Legal

Privacy Policy

Last updated 21 August 2026

The short version

  • We collect what we need to run your account and your monitors, and not much else.
  • No advertising trackers, no third-party analytics, and no tracking cookies.
  • We do not sell your personal data, and we never will.
  • Card details go straight to Stripe. We never see or store your full card number.
  • You can get a copy of your data, correct it, or have it deleted, by emailing us.

1. Who we are

Tesseract Hosting, a sole trader business in the United Kingdom, is the data controller for the personal data described here.

Contact for any privacy matter, including exercising your rights: [email protected].

This policy covers our website at tesseracthosting.co.uk and our products, including lookout.host.

2. What we collect

Information you give us

Information created by using the service

Information we get from others

3. Why we use it, and our lawful basis

Under UK GDPR we must have a lawful basis for each use. Ours are:

What we doWhyLawful basis
Create and run your accountYou cannot use the service without onePerformance of a contract
Run your checks and send your alertsIt is the service you asked forPerformance of a contract
Take payment and handle refundsTo charge for paid plansPerformance of a contract
Reply to your emailsTo support youPerformance of a contract, or legitimate interests
Keep the service secure and diagnose faultsTo prevent abuse and fix problemsLegitimate interests
Send service notices — outages, security, changes to termsYou need to knowLegitimate interests, or legal obligation
Keep financial recordsTax and accounting lawLegal obligation
Send optional product updatesOnly if you opt inConsent — withdrawable at any time

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights, and concluded it is not. You can object — see section 9.

4. Cookies and similar technologies

We do not use advertising cookies, and we do not run third-party analytics on our sites. There is no Google Analytics, no advertising pixel, and no cross-site tracking of any kind.

What we do use:

Because these are strictly necessary or purely local, no cookie consent banner is required, which is why you have not been shown one.

5. Who else touches your data

We keep the list of third parties deliberately short. Each one processes data on our instructions, under a contract:

ProviderWhat forWhat they receive
StripePayment processingYour email, billing details and card data, which you enter directly with them
CloudflareHosting, content delivery, and the monitoring stations themselvesTechnical request data such as IP address; the endpoints being checked
PurelymailEmail for our own addressesThe contents of correspondence with us
Alert destinations you chooseDelivering your alertsOnly what is in the alert. If you send alerts to Slack, Discord or Telegram, their own privacy policies apply to what arrives there.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever restructured — for instance incorporated as a limited company — or sold, data may transfer with it, and this policy will continue to apply until you are told otherwise.

We do not sell personal data, and we do not share it for anyone else’s marketing.

6. Where your data goes

We are based in the United Kingdom. Some of our providers process data outside the UK, including in the United States, and our monitoring stations are distributed worldwide by design — that is the point of them.

Where data leaves the UK we rely on the safeguards the law provides, such as UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses. You can ask us for detail on any specific transfer.

7. How long we keep it

DataKept for
Account detailsWhile your account is open, then deleted within 30 days of closure
Monitoring configuration and historyPer your plan’s retention period; deleted within 30 days of account closure
Technical and security logsUp to 12 months
Support correspondenceUp to 24 months after the matter is closed
Financial and transaction records6 years, as UK tax law requires

Backups are overwritten on a rolling cycle, so deleted data may persist in a backup for a short period after removal from live systems — normally no more than 30 days.

8. Security

All traffic to our services runs over HTTPS. Passwords are stored as salted hashes, never in a readable form. Access to production systems is limited to those who need it, which at present is one person. Card data is handled entirely by Stripe, a PCI DSS Level 1 provider.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and tell you without undue delay where the risk is high.

9. Your rights

Under UK GDPR you have the right to:

Email [email protected] and we will respond within one month. There is no charge. We may need to verify who you are first, which normally means replying from the address on the account.

You can delete your account yourself at any time — see Delete your account.

10. Children

The service is not directed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, tell us and we will remove it.

11. Changes to this policy

We will update this page when our practices change, and change the date at the top. If a change is significant, we will email account holders rather than relying on you to notice.

12. Complaints

Please raise anything with us first at [email protected] — most things are a misunderstanding we can clear up quickly.

You also have the right to complain to the UK supervisory authority:

Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113 · ico.org.uk