za. Complaints are lodged on the Regulator's prescribed form. If you are in the EU or UK, you may instead complain to your local supervisory authority.
13Children#
Our services are sold to adults and to businesses. We do not knowingly collect personal information from children under 18 without the consent of a competent person. If you believe a child has given us personal information, contact us and we will delete it.
14Changes to this policy#
We update this policy when our practices, our suppliers or the law change. The effective date at the top of this page always reflects the current version. Where a change materially affects your rights, we will bring it to your attention rather than relying on you to notice it.
Continuing to use our services after a change takes effect means you accept the updated policy.
Questions about this document
If anything here is unclear, ask us — we would rather explain it up front than have you agree to something you do not understand.
- General enquiries
- Contact form
- Privacy requests
- Privacy request form
- Abuse reports
- Abuse report form








