View Categories

HOSTING AND INFRASTRUCTURE POLICY

21 min read

HOSTING & INFRASTRUCTURE POLICY #

Effective Date: 01 February 2026

Applicable To: All clients, partners, licensees, resellers, and authorised shared-service operators using Fludnox hosting and infrastructure services.


This Hosting and Infrastructure Policy sets out the terms governing Your use of hosting, server, network, email, DNS, content-delivery, storage and related infrastructure services supplied by The Xdemór Group Limited under the Fludnox brand.

In this Policy, “You” and “Your” refer to the business, organisation or professional purchasing or using the Services and any person authorised to act on its behalf. “Fludnox”, “We”, “Us” and “Our” refer to The Xdemór Group Limited, trading as Fludnox. “Services” means the hosting and infrastructure services identified in the applicable Order Form, Proposal, service description or Individual Agreement. “Content” means all websites, applications, code, files, databases, email, communications, media, credentials and other information uploaded to, stored within or transmitted through the Services.

1. Application of this Policy #

1.1 Contractual Status #

This Policy forms part of the contractual framework governing the Services and applies together with the Shared Services Terms of Service, the Shared Services Data Processing Agreement, the Shared Services Acceptable Use Policy, all applicable Fludnox service-specific policies and the Order Form or Individual Agreement governing the relevant Service.

This Policy applies only to business and professional use. The Services are not offered under this Policy for personal, family or household purposes.

1.2 Acceptance #

You accept this Policy when You order, pay for, activate, renew, access or use a Service, or when You instruct Us to begin provisioning, migration, configuration or other work connected with a Service.

A person accepting this Policy on behalf of a company or other organisation represents that they have authority to bind that organisation.

1.3 Order of Precedence #

If there is any inconsistency between documents governing the Services, mandatory applicable law shall prevail, followed by an expressly negotiated Individual Agreement or Order Form, the Shared Services Data Processing Agreement solely in relation to personal-data processing, the Shared Services Terms of Service, this Policy and then any other incorporated policy or service description.

A higher-ranking document prevails only to the extent of the inconsistency.

2. Scope of the Services #

2.1 Service Models #

Fludnox may provide shared hosting, managed website hosting, WordPress hosting, virtual private servers, isolated or dedicated infrastructure, database hosting, business email, DNS management, content-delivery services, security services, monitoring, backups, restoration and migration assistance.

The precise Services supplied to You are limited to those expressly identified in the applicable Order Form, Proposal, Individual Agreement or published service description effective at the time of Your order.

The availability of a feature within a control panel, upstream platform or technical environment does not mean that the feature is included in Your purchased Service.

2.2 Managed and Client-Managed Components #

A component is managed by Fludnox only where the applicable Service description or written agreement expressly states that We are responsible for its management.

Unless expressly included, You remain responsible for Your websites, applications, custom code, plugins, themes, databases, users, passwords, access permissions, third-party accounts, integrations, DNS records, email clients and software installed or controlled by You.

Providing temporary support, access assistance or investigation does not convert a Client-managed component into a managed component or create an ongoing maintenance obligation.

2.3 Out-of-Scope Work #

Any configuration, migration, repair, restoration, security review, software update, development, data correction, compatibility work or other activity not expressly included in the Services is out of scope and may require a separate written agreement and additional payment.

3. Provisioning and Activation #

3.1 Provisioning Requirements #

Before activating a Service, We may require cleared payment, accurate onboarding information, proof of identity or authority, valid technical credentials, domain or DNS access, information about the intended workload and completion of any necessary legal, compliance, security or risk review.

We may decline or delay provisioning where required information has not been supplied, payment has not cleared, the proposed workload is unsuitable for the selected Service or the Service would expose Fludnox, another client or an upstream provider to unacceptable legal, regulatory, security or operational risk.

3.2 Service Activation #

A Service becomes active when We confirm activation or make the relevant hosting or infrastructure environment available to You.

Estimated provisioning dates are not guaranteed unless expressly stated as binding in an Individual Agreement.

3.3 Suitability of the Selected Service #

You are responsible for selecting a Service suitable for Your workload, expected traffic, data volume, security requirements and legal obligations.

Where actual use materially exceeds the disclosed or intended use of the selected Service, We may require optimisation, an upgrade, migration to another environment or discontinuation of the unsuitable workload.

4. Upstream Providers and External Terms #

4.1 Use of Upstream Providers #

We may use third-party data centres, server providers, network operators, software vendors, domain registrars, registries, email providers, security providers, storage providers and other infrastructure suppliers to deliver the Services.

The use of an upstream provider does not transfer responsibility for managing Your contract to that provider and does not create a direct contractual relationship between You and that provider unless expressly stated otherwise.

4.2 Applicable Upstream Restrictions #

You must comply with any materially applicable technical restrictions, acceptable-use requirements, export-control restrictions, sanctions requirements, software licence terms, registry rules and security requirements imposed by an upstream provider used to deliver Your Service.

We will identify materially applicable upstream requirements through the applicable Service description, Order Form, client portal, policy portal or written notice. You will not be bound through this Policy by upstream terms that are unrelated to Your Service.

A material breach of an applicable upstream restriction constitutes a breach of this Policy.

4.3 Current Principal Upstream Terms #

Where SpeedyPage infrastructure is used to supply a Service, the relevant upstream documents may include:

https://speedypage.com/terms-of-service

https://speedypage.com/acceptable-use

https://speedypage.com/dpa

Where Spaceship infrastructure or licensed products are used to supply a Service, the relevant upstream hosting terms may include:

https://www.spaceship.com/legal/hosting-tos/

The current upstream providers, processing locations and data-transfer arrangements applicable to hosted personal data are maintained in the Fludnox Subprocessor and Data Location Register. The Shared Services Data Processing Agreement, not an upstream provider’s customer-facing terms, governs the data-processing relationship between You and The Xdemór Group Limited.

4.4 Upstream Changes and Enforcement #

We may modify, replace, migrate, restrict or discontinue an affected component where an upstream provider changes or withdraws infrastructure, software, licences, locations, functionality or support.

We may also take action where an upstream provider requires content removal, technical isolation, workload migration, account verification, security remediation, suspension or termination.

Where reasonably practicable, We will notify You before taking materially adverse action. We may act immediately where delay would increase legal, security, abuse, data-integrity or infrastructure risk.

5. Permitted Use and Service Restrictions #

5.1 Intended Use #

Shared hosting is intended primarily for hosting websites, web applications and ordinary business email connected with those websites.

Unless We approve otherwise in writing, shared hosting must not be used primarily for batch processing, video encoding, continuous crawling, general file hosting, cyberlocker services, remote backup storage, long-term email archiving, artificial traffic generation, crypto-asset mining or another workload unrelated to ordinary website hosting.

Detailed prohibited activities and content restrictions are set out in the Fludnox Hosting Acceptable Use Policy.

5.2 Regulated and High-Risk Workloads #

You must not use a standard or shared hosting Service for payment-card environments, medical or clinical systems, criminal-justice data, classified information, special-category personal data or another regulated workload unless We have expressly approved the workload in writing.

Unless expressly confirmed in an Individual Agreement, We do not represent that a standard Service satisfies PCI DSS, healthcare-sector hosting requirements, financial-sector outsourcing standards, government security classifications or another sector-specific certification.

5.3 Lawful Use #

You must use the Services only for lawful purposes and in compliance with the laws applicable to You, Your Content, Your users and the territories in which Your website, application or service operates.

You remain responsible for determining whether Your Content, products, services, communications and processing activities are lawful.

6. Resource Allocation and Fair Use #

6.1 Technical Limits #

Services may be subject to limits on processor usage, memory, storage, file or inode count, database size, network traffic, bandwidth, concurrent processes, execution time, API requests, email volume, mailbox size and backup capacity.

Applicable limits may be stated in the Order Form, service description, control panel or technical documentation.

6.2 Unlimited and Unmetered Services #

A Service described as unlimited or unmetered remains subject to physical capacity, software restrictions, reasonable use, the intended purpose of the Service and the need to protect other users of shared infrastructure.

Unlimited or unmetered does not mean infinite capacity or unrestricted use for purposes unrelated to the purchased Service.

6.3 Excessive Use #

Where Your use threatens system stability, security, network reputation or the availability of Services to other clients, We may throttle resources, limit processes, temporarily isolate the affected workload, require optimisation, require an upgrade or migrate the workload to a more suitable environment.

Where immediate action is not required, We will normally notify You and allow a reasonable opportunity to reduce or correct the affected usage.

7. Infrastructure Management #

7.1 Operational Control #

We control the design, allocation, configuration and management of the infrastructure used to deliver the Services, except for components expressly placed under Your control.

We may implement technical changes necessary to maintain security, reliability, performance, legal compliance, upstream compatibility, capacity or service continuity.

7.2 Server and Data-Centre Changes #

Subject to any express location commitment in an Individual Agreement, We may change the physical or virtual server, server cluster, storage system, network path, data centre, hosting region, control panel, operating system, software version, security tooling or upstream provider used to supply a Service.

Where a material change adversely affects an agreed service characteristic or data-location commitment, We will provide reasonable prior notice unless the change is required urgently by law, security, an upstream provider or an event outside Our reasonable control.

Any change involving personal-data processing, a new subprocessor or an international transfer remains subject to the Shared Services Data Processing Agreement and the Fludnox Subprocessor and Data Location Register.

7.3 Maintenance #

We may perform planned and emergency maintenance to preserve security, compatibility, stability or performance.

Where reasonably practicable, planned maintenance affecting availability will be announced through email, the client portal, a dashboard notice, the Service status page or another recorded communication channel.

Emergency maintenance may be performed without prior notice where delay would materially increase the risk of compromise, data loss, service instability, abuse or a wider outage.

8. IP Addresses, DNS and Technical Subdomains #

8.1 IP Addresses #

Any IP address allocated in connection with a Service remains under the ownership or control of Fludnox or the relevant upstream provider.

You receive a temporary right to use the allocated IP address only for the duration and permitted purpose of the Service. You acquire no ownership, portability or permanent allocation right.

We may replace an IP address where reasonably required for migration, security, reputation management, network administration, upstream changes or service continuity.

8.2 Dedicated IP Addresses #

A dedicated IP address is exclusive to the applicable hosting environment but is not owned by You and may not be transferred to another service or provider unless We expressly agree otherwise.

Cancellation, expiry or termination of the underlying hosting Service will also terminate the right to use any associated dedicated IP address.

8.3 DNS #

Where You manage DNS, You are responsible for the accuracy, security and maintenance of the relevant records.

Where We manage DNS, We will act on instructions issued through an authorised account or contact, except where emergency changes are reasonably necessary to protect the Services.

DNS propagation, resolver caching, registry delays and failures within third-party DNS systems are outside Our direct control.

8.4 Technical Subdomains #

We may assign a technical subdomain for provisioning, migration, control-panel access, testing, monitoring or other operational purposes.

A technical subdomain remains under Our control, may be changed or withdrawn and must not be treated as a permanent public domain or business asset unless We expressly agree otherwise.

9. Third-Party Software #

9.1 Included Software #

The Services may include third-party control panels, operating systems, security tools, caching systems, content-management software, database systems and other licensed products.

Third-party software is supplied subject to the applicable provider’s licence terms and continued availability. You must comply with those terms when using the software.

9.2 Licence and Use Restrictions #

Unless the applicable licence expressly permits otherwise, You must not copy, redistribute, sublicense, reverse engineer, decompile, bypass licensing controls, share licences outside the authorised Service environment or create unauthorised derivative works from third-party software.

Your right to use software supplied through a Service ends when the relevant licence or Service ends.

9.3 Software Changes #

We may update, replace, restrict or remove third-party software where required for security, compatibility, licensing, support or upstream compliance.

We do not guarantee that a particular software product, edition, version or feature will remain available throughout the Service term unless that commitment is expressly stated in an Individual Agreement.

9.4 Client-Installed Software #

You may install or use third-party software only where it is compatible with the Service, properly licensed and permitted under the Fludnox Hosting Acceptable Use Policy.

You remain responsible for licence fees, configuration, security, updates, compatibility, operation and any loss or disruption arising from software selected or installed by You.

We may require the removal, disabling or updating of software that is unsupported, vulnerable, incompatible or harmful to the Services.

10. Security and Access #

10.1 Shared Responsibility #

Security responsibility is divided according to the Service model.

We are responsible for reasonable technical and organisational measures applicable to the infrastructure and managed components under Our control. You are responsible for Your applications, users, credentials, Content, Client-managed software and use of the Services.

10.2 Client Security Obligations #

You must use strong and unique credentials, enable multi-factor authentication where available, restrict privileged access, maintain supported software, remove unused accounts and components, protect API keys and access tokens and promptly investigate security warnings.

You must notify Us without undue delay if You become aware of suspected unauthorised access, malware, compromised credentials, data loss, security weakness or another incident capable of affecting the Services.

10.3 Security Services #

DDoS mitigation, application firewalls, managed malware removal, penetration testing, security monitoring, compliance auditing and specialist incident response are included only where expressly stated in the applicable Service description or Individual Agreement.

No Service can be guaranteed to prevent every vulnerability, attack, failure or malicious act.

10.4 SSH and Administrative Access #

SSH, shell, root, administrator or other privileged access may be restricted, isolated or unavailable depending on the Service.

Any privileged access granted to You is personal to the authorised account and must not be used to bypass resource, security or isolation controls. Misuse may result in immediate revocation, suspension or termination.

11. Monitoring and Support Access #

11.1 Operational Monitoring #

We may monitor service availability, resource consumption, network activity, authentication events, process activity, email reputation, security alerts, system logs and abuse indicators where reasonably necessary to operate, secure and protect the Services.

11.2 Access to Content #

We do not routinely review Your Content.

We may access relevant systems, Content, metadata, logs or configurations where reasonably necessary to provide authorised support, investigate an incident or complaint, restore a managed component, prevent harm, comply with law or verify compliance with the contractual framework.

Access will be limited to authorised personnel and the purpose for which it is required.

11.3 Support Requests #

By requesting support that requires access to Your environment, You authorise Us to perform the reasonably necessary investigation or operation.

You must maintain an appropriate backup before requesting work capable of affecting Content or configuration. Where credentials are supplied for support, temporary credentials should be used where possible and changed after the work is completed.

Support may be refused where the request is outside scope, the environment contains unsupported or unlawful components, required access has not been provided or the requested action would expose Us to legal, security or operational risk.

12. Backups and Data Recovery #

Backups are included only where stated in the applicable Service description, Order Form or Individual Agreement.

The existence of an internal, operational or upstream backup does not by itself create a contractual right to access or restore that backup.

Unless expressly guaranteed in writing, backups are maintained on a reasonable-efforts basis, may exclude certain files or systems and are not guaranteed to be complete, current or recoverable in every circumstance.

You remain responsible for maintaining independent and current copies of Content that is critical to Your business, legal obligations or continuity arrangements.

Backup schedules, retention periods, storage locations, restoration procedures, exclusions and deletion cycles are governed by the Fludnox Backup and Data Recovery Policy.

The Services must not be used as a general backup, archive or long-term file-storage system unless a specific archival or backup service has been purchased.

13. Content and Downstream Users #

13.1 Responsibility for Content #

You remain responsible for the legality, accuracy, ownership, security and regulatory compliance of Your Content.

We do not approve, validate or assume responsibility for Your Content merely because it is hosted, transmitted, cached, backed up or technically processed through the Services.

13.2 Third-Party Content #

Where Your website, application or service permits users to submit, upload, publish or distribute content, You must maintain an effective mechanism for reporting unlawful, infringing, abusive or privacy-violating content.

You must monitor that mechanism, investigate complaints within a reasonable period, preserve relevant evidence and take appropriate action.

Failure to maintain or operate an effective complaint process may result in restriction, content removal, suspension or termination under the Fludnox Abuse and Content Complaint Procedure.

13.3 Resellers and White-Label Operators #

Where You resell, manage or make the Services available to downstream clients or users, You remain responsible for their activity and must impose contractual conditions no less protective than the applicable Fludnox policies.

You must not represent Fludnox infrastructure, upstream infrastructure or third-party software as technology owned or independently developed by You.

14. Personal Data #

Where We process personal data contained in hosted Content on Your behalf, You ordinarily act as Controller and The Xdemór Group Limited ordinarily acts as Processor.

Account, billing, support, security and commercial relationship data may be processed by The Xdemór Group Limited as an independent Controller under the Shared Services Privacy Policy.

Hosted personal-data processing is governed by the Shared Services Data Processing Agreement and the Fludnox Hosting Data Processing Schedule. Those documents regulate processing instructions, confidentiality, security, subprocessors, international transfers, assistance, audit rights and deletion or return of personal data.

Applicable UK data-protection legislation includes the UK GDPR and the Data Protection Act 2018:

https://www.legislation.gov.uk/eur/2016/679/contents

https://www.legislation.gov.uk/ukpga/2018/12/contents

You must not upload special-category personal data, criminal-offence data or another regulated high-risk dataset to a standard Service unless We have approved the processing in writing and the applicable data-processing and security requirements have been documented.

15. Availability and Service Levels #

A service-level commitment applies only where the applicable Service expressly includes one or an Individual Agreement incorporates the Fludnox Service Level Agreement.

In the absence of an applicable SLA, We do not guarantee uninterrupted or error-free availability.

Availability may be affected by maintenance, upstream provider outages, internet-routing failures, denial-of-service attacks, third-party software failures, external DNS systems, Client configurations, resource-limit breaches, security isolation and events outside Our reasonable control.

Support response means that a request has been acknowledged or investigation has commenced. It does not mean that the issue has been resolved within the response period.

Any uptime calculation, exclusions, response targets, service credits and claim procedure are governed exclusively by the Fludnox Service Level Agreement.

16. Suspension, Migration and Termination #

We may suspend, isolate, throttle, restrict, migrate or disable all or part of a Service where reasonably necessary because of non-payment, contractual breach, unlawful activity, abusive use, excessive resource use, malware, compromise, infrastructure risk, network or email reputation damage, a valid complaint, an upstream requirement or a legal or regulatory obligation.

Where reasonably practicable, We will use a proportionate measure and give You an opportunity to remedy the issue.

We may act without prior notice where delay would materially increase legal, security, abuse, financial, data-integrity or infrastructure risk.

Upon expiry or termination, Your right to use the Service, associated IP addresses, technical subdomains, supplied credentials and included software licences ends.

You are responsible for completing any permitted export or migration before the Service ends or within any expressly provided export period. We do not guarantee that Content or backups will remain available after termination.

Nothing in this Policy limits any mandatory obligation to return, delete, restrict, preserve or disclose personal data under the Shared Services Data Processing Agreement or applicable data-protection law.

Detailed suspension, remediation, reinstatement, migration, export and closure rules are governed by the Fludnox Migration, Suspension and Termination Procedure.

17. Ownership and Licence to Process Content #

You retain Your rights in Your Content.

You grant The Xdemór Group Limited and its authorised upstream providers a limited, non-exclusive licence to host, store, reproduce, cache, transmit, encrypt, back up, restore, migrate and technically adapt Your Content only to the extent reasonably necessary to provide, secure, support and administer the Services, comply with documented instructions or meet legal obligations.

This licence ends when the relevant processing is no longer required, subject to lawful retention, security evidence, backup cycles and the Shared Services Data Processing Agreement.

All rights in Fludnox infrastructure, deployment methods, automation, monitoring systems, security configurations, technical documentation and proprietary software remain with The Xdemór Group Limited or the applicable licensor.

Payment for a Service does not transfer ownership of infrastructure, servers, control panels, IP addresses, software licences, internal configurations or operational systems.

18. Liability #

Liability arising from the Services is governed by the Shared Services Terms of Service and any applicable Individual Agreement.

To the fullest extent permitted by applicable law, We are not responsible for loss or disruption caused by Your Content, Your instructions, Client-managed components, compromised Client credentials, unsupported software, Your configuration, Your failure to maintain independent backups, third-party integrations selected by You or Your failure to follow a reasonable security, migration or remediation instruction.

We do not guarantee the continued operation or availability of any upstream provider or third-party software.

Nothing in this Policy excludes or limits liability for death or personal injury caused by negligence, fraud, fraudulent misrepresentation or any other liability that cannot lawfully be excluded or limited.

19. Changes to this Policy #

We may amend this Policy to reflect changes in law, regulation, security requirements, technology, upstream providers, the Services or Our operational arrangements.

Except where an urgent exception applies, We will provide at least thirty days’ notice before a material change takes effect. Notice may be provided by email, through the client portal or by a prominent notice on the Shared Services Policy Portal.

A shorter period or immediate change may apply where required by law, a competent authority, security, abuse prevention, an urgent upstream requirement, service continuity or correction of an evident error.

Where a notified material change directly and materially disadvantages an affected Service, any right to terminate that Service before the change takes effect is governed by the Shared Services Terms of Service and the applicable Order Form.

Continued use of the affected Service after the effective date of a notified amendment constitutes acceptance of the amended Policy.

20. Notices and Contact #

Operational support requests relating to Fludnox hosting and infrastructure must be submitted to support-fludnox@shared-services.co or through the authenticated support channel made available to You.

Formal contractual and legal notices to The Xdemór Group Limited must be sent to legal@xdemor.com.

A support request, chat message or communication with technical personnel does not constitute a formal legal notice.

21. Governing Law and Jurisdiction #

This Policy and any non-contractual obligations arising from it are governed by the laws of England and Wales.

The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rule that cannot lawfully be excluded.

This Policy operates together with the policies and contractual documents published through the Shared Services Policy Portal at https://policies.shared-services.co/, including the Shared Services Terms of Service, Shared Services Privacy Policy, Shared Services Data Processing Agreement, Shared Services Acceptable Use Policy and the applicable Fludnox service-specific policies.

The applicable Fludnox service-specific documents include the Fludnox Hosting Acceptable Use Policy, Fludnox Backup and Data Recovery Policy, Fludnox Domain Registration Agreement, Fludnox Service Level Agreement, Fludnox Client Data Usage Policy, Fludnox Hosting Data Processing Schedule, Fludnox Subprocessor and Data Location Register, Fludnox Abuse and Content Complaint Procedure and Fludnox Migration, Suspension and Termination Procedure.

Legal certainty: medium-high. The contractual structure and UK GDPR separation are established. Plan-specific limits, backup schedules, supported locations and exact SLA commitments must remain outside this master policy until the Fludnox service plans and upstream configurations are formally fixed.

Submit a Request

Submitting a request through the general hosting support channel does not guarantee that it will be treated as a formal legal, compliance, or data protection notice unless the nature of the request is clearly identified.