Last updated: 18 September 2026
This page explains how ElySpace handles personal data, which data protection laws apply to us, what your rights are, and how to use them. It covers the EU General Data Protection Regulation (GDPR), the UK GDPR and the Data Protection Act 2018, the Digital Personal Data Protection Act 2023 in India, and the privacy laws of the US states where they are in force.
It sits alongside our Privacy Policy, which describes in detail what personal data we collect and why, and our Cookie Policy, which covers cookies and similar technologies. Where this page and those documents overlap, they are meant to say the same thing; if you find a difference, please tell us and we will fix it.
ElySpace IT Services LLP is established in India. We sell our services to customers in the United States, Canada, the United Kingdom, the European Union and India, we price our services in US Dollars, Euro and Indian Rupees, and we operate servers in several countries, as set out in section 3.1 of our Service Agreement. Because of that, more than one data protection law applies to us at the same time:
Nothing in our Service Agreement, our Domain Agreement or our Affiliate Terms (including the clauses in those documents that choose the law of Delaware or of Washington State) limits your rights under these data protection laws, or your right to bring a claim or a complaint where you live.
ElySpace IT Services LLP is an Indian limited liability partnership, LLP registration number AAV-5130, with its registered office at Watergam, Baramulla, Jammu and Kashmir, 193303, India. We are the controller (in Indian terms, the Data Fiduciary) of the personal data described in our Privacy Policy.
We trade as ElySpace at elyspace.com and we run our client area and billing system at my.elyspace.com.
You can reach us about anything on this page by email at [email protected], by opening a ticket at my.elyspace.com/submitticket.php, or by post at ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India.
Our data protection contact. ElySpace has not designated a Data Protection Officer and does not use that title. The person able to answer questions about our processing is Jahangir Ahmad War, Chief Operating Officer, who can be reached at [email protected]
Our Grievance Officer. If you are in India, or you would prefer to use our formal grievance route wherever you are, you can contact our Grievance Officer:
We acknowledge every grievance within 24 hours and give you a ticket number, and we aim to resolve it within 15 days of receiving it. The full procedure is set out under Grievance Redressal in our Terms of Service.
Our representatives in the EU and the UK. Because we are established in India and not in the European Union or the United Kingdom, Article 27 of the GDPR and Article 27 of the UK GDPR require us to appoint representatives there, unless a narrow exemption applies. Until the details of a representative are published here, contact us directly at [email protected] about anything to do with our processing of your personal data.
ElySpace acts as both a data controller and a data processor, and which one we are depends on whose data it is.
We are a controller for the personal data we collect to run our own business and our relationship with you: your account and contact details, your billing records and payment history, your support tickets and correspondence, our server and security logs, and the information collected about visitors to elyspace.com. We decide why and how that data is used, and our Privacy Policy is our notice to you about it.
We are a processor for the personal data that you put onto our platform: the contents of your website, your databases, your mailboxes, your uploaded files and the backups of them. We hold that data on your behalf and process it on your instructions. We do not decide what personal data you collect from your own users, why you collect it, or how long you keep it. Towards those people, you are the controller, and you owe them the duties that data protection law places on a controller.
This split has practical consequences we take seriously. We do not routinely inspect the content you host with us and we have no obligation to do so. Where we do need to access it, to give you technical support you have asked for, to operate, secure, back up or repair the service, to investigate a suspected breach of our Resource Usage Policies or a security incident on our network, or where we are compelled to by a law that applies to us, we access the minimum we need, and we tell you where we are lawfully able to.
Data protection law requires us to have a lawful reason for every use we make of your personal data, and to tell you what that reason is. We set them out purpose by purpose in the Privacy Policy. In summary, most of what we do rests on the contract between us: we cannot host your site or register your domain without processing your details. Some of it rests on legal obligations, such as keeping tax and accounting records. Some of it rests on our legitimate interests, such as keeping our network secure and preventing fraud, and where we rely on that you can object. Analytics and advertising technologies, and marketing messages, rest on your consent, which you can withdraw at any time.
For people in India, our lawful basis is either your consent under section 6 of the Digital Personal Data Protection Act 2023 or one of the specific legitimate uses listed in section 7 of that Act. India does not have a general “legitimate interests” basis, and we do not rely on one for Indian users.
If the GDPR or the UK GDPR applies to our processing of your data, you have the following rights. They are free to use, and for most of them you do not have to give a reason.
When we cannot do what you ask. Erasure in particular has limits, and we would rather be straight with you about them than promise something we cannot deliver. We have to keep billing, tax and accounting records for the periods Indian law requires. We have to keep some domain registration data for as long as ICANN and the relevant registry require it. Indian rules that apply to us as a provider of servers and hosting require us to keep certain subscriber records for a set period after an account closes. See How long we keep your personal data. And we may need to keep data to establish, exercise or defend a legal claim. If we cannot delete something you have asked us to delete, we will tell you which of these applies.
Tell us which right you want to use and give us enough information to find your records. The quickest route, if you have an account, is a ticket at my.elyspace.com/submitticket.php, because you are already signed in and we can identify you straight away. You can also email us at [email protected] or write to us at the address above.
If we cannot be sure who you are, we will ask you for proof of identity, and we will only ask for what we genuinely need to be sure. We will never ask you to send us a copy of a payment card.
Our timeframes. We answer requests under the GDPR and the UK GDPR within one month of receiving them. If a request is complicated, or if you have made several, we may need up to two further months. If that happens we will tell you inside the first month and explain why. We do not charge for this. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and if we refuse we will tell you why and tell you how to complain.
Where a request reaches us through an authorised agent, or through a Consent Manager registered with the Data Protection Board of India, we act on it in the same way as one that comes directly from you.
If you are in India, the Digital Personal Data Protection Act 2023 gives you these rights over the personal data we hold about you as a Data Fiduciary:
You may also give, manage, review or withdraw consent through a Consent Manager registered with the Data Protection Board. We will act on instructions received that way in the same manner as instructions received directly from you.
The Act also places a duty on you not to impersonate another person when exercising these rights and not to make a false or frivolous complaint. We mention it because the Act does; it is not a discouragement from contacting us.
The fuller version of this section, including what we collect, how long we keep it, consent and withdrawal, children, and how to complain to the Data Protection Board, is in our Privacy Policy.
How long we take. We answer a request under the Digital Personal Data Protection Act 2023 within fifteen (15) days of receiving it, which is the same period we give ourselves for a grievance. Where we have to establish who you are before we can act, that period runs from the point at which we have what we need, and we tell you what that is inside the same fifteen days.
The Act and the rules made under it come into force in stages, and each obligation binds us from the date notified for it. We are not waiting for those dates to answer you: the rights set out above are open to you now, on the timescales given on this page, and any obligation that is not yet in force we will meet from the day it is.
We are based in India and we run servers in several countries. Personal data we hold will therefore be sent to, and stored in, countries outside the European Economic Area and outside the United Kingdom.
Some of those countries have been formally recognised by the European Commission, or by the UK government, as giving personal data a level of protection essentially equivalent to the protection it has in the EEA or the UK. Canada is one, for commercial organisations. Transfers to companies in the United States are covered where the company receiving the data is certified under the EU–US Data Privacy Framework, or its UK Extension for UK data.
India and Singapore have not been recognised in this way. Where the GDPR or the UK GDPR requires a safeguard for a transfer, we are responsible for providing one those laws recognise. Google, Meta and Cloudflare build the European Commission’s Standard Contractual Clauses into their business terms or are certified under the Data Privacy Framework.
You can ask us which safeguard applies to your data. Write to [email protected].
Data leaving India. Under section 16 of the DPDP Act 2023, personal data may be transferred outside India except to a country the Central Government restricts by notification. We will comply with any such notification. Separate rules apply to payment data under the Reserve Bank of India’s directions.
We keep personal data only as long as we need it, and then we delete it or anonymise it. Several laws that apply to us set minimum periods we cannot go below: Indian tax and company law for financial records, Indian rules on intermediaries and on providers of servers and cloud services for subscriber and log data, and ICANN and registry rules for domain registrations. The full schedule is in the Privacy Policy.
Where we cannot delete something immediately (for example because it sits in an encrypted backup that rotates on a schedule), we isolate it from active use and delete it when that backup is next overwritten.
We use other companies to help us run our business, and some of them process personal data on our behalf. They are our processors, they act only on our instructions, and they are bound by contract to protect the data and not to use it for their own purposes.
The categories are: infrastructure and data centre providers; our billing, client area and ticketing platform; payment providers; our domain registration provider; analytics and advertising providers; content delivery and security providers; and email delivery providers.
The companies we can name today are:
We also use payment providers, infrastructure and data centre providers, and email delivery providers. You can ask us for their names at [email protected].
If you are a business customer and you store other people’s personal data on our platform, you need a written data processing agreement with us. Article 28 of the GDPR requires it, and your own compliance depends on having one.
Contact us at [email protected] to put a data processing agreement in place before you store other people’s personal data with us.
If there is a security incident that affects personal data, we investigate it immediately and contain it. What happens next depends on who the data belongs to and which law applies.
We keep a record of every personal data breach we become aware of, including the ones we decide do not need to be reported, and why.
If you are not happy with how we have handled your personal data, please tell us first. We would rather fix it. But you always have the right to complain to a regulator, and using our complaints process does not take that right away.
Our Cookie Policy lists every cookie and similar technology we use, what it is for, who sets it and how long it lasts, and it explains how to give, change or withdraw your consent.
In short: cookies that are strictly necessary to make the site and the client area work are always on. Everything else (analytics, our support chat, and advertising and measurement) is only set if you agree to it, and you can change your mind at any time from the “Cookie preferences” link in the footer of every page.
Both the GDPR, in Article 32, and the DPDP Act 2023, in section 8(5), require us to put appropriate technical and organisational measures in place and to keep them appropriate as risks change. Our Privacy Policy describes the measures we use: encryption in transit and at rest, least-privilege access control for our staff, two-factor authentication for your client area and for cPanel and WHM, vulnerability scanning, and monitoring of our infrastructure.
Separately from the backups we provide as part of your hosting service, we maintain our own ability to restore the personal data we hold about you as our customer.
Our services are sold to adults. You must be 18 or over to open an account with us, which is the same age our Service Agreement requires. We do not knowingly collect the personal data of anyone under 18 without verifiable parental or guardian consent, and we do not direct behavioural tracking or targeted advertising at children. If you believe a child has given us personal data, contact us at [email protected] or our Grievance Officer and we will delete it.
We review this page at least once a year, and we update it whenever what we do changes. If we make a material change we will tell you here, by email, or by a notice on our home page, at least thirty (30) days before the change takes effect. The date at the top of this page tells you when it was last updated.