Effective Date: 01 February 2026
Applicable To: All clients, partners, licensees, resellers and authorised shared-service operators using Fludnox hosting and infrastructure services.
This Client Data Usage Policy (“Policy”) explains how The Xdemór Group Limited, acting under the Fludnox brand, may access, use, store, disclose and otherwise process data supplied to or generated through Fludnox hosting and infrastructure services.
In this Policy, “You” and “Your” refer to the business, organisation or professional using the Services and any person authorised to act on its behalf. “Fludnox”, “We”, “Us” and “Our” refer to The Xdemór Group Limited acting under the Fludnox brand. “Client Data” means Content, personal data, files, databases, communications, email, credentials, logs, configurations and other information submitted to, stored within, transmitted through or generated by the Services. “Services” means the applicable Fludnox hosting and infrastructure services.
1. Application of this Policy #
1.1 Contractual Status #
This Policy forms part of the contractual framework governing the Services and applies together with the Shared Services Terms of Service, Shared Services Privacy Policy, Shared Services Data Processing Agreement, Fludnox Hosting and Infrastructure Policy, Fludnox Backup and Data Recovery Policy, applicable Order Form or Individual Agreement and the Fludnox Hosting Data Processing Schedule.
The Shared Services Data Processing Agreement prevails where this Policy concerns personal data processed by Fludnox on Your behalf. The Shared Services Privacy Policy governs personal data processed by The Xdemór Group Limited for its own account, billing, administration, legal, security and commercial purposes.
1.2 Acceptance #
You accept this Policy when You order, activate, access, renew or use the Services, submit Client Data to the Services or authorise Fludnox to access, migrate, restore, support or administer a Service environment.
1.3 Applicable Data Protection Law #
Where applicable, personal-data processing is subject to the UK GDPR, the Data Protection Act 2018 and other applicable amendments and regulations in force from time to time.
The principal statutory sources are:
https://www.legislation.gov.uk/eur/2016/679/contents
https://www.legislation.gov.uk/ukpga/2018/12/contents
https://www.legislation.gov.uk/ukpga/2025/18/contents
2. Data Roles #
2.1 Hosted Client Data #
Where Fludnox processes personal data contained in Your websites, applications, databases, email accounts, files, backups or other hosted Content solely to provide the Services on Your instructions, You ordinarily act as Controller and The Xdemór Group Limited ordinarily acts as Processor.
You determine the purposes for which the personal data is collected and used. Fludnox processes that personal data only within the scope of the Services, Your documented instructions and applicable law.
2.2 Fludnox Account and Administration Data #
The Xdemór Group Limited acts as an independent Controller where it determines the purposes and means of processing personal data required for:
account creation and management; billing and payment administration; fraud prevention; client verification; support administration; contract management; security monitoring; legal compliance; service communications; complaints; disputes; and protection of its business, infrastructure and legal rights.
That processing is governed by the Shared Services Privacy Policy.
2.3 Other Data Roles #
A domain Registry, Registrar, payment provider, external communication provider or other third party may act as an independent Controller where it determines processing under its own legal, contractual or regulatory responsibilities.
The use of a third party does not automatically make Fludnox a joint Controller with that party.
3. Permitted Use of Client Data #
3.1 Service Provision #
Fludnox may process Client Data to the extent reasonably necessary to provide the Services, including to:
host and transmit Content; operate websites, applications, databases, email and DNS; authenticate users; manage accounts and permissions; allocate infrastructure resources; create and manage backups; perform migrations and restorations; provide support; monitor availability; maintain service continuity; and administer the applicable contractual arrangement.
3.2 Security and Service Protection #
Fludnox may process relevant Client Data, logs, metadata and technical information to:
detect and prevent unauthorised access; investigate malware or compromise; protect accounts and credentials; prevent fraud and abuse; maintain network and email reputation; identify harmful processes; enforce resource limits; respond to security alerts; isolate affected systems; and protect Fludnox, its clients, users and infrastructure providers.
Security processing will be limited to information reasonably necessary for the relevant purpose.
3.3 Support and Client Instructions #
Where You request support, troubleshooting, migration, restoration, configuration or investigation, Fludnox may access and process the Client Data reasonably necessary to perform the requested work.
Your documented instructions may include an Order Form, Individual Agreement, support request, authorised email, authenticated account instruction, control-panel configuration or other recorded instruction issued by an authorised person.
Fludnox may refuse an instruction that is unlawful, technically unsafe, outside the Services, inconsistent with the contractual framework or issued by a person whose authority cannot reasonably be verified.
3.4 Legal and Regulatory Requirements #
Fludnox may process, preserve or disclose Client Data where required by applicable law, court order, regulatory requirement or legally binding request from a competent authority.
Where legally permitted, Fludnox will notify You before disclosing Client Data processed on Your behalf. Notice may be delayed or withheld where disclosure is prohibited or where prior notice would prejudice a lawful investigation, security response or enforcement action.
3.5 Enforcement and Dispute Management #
Fludnox may preserve and use relevant Client Data, account records, logs and communications where reasonably necessary to:
investigate a contractual breach; respond to an abuse report; establish service delivery; defend or pursue a legal claim; investigate fraud; resolve a payment dispute; respond to a domain dispute; or comply with a legal-preservation obligation.
Data retained for such purposes will be restricted to the relevant matter and retained only for as long as the applicable purpose or legal requirement continues.
4. Restricted Uses #
4.1 No Sale of Hosted Personal Data #
Fludnox will not sell personal data contained in Client-hosted Content to data brokers, advertisers or unrelated third parties.
Fludnox will not use hosted personal data to build advertising profiles or deliver behaviourally targeted advertising unrelated to the Services.
4.2 No Independent Marketing Use #
Fludnox will not use the contents of Your hosted databases, customer lists, mailboxes, form submissions or user accounts to market unrelated products or services to the individuals contained in those datasets.
This restriction does not prevent Fludnox from communicating directly with You or Your authorised account contacts about the Services under the Shared Services Privacy Policy.
4.3 No General AI Model Training #
Fludnox will not use identifiable or pseudonymised personal data contained in Client-hosted Content to train a general-purpose artificial-intelligence model unless:
You have expressly authorised the processing in a separate written agreement; the processing is lawful; the affected data subjects have received all required information; any required assessment or consent has been completed; and the applicable DPA and processing schedule expressly permit the activity.
Anonymised information may be used only where the anonymisation is effective and individuals are not identifiable by means reasonably likely to be used.
Pseudonymised data remains personal data where additional information or other reasonably available means could be used to identify an individual.
4.4 No Unauthorised Human Review #
Fludnox personnel will not routinely inspect the substantive contents of Client Data.
Human access may occur only where reasonably necessary for authorised support, incident response, security investigation, abuse handling, restoration, migration, legal compliance or another purpose permitted by this Policy and the applicable contractual framework.
5. Service Telemetry and Technical Data #
5.1 Operational Telemetry #
Fludnox may collect and process technical telemetry relating to the operation of the Services, including resource consumption, request volumes, error events, uptime, latency, software versions, authentication events, security alerts, network activity and feature usage.
Operational telemetry may contain IP addresses, device information, account identifiers or other personal data and will be treated accordingly where an individual is identifiable.
5.2 Service Improvement #
Fludnox may use technical telemetry to maintain, secure, troubleshoot, capacity-plan and improve the Services.
Where service-improvement analysis does not require identifiable information, Fludnox will use aggregated or effectively anonymised information where reasonably practicable.
Service improvement does not authorise Fludnox to use the substantive contents of hosted Client databases, communications or files for unrelated commercial purposes.
5.3 Aggregated Information #
Fludnox may create statistical and aggregated information concerning general infrastructure use, incident frequency, resource consumption, service performance and operational trends.
Aggregated information may be used for reporting, capacity planning, security research and service development where it does not identify You, Your users or another individual.
6. Client Responsibilities #
6.1 Lawful Authority #
You must have a valid legal basis and all necessary authority to collect, upload, host, transmit, disclose and otherwise process Client Data through the Services.
You are responsible for identifying and documenting the lawful basis applicable to Your processing and for meeting any additional condition required for special-category or criminal-offence data.
Fludnox does not determine Your lawful basis merely by providing technical infrastructure.
6.2 Transparency #
You must provide all privacy notices, cookie information, user disclosures and other information required by applicable law.
Your notices must accurately describe the relevant hosting, security, backup, analytics, support, international-transfer and subprocessor arrangements where those matters are required to be disclosed.
6.3 Data Minimisation #
You must not submit personal data that is excessive, irrelevant or unnecessary for the operation of Your service.
You must configure forms, databases, logs, applications, integrations and retention settings so that they collect and retain only the information reasonably required for Your documented purposes.
6.4 Accuracy and Retention #
You are responsible for maintaining the accuracy of personal data for which You act as Controller and for establishing appropriate retention periods.
The availability of hosting capacity does not authorise indefinite retention. You must delete or anonymise personal data when it is no longer required, subject to applicable legal-retention obligations.
6.5 Data Subject Rights #
You remain responsible for responding to access, rectification, erasure, restriction, portability, objection and other data-subject requests relating to Client Data for which You act as Controller.
Fludnox will provide assistance in accordance with the Shared Services Data Processing Agreement, taking into account the nature of the processing and information available to Fludnox.
6.6 Security Configuration #
You must protect credentials, restrict access, maintain supported software, remove unused accounts, configure permissions appropriately and follow reasonable security instructions.
You must notify Fludnox without undue delay where You become aware of unauthorised access, malware, compromised credentials, unlawful disclosure, data loss or another incident affecting the Services.
7. Special-Category and Restricted Data #
You must not process special-category personal data, criminal-offence data, medical records, biometric identifiers, payment-card data or another regulated high-risk dataset through a standard or shared Service unless Fludnox has approved the proposed processing in writing.
Approval may require:
a suitable hosting plan; additional technical controls; a documented lawful basis and additional processing condition; a Data Protection Impact Assessment; an updated Hosting Data Processing Schedule; sector-specific contractual terms; and additional fees.
Approval of the infrastructure does not constitute confirmation that Your processing is lawful or that all regulatory requirements have been satisfied.
Fludnox may require removal, migration, restriction or suspension where restricted data is processed in an unsuitable or unapproved environment.
8. Access and Authorised Personnel #
8.1 Access Control #
Fludnox will limit access to Client Data to authorised personnel and service providers who require access for a permitted purpose.
Personnel authorised to access Client Data will be subject to appropriate confidentiality obligations.
8.2 Privileged Access #
Administrative and privileged access will be granted according to operational need and the applicable security model.
Fludnox may record administrative access, support actions and security-sensitive changes for accountability, investigation and service-protection purposes.
8.3 Client Credentials #
Where You provide credentials for support or migration, temporary and limited credentials should be used where reasonably practicable.
You remain responsible for changing or revoking supplied credentials after the authorised work has been completed.
Fludnox will not request Your password where a delegated, temporary or account-specific access method is reasonably available.
9. Subprocessors and Service Providers #
Fludnox may use authorised subprocessors to provide infrastructure, storage, networking, email, backup, security, monitoring, support and related service functions.
Subprocessors processing personal data on behalf of Fludnox will be appointed in accordance with the Shared Services Data Processing Agreement.
The current provider identity, processing purpose, relevant location and transfer arrangement will be maintained in the Fludnox Subprocessor and Data Location Register.
A provider that acts as an independent Controller is not treated as a subprocessor for the processing it determines independently.
Fludnox will not disclose Client Data to an unrelated third party merely because that party requests access or proposes a commercial use.
10. International Transfers #
Where Client personal data is transferred or made accessible to a separate organisation outside the United Kingdom, Fludnox will apply the transfer requirements contained in applicable data-protection law and the Shared Services Data Processing Agreement.
Applicable safeguards may include an adequacy regulation, the United Kingdom International Data Transfer Agreement, the United Kingdom Addendum to approved Standard Contractual Clauses or another legally recognised transfer mechanism.
The current Information Commissioner’s Office guidance on international transfers is available at:
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/
The use of infrastructure located outside the United Kingdom will be identified through the applicable Service information, Hosting Data Processing Schedule or Subprocessor and Data Location Register.
11. Security #
Fludnox will implement technical and organisational measures appropriate to the risks presented by the processing and the nature of the applicable Service.
Measures may include access control, authentication, logging, encryption, network security, vulnerability management, backup controls, incident response, personnel confidentiality and infrastructure isolation.
The applicable security measures for hosted personal data are governed by the Shared Services Data Processing Agreement and Fludnox Hosting Data Processing Schedule.
No security measure eliminates every risk. You remain responsible for Client-managed applications, users, software, credentials, permissions and configurations.
The statutory security requirements are set out principally in Article 32 UK GDPR:
https://www.legislation.gov.uk/eur/2016/679/article/32
12. Personal Data Breaches #
A confirmed personal-data breach affecting Client personal data processed by Fludnox on Your behalf will be handled under the Shared Services Data Processing Agreement and applicable incident-response procedure.
Fludnox will notify You without undue delay after becoming aware of a qualifying breach affecting Your personal data and will provide available information reasonably required for Your assessment and response.
An initial notice may be supplemented as further information becomes available.
You remain responsible for determining whether notification to a supervisory authority, affected individual or another person is required where You act as Controller.
13. Retention and Deletion #
13.1 Active Services #
Client Data may be retained for the duration of the applicable Service and for the period reasonably necessary to provide the Service, comply with Your documented instructions and meet legal or security requirements.
Specific retention periods may depend on the type of data, Service configuration, backup cycle, account status and applicable legal obligation.
13.2 Service Termination #
At the end of the applicable processing service, personal data processed on Your behalf will be returned or deleted in accordance with the Shared Services Data Processing Agreement and Your documented choice, unless applicable law requires continued retention.
Commercial handover restrictions do not override a mandatory obligation concerning the return, deletion, restriction, preservation or disclosure of personal data.
13.3 Backup Copies #
Data may remain in protected rotational backups until the relevant backup is overwritten or securely destroyed under the applicable retention cycle.
During that period, the data will not be restored to ordinary active use except where required for legitimate recovery, legal compliance or authorised investigation.
Backup retention and deletion are governed by the Fludnox Backup and Data Recovery Policy.
13.4 Account and Legal Records #
Account, billing, support, security, complaint and contractual records controlled by The Xdemór Group Limited may be retained separately under the Shared Services Privacy Policy and applicable legal-retention requirements.
Deletion of hosted Client Data does not automatically require deletion of records that The Xdemór Group Limited is independently entitled or required to retain.
14. Data Export and Portability #
You are responsible for exporting Client Data that You wish to retain before the applicable Service expires or terminates.
Fludnox will provide available standard export mechanisms included in the applicable Service. Custom data extraction, conversion, reconstruction, restoration or migration assistance may require a separate agreement and charge.
Fludnox does not guarantee that an export will be compatible with another provider, application or data format.
Personal-data portability obligations between You and affected data subjects remain Your responsibility where You act as Controller. Fludnox will provide contractually required assistance under the Shared Services Data Processing Agreement.
15. Ownership and Limited Processing Licence #
You retain Your rights in Client Data.
You grant The Xdemór Group Limited and its authorised service providers a limited, non-exclusive licence to host, store, reproduce, cache, transmit, encrypt, back up, restore, migrate, scan and technically adapt Client Data only to the extent reasonably necessary to:
provide and secure the Services; carry out Your documented instructions; provide authorised support; prevent abuse; comply with law; and exercise rights under the applicable contractual framework.
This licence does not transfer ownership of Client Data and ends when the relevant processing is no longer required, subject to lawful retention, backup cycles and preservation obligations.
16. Resellers and Downstream Clients #
Where You use the Services for a downstream client, You must have lawful authority to submit and manage that client’s data.
You must ensure that the downstream client understands the relevant Controller and Processor roles and is bound by appropriate data-protection and confidentiality terms.
You must not instruct Fludnox to process downstream Client Data beyond the authority granted to You.
You remain responsible for downstream Controller instructions, privacy notices, lawful bases, data-subject handling and the accuracy of information provided to Fludnox.
Fludnox may require direct confirmation from a downstream Controller where authority is disputed, unclear or materially affects data protection or security.
17. Confidentiality #
Fludnox will treat Client Data as confidential except where the information:
is publicly available without breach of obligation; was lawfully known without confidentiality restriction; is independently developed without use of the Client Data; is lawfully received from another source; is authorised for disclosure by You; or must be disclosed under applicable law.
Confidentiality obligations do not prevent limited disclosure to authorised personnel, subprocessors, advisers, insurers, auditors or competent authorities where the recipient has a legitimate need to receive the information and appropriate protections apply.
18. Requests, Complaints and Contact #
Operational requests concerning access, export, restoration or hosted data must be submitted through the authenticated Fludnox support channel or to support-fludnox@shared-services.co.
Privacy requests and questions concerning processing by The Xdemór Group Limited may be submitted to privacy@xdemor.com.
Matters requiring the attention of the Data Protection Officer may be submitted to dpo@xdemor.com.
Formal contractual and legal notices must be sent to legal@xdemor.com.
A support request does not constitute a formal legal notice unless Fludnox expressly confirms otherwise.
19. Changes to this Policy #
Fludnox may amend this Policy to reflect changes in law, regulatory guidance, security requirements, Service design, data practices or operational arrangements.
Except where an urgent exception applies, Fludnox will provide reasonable notice before a material amendment takes effect.
A shorter notice period or immediate amendment may apply where required by law, a competent authority, security, incident response, abuse prevention or service continuity.
No amendment will retrospectively authorise a materially different use of hosted personal data where additional Client instructions, transparency, lawful basis or consent are legally required.
20. Governing Law and Related Documents #
This Policy and any non-contractual obligations arising from it are governed by the laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction, subject to any mandatory rule that cannot lawfully be excluded.
This Policy operates together with the contractual documents published through the Shared Services Policy Portal at https://policies.shared-services.co/, including the Shared Services Terms of Service, Shared Services Privacy Policy, Shared Services Data Processing Agreement, Fludnox Hosting and Infrastructure Policy, Fludnox Backup and Data Recovery Policy, Fludnox Hosting Data Processing Schedule and Fludnox Subprocessor and Data Location Register.