Version 1.0 — Effective 20 March 2026 — Reviewed annually. Next review due 20 March 2027.
1. Introduction
Vatora Limited ("Vatora", "we", "us", "our") is committed to handling personal data responsibly, transparently, and in full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what your rights are.
This policy applies to personal data collected through our website (vatora.uk), through the provision of our services, through our support channels, and through any other interaction you have with Vatora.
Please read this policy carefully. If you have any questions, contact our Data Protection Officer (DPO) using the details in section 14.
2. Who We Are
The data controller for personal data collected through vatora.uk and in connection with our services is:
Vatora Limited
Company No. 16241301
West Midlands House, Willenhall, WV13 2HA, United Kingdom
Email: [email protected]
Data Protection Officer:
Email: [email protected]
Telephone: 01922 333 406
ICO Registration: Vatora Limited is registered with the Information Commissioner's Office under registration reference ZB870934 (registered 27 February 2025, Tier 1). You can verify this registration at ico.org.uk.
3. Data We Collect
The personal data we collect depends on how you interact with us. Categories of personal data we may process include:
- Identity data: name, job title, company name.
- Contact data: email address, telephone number, postal address.
- Financial data: billing address, payment records (we do not store full payment card details — these are handled by our payment processor).
- Technical data: IP addresses, browser type and version, device identifiers, server access logs, and usage data generated through interaction with our website or services.
- Account data: login credentials, service configuration, API keys (stored in hashed or encrypted form).
- Communications data: the content of emails, contact forms, and support tickets.
- Network data: for IP subnet and ASN customers, routing data and RIPE WHOIS registration information associated with leased address space.
We do not knowingly collect personal data from persons under 18 years of age. If you believe we have inadvertently collected data relating to a minor, please contact us immediately at [email protected].
4. How We Collect Data
We collect personal data through the following means:
- Directly from you: when you complete a contact or ENQUIRY form, place an order, register for a service, or communicate with us by email, telephone, or live chat.
- Automatically: through our website and service infrastructure, including server logs, cookies, and analytics tools, when you visit vatora.uk or use our services.
- From third parties: where you are introduced to us by a third party, or where we receive your contact details in the context of a business referral.
- From public sources: for network services customers, publicly available RIPE WHOIS data.
5. Lawful Basis for Processing
We process personal data only where we have a lawful basis for doing so under UK GDPR Article 6. The table below sets out our processing activities and the lawful basis for each.
| Processing Activity |
Lawful Basis |
| Responding to enquiries and contact form submissions |
Legitimate interests (responding to business enquiries) |
| Providing contracted services and managing service accounts |
Performance of a contract |
| Invoicing and processing payments |
Performance of a contract; Legal obligation (HMRC) |
| Maintaining financial and business records |
Legal obligation (Companies Act, tax legislation) |
| Providing technical support and handling support tickets |
Performance of a contract |
| Security monitoring, incident detection, and infrastructure protection |
Legitimate interests (protecting our infrastructure and customers) |
| Network services — RIPE WHOIS data for leased IP space |
Performance of a contract; Legal obligation (RIPE policy) |
| Website analytics and performance monitoring |
Legitimate interests (improving our website and services) |
| Fraud prevention and abuse detection |
Legitimate interests; Legal obligation |
| Sending service notifications and updates |
Performance of a contract; Legitimate interests |
| Marketing communications (where opted in) |
Consent |
| Compliance with legal obligations and regulatory requirements |
Legal obligation |
Where we rely on legitimate interests as our lawful basis, we have conducted a legitimate interests assessment to ensure our interests are not overridden by the rights and interests of the individuals concerned. You may request a copy of any legitimate interests assessment by contacting our DPO.
6. How We Use Your Data
We use your personal data only for the purposes described in section 5. We do not sell personal data to third parties. We do not use personal data for automated decision-making or profiling in ways that produce legal or similarly significant effects.
Where we process personal data on behalf of a customer as a data processor (for example, personal data stored by a customer on Vatora-managed infrastructure), we process that data solely as instructed by the customer and for no other purpose.
7. Third-Party Processors
We share personal data with third-party service providers where necessary to operate our services and our business. All third-party processors are bound by data processing agreements and may only process personal data on our instruction. Our current third-party processors include:
- Cloudflare, Inc. (United States) — Content delivery, DDoS mitigation, DNS management, and web security for vatora.uk. Data transfer safeguard: UK-US Data Bridge and Standard Contractual Clauses.
- MailChannels Corporation (Canada) — Outbound email filtering for managed hosting email services. Transfer safeguard: Standard Contractual Clauses. Canada holds an EU adequacy decision; UK-Canada transfers are treated as adequate.
- RIPE (Netherlands) — Internet registry data for network services customers, including WHOIS registration. Transfers within the EEA are covered by UK adequacy decisions for the EU.
- Payment Processing Provider — Processing of payments for Vatora services. Full card data is handled solely by our payment processor and is not stored by Vatora. We will update this entry with the specific provider name upon finalisation.
- Trustpilot A/S (Denmark) — Review and reputation management platform. Transfers covered by EEA/EU adequacy.
- GitHub, Inc. (Microsoft) (United States) — Source code management and CI/CD pipeline tooling used in DevOps services. Transfer safeguard: Standard Contractual Clauses.
We review our third-party processor relationships regularly and will update this list when processors change. You can request a current list from our DPO at any time.
8. International Transfers
Vatora's primary infrastructure is located in the United Kingdom (Coventry, London) and the Netherlands (Amsterdam). UK-to-Netherlands transfers are covered by the UK's adequacy decision for the European Economic Area.
Some of our third-party processors (including Cloudflare and GitHub) are based in the United States. Transfers of personal data to the United States are protected by one or more of the following safeguards: the UK-US Data Bridge, Standard Contractual Clauses approved by the ICO, or equivalent UK transfer mechanisms. Where we rely on Standard Contractual Clauses, we carry out a transfer impact assessment to ensure the level of protection afforded in the destination country is essentially equivalent to that in the UK.
We do not transfer personal data to countries that do not have adequate data protection frameworks without appropriate safeguards in place. You may request further information about the safeguards we use by contacting our DPO.
9. Data Retention
We retain personal data for no longer than necessary for the purposes for which it was collected, in accordance with UK GDPR Article 5(1)(e). Our retention schedules are set out in full in our Data Retention Policy. In summary:
- Customer account and contract records are retained for the duration of the relationship and for 6 years following termination.
- Financial and billing records are retained for 7 years to meet HMRC requirements.
- Support and correspondence records are retained for 3 years from closure.
- System access and security logs are retained on a rolling 90-day basis; logs relating to security incidents are retained for 3 years.
- Website analytics data is retained for 12 months.
- Marketing contact data is retained until consent is withdrawn.
10. Your Rights
Under UK GDPR, you have the following rights in relation to personal data we hold about you as data controller. We will respond to all valid requests within one calendar month of receipt, as required by UK GDPR Article 12.
- Right of access (Article 15): to request a copy of the personal data we hold about you.
- Right to rectification (Article 16): to request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): to request deletion of your personal data where there is no longer a lawful basis for us to retain it, subject to legal retention obligations.
- Right to restriction of processing (Article 18): to request that we restrict processing of your personal data in certain circumstances.
- Right to data portability (Article 20): to receive personal data you have provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Right to object (Article 21): to object to processing based on legitimate interests or for direct marketing. Where you object to direct marketing, we will cease processing immediately. Where you object to legitimate interests processing, we will cease unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
- Rights in relation to automated decision-making: not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects. We do not carry out such processing.
To exercise any of these rights, contact our DPO at [email protected] or by telephone on 01922 333 406. We may need to verify your identity before processing a request.
Where Vatora holds personal data as a data processor on behalf of a customer, data subject requests relating to that data should be directed to the customer (the data controller) in the first instance. We will assist customers in fulfilling such requests in accordance with UK GDPR Article 28.
11. Cookies
Our website uses cookies and similar technologies. Essential cookies are required for the website to function and are set automatically. We do not set non-essential cookies without your consent.
We use Cloudflare's services for website security and performance, which may set cookies as part of their operation. For details of how Cloudflare handles data, see Cloudflare's Privacy Policy.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect website functionality.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or by posting a notice on our website before the change takes effect. The current version is always available at vatora.uk/privacy-policy.
14. Contact and Complaints
For any data protection ENQUIRY, rights request, or concern, please contact our DPO:
Data Protection Officer
Email: [email protected]
Telephone: 01922 333 406
Post: Data Protection Officer, Vatora Limited, West Midlands House, Willenhall, WV13 2HA
If you are not satisfied with how we have handled your personal data or with our response to a request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113
We would appreciate the opportunity to address any concerns directly before you contact the ICO, but you are entitled to contact the ICO at any time.