Data Protection

The Policies and Terms listed on this page apply to your purchase and use of any services ElySpace makes available to you. To review any of our Policy/Terms please click on the corresponding name in the left-hand side menu.

Last updated: 18 September 2026

This page explains how ElySpace handles personal data, which data protection laws apply to us, what your rights are, and how to use them. It covers the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018, the Digital Personal Data Protection Act 2023 in India, and the privacy laws of the US states where they are in force.

It sits alongside our Privacy Policy, which describes in detail what personal data we collect and why, and our Cookie Policy, which covers cookies and similar technologies. Where this page and those documents overlap, they are meant to say the same thing; if you find a difference, please tell us and we will fix it.

Which data protection laws apply to us

ElySpace IT Services LLP is established in India. We sell our services to customers in the United States, Canada, the United Kingdom, the European Union and India, we price our services in US Dollars, Euro and Indian Rupees, and we operate servers in several countries, as set out in section 3.1 of our Service Agreement. Because of that, more than one data protection law applies to us at the same time:

  • the EU General Data Protection Regulation applies to us under its Article 3(2) when we process the personal data of people in the European Union;
  • the UK GDPR and the Data Protection Act 2018 apply to us under their equivalent provisions when we process the personal data of people in the United Kingdom;
  • the Digital Personal Data Protection Act 2023 applies to us in India, together with the Information Technology Act 2000 and the rules made under it for as long as they remain in force; and
  • US state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act, apply to us in the states where they are in force and where we meet the thresholds they set.

Nothing in our Service Agreement, our Domain Agreement or our Affiliate Terms (including the clauses in those documents that choose the law of Delaware or of Washington State) limits your rights under these data protection laws, or your right to bring a claim or a complaint where you live.

Who we are

ElySpace IT Services LLP is an Indian limited liability partnership, LLP registration number AAV-5130, with its registered office at Watergam, Baramulla, Jammu and Kashmir, 193303, India. We are the controller (in Indian terms, the Data Fiduciary) of the personal data described in our Privacy Policy.

We trade as ElySpace at elyspace.com and we run our client area and billing system at my.elyspace.com.

How to contact us about data protection

You can reach us about anything on this page by email at [email protected], by opening a ticket at my.elyspace.com/submitticket.php, or by post at ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India.

Our data protection contact. ElySpace has not designated a Data Protection Officer and does not use that title. The person able to answer questions about our processing is Jahangir Ahmad War, Chief Operating Officer, who can be reached at [email protected]

Our Grievance Officer. If you are in India, or you would prefer to use our formal grievance route wherever you are, you can contact our Grievance Officer:

  • Name: Jahangir Ahmad War
  • Designation: Chief Operating Officer
  • Email: [email protected]
  • Telephone: +91 91038 53627, Monday to Saturday, 10:00 to 18:00 IST, excluding public holidays
  • Address: ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India

We acknowledge every grievance within 24 hours and give you a ticket number, and we aim to resolve it within 15 days of receiving it. The full procedure is set out under Grievance Redressal in our Terms of Service.

Our representatives in the EU and the UK. Because we are established in India and not in the European Union or the United Kingdom, Article 27 of the GDPR and Article 27 of the UK GDPR require us to appoint representatives there, unless a narrow exemption applies. Until the details of a representative are published here, contact us directly at [email protected] about anything to do with our processing of your personal data.

Our role: we are both a controller and a processor

ElySpace acts as both a data controller and a data processor, and which one we are depends on whose data it is.

We are a controller for the personal data we collect to run our own business and our relationship with you: your account and contact details, your billing records and payment history, your support tickets and correspondence, our server and security logs, and the information collected about visitors to elyspace.com. We decide why and how that data is used, and our Privacy Policy is our notice to you about it.

We are a processor for the personal data that you put onto our platform: the contents of your website, your databases, your mailboxes, your uploaded files and the backups of them. We hold that data on your behalf and process it on your instructions. We do not decide what personal data you collect from your own users, why you collect it, or how long you keep it. Towards those people, you are the controller, and you owe them the duties that data protection law places on a controller.

This split has practical consequences we take seriously. We do not routinely inspect the content you host with us and we have no obligation to do so. Where we do need to access it, to give you technical support you have asked for, to operate, secure, back up or repair the service, to investigate a suspected breach of our Resource Usage Policies or a security incident on our network, or where we are compelled to by a law that applies to us, we access the minimum we need, and we tell you where we are lawfully able to.

Data protection law requires us to have a lawful reason for every use we make of your personal data, and to tell you what that reason is. We set them out purpose by purpose in the Privacy Policy. In summary, most of what we do rests on the contract between us: we cannot host your site or register your domain without processing your details. Some of it rests on legal obligations, such as keeping tax and accounting records. Some of it rests on our legitimate interests, such as keeping our network secure and preventing fraud, and where we rely on that you can object. Analytics and advertising technologies, and marketing messages, rest on your consent, which you can withdraw at any time.

For people in India, our lawful basis is either your consent under section 6 of the Digital Personal Data Protection Act 2023 or one of the specific legitimate uses listed in section 7 of that Act. India does not have a general “legitimate interests” basis, and we do not rely on one for Indian users.

Your rights under the GDPR and the UK GDPR

If the GDPR or the UK GDPR applies to our processing of your data, you have the following rights. They are free to use, and for most of them you do not have to give a reason.

  • Access Ask us to confirm whether we hold personal data about you, and to give you a copy of it together with information about how we use it.
  • Rectification Ask us to correct personal data about you that is wrong, or to complete data that is incomplete.
  • Erasure Ask us to delete personal data about you where we no longer need it, where you withdraw the consent we were relying on, or where we have processed it unlawfully.
  • Restriction Ask us to stop using your data, but keep it, while a dispute about its accuracy or about our legal basis is sorted out.
  • Portability Ask us to give you the personal data you provided to us in a common, machine-readable format, or to send it directly to another provider where that is technically feasible. For a hosting account you can also do this yourself at any time using the backup and export tools in cPanel.
  • Objection Object to processing we carry out on the basis of our legitimate interests. If you object to direct marketing we will stop, immediately and always, with no balancing test.
  • Withdraw consent Where we rely on your consent, you can withdraw it at any time, and withdrawing it is as easy as giving it. Withdrawal does not affect anything we did lawfully before you withdrew it.
  • Automated decisions We run automated checks on orders to detect fraud and payment abuse, and an order can be declined automatically. If that happens to you, you can ask a member of our team to look at the decision, put your side of it, and challenge the outcome.

When we cannot do what you ask. Erasure in particular has limits, and we would rather be straight with you about them than promise something we cannot deliver. We have to keep billing, tax and accounting records for the periods Indian law requires. We have to keep some domain registration data for as long as ICANN and the relevant registry require it. Indian rules that apply to us as a provider of servers and hosting require us to keep certain subscriber records for a set period after an account closes. See How long we keep your personal data. And we may need to keep data to establish, exercise or defend a legal claim. If we cannot delete something you have asked us to delete, we will tell you which of these applies.

How to make a request, and how long we take

Tell us which right you want to use and give us enough information to find your records. The quickest route, if you have an account, is a ticket at my.elyspace.com/submitticket.php, because you are already signed in and we can identify you straight away. You can also email us at [email protected] or write to us at the address above.

If we cannot be sure who you are, we will ask you for proof of identity, and we will only ask for what we genuinely need to be sure. We will never ask you to send us a copy of a payment card.

Our timeframes. We answer requests under the GDPR and the UK GDPR within one month of receiving them. If a request is complicated, or if you have made several, we may need up to two further months. If that happens we will tell you inside the first month and explain why. We do not charge for this. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and if we refuse we will tell you why and tell you how to complain.

Where a request reaches us through an authorised agent, or through a Consent Manager registered with the Data Protection Board of India, we act on it in the same way as one that comes directly from you.

Your rights in India under the DPDP Act 2023

If you are in India, the Digital Personal Data Protection Act 2023 gives you these rights over the personal data we hold about you as a Data Fiduciary:

  • Access A summary of the personal data we process about you, what we do with it, and the identities of the other Data Fiduciaries and Data Processors we have shared it with.
  • Correction, completion, updation and erasure Ask us to correct data that is wrong, complete data that is incomplete, bring it up to date, or erase it where the law does not require us to keep it.
  • Grievance redressal Use our Grievance Officer route above. The Act requires you to use this before approaching the Data Protection Board.
  • Nomination Nominate another individual to exercise these rights on your behalf if you die or become incapable of exercising them yourself. Tell us who, in writing, and we will record it.
  • Withdrawal of consent Withdraw consent you have given us, at any time, as easily as you gave it. Where the consent you withdraw was necessary for us to provide a service, we may not be able to continue providing that service, and we will tell you so before you confirm. Withdrawing consent for analytics or marketing has no effect on your service.

You may also give, manage, review or withdraw consent through a Consent Manager registered with the Data Protection Board. We will act on instructions received that way in the same manner as instructions received directly from you.

The Act also places a duty on you not to impersonate another person when exercising these rights and not to make a false or frivolous complaint. We mention it because the Act does; it is not a discouragement from contacting us.

The fuller version of this section, including what we collect, how long we keep it, consent and withdrawal, children, and how to complain to the Data Protection Board, is in our Privacy Policy.

How long we take. We answer a request under the Digital Personal Data Protection Act 2023 within fifteen (15) days of receiving it, which is the same period we give ourselves for a grievance. Where we have to establish who you are before we can act, that period runs from the point at which we have what we need, and we tell you what that is inside the same fifteen days.

The Act and the rules made under it come into force in stages, and each obligation binds us from the date notified for it. We are not waiting for those dates to answer you: the rights set out above are open to you now, on the timescales given on this page, and any obligation that is not yet in force we will meet from the day it is.

Sending personal data outside the EEA and the UK

We are based in India and we run servers in several countries. Personal data we hold will therefore be sent to, and stored in, countries outside the European Economic Area and outside the United Kingdom.

Some of those countries have been formally recognised by the European Commission, or by the UK government, as giving personal data a level of protection essentially equivalent to the protection it has in the EEA or the UK. Canada is one, for commercial organisations. Transfers to companies in the United States are covered where the company receiving the data is certified under the EU–US Data Privacy Framework, or its UK Extension for UK data.

India and Singapore have not been recognised in this way. Where the GDPR or the UK GDPR requires a safeguard for a transfer, we are responsible for providing one those laws recognise. Google, Meta and Cloudflare build the European Commission’s Standard Contractual Clauses into their business terms or are certified under the Data Privacy Framework.

You can ask us which safeguard applies to your data. Write to [email protected].

Data leaving India. Under section 16 of the DPDP Act 2023, personal data may be transferred outside India except to a country the Central Government restricts by notification. We will comply with any such notification. Separate rules apply to payment data under the Reserve Bank of India’s directions.

How long we keep personal data

We keep personal data only as long as we need it, and then we delete it or anonymise it. Several laws that apply to us set minimum periods we cannot go below: Indian tax and company law for financial records, Indian rules on intermediaries and on providers of servers and cloud services for subscriber and log data, and ICANN and registry rules for domain registrations. The full schedule is in the Privacy Policy.

Where we cannot delete something immediately (for example because it sits in an encrypted backup that rotates on a schedule), we isolate it from active use and delete it when that backup is next overwritten.

The companies that process personal data for us

We use other companies to help us run our business, and some of them process personal data on our behalf. They are our processors, they act only on our instructions, and they are bound by contract to protect the data and not to use it for their own purposes.

The categories are: infrastructure and data centre providers; our billing, client area and ticketing platform; payment providers; our domain registration provider; analytics and advertising providers; content delivery and security providers; and email delivery providers.

The companies we can name today are:

  • Google Google Tag Manager, Google Analytics and Google Ads measurement, only where you have accepted those cookies. United States.
  • Meta Platforms The Meta Pixel, only where you have accepted advertising cookies. United States and Ireland.
  • Cloudflare Content delivery and protection against attacks for our website. United States, with processing in its global network.
  • OpenAI and Anthropic AI models behind our AI products and our chat assistant. What you type into those products is sent to them to generate a response. United States.
  • PDR Ltd Our domain registration provider, which receives the registrant details a domain registration requires.

We also use payment providers, infrastructure and data centre providers, and email delivery providers. You can ask us for their names at [email protected].

Data Processing Addendum for business customers

If you are a business customer and you store other people’s personal data on our platform, you need a written data processing agreement with us. Article 28 of the GDPR requires it, and your own compliance depends on having one.

Contact us at [email protected] to put a data processing agreement in place before you store other people’s personal data with us.

If there is a personal data breach

If there is a security incident that affects personal data, we investigate it immediately and contain it. What happens next depends on who the data belongs to and which law applies.

  • Where we are the controller and the law requires it, we report the incident to the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it. If we report later than that, we say why.
  • Where an incident is likely to put your rights or freedoms at high risk, we tell you directly, without undue delay, in plain language: what happened, what data was involved, what we are doing about it, what we suggest you do, and who to contact for more.
  • Where we are your processor (that is, where the affected data is data you host with us), we notify you without undue delay, because your own clock starts when we tell you. We give you what we know about the nature of the breach, the categories and approximate number of people and records affected, the likely consequences and the measures we have taken, and we keep you updated as the investigation develops.
  • In India, we intimate affected individuals and the Data Protection Board without delay, and we report reportable cyber security incidents to CERT-In within the time its directions require.

We keep a record of every personal data breach we become aware of, including the ones we decide do not need to be reported, and why.

Complaining to a data protection regulator

If you are not happy with how we have handled your personal data, please tell us first. We would rather fix it. But you always have the right to complain to a regulator, and using our complaints process does not take that right away.

  • In the European Union, you can complain to the supervisory authority in the country where you live, where you work, or where you think the problem happened. The list is published by the European Data Protection Board at edpb.europa.eu. Because we are not established in the EU, there is no single lead authority for us. Any of them can take your complaint.
  • In the United Kingdom, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint, or by telephone on 0303 123 1113.
  • In India, raise a grievance with our Grievance Officer first, as the DPDP Act requires, and then, if you are still not satisfied, with the Data Protection Board of India. If your complaint is about content or about how we handled a content complaint, you may also appeal to a Grievance Appellate Committee under Rule 3A of the IT Rules 2021 within 30 days of our decision.
  • In the United States, you can complain to the Attorney General of your state, and in California also to the California Privacy Protection Agency. Several states require us to offer an internal appeal first. See our US state privacy rights section.

Cookies and tracking

Our Cookie Policy lists every cookie and similar technology we use, what it is for, who sets it and how long it lasts, and it explains how to give, change or withdraw your consent.

In short: cookies that are strictly necessary to make the site and the client area work are always on. Everything else (analytics, our support chat, and advertising and measurement) is only set if you agree to it, and you can change your mind at any time from the “Cookie preferences” link in the footer of every page.

How we protect personal data

Both the GDPR, in Article 32, and the DPDP Act 2023, in section 8(5), require us to put appropriate technical and organisational measures in place and to keep them appropriate as risks change. Our Privacy Policy describes the measures we use: encryption in transit and at rest, least-privilege access control for our staff, two-factor authentication for your client area and for cPanel and WHM, vulnerability scanning, and monitoring of our infrastructure.

Separately from the backups we provide as part of your hosting service, we maintain our own ability to restore the personal data we hold about you as our customer.

Children

Our services are sold to adults. You must be 18 or over to open an account with us, which is the same age our Service Agreement requires. We do not knowingly collect the personal data of anyone under 18 without verifiable parental or guardian consent, and we do not direct behavioural tracking or targeted advertising at children. If you believe a child has given us personal data, contact us at [email protected] or our Grievance Officer and we will delete it.

Changes to this page

We review this page at least once a year, and we update it whenever what we do changes. If we make a material change we will tell you here, by email, or by a notice on our home page, at least thirty (30) days before the change takes effect. The date at the top of this page tells you when it was last updated.