Skip to content
FreeWebsite design free — you only pay for hosting, domain and email
← Legal centre

Privacy Policy

How Lanex Group, LLC collects, uses, shares, transfers and protects your personal data, and how to exercise your rights under the GDPR.

Version in force · Last updated 6 February 2026

1. Who we are and scope of this policy

  • 1.1 Lanex Group, LLC ("Alta Ignite", "we", "us", "our"), registered office United States, a United States limited liability company, is the data controller for the personal data described in this policy unless stated otherwise.
  • 1.2 This policy applies to personal data we process about website visitors, prospective and existing customers, domain registrants, mailbox users, and individuals who contact us, in connection with altaignite.com and the subscription Services described in our Terms of Service.
  • 1.3 Where we process personal data on behalf of a customer as part of hosting or email Services, we act as processor and the terms of our Data Processing Agreement, not this policy, govern that processing; the customer's own privacy notice applies to that customer's end users.
  • 1.4 Our Data Protection Officer can be contacted at privacy@altaignite.com or by post at the address above, marked "Data Protection Officer".

2. Categories of personal data we collect

  • 2.1 Account and billing data: name, email address, phone number, billing address, VAT number, payment method token and transaction history (full card numbers are processed only by our payment processor Stripe and are never received or stored by us).
  • 2.2 Domain registrant data: registrant, administrative and technical contact name, organisation, address, email and phone number required by the relevant domain registry.
  • 2.3 Service content: the Client Materials, website content, design assets, source code and configuration you upload or that we create for you, and business email content processed through mailboxes included in your Plan.
  • 2.4 Communications: support tickets, chat messages, call recordings where notified, and correspondence with our sales, support and legal teams.
  • 2.5 Technical and usage data: IP address, device and browser identifiers, log files, pages viewed, referral source and analytics events collected via cookies and similar technologies as described in our Cookie Policy.
  • 2.6 Marketing preferences: email subscription status, campaign engagement and consent records where you opt in to marketing communications.

3. Purposes and legal bases (GDPR Article 6)

  • 3.1 Providing and administering the Services, including account creation, hosting, domain registration and email provisioning: necessary for performance of a contract to which you are party (Art. 6(1)(b) GDPR).
  • 3.2 Billing, invoicing, tax compliance and fraud prevention: necessary for performance of a contract (Art. 6(1)(b)) and to comply with our legal obligations under United States tax and accounting law (Art. 6(1)(c)).
  • 3.3 WHOIS and registry disclosure, ICANN-mandated verification and abuse handling: necessary to comply with our legal and contractual obligations as an ICANN-accredited-registrar reseller (Art. 6(1)(c) and 6(1)(f), our legitimate interest in preventing domain abuse).
  • 3.4 Customer support, service communications and security monitoring: necessary for performance of a contract (Art. 6(1)(b)) and our legitimate interest in maintaining a secure, reliable service (Art. 6(1)(f)).
  • 3.5 Product analytics, website performance measurement and marketing communications: based on your consent (Art. 6(1)(a)), which you may withdraw at any time, or, for existing customers regarding similar products, our legitimate interest subject to an unconditional opt-out (Art. 6(1)(f)), in each case consistent with the ePrivacy Directive and equivalent national implementing laws.
  • 3.6 Compliance with law enforcement, court orders and regulatory requests: necessary to comply with a legal obligation (Art. 6(1)(c)) or to establish, exercise or defend legal claims (Art. 6(1)(f)).

4. WHOIS and domain registry disclosure

  • 4.1 Where you register or transfer a domain through us, your registrant, administrative and technical contact details are submitted to the relevant domain registry and, unless you enable an eligible privacy or proxy service, may be published in the public WHOIS/RDAP directory as required by that registry's policy and, for generic top-level domains, ICANN's Temporary Specification and successor policies.
  • 4.2 Where a privacy or proxy service is available for your top-level domain and you request it, we will substitute proxy contact details in the public record while retaining your underlying details as required for registry compliance and abuse response.
  • 4.3 We disclose registrant data to registries, registrars, ICANN-approved dispute-resolution providers (for UDRP proceedings) and law enforcement where required by applicable domain policy or law.

5. Cookies and similar technologies

  • 5.1 We use cookies, pixels and local storage for essential site functionality, analytics and, where you consent, marketing. Full details of each category, its purpose, duration and the consent mechanism are set out in our Cookie Policy, which forms part of this Privacy Policy by reference.

6. Recipients of personal data

  • 6.1 We share personal data with the categories of recipient necessary to provide the Services, including payment processors, cloud hosting and email infrastructure providers, domain registry operators, customer support platforms, and professional advisers.
  • 6.2 A current list of the specific subprocessors we use, their role and location, is maintained in our Subprocessors page, updated when we onboard or replace a vendor and, for Data Processing Agreement customers, notified in accordance with the objection procedure in that agreement.
  • 6.3 We do not sell personal data. We disclose personal data to third parties only as described in this policy, under a written agreement imposing data protection obligations at least equivalent to those in this policy, or where required by law.

7. International transfers

  • 7.1 Personal data may be transferred to, and processed in, countries outside the European Economic Area, including the United States, where our hosting, email and payment subprocessors operate infrastructure.
  • 7.2 Where such a transfer occurs to a country not covered by an adequacy decision of the European Commission under GDPR Art. 45, we rely on appropriate safeguards under GDPR Art. 46, in particular the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures such as encryption in transit and at rest, in accordance with GDPR Arts. 44 to 49.
  • 7.3 You may request a copy of the relevant safeguard by writing to privacy@altaignite.com.

8. Retention periods

  • 8.1 Account and billing data is retained for the duration of your subscription and for seven (7) years afterwards to comply with United States federal and state tax and accounting record-keeping obligations.
  • 8.2 Domain registrant data is retained for as long as required by the applicable registry policy, and in any event for the duration of the registration plus any period mandated by ICANN's data retention specification.
  • 8.3 Hosted website content and email mailbox content is retained for thirty (30) days after subscription termination as described in our Terms of Service, after which it is irretrievably deleted from production systems, subject to routine backup rotation cycles of up to ninety (90) days.
  • 8.4 Support communications are retained for three (3) years after the last interaction to allow us to resolve recurring issues and defend against claims.
  • 8.5 Marketing consent records and unsubscribe preferences are retained for as long as necessary to honour your preference and demonstrate compliance, and analytics data is retained in identifiable form for no longer than twenty-six (26) months.

9. Your rights under the GDPR

  • 9.1 Subject to the conditions and exemptions in each Article, you have the right to: access your personal data (Art. 15); rectify inaccurate or incomplete data (Art. 16); erasure of your data (Art. 17); restriction of processing (Art. 18); data portability in a structured, commonly used, machine-readable format (Art. 20); and to object to processing based on legitimate interests or carried out for direct marketing (Art. 21).
  • 9.2 Where processing is based on consent, you may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)).
  • 9.3 To exercise any of these rights, contact privacy@altaignite.com. We will acknowledge your request within seventy-two (72) hours and respond substantively within one (1) month, extendable by a further two (2) months for complex or numerous requests, as permitted by Art. 12(3). We may need to verify your identity before acting on a request.
  • 9.4 If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority of your own EU member state of residence or work.

10. Automated decision-making

  • 10.1 We do not use your personal data for any decision that produces legal effects concerning you, or similarly significantly affects you, based solely on automated processing, including profiling, within the meaning of GDPR Art. 22.
  • 10.2 We do use automated systems for fraud and abuse screening of payments and domain registrations, but any resulting suspension or refusal is reviewed by a member of our team on request before it is treated as final.

11. Children's data

  • 11.1 Our Services are directed at businesses and individuals aged eighteen (18) or over. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

12. Security measures

  • 12.1 We implement technical and organisational measures appropriate to the risk, as required by GDPR Art. 32, including encryption of data in transit via TLS, encryption of sensitive data at rest, role-based access control, multi-factor authentication for administrative access, network segmentation, logging and monitoring, and regular vulnerability assessment.
  • 12.2 Access to personal data is restricted to personnel who need it to perform their role and who are bound by confidentiality obligations. We maintain an incident response process and will notify affected customers and, where legally required, the Autoriteit Persoonsgegevens and affected data subjects, without undue delay and in any event within seventy-two (72) hours of becoming aware of a qualifying personal data breach, in accordance with GDPR Arts. 33 and 34.

13. Processors and subprocessing

  • 13.1 Where we act as processor for personal data you control (for example, data within your hosted website or included email mailboxes), we process it only on your documented instructions, under the terms of our Data Processing Agreement, in accordance with GDPR Art. 28.
  • 13.2 We engage subprocessors under written agreements imposing data protection obligations equivalent to those in our Data Processing Agreement, and we remain liable for their performance. Our current subprocessor list is published and updated on our Subprocessors page.

14. Legal and regulatory disclosures

  • 14.1 We may disclose personal data where required to comply with a legal obligation, a valid order of a competent court or authority, or to protect the rights, property or safety of Alta Ignite, our customers or the public, always assessing proportionality and, where lawful, notifying the affected individual.
  • 14.2 Requests from law enforcement or regulators should be directed to legal@altaignite.com and will be reviewed by our legal team before any data is disclosed.

15. Changes to this policy

  • 15.1 We may update this Privacy Policy to reflect changes in our processing activities or legal requirements. Material changes will be notified by email or in-app notice at least thirty (30) days before they take effect, except where a shorter period is required for legal or security reasons.
  • 15.2 The version in force at any time is published at altaignite.com/legal/privacy with its effective date stated at the top of the page.

Questions about this policy or a request to exercise your data protection rights: privacy@altaignite.com (Data Protection Officer) — Lanex Group, LLC, United States.