Krunus Privacy Policy
Last updated: 10 August 2026
This policy explains what personal data KRUNUS LTD collects, why, and what you can do about it. We are a company registered in England and Wales, company number 15763741, and we are registered with the UK Information Commissioner's Office as a data controller. You can contact us about anything in this policy at info@krunus.com.
We are the controller of the data described in section 1 — the data about you as our customer. Where you use our hosting to run your own website or application, we are a processor of the personal data you put on it; that is covered in section 7.
1. What we collect and why
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Name, email address, postal address, phone number, and for business customers the company name and VAT number | To open your account, provide the services, invoice you correctly, and calculate VAT | Performance of a contract; legal obligation for tax records |
| Billing records — invoices, amounts, dates, the last four digits and card type of the payment method | To take payment, handle renewals and refunds, and meet our accounting obligations | Contract; legal obligation |
| Technical data — IP addresses, access and error logs, authentication events | To run the platform, investigate faults, and detect and prevent abuse, fraud and intrusion | Legitimate interests (security and service integrity) |
| Support tickets and email correspondence, including anything you tell us in them | To answer you and to keep a record of what was agreed | Contract; legitimate interests |
| Messages you send to our AI support assistant | To generate an answer to your question — see section 4 | Contract; legitimate interests |
| Domain registration details — the registrant name, address, email and phone you give us | To register the domain in your name — see section 5 | Contract; legal obligation under registry and ICANN rules |
We never see your card details. Payments are handled entirely by Stripe and PayPal. Your card number does not pass through our systems and we do not store it.
2. Where your data lives
Krunus is a UK company, and our production infrastructure is located in the European Union. Our encrypted off-site backups are held in the European Union as well. If you need to know the specific country a particular service runs in, ask us and we will tell you.
Transfers from the UK to the EU are covered by the UK's adequacy regulations for the EEA. Where we use a supplier outside the UK and EEA (see section 3), that transfer is covered by the UK International Data Transfer Addendum, Standard Contractual Clauses, or an applicable adequacy decision, as appropriate.
3. Who else processes your data
We use a small number of suppliers to run the business. Each one is bound by a contract that restricts what they may do with your data.
| Supplier | What they do | Where |
|---|---|---|
| Stripe | Card payments and subscription charges | Ireland / United States |
| PayPal | PayPal payments | Luxembourg / United States |
| Hetzner Online GmbH | Hosting infrastructure and encrypted backup storage | European Union |
| OVH SAS | Hosting infrastructure for our billing platform | European Union |
| Openprovider | Domain registrar | European Union |
| EmailArray / PolarisMail | Outbound email delivery | United States |
| Anthropic | The AI model behind our support assistant | United States |
| Let's Encrypt (ISRG) | TLS certificate issuance | United States |
We do not sell your personal data, and we do not share it with advertisers or data brokers.
4. Our AI support assistant
Our support assistant is powered by a large language model provided by Anthropic. When you send it a message, the text of that message is transmitted to Anthropic in order to generate a reply. Do not paste passwords, API keys, card numbers or other secrets into it — as with any support channel.
Anthropic processes this text on our behalf as a processor and under contract does not use it to train its models. If you would prefer not to use it, every question can be raised instead by email or by opening a normal support ticket, and a human will answer.
5. Domain registrations and WHOIS
If you register or transfer a domain through us, the registrant details you provide are passed to the registrar and to the registry that operates the extension. Registries are required to hold this data, and depending on the extension and on your status as an individual or an organisation, some of it may be published in a public WHOIS or RDAP record.
This is a requirement of the domain name system, not a choice we make. Where the registry supports privacy protection we will tell you at the point of purchase; some extensions do not offer it at all.
6. How long we keep things
- Billing and tax records — six years after the end of the accounting period they relate to, because UK tax law requires it. This is why closing your account does not erase your invoices.
- Account and contact data — for as long as you have an account, and then for the period above where it forms part of a billing record.
- Hosting content and databases — 14 days after a service is terminated, then deleted, unless we are required to preserve it.
- Access and security logs — normally 90 days.
- Support tickets — three years after the ticket is closed.
- Backups — encrypted backups rotate on their own schedule, so data may persist in a backup for a short period after deletion from the live system. It is not restored to the live system except as part of a disaster recovery.
7. When you are the controller
When you use our hosting to run your own site, you decide what personal data you collect from your own visitors and customers. For that data you are the controller and we are your processor. We process it only to provide the hosting, we do not access it except where necessary to run or repair the service or where the law requires it, and we apply the security measures described in section 8.
If you need a signed data processing agreement recording this — many business customers do — email us and we will provide one.
8. How we protect it
Accounts on our shared platform are isolated from one another at the operating-system level, with enforced resource limits and per-account filesystem confinement. Administrative access to our infrastructure is restricted to named individuals using SSH keys; password authentication is disabled everywhere. Provider credentials and other secrets are encrypted at rest. All customer-facing traffic is served over TLS. Backups are encrypted before they leave the machine, to keys the storage provider does not hold.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours as required, and we will tell you directly where the risk is high.
9. Cookies
We use cookies that are strictly necessary to make the site and your account work — keeping you signed in, remembering your basket, and protecting forms against cross-site request forgery. These do not require consent and cannot be switched off without breaking the service.
We do not use advertising or cross-site tracking cookies. If we ever introduce analytics or marketing cookies we will ask for your consent first and give you a way to withdraw it.
10. Your rights
Under the UK GDPR and, where you are in the EU, the EU GDPR, you have the right to:
- ask what personal data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we do not have an overriding obligation to keep it — note that tax law prevents us erasing invoices;
- restrict or object to processing we carry out on the basis of legitimate interests;
- receive the data you gave us in a portable, machine-readable form;
- withdraw consent at any time, where we relied on consent.
To exercise any of these, email info@krunus.com. We will respond within one month. We do not charge for this.
If you are unhappy with how we have handled your data you can complain to the UK Information Commissioner's Office at ico.org.uk. If you are in the EU, you may instead complain to the supervisory authority in the country where you live or work.
11. Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always tells you when it last changed.