Privacy Policy
Effective 16 September 2026
This Privacy Policy explains how Aspirium Ltd uses personal information when acting as a data controller. It covers visitors to our websites, prospective and current business customers, account users, suppliers and other business contacts. When we host or otherwise process personal data solely on a customer’s behalf, the customer is normally the controller and our Data Processing Agreement applies.
1. Who we are
1.1 Controller Aspirium Ltd is a company registered in England and Wales under company number 16989063. Our registered office is 23 The Mead, Ashton Keynes, Swindon, England, SN6 6PL. Aspirium Ltd is the controller of the personal information described in this Privacy Policy unless we state otherwise.
1.2 ICO registration We are registered with the Information Commissioner’s Office under registration number ZC245198.
1.3 Contacting us You can contact us through the contact details published at aspirium.co.uk/contact, through your Aspirium client area or by writing to our registered office. Please mark data protection correspondence for the attention of the Data Protection Contact.
2. Scope of this policy
2.1 Services and websites This policy applies to aspirium.co.uk, our client area and our communications and business activities. It also applies to personal information we use to sell, administer, secure and support hosting, domains, website services, marketing tools, digital tools, website care and related services.
2.2 Customer controlled data Customers may place personal information in websites, email accounts, support materials, analytics tools or other Services. When we process that information only on the customer’s instructions, Aspirium acts as a processor. The customer’s own privacy notice should explain that processing, and our Data Processing Agreement governs our processor obligations.
2.3 External services Our websites and Services may link to third-party websites or allow customers to connect separate accounts. The operator’s privacy notice applies when it determines how and why personal information is used. We are not responsible for an unrelated third party’s privacy practices.
3. Personal information we collect
Depending on how you interact with us, we may collect:
- identity and business information, including your name, job title, organisation and authorised-user status;
- contact information, including business and billing addresses, email addresses and telephone numbers;
- account information, including usernames, authentication records, preferences, subscriptions and service configuration;
- transaction information, including orders, invoices, payment status, refunds and payment-provider tokens or references. Aspirium does not normally receive or store complete payment-card details;
- service information, including domains, websites, hosting accounts, service usage, plan limits, licences and requested features;
- communications, including enquiries, demonstrations, support tickets, call notes, feedback and correspondence;
- migration and support information, which may include temporary access credentials, configuration details, files, logs and diagnostic information supplied to resolve a request;
- technical and security information, including IP addresses, browser and device information, timestamps, authentication events, referral pages, cookies, logs and suspected abuse or fraud indicators;
- marketing information, including subscription choices, campaign engagement and the source of an enquiry; and
- content submitted to optional tools, including prompts, uploads, designs and analytics configuration, where you choose to use those tools.
Information from other sources We may receive information from an organisation that authorises you to use its account, referral partners, domain registrars and registries, payment and fraud-prevention providers, service platforms, public business sources and connected services that you ask us to use.
4. How we use personal information
- to respond to enquiries, arrange demonstrations and take steps requested before entering into a contract;
- to create accounts, verify authority, process orders and supply the Services;
- to administer subscriptions, billing, payments, renewals, cancellations, domains and licences;
- to migrate, configure, maintain, secure, troubleshoot and support Services;
- to communicate service, security, billing and contractual information;
- to prevent fraud, spam, abuse, unauthorised access and threats to our systems or other users;
- to maintain business records, enforce agreements, resolve disputes and establish or defend legal claims;
- to meet tax, accounting, regulatory, law-enforcement and other legal obligations;
- to understand and improve our websites, Services, support and customer experience; and
- to send relevant business marketing where permitted and manage marketing preferences.
5. Our lawful bases
Contract We use personal information when necessary to enter into or perform a contract with you, including setting up an account, supplying and supporting Services and administering payment. If you act for an organisation, this processing may instead rely on our legitimate interests in performing the organisation’s contract.
Legitimate interests We use information where necessary for our legitimate interests or those of another person and those interests are not overridden by your rights. These interests include operating and improving our business, supporting customers, securing systems, preventing fraud and abuse, keeping records, recovering debts and marketing relevant business services.
Legal obligation We use information where required to comply with tax, accounting, company, data protection, law-enforcement and other legal obligations.
Consent We rely on consent where the law requires it, including for certain cookies and electronic marketing. You may withdraw consent at any time, without affecting processing that took place before withdrawal.
Vital interests and public tasks These bases are unlikely to apply to our ordinary activities, but we may rely on them where the legal conditions are met, for example to protect a person in an emergency.
6. Payments fraud checks and automated tools
6.1 Payments Payments are processed by Stripe or another payment provider identified at checkout. The provider receives payment and transaction information under its own privacy terms. Aspirium generally receives confirmation, limited card information such as brand and final digits, payment references and fraud or risk indicators rather than the full card number.
6.2 Fraud and security We and our providers may use automated signals to identify suspicious orders, login attempts, spam, malware and misuse. These signals may cause a transaction or activity to be held, challenged or referred for review. We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects, unless we tell you and provide the safeguards required by law.
6.3 Artificial intelligence Where you choose an AI-enabled Service, prompts, uploads and related technical information may be sent to the provider identified for that feature. You must not submit patient-identifiable information, special-category data or other restricted information unless the applicable Order and Data Processing Agreement expressly permit it. We do not use customer prompts to make clinical decisions about individuals.
7. Who receives personal information
We disclose personal information only where reasonably necessary for the purposes described above. Recipients may include:
- com UK Services Ltd, which operates the Stablepoint hosting platform, and its infrastructure, datacentre, network, security, email and backup suppliers;
- Upmind for customer accounts, client-area functionality, subscriptions, service administration and billing records;
- Stripe and other payment, banking, accounting and fraud-prevention providers;
- domain registrars, registries, ICANN, Nominet and related domain-service providers;
- ActiveCampaign for customer communications, onboarding and permitted marketing;
- Cloudflare, including Turnstile and related security services, where used on our websites;
- AgencyAnalytics, Polotno, Site.pro, OpenAI or other providers used to deliver optional analytics, design, website-building or AI features selected by the customer;
- website-support, migration, maintenance and security providers, including Fixed.net where engaged for an eligible request;
- professional advisers, insurers, auditors, debt-recovery providers and prospective purchasers or investors involved in a genuine business transaction; and
- courts, regulators, tax authorities, law-enforcement bodies and other persons where disclosure is required by law or reasonably necessary to protect rights, security or users.
We do not sell personal information. A provider may also act as an independent controller for information it uses for its own lawful purposes, such as payment compliance, domain-registry administration or fraud prevention. Its own privacy notice will then apply.
8. International transfers
Some providers or support personnel may process personal information outside the United Kingdom. This can occur when a customer selects a hosting region outside the UK, when a global domain registry receives registrant information, or when an optional software provider operates internationally.
Where a transfer is restricted under UK data protection law, we use an available lawful safeguard. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another permitted mechanism. We also consider supplementary technical and organisational measures where required. You may contact us for information about the safeguard relevant to your information, subject to confidentiality and third-party restrictions.
9. Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and dispute-resolution requirements. Our normal approach is:
- prospective-customer enquiries and demonstration records are normally kept for up to two years after the last meaningful contact, unless the person becomes a customer or asks us to delete them sooner;
- account, contract, order, invoice and payment records are normally kept for six years after the relevant financial period or customer relationship ends, where needed for tax, accounting and legal claims;
- support tickets and operational correspondence are retained for a period appropriate to the Service, security and potential claims, normally no longer than six years after the relationship ends;
- temporary migration credentials should be removed after the migration or support task is complete. Technical copies may remain for a limited period in protected backups or logs;
- security, access and service logs are retained for periods appropriate to their purpose and risk, then deleted, overwritten or anonymised;
- marketing contact information is kept until you opt out or it is no longer relevant. We may retain a minimal suppression record to ensure that an opt-out remains effective; and
- cookies and similar technologies are retained for the periods stated in our Cookie Policy or consent tool.
When Aspirium acts as a processor, customer-controlled data is retained and deleted under the Agreement, the Data Processing Agreement, the applicable Service and the customer’s instructions.
10. Marketing
We may send business contacts information about Aspirium services, events, offers and relevant content where they have consented or where permitted by the Privacy and Electronic Communications Regulations and our legitimate interests. We consider the nature of the relationship, the relevance of the message and the recipient’s reasonable expectations.
You can opt out at any time by using the unsubscribe link in a marketing email, changing available account preferences or contacting us. Opting out of marketing does not prevent essential service, security, billing or contractual communications.
11. Cookies and similar technologies
Our websites use necessary cookies and may use analytics, functional or advertising technologies where enabled. Non-essential cookies are used only in accordance with applicable consent requirements. Our Cookie Policy and consent tool provide current information about the technologies in use, their providers, purposes and duration, and allow you to change your preferences.
Marketing emails may contain tracking technologies that record delivery, opening or link interaction. We use this information to assess communications and improve relevance, subject to applicable law and available settings.
12. Security
We use technical and organisational measures designed to protect personal information against accidental or unlawful loss, alteration, disclosure or access. Measures include access controls, confidentiality obligations, appropriate authentication, encryption in transit, system and supplier controls, logging, backups where applicable and incident-response procedures. The measures used depend on the Service, processing risk and parts of the environment controlled by Aspirium or its suppliers.
No internet-connected system can be guaranteed completely secure. Customers must protect their credentials, devices and Customer-controlled configurations and should promptly report suspected unauthorised access.
13. Children and sensitive information
Aspirium supplies business services and does not knowingly offer accounts directly to children. Our business contacts should not provide special-category data, criminal-offence data, patient-identifiable information or other highly sensitive information unless it is necessary, lawful and expressly permitted for the relevant Service.
A customer’s website or hosted systems may contain information about children, patients or other individuals. In that situation, the customer normally determines the purpose and lawful basis and Aspirium processes the information on the customer’s behalf under the Data Processing Agreement.
14. Your data protection rights
Depending on the circumstances, you may have the right to:
- request access to your personal information and information about its use;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information where there is no lawful reason to retain it;
- ask us to restrict processing in specified circumstances;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain information in a structured, commonly used and machine-readable format and ask for it to be transferred where technically feasible;
- withdraw consent where processing relies on consent; and
- request safeguards relating to qualifying solely automated decisions.
These rights are subject to conditions and exemptions. To exercise a right, contact us using section 1. We may ask for information reasonably necessary to confirm identity and authority, but we will not routinely require excessive identification. We normally respond within one month, subject to any lawful extension.
If your request concerns information controlled by an Aspirium customer, such as information submitted through that customer’s website, please contact the customer first. We will assist the customer where required by our Data Processing Agreement.
15. Complaints
Please contact us first if you have a concern so that we can investigate it. You may also complain to the Information Commissioner’s Office. Current contact and complaint information is available at ico.org.uk/make-a-complaint or by calling 0303 123 1113. If you are outside the UK, you may also have a right to contact the data protection authority where you live or work.
16. Changes to this policy
We may update this policy to reflect changes in law, our Services, suppliers or processing. We will publish the current version on our website and change the effective date. We will provide additional notice where a change materially affects how we use personal information or where the law requires it. Earlier versions may be requested from us where available.







