Last updated: 18 September 2026
ElySpace IT Services LLP. ("ElySpace") has created this privacy statement in order to demonstrate our commitment to privacy to our customers and users of our consulting services, online services, websites, and web services ("Services"). This privacy policy governs the manner in which ElySpace uses, maintains and discloses information collected from its customers and users of our Services.
ElySpace IT Services LLP is an Indian limited liability partnership, LLP registration number AAV-5130, with its registered office at Watergam, Baramulla, Jammu and Kashmir, 193303, India. We are the controller (the Data Fiduciary, in Indian terms) of the personal data described in this policy, and we are the agency that collects and retains it.
We sell to customers in the United States, Canada, the United Kingdom, the European Union and India, we price in US Dollars, Euro and Indian Rupees, and we run servers in several countries. More than one privacy law therefore applies to us at once: the EU GDPR, the UK GDPR and the Data Protection Act 2018, India’s Digital Personal Data Protection Act 2023, and US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act.
This policy is written to cover all of them. Where a right or a rule applies only in one place, we say so. Nothing in our Service Agreement, Domain Agreement or Affiliate Terms (including the clauses that choose the law of Delaware or of Washington State) limits your rights under these laws or your right to complain where you live. Our Data Protection page gives an overview of the same ground.
Write to us at [email protected], open a ticket at my.elyspace.com/submitticket.php, or write to ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India.
ElySpace has not designated a Data Protection Officer and does not use that title. The person able to answer questions about our processing is Jahangir Ahmad War, Chief Operating Officer, who can be reached at [email protected]
If you are in the EU or the UK. Contact us directly at [email protected] about anything to do with your personal data.
If you have a complaint about how we have handled your personal data, or about anything else, you can bring it to our Grievance Officer.
You can also open a ticket at my.elyspace.com/submitticket.php and mark it for the Grievance Officer.
We acknowledge every complaint within 24 hours and give you a ticket number, and we resolve it within 15 days of receiving it. The full procedure, including what to include in a complaint and what you can do if you are not satisfied with our answer, is set out under Grievance Redressal in our Terms of Service.
The same person is the contact for questions about how we process your personal data. If your complaint is about your personal data and our answer does not resolve it, you may complain to the Data Protection Board of India. See India: your rights under the Digital Personal Data Protection Act 2023 below.
ElySpace is committed to developing long-lasting relationships based on trust. As such, ElySpace will do everything in its power to ensure that your right to privacy is maintained and protected. You must be 18 or older to open an account with us, and our Services are not directed at children. See Children and age limits below.
ElySpace IT Services LLP cares about your privacy. For this reason, we collect and use personal data only as it might be needed for us to deliver to you our world-class products, services and websites (collectively, our"Services"). Your personal data includes information such as:
Our Privacy Policy is intended to describe to you how and what data we collect, and how and why we use your personal data. It also describes options we provide for you to access, update or otherwise take control of your personal data that we process.
If at any time you have questions about our practices or about any of the rights described in this policy, use the routes under Who to contact about your personal data above.
We collect information so that we can provide the best possible experience when you utilize our Services. Much of what you likely consider personal data is collected directly from you when you:
However, we also collect additional information when delivering our Services to you to ensure necessary and optimal performance. These methods of collection may not be as obvious to you, so we wanted to highlight and explain below a bit more about what these might be (as they vary from time to time) and how they work:
Account related information is collected in association with your use of our Services, such as account number, purchases, when products renew or expire, information requests, support requests, and notes or details explaining what you asked for and how we responded.
Cookies and similar technologies on our websites collect information about how you use and interact with our Services, and about the device you use. What each one is, who sets it, what it does, how long it lasts and whether it needs your consent is set out in our Cookie Policy, and the summary is under Cookies, tracking and your choices below.
Data about Usage of Services is automatically collected when you use and interact with our Services, including metadata, log files, cookie/device IDs and location information. This information includes specific data about your interactions with the features, content and links (including those of third-parties, such as social media plugins) contained within the Services, IP address, browser type and settings, the date and time the Services were used, information about browser configuration and plugins, language preferences and cookie data, information about devices accessing the Services, including type of device, what operating system is used, device settings, application IDs, unique device identifiers and error data, and some of this data collected might be capable of and be used to approximate your location.
Data from other sources. If you provide us with personal information about other people, or if other people give us your information, we will only use that information for the specific reason for which it was provided to us. Where information about you reaches us this way, we will tell you where it came from if you ask, and we will not send you marketing on the strength of it unless you have separately told us that you want to hear from us.
We strongly believe in both minimising the data we collect and limiting its use and purpose to only that (1) for which we have been given permission, (2) as necessary to deliver the Services you purchase or interact with, or (3) as we might be required or permitted for legal compliance or other lawful purposes. These uses include: Delivering, improving, updating and enhancing the Services we provide to you. We collect various information relating to your purchase, use and/or interactions with our Services. We utilize this information to:
Often, much of the data collected is aggregated or statistical data about how individuals use our Services, and is not linked to any personal data, but to the extent it is itself personal data or is linked or linkable to personal data, we treat it accordingly.
Sharing with trusted third parties. We may share your personal data with third parties with which we have partnered to allow you to integrate their services into our own Services, and with trusted third party service providers as necessary for them to perform services on our behalf, such as:
We only share your personal data as necessary for any third party to provide the services as requested or as needed on our behalf. These third parties (and any subcontractors) are subject to strict data processing terms and conditions and are prohibited from utilizing, sharing or retaining your personal data for any purpose other than as they have been specifically contracted for (or without your consent).
Communicating with you. We may contact you directly or through a third party service provider regarding products or services you have signed up to or purchased from us, such as necessary to deliver transactional or service-related communications. We may also contact you with offers for additional services we think you’ll find valuable. Where you are in India, we send you those offers only if you have given us your consent, and you can withdraw that consent at any time. See India: your rights under the Digital Personal Data Protection Act 2023. Where you are in the European Union or the United Kingdom, we send them on the basis set out under Why we use your personal data, and our legal basis. You don’t need to provide consent as a condition to purchase our goods or services. These contacts may include:
You may also update your subscription preferences with respect to receiving communications from us and/or our partners in your client area at my.elyspace.com, or by opening a ticket at my.elyspace.com/submitticket.php.
If we collect information from you in connection with a co-branded offer, it will be clear at the point of collection who is collecting the information and whose privacy policy applies. In addition, it will describe any choice options you have in regards to the use and/or sharing of your personal data with a co-branded partner, as well as how to exercise those options.
If you make use of a service that allows you to import contacts (eg. using email marketing services to send emails on your behalf), we will only use the contacts and any other personal information for the requested service. If you believe that anyone has provided us with your personal information and you would like to request that it be removed from our database, please open a ticket at my.elyspace.com/submitticket.php and we will remove it.
Transfer of personal data abroad. Your personal data will be sent to and stored in countries other than your own. How that is done and what protects it is set out under Sending your personal data to other countries below.
Compliance with legal, regulatory and law enforcement requests. We cooperate with government and law enforcement officials to enforce and comply with the law. We will disclose information about you to government or law enforcement officials where we are required to by a law that applies to us, or where it is necessary to respond to legal process such as a subpoena or a court order, to establish, exercise or defend a legal claim, or to protect the safety of the public or of any person.
To the extent we are legally permitted to do so, we will take reasonable steps to notify you in the event that we are required to provide your personal information to third parties as part of legal process. We will also share your information to the extent necessary to comply with ICANN or any ccTLD rules, regulations and policies when you register a domain name with us.
Website analytics and advertising. We use Google Tag Manager, Google Analytics, the Meta Pixel and Cloudflare Insights on our website. What each of them does, what it collects, who receives it and how to give, change or withdraw your consent is set out in our Cookie Policy and summarised under Cookies, tracking and your choices below.
Third-party websites. Our website and our mobile applications contain links to third-party websites. We are not responsible for the privacy practices or the content of third-party sites. Please read the privacy policy of any website you visit.
We have to have a lawful reason for everything we do with your personal data, and we have to tell you what it is. Here is the list, purpose by purpose. Where we name a GDPR article, the equivalent provision of the UK GDPR applies in the United Kingdom.
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and recorded that assessment. You can ask us for a summary of it, and you can object to that processing at any time. See Your rights over your personal data.
Do you have to give us your personal data? No, but we cannot open an account, take payment, register a domain name or give you support without the information marked as required when you sign up. If you do not give it to us, we cannot provide the service. Domain registries and ICANN require accurate registrant contact details; if you do not provide them, your domain registration can be suspended or cancelled.
If the GDPR or the UK GDPR applies to our processing of your data, you have the rights below. They are free to use and you do not have to give a reason for most of them.
How to use them. Open a ticket at my.elyspace.com/submitticket.php (the quickest route, because you are already signed in), or email [email protected], or write to us at our registered address. Tell us which right you want to use and give us enough to find your records. If we cannot be sure who you are we will ask for proof of identity, and only for what we genuinely need. We will never ask you to post or email us a copy of a payment card.
How long we take. One month. If your request is complicated, or if you have made several, we may need up to two further months, and we will tell you inside the first month and explain why. There is no charge. If a request is manifestly unfounded or excessive we may charge a reasonable fee or refuse it, and if we refuse we will tell you why and how to complain.
When we cannot delete something. We have to keep billing, tax and accounting records for the periods Indian law sets. We have to keep some domain registration data for as long as ICANN and the registry require. Indian rules that apply to providers of servers, VPS and cloud services require us to keep certain validated subscriber records for a period after an account closes. The periods are in How long we keep your personal data. And we may need to keep data to defend a legal claim. If we cannot delete something, we will tell you which of these applies rather than simply refusing.
When you place an order we run automated checks to detect fraud and payment abuse. They look at things like the payment method used, the billing address, the IP address and the device the order came from, and whether the order matches patterns we have seen in past fraudulent orders. If an order fails these checks we may decline it or hold it for review, and that decision can be made automatically.
If your order is declined by an automated check, you have the right to ask a member of our team to look at it, to explain your side of it, and to challenge the outcome. Open a ticket at my.elyspace.com/submitticket.php or email [email protected] and a person will review the decision.
This section applies to you if you are in India. It is our notice to you under section 5 of the Digital Personal Data Protection Act 2023, and it explains the rights that Act gives you and how to use them. The Act calls you a Data Principal and it calls us a Data Fiduciary, because we decide why and how your personal data is processed.
The rest of this Privacy Policy still applies to you. Where anything in this section says something different from another part of this policy, this section is the one that applies to people in India.
Who we are, for this purpose: ElySpace IT Services LLP, Watergam, Baramulla, Jammu and Kashmir, 193303, India. The person who can answer questions about how we process your personal data is Jahangir Ahmad War, Chief Operating Officer, and you can reach them through the details under Grievance Officer above.
Where an obligation under the Digital Personal Data Protection Act 2023, or under the rules made under it, has not yet been brought into force, we follow the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 in its place, and we give you the rights set out in this section as a matter of policy in the meantime, so that nothing you can ask us for here waits on a commencement date.
We process only the personal data we need, and only for the purposes listed below. Each item says what it is for, whether we rely on your consent or on a legitimate use permitted by the Act, and how long we keep it.
We do not sell your personal data.
We keep personal data only for as long as we need it for the purpose we collected it for, and then we delete it, unless a law requires us to keep it for longer. Where a law requires it, we keep it and we tell you why. The full schedule for all customers is under How long we keep your personal data. The Indian minimum periods are:
This means that cancelling an account does not always delete everything about you straight away. Where we are required to keep a record, we keep it, we do not use it for anything else, and we delete it when the period ends.
Where we rely on your consent, we ask for it clearly, for a specific purpose, before we process the data, and we do not bundle it with anything else. You do not have to consent to marketing in order to buy from us.
Withdrawing consent is as easy as giving it. You can withdraw at any time:
When you withdraw, we stop the processing that depended on that consent within a reasonable time, and we ask anyone processing that data on our behalf to do the same. Withdrawing does not make anything we did before you withdrew unlawful.
Be aware of the consequence, because the Act requires us to tell you: if you withdraw consent for something the service actually needs, we may not be able to continue providing that service. Withdrawing consent for marketing or for analytics has no effect on your service at all.
You may also give, manage, review or withdraw your consent through a Consent Manager registered with the Data Protection Board of India. We will act on an instruction that reaches us that way in the same manner as one that comes from you directly.
We keep a record of the consents you give and withdraw. On our website, your choice and the date you made it are stored in a consent cookie on your device, and advertising and analytics tags do not load until that record says you agreed. Consent you give in your client account, such as agreeing to marketing emails, is recorded in your account.
You must be 18 or older to open an account with us.
Separately from that, we do not knowingly process the personal data of anyone under 18 without the verifiable consent of a parent or lawful guardian, and we do not knowingly process the personal data of a person with a disability who has a lawful guardian without that guardian’s verifiable consent.
We do not carry out tracking or behavioural monitoring of children, and we do not direct advertising at children. The Act prohibits this outright, and consent (yours or a guardian’s) cannot make it permissible.
If you believe we hold a child’s personal data without the right consent, tell our Grievance Officer and we will look into it and delete it.
As a Data Principal you have the following rights in relation to the personal data you have given us, or that we hold about you because of something you asked us to do.
The Act also places some duties on you, and we set them out here so that you know about them rather than to discourage you from complaining. You must not impersonate another person when giving personal data; you must not suppress material information when giving personal data where the law requires it; you must not register a false or frivolous grievance or complaint; and the information you give us when asking for correction or erasure must be authentic. The Act provides for a penalty of up to INR 10,000 for breaching these duties.
If you are not satisfied with how we have answered a complaint about your personal data, you may complain to the Data Protection Board of India. The Act asks you to raise the matter with us first and give us the chance to resolve it, so please use our Grievance Officer before you go to the Board.
A complaint to the Board is made in the manner, and to the address, that the Board itself publishes. Ask our Grievance Officer and we will give you the Board's current details as they stand on the day you ask. We will not ask you to withdraw a complaint, and we will not treat you any differently for having made one.
This is in addition to, and not instead of, your other rights. If you are a consumer you may also complain to a consumer commission, including the one where you live or work.
We and the providers we use process personal data both inside and outside India. Section 16 of the Act permits this, except to a country or territory that the Central Government restricts by notification, and we will comply with any such notification if one is made. Where other Indian law imposes a stricter requirement, for example on where payment data may be stored, we follow that stricter requirement.
You can ask for this notice in English or in any language listed in the Eighth Schedule to the Constitution of India. Ask our Grievance Officer and we will provide it.
We are based in India and we run servers in several countries, so your personal data will be sent to and stored in countries other than your own. If you call us or start a chat, you may be helped from one of our locations outside your country.
Some countries have been formally recognised by the European Commission or by the UK government as giving personal data protection essentially equivalent to that in the EEA or the UK. Canada is one, for commercial organisations. Transfers to US companies are covered where the recipient is certified under the EU–US Data Privacy Framework, or its UK Extension for UK data.
India and Singapore have not been recognised in this way. Where the law of your country requires a safeguard for a transfer, we are responsible for providing one that the law recognises. Google, Meta and Cloudflare, whose services we use, build the European Commission’s Standard Contractual Clauses into their business terms or are certified under the EU–US Data Privacy Framework. You can ask us about the safeguard that applies to your data at [email protected].
Under section 16 of India’s DPDP Act 2023, personal data may be transferred outside India except to a country the Central Government restricts by notification; we will comply with any such notification. Payment data is handled in line with the Reserve Bank of India’s requirements.
We keep personal data only as long as we need it, and then we delete it or anonymise it. Some periods are set by laws that apply to us and we cannot go below them; where that is the case we say which law.
Where we cannot delete something immediately (for example because it sits in an encrypted backup that rotates on a schedule), we isolate it from active use and delete it when that backup is next overwritten.
Our Cancellations section warns that your files and emails may be removed immediately and permanently once a cancellation request is processed. That is true of your content. It is not true of the billing records and validated subscriber records listed above, which we are required to keep. We would rather you knew that than found it out later.
Where a period above is set by law, we apply that period and we do not shorten it; where it is not, we keep the record only while the purpose it was collected for still needs it, and we go through these categories at least once a year to check that nothing is being kept out of habit. If you want to know what we still hold about you, and for how long, ask us at [email protected] and we will tell you.
If there is a security incident that affects personal data, we investigate immediately and contain it.
Where we are the controller and the law requires it, we report the incident to the relevant data protection authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and if we report later than that, we say why. Where an incident is likely to put your rights or freedoms at high risk, we tell you directly and without undue delay, in plain language: what happened, what data was involved, the likely consequences, what we are doing about it, what we suggest you do, and who to contact for more.
Where the affected data is data you host with us, we are your processor and you are the controller. In that case we notify you without undue delay, with what we know about the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures we have taken or propose to take, and we keep you updated, and give you reasonable assistance, so that you can meet your own obligations.
In India we intimate affected individuals and the Data Protection Board without delay, and we report reportable cyber security incidents to CERT-In within the time its directions require. Where a US state breach notification law applies, we notify under that law as well.
We keep a record of every personal data breach we become aware of, including the ones we decide do not need to be reported, and why.
Our Grievance Officer, Jahangir Ahmad War, Chief Operating Officer, decides whether an incident has to be reported, and he, or somebody he names, makes the report to CERT-In, to the Data Protection Board of India and to the people affected. Because the CERT-In deadline is counted in hours rather than in working days, this route does not wait for office hours: whoever finds an incident escalates it to him straight away, on any day and at any hour, and if he cannot be reached the report is made without him rather than made late.
ElySpace may also disclose aggregate, anonymous, data based on information collected from Users to investors and potential partners. In such cases, statistical information only will be disclosed and personally identifiable data will be kept strictly confidential. In case ElySpace is sold, the information collected from users may be transferred to the new owners.
ElySpace may from time to time engage third parties, including its own subsidiaries and affiliated companies, to preserve, analyze or otherwise store or manipulate data received by ElySpace from its customers. In all such cases, such third party service providers will be required to treat all such data with the same degree of care as ElySpace and they will be prohibited from disclosing such data to any other person or party, except as otherwise provided for in this Privacy Policy.
Our customers and users will occasionally receive information on products, services, special deals, and possibly a newsletter. Out of respect for the privacy of our users we present the option to not receive these types of communications.
On rare occasions, it is necessary to send out a strictly service related announcement, if, for instance, our service is temporarily suspended for maintenance. Generally, users may not opt-out of these communications, though they can deactivate their account. However, these communications are not promotional in nature.
Though we make every effort to preserve your privacy, we may need to disclose personal information when required by law, if we have a good-faith belief that such action is necessary and required to comply with a current judicial proceeding, a court order or legal process served on ElySpace. ElySpace websites contain links to other sites. Please be aware that ElySpace is not responsible for the privacy practices of such other sites. We encourage you to read the privacy statements of each and every Web site that collect personally identifiable information. The ElySpace Privacy Policy as described herein applies solely to information collected by ElySpace.
The information you provide to ElySpace may be stored in one or more databases directly or indirectly maintained by ElySpace, and is kept for the periods set out under How long we keep your personal data above, not indefinitely. ElySpace employs industry standard security measures to protect the confidentiality of the information.
While we cannot guarantee that loss, misuse or alteration to data will not occur; we make every effort to prevent such occurrences. Any other particularly sensitive information, such as credit card numbers collected for commercial transactions, is encrypted prior to transmission by you to ElySpace.
You can access, edit and update your personal details in your client area at my.elyspace.com at any time. If you have any difficulty doing so, open a ticket at my.elyspace.com/submitticket.php and we will help.
We follow generally accepted standards to store and protect the personal data we collect, both during transmission and once received and stored, including utilisation of encryption where appropriate.
We retain personal data only for as long as necessary to provide the Services you have requested, and after that only where a law, a contract or the defence of a legal claim requires it. The period for each category of data is set out under How long we keep your personal data above.
If you have any questions about the security or retention of your personal data, use the routes under Who to contact about your personal data above.
You are responsible for the security of the login information, such as usernames and passwords, which give you access to your private information maintained by elyspace. Make sure you keep login information in a safe place and do not share it with others.
Note that key-loggers, viruses, or other surveillance devices can intercept login information on the computers from which you access our Services, so you should take precautions regarding such devices, especially from public computers. In addition, you should always log out from any relevant Services when you are not actively using them.
We reserve the right to modify this Privacy Policy at any time. If we decide to change our Privacy Policy, we will post those changes to this Privacy Policy and any other places we deem appropriate, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If we make material changes to this Privacy Policy, we will notify you here, by email, or by means of a notice on our home page, at least thirty (30) days prior to the implementation of the changes.
We implement technical and organisational measures appropriate to the risk, and we keep them appropriate as risks change. Article 32 of the GDPR and section 8(5) of India’s Digital Personal Data Protection Act 2023 both require this of us, and the measures below are what we do about it.
ElySpace operates global infrastructure designed to provide state-of-the-art security through the entire information processing lifecycle. This infrastructure is built to provide secure deployment of services, secure storage of data with end-user privacy safeguards, secure communications between services, secure and private communication with customers over the Internet, and safe operation by administrators.
We designed the security of our infrastructure in layers that build upon one another, from the physical security of our upstream providers ( Amazon, DigitalOcean, IBM, etc. ), to the security protections of our hardware and software, to the processes we use to support operational security. This layered protection creates a strong security foundation for everything we do.
ElySpace uses encryption to protect data in transit and at rest. Data in transit is protected using HTTPS, which is activated by default for all users and any other type of data is stored on machines that have at least 3 layers of security with limited access for anyone in the company.
For ElySpace employees, access rights and levels are based on job function and role, using the concepts of least-privilege and need-to-know to match access privileges to defined responsibilities. Requests for additional access follow a formal process that involves a request and an approval from a data or system owner, manager, or other executives, as dictated by ElySpace's security policies.
We scan for vulnerabilities using a combination of commercially available and purpose-built in-house tools, intensive automated and manual penetration testing, quality assurance processes, software security reviews, and external audits. We also rely on the broader security research community and greatly value their help identifying vulnerabilities in all of our products. We encourage researchers to report design and implementation issues that may put customer data at risk and most of the time we reward them with credit and free ElySpace services.
Each and every customer can enable two-factor authentication (2FA) greatly reduces the risk of unauthorized access by asking users for additional proof of identity when signing in. This can be enabled for your client area at my.elyspace.com and for cPanel/WHM as well; if you are not sure how, open a ticket at my.elyspace.com/submitticket.php and we will walk you through it.
On our infrastructure we also use an in house developed firewall that watch any suspicious login attempt and helps detect suspicious logins using robust machine learning capabilities also the entire infrastructure is monitored in real time 24/7/365 by real humans that can be proactive and take care of any kind of suspicious activity at the server level.
This section applies if you live in a US state with a comprehensive privacy law. It is written primarily to the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the differences that apply in other states are set out at the end.
In the last twelve months we have collected the following categories of personal information. For each we give examples, where it comes from, why we use it, and who we disclose it to. How long we keep each category is set out in How long we keep your personal data.
We do not sell your personal information for money, and we have not done so in the last twelve months.
We do share it, in the specific sense California law gives that word. Our site uses the Meta Pixel and Google advertising and analytics tags, and these send identifiers and information about your activity on our site to Meta and to Google for cross-context behavioural advertising and measurement. Under California law that is “sharing”, whether or not money changes hands, and you have the right to opt out of it. The categories shared are identifiers, internet or other electronic network activity information, and approximate geolocation. We do not share sensitive personal information, and we do not knowingly sell or share the personal information of anyone under 16.
Use the Do Not Sell or Share My Personal Information link in the footer of every page, which opens our cookie preference controls. Turning off the advertising category stops the sharing described above.
We also honour opt-out preference signals, including Global Privacy Control, as a valid opt-out request. If your browser or extension sends one, we treat it as an opt-out for that browser without you having to do anything else.
You do not need an account to opt out, and we will not ask you to create one. You can also send an opt-out through an authorised agent, in which case we may ask the agent for proof that you authorised them.
We do not offer any discount, credit, free domain or other incentive in exchange for your personal information, for accepting marketing, or for agreeing to data sharing.
Open a ticket at my.elyspace.com/submitticket.php, or email [email protected]. Those are our two designated methods. We will confirm we have your request within 10 business days and respond substantively within 45 calendar days, which we may extend once by a further 45 days if we need to, telling you why. We verify your identity before we disclose or delete anything; if you have an account, signing in is the easiest way for us to do that.
You can appeal. Reply to our decision within 60 days and ask for it to be reviewed, and we will tell you the outcome and our reasons within 60 days of receiving the appeal. If we still say no, we will tell you how to complain to your state Attorney General. This appeal route is required in several states, and we offer it to everyone.
If you live in a state whose law requires opt-in consent before sensitive data is processed, we will ask for it rather than relying on an opt-out. We recognise universal opt-out mechanisms in the states that require them, using the same signal handling described above. Residents of every state with a comprehensive privacy law have, at a minimum, rights to access, correct, delete and port their personal data, to opt out of targeted advertising and sale, and to appeal a refusal.
We give these rights to residents of those states as a matter of policy, whether or not the thresholds that make a particular state's law apply to a business of our size have been met, so you do not have to work out which law covers you before you ask.
We use cookies and similar technologies on elyspace.com and in our client area. Some are strictly necessary to make the site and your account work (keeping you signed in, remembering what is in your cart, protecting against attacks), and those are always on. Everything else, including analytics and advertising measurement, is only set if you agree to it.
Our Cookie Policy lists each cookie and technology individually: what it is, who sets it, what it does, how long it lasts and which category it is in. It also explains how to give, change or withdraw your consent, and how to control cookies in your browser.
You can change your choices at any time using the Cookie preferences link in the footer of every page. Withdrawing consent is as easy as giving it, and it takes effect straight away.
Our analytics and advertising providers are Google and Meta Platforms. Where you consent to advertising cookies, we and Meta Platforms are joint controllers for the collection of your data on our site and its transmission to Meta. We are responsible for having a lawful basis and for giving you this information, and Meta is responsible for what it does with the data afterwards. You can exercise your rights against either of us. The details are in the Cookie Policy.
Our services are sold to adults, and you must be 18 or over to open an account with us. That is the same age our Service Agreement requires, so there is one answer rather than two.
We do not knowingly collect personal data from anyone under 18 without verifiable parental or guardian consent, and we do not direct behavioural tracking or targeted advertising at children. Indian law prohibits that outright for anyone under 18, and consent does not make it lawful. If you believe a child has given us personal data, contact us at [email protected] or our Grievance Officer, and we will delete it.
None of this applies to personal data that our customers hold on the sites they host with us. For that data our customer is the controller, and it is governed by their own privacy notice and by our agreement with them.
If you are unhappy with how we have handled your personal data, tell us first (email [email protected] or open a ticket) and we will try to put it right. You do not have to, and using our process does not affect your right to go to a regulator.
If you have any questions, concerns or complaints about this Privacy Policy, about our practices, or about our Services, write to us at [email protected], open a ticket at my.elyspace.com/submitticket.php, or contact our Grievance Officer using the details under Grievance Officer above. We would rather hear from you and put something right than have you go elsewhere first.
You are not obliged to come to us first, and doing so does not affect your right to complain to a regulator. See Complaining to a data protection regulator above.