How we collect, use and protect your personal data — and the choices you have.
Last updated: 22 September 2026
SeloraCloud is the data controller for personal data processed through this website and our billing platform. We are established in the United Kingdom and offer services to customers in the UK and the EU/EEA, so this policy addresses both the UK GDPR (with the Data Protection Act 2018) and the EU GDPR (Regulation (EU) 2016/679).
Lakewren Digital Ltd — company number 17478291.
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom.
VAT number: [VAT NUMBER — TO BE PROVIDED IF REGISTERED]
[PLACEHOLDER — support e-mail, legal e-mail, billing e-mail, abuse e-mail and telephone number: to be provided by the company before launch. Do not publish with placeholder company details.]
[PLACEHOLDER — if the company has no establishment in the EU/EEA, EU GDPR Article 27 requires an EU representative; if it has no establishment in the UK, UK GDPR Article 27 requires a UK representative. Provide representative name, address and e-mail if applicable, or confirm no representative is required.]
If we are required to appoint a Data Protection Officer, their contact details appear above; otherwise data protection enquiries go to our legal e-mail address.
Account and order data: name, contact details, billing address and order history, collected when you register or place an order through our billing platform.
Support data: the contents of tickets, e-mails and chat messages you send us.
Contact and quote forms: when you use the contact or newsletter form on this website, the details you enter are handed to the contact page of our billing platform so we can respond. This website itself does not store form entries.
Technical data: IP address, browser type and pages visited, collected in server logs for security, abuse prevention and to operate the service.
Cookies: see our Cookie Policy. This website itself sets no analytics or marketing cookies; strictly necessary cookies (including your cookie choice) are stored locally in your browser.
To provide and administer the services you order, including provisioning through our billing platform.
To invoice you and process payments (payment card data is handled by our payment providers, not stored by us).
To provide support and communicate about your services.
To meet legal obligations (including tax and accounting law, and obligations under the Digital Services Act where we host content for EU recipients), prevent fraud and abuse, and protect our infrastructure.
With your consent, to send marketing communications — which you can unsubscribe from at any time.
Performance of a contract (Art. 6(1)(b)): processing needed to deliver the services you order.
Legal obligation (Art. 6(1)(c)): retaining invoices and accounting records, and responding to lawful requests.
Legitimate interests (Art. 6(1)(f)): security logging, abuse prevention, fraud detection and network integrity. You can object to this processing as described below.
Consent (Art. 6(1)(a)): any optional cookies or marketing communications, which you can withdraw at any time without affecting processing already carried out.
We share personal data only with processors who need it to deliver the service: our hosting and billing platform provider (WHMCS), payment providers (including SpicePay and, where used at checkout, its card processor), domain registries where you register a domain through us, and e-mail delivery providers.
We do not sell personal data and we do not share it for advertising.
We may disclose data where required by law, by a court or competent authority, or to protect our network and customers from abuse — including under notice-and-action and information obligations of the EU Digital Services Act.
Where personal data leaves the UK, transfers rely on UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
Where personal data leaves the EU/EEA, transfers rely on European Commission adequacy decisions or the EU Standard Contractual Clauses, with supplementary measures where needed.
You can request details of the safeguards in place by contacting us.
Account and order records are kept for the life of the account and then for the period required by applicable tax and company law (in the UK generally six years from the end of the relevant accounting period; in EU member states the period required by local law).
Security logs are kept for a limited period and then deleted or anonymised.
Under the UK GDPR and EU GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests or to direct marketing.
You have the right to withdraw consent at any time where we rely on consent.
To exercise any right, contact us using the details above. We respond without undue delay and within one month.
If you are in the UK you can complain to the Information Commissioner’s Office (ico.org.uk). If you are in the EU/EEA you can complain to the supervisory authority of your member state.
We use TLS encryption for the website and billing platform, restrict access to personal data to staff and processors who need it, and review our security measures regularly.
Our services are not directed to children under 16 and we do not knowingly collect their data. In the UK, consent for information society services offered directly to a child is valid from age 13; we still do not market to or knowingly onboard children.
We may update this policy; the version on this page with the “last updated” date above applies. Material changes are announced through the client area or by e-mail.