Legal

Privacy Policy

What we collect when you order and run infrastructure with us, why we hold it, and how long it stays.

Last updated: 7 September 2026

1. Who is responsible for your data

HBING LIMITED is the data controller for the personal data described in this policy. We decide why and how it is processed.

You can reach us about anything in this policy at legal@hbing.uk.

Our registered office is 124 City Road, London, United Kingdom, EC1V 2NX. Privacy requests are handled by our compliance team at that address or by email.

2. What we collect

  • Account data: name, company name, billing email, contact email, and any phone number you give us.
  • Order data: the products you ordered, their configuration, prices, invoices and payment status.
  • Payment data: the cryptocurrency asset used, the receiving address we generated for you, the transaction hash, the amount and the number of confirmations. We never hold card details because we do not accept cards.
  • Service data: IP addresses assigned to you, hostnames, rack and power allocation, and out-of-band management records.
  • Technical logs: IP address, timestamps, request paths and user agent for logins and portal actions; power actions requested through IPMI; and network flow records used for abuse and capacity work.
  • Support data: the content of tickets and emails you send us, including any attachments.

3. What we do not collect

We do not run advertising trackers, we do not sell personal data, and we do not build marketing profiles.

We do not inspect the content of data stored on your dedicated server or colocated equipment. We only look at traffic metadata when investigating abuse, an attack or a fault.

There is no public sign-up form, so we do not collect data from people who are not customers, other than the technical logs any web server keeps.

4. Why we process it and on what basis

  • To provide the service you ordered — performance of a contract.
  • To take payment, issue invoices and reconcile on-chain transactions — performance of a contract.
  • To keep accounting and tax records — legal obligation.
  • To respond to abuse reports, law enforcement requests and registry requirements — legal obligation and legitimate interests.
  • To keep the network secure, detect fraud and mitigate attacks — legitimate interests.
  • To send service notices such as maintenance windows and incident updates — legitimate interests. These are not marketing and cannot be switched off while you have an active service.

5. Cryptocurrency payments and blockchain data

Blockchains are public and permanent. When you pay us, the transaction, the amount, our receiving address and your sending address are visible to anyone, forever, and neither we nor you can delete or amend that record.

We store the transaction hash, asset, amount, confirmation count and the address we generated for your order so we can prove your invoice was paid. We do not attempt to identify the owners of sending addresses or to trace your wider wallet activity.

To confirm a payment we query public blockchain data through third-party nodes and explorers. Those queries contain the address or transaction hash involved, not your name.

Where a payment processor is used, it acts as a processor for us under a written agreement; API credentials are held on our servers and are never sent to your browser.

6. Who we share data with

We share personal data only where it is needed to run the service, and always under a contract that limits what the recipient may do with it.

  • Infrastructure and datacenter partners, for facility access and remote hands work.
  • Upstream carriers and registries, where required for IP address justification or abuse handling.
  • Payment and blockchain data providers, to confirm transactions.
  • Email delivery, ticketing and hosting suppliers that operate our own systems.
  • Accountants, auditors and lawyers, and public authorities where we are legally required to disclose.
  • A buyer or successor, if the business or part of it is transferred — you will be told before that happens.

7. International transfers

Some of our suppliers operate outside the country where you are based. Where personal data is transferred internationally we rely on an adequacy decision where one exists, or on standard contractual clauses together with additional safeguards.

Our suppliers operate in the United Kingdom, the European Economic Area, the United States, South Africa and Türkiye. Transfers outside the UK and EEA are made under the UK International Data Transfer Addendum or the EU standard contractual clauses.

8. How long we keep it

  • Account and service records: for the life of the service and then for the period required by law.
  • Invoices, payment records and transaction hashes: normally seven years, to meet accounting and tax rules.
  • Portal and authentication logs: 90 days on a rolling basis, longer only where an investigation is open.
  • Abuse and incident records: as long as needed to handle the matter and to defend legal claims.
  • Support tickets: 24 months after the ticket is closed.
  • Server content after termination: deleted permanently after the grace period stated in the Terms of Service.

9. Security

Passwords are stored hashed, never in plain text. Portal sessions are protected and expire, and state-changing actions are protected against cross-site request forgery.

Authorisation is enforced server-side and scoped per account, so one customer cannot read or act on another customer's services, invoices or management interfaces.

Out-of-band management credentials are stored server-side only. Requests you make from the portal are executed by our systems; the credentials themselves are never sent to your browser.

API keys and payment secrets exist only in server-side configuration. Access to production systems is limited to staff who need it and is logged.

10. Your rights

Depending on where you live, you can ask for a copy of your data, ask for it to be corrected or deleted, object to or restrict certain processing, and ask for it in a portable format.

Some data cannot be deleted on request — invoices and payment records we must keep for tax purposes, and blockchain records that are outside anyone's control.

To exercise a right, email legal@hbing.uk. We answer within one month and may ask you to confirm your identity first. If you are unhappy with our answer you can complain to your local data protection authority.

11. Deleting your account yourself

You can delete your account at any time from Settings in the customer portal. This removes your login, profile details, username, profile photo and support conversations from our systems immediately.

Active or provisioning services must be cancelled with support first, so that we do not delete the account behind running hardware.

Invoices, payment records and abuse-related logs we are legally required to keep are retained for the periods listed above and are no longer linked to a usable login. Blockchain transactions remain public and cannot be removed by us or anyone else.

12. Cookies

We use only the cookies and local storage entries needed to keep you signed in to the customer portal and to remember basic interface preferences. There are no advertising or analytics cookies, so there is no consent banner.

If we ever add analytics or any non-essential cookie, we will list it here and ask for your consent before it is set.

13. Changes and contact

We update this policy when our processing changes. The date at the top always shows the current version, and material changes are announced by email and in the portal.

Privacy questions: legal@hbing.uk. Abuse reports: abuse@hbing.uk.

If anything here is unclear, or you want to exercise one of the rights described above, email legal@hbing.uk and a person — not a bot — will answer.