Hosting Shared Hosting WordPress Hosting India Hosting Free Web Hosting Reseller Hosting LiteSpeed Hosting Free Migration
Domains Domain Registration Domain Transfer Domain Checker .COM Domain .IN Domain .XYZ Domain .SHOP Domain WHOIS Lookup
Servers VPS Hosting Cloud Hosting Dedicated Servers Enterprise All Plans
Pricing
Company About Us Why Ceohost Team Careers Partnership Blog Contact Us Sitemap
Support Knowledge Base Submit Ticket Live Chat System Status SLA & Uptime Refund Policy Privacy Policy Terms of Service Acceptable Use
Client Login Order Now
Legal · privacy

Privacy, plainly.

This policy explains what data we collect, why we collect it, how long we keep it, and who we share it with. Aligned with India's Digital Personal Data Protection Act, 2023.

Trusted stack

Powered by the same tech
as the world's fastest hosts.

LiteSpeedCloudflarecPanelNVMeImunify360AMD EPYCIntel XeonWordPressWHMCSMariaDBRedisUbuntuAlmaLinuxLiteSpeedCloudflarecPanelNVMeImunify360AMD EPYCIntel XeonWordPressWHMCSMariaDBRedisUbuntuAlmaLinux

Privacy Policy

Version 1.0 · Effective & Last Updated · July 10, 2026 · Download PDF

1. Introduction

This Privacy Policy describes how Ceohost ("Ceohost," "we," "us," "our"), operating at www.ceohost.in, collects, uses, stores, shares, and protects personal information when you visit our website, purchase our hosting services, or use our client portal. This Policy applies to visitors, prospective customers, and existing customers of Ceohost.

We have written this Policy to be as clear and specific as possible, in line with the principles of India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025. Please read it carefully. By using our website or Services, you acknowledge the practices described here.

2. Definitions

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Data Principal" means the individual to whom the personal data relates (i.e., you, our customer or website visitor) — the DPDP Act's term for what other laws call a "data subject."
  • "Data Fiduciary" means Ceohost, as the entity that determines the purpose and means of processing your personal data.
  • "Processing" means any operation performed on personal data, including collection, storage, use, sharing, or deletion.
  • "Consent" means your free, specific, informed, and unambiguous agreement to the processing of your personal data for a stated purpose.

3. Information We Collect

When you register, place an order, or contact us, we may collect:

  • Full name, email address, phone number, and billing/mailing address;
  • Company name and GST details, where applicable, for business customers;
  • Government-issued identification documents where KYC verification is required (see Section 5 and our Terms of Service, Section 3);
  • Account credentials (username; passwords are stored in encrypted/hashed form and are never visible to our staff in plain text);
  • Support ticket and communication history with our team.

4. Information Collected Automatically

When you visit our website or use our client portal, certain information is collected automatically:

  • IP address, browser type and version, device type, operating system;
  • Referring/exit pages, date/time stamps, and clickstream/navigation data;
  • Server and application logs generated by your use of hosting services (e.g., access logs, error logs).

This automatically-collected technical data is generally used in aggregate for analytics, security, and troubleshooting, and is not combined with personally identifiable information except where necessary to investigate abuse or a security incident (see our Acceptable Use Policy, Section 26, Evidence Preservation During Investigations).

5. Hosting & Customer Data (Including KYC)

As a hosting provider, we additionally process:

  • Website Content Data: The files, databases, emails, and application data you upload to your hosting account remain your data/content; Ceohost processes and stores it solely to provide the hosting service you have purchased, and does not review or use it for any other purpose except where necessary to investigate a reported abuse issue (see our Acceptable Use Policy).
  • KYC Data: For plans requiring identity verification (e.g., certain Indian VPS, Dedicated Server, or Cloud Hosting plans, per our Terms of Service Section 3), we collect government-issued ID proof such as Aadhaar Card, PAN Card, Passport, Voter ID, or Driving Licence. This data is collected solely to comply with applicable cybersecurity/regulatory requirements, prevent fraud, and verify your identity.
  • Payment/Billing Records: Invoice history, payment status, and transaction references (see Section 10, Payment Information, regarding card/UPI data specifically).

6. How We Use Your Information

We use collected information to:

  • Provision, activate, and manage your hosting account and related services;
  • Process payments, generate invoices, and manage billing/renewals;
  • Provide customer support and respond to your tickets/queries;
  • Verify your identity where KYC is required by law or our Terms of Service;
  • Detect, investigate, and prevent fraud, abuse, or security threats (see our Acceptable Use Policy);
  • Send you important service communications (e.g., renewal reminders, maintenance notices, security alerts);
  • Send you optional marketing communications, where you have opted in (see Section 25);
  • Improve our website, services, and customer experience through aggregate, non-identifying analytics.

7. Legal Basis for Processing

In accordance with the DPDP Act, we process your personal data on one or more of the following legal bases:

  • Consent: Where you have given free, specific, informed consent for a stated purpose (e.g., subscribing to marketing emails).
  • Performance of a Contract: Where processing is necessary to provide the hosting services you have purchased under our Terms of Service.
  • Legal Obligation: Where we must process data to comply with applicable law, such as KYC/CERT-In requirements, tax law, or a valid legal request.
  • Legitimate Use: As recognized under Section 7 of the DPDP Act, for purposes such as data you have voluntarily provided for a specified purpose without indicating objection, fraud prevention, and network/information security.

8. Cookies & Similar Technologies

Our website uses cookies and similar technologies (such as local storage) to:

  • Remember your login session and preferences;
  • Understand aggregate website traffic and usage patterns to improve our site;
  • Support essential functionality such as shopping cart/checkout flows.

You can control or disable cookies through your browser settings at any time. Disabling cookies may affect certain website features (e.g., staying logged into the client portal) but will not prevent you from browsing our public website.

9. Third-Party Services

We work with trusted third-party service providers to operate our business, including payment gateways (e.g., Razorpay), email delivery services, analytics providers, and infrastructure/datacenter partners. These providers process personal data only as necessary to perform their function for us and are expected to maintain appropriate confidentiality and security safeguards. We do not control the independent privacy practices of these third parties beyond our contractual arrangements with them.

10. Payment Information

All card, UPI, net-banking, and wallet payment details are processed directly by our payment gateway partner(s) and are not stored on Ceohost's own servers. Ceohost retains only transaction references, invoice records, and payment status necessary for accounting, support, and legal compliance.

11. Communications

We may contact you via email, SMS, or WhatsApp regarding: order confirmations, invoices and renewal reminders, service/maintenance notices, security alerts, support ticket responses, and (where you have opted in) marketing offers. Transactional/service communications are necessary for providing the Service and cannot be opted out of while your account remains active; marketing communications can be opted out of at any time (see Section 25).

12. Information Sharing & Disclosure

We do not sell your personal data. We may share personal data only in the following circumstances:

  • With trusted service providers (payment gateways, email/SMS providers, infrastructure partners) strictly to perform services on our behalf;
  • With domain registrars/ICANN, where necessary for domain registration and WHOIS compliance;
  • Where required to comply with applicable law, a valid court order, or a legal request from a government or regulatory authority (see Section 19);
  • In connection with a business transfer, as described in Section 21;
  • With your explicit consent for any other specific purpose.

13. International Data Transfers

Ceohost primarily stores and processes Indian-customer hosting data on servers located in India. Where a customer opts for an offshore hosting plan (e.g., Singapore or other international datacenter), their website content data will be stored in that selected jurisdiction as part of the service they have chosen. Where any personal data is transferred outside India (for example, to a service provider located abroad), we take reasonable steps to ensure it continues to receive an appropriate standard of protection, consistent with the DPDP Act's provisions on cross-border data transfer.

14. Data Retention

  • Account Data: Retained for as long as your account remains active, and for a reasonable period thereafter for accounting, tax, and legal purposes (see also our Terms of Service, Section 13, Suspension for Non-Renewal & Data Retention, regarding the 14-day post-suspension window).
  • KYC Data: Retained only as long as necessary to satisfy the regulatory purpose for which it was collected, and in line with applicable law's minimum retention requirements; securely deleted or anonymized thereafter.
  • Financial/Invoice Records: Retained for the period required under applicable Indian tax and accounting law (generally up to 7-8 years).
  • Marketing Data: Retained until you withdraw consent/unsubscribe, after which we stop using it for marketing purposes.

15. Your Privacy Rights (Data Principal Rights)

As a Data Principal under the DPDP Act, you have the right to:

  • Access a summary of the personal data we hold about you and the processing activities undertaken;
  • Correction & Update of inaccurate or incomplete personal data;
  • Erasure of personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations;
  • Withdraw Consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  • Grievance Redressal through our designated contact (Section 30) before escalating a complaint to the Data Protection Board of India;
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

To exercise any of these rights, please email privacy@ceohost.in with your request. We aim to respond within a reasonable timeframe, and in any case within the period prescribed under applicable law.

16. Data Security

  • We store sensitive data (including KYC documents and account credentials) using industry-standard encryption, both in transit (via SSL/TLS) and, where applicable, at rest.
  • Access to sensitive personal data is restricted to authorized personnel on a need-to-know basis.
  • We conduct regular security reviews, malware scanning, and monitoring of our infrastructure to identify and address vulnerabilities.
  • While we implement reasonable and appropriate security safeguards, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.

17. Customer Responsibilities

You are responsible for keeping your account password and any application-level credentials (e.g., WordPress admin login) confidential, for providing accurate information when creating or updating your account, and for promptly notifying us if you suspect unauthorized access to your account. Under the DPDP Act, you also have a duty not to impersonate another person while providing your personal data to us, and not to suppress any material information while providing your personal data.

18. Children's Privacy

Our Services are intended for individuals who are at least 18 years of age, or who otherwise have the legal capacity to enter into a binding contract in their jurisdiction. We do not knowingly collect personal data from children. Consistent with the DPDP Act's provisions on children's data, we do not process data in a manner that tracks, behaviorally monitors, or targets advertising at children, and we do not knowingly process a child's personal data without verifiable parental/guardian consent where such processing is identified.

19. Law Enforcement & Legal Requests

Ceohost may disclose personal data, account information, or content where required to do so by a valid court order, subpoena, or a lawful request from a government or law-enforcement authority under applicable Indian law, including the Information Technology Act, 2000 and CERT-In directions. Where legally permitted, we will make reasonable efforts to notify the affected customer of such a request.

20. Data Breach Response

In the unlikely event of a personal data breach, Ceohost will:

  • Notify the Data Protection Board of India without delay upon discovering the breach, as required under the DPDP Act, describing its nature, extent, and mitigation steps taken;
  • Provide a follow-up report with remedial actions and root-cause findings within the timeframe prescribed under applicable rules;
  • Notify affected Data Principals as required by law, describing the nature of the breach and steps they can take to protect themselves;
  • Take immediate technical and organizational steps to contain the breach and prevent recurrence.

21. Business Transfers

If Ceohost is involved in a merger, acquisition, restructuring, or sale of business assets, personal data may be transferred as part of that transaction, subject to the receiving party agreeing to honor the commitments in this Privacy Policy (or to provide you with notice and choices consistent with applicable law) with respect to your personal data. This should be read together with our Terms of Service, Section 24.2 (Service Discontinuation & Business Wind-Down), which describes our commitment to data export opportunity and advance notice in the rare event of a broader business closure.

22. Automated Decision-Making

Ceohost does not currently use fully automated decision-making processes that produce legal or similarly significant effects concerning you without human involvement. Where any automated system (e.g., fraud-detection scoring) flags an account for review, a human review is conducted before any suspension or termination decision is finalized, consistent with our Terms of Service and Acceptable Use Policy enforcement processes.

23. AI Services & AI Data Processing

Where Ceohost uses AI-based tools internally (for example, for support-ticket triage, fraud/abuse pattern detection, or content moderation assistance), such tools process data solely to support these operational functions and do not make final enforcement decisions without human review (see Section 22). If you host your own AI-generated content, chatbots, or automated agents using our Services, you remain solely responsible for that content and any data it processes, as set out in our Acceptable Use Policy, Section 37.

24. Do Not Track (DNT) Signals

Some browsers offer a "Do Not Track" (DNT) signal. As there is currently no universally accepted industry standard for recognizing and responding to DNT signals, Ceohost's website does not currently respond differently to DNT signals; however, you can still manage cookies directly through your browser settings as described in Section 8.

25. Marketing Communications & Consent

We will only send you marketing/promotional communications where you have opted in (for example, by subscribing to our newsletter or checking a consent box at signup). You may withdraw this consent and unsubscribe at any time using the unsubscribe link in any marketing email, or by emailing privacy@ceohost.in. Withdrawing marketing consent does not affect transactional/service communications necessary for your active hosting account.

26. Data Accuracy & Updates

You can review, update, or correct your account information at any time through your client portal, or by contacting our support team. We encourage you to keep your contact and billing information accurate and up to date, as this information is used for important service and security communications.

27. Account Closure & Data Deletion

When you close your account or your service is terminated, we will delete or anonymize your personal data in line with the retention periods described in Section 14 and our Terms of Service (Section 13, Suspension for Non-Renewal & Data Retention, and Section 20, Data Portability on Account Closure). Certain records (e.g., invoices, KYC records required by law) may be retained beyond account closure strictly for legal/regulatory compliance purposes.

28. Third-Party Links Disclaimer

Our website and, in some cases, customer-hosted websites may contain links to third-party sites. These third-party sites operate under their own independent privacy policies, and Ceohost has no responsibility or liability for their content or privacy practices. We encourage you to review the privacy policy of any third-party site you visit.

29. Business Discontinuation & Data Handling

In the rare event that Ceohost needs to discontinue a service, product line, or its overall operations — whether for commercial, technical, regulatory, or other reasons, as described in our Terms of Service, Section 24.2 — we will handle any personal data involved consistent with this Privacy Policy: providing reasonable advance notice where possible, an opportunity to export your data, and secure deletion of retained personal data thereafter in line with our standard retention practices, except where further retention is legally required.

30. Changes to This Privacy Policy

Ceohost may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on our website with a revised "Last Updated" date, and, for material changes, will make reasonable efforts to notify you via email or a website/portal notice. Continued use of our Services after an update constitutes your acknowledgment of the revised Policy.

31. Governing Law

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and applicable rules made thereunder. Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the competent courts having territorial jurisdiction over Ceohost's principal place of business in India.

32. Contact Us & Grievance Redressal

For any questions about this Privacy Policy, to exercise your Data Principal rights, or to raise a grievance, please contact us at: privacy@ceohost.in or visit www.ceohost.in/contact. We will acknowledge and address grievances in accordance with applicable law, before you have the right to escalate any unresolved complaint to the Data Protection Board of India.

Transparency

Trust you can
actually verify.

No badges we can't back up. Here's what you can go check yourself, right now.

See live status
Named founder & team
Not an anonymous reseller
Public status page
Live uptime, 24/7, no login needed
7-day money-back
No questions, no cancellation forms
Imunify360 + WAF
Real-time malware defense, every plan
Daily off-site backups
30-day retention, one-click restore
Bootstrapped since 2019
No VC pressure to cut corners
FAQ

Questions,
answered.

Can't find what you're looking for? Our team is one click away — anytime, day or night.

Open a support ticket
Response in < 15 min
Knowledge base
200+ how-to guides
Talk to sales
Custom / bulk pricing
Client area
Manage services & billing
What kind of hosting do I need for my website?×
For personal sites, portfolios and small business sites — Shared Hosting (₹19/mo) is perfect. Running WordPress? Pick WordPress Hosting for pre-configured caching and staging. Selling to Indian customers? India Hosting (Mumbai DC) offers lightning-fast local performance. Need more control or higher traffic? Move to VPS, Cloud or Dedicated servers.
How fast is Ceohost compared to my current host?+
On identical WordPress + WooCommerce installs from Mumbai, we typically see 3-5× faster TTFB and 2× faster full-page load thanks to LiteSpeed, NVMe and free Cloudflare Enterprise routing.
Do you provide free migration from my current host?+
Yes — up to 200 GB is migrated free by real Linux engineers (not scripts). Zero downtime, staged testing and a rollback safety net if anything goes wrong.
Is there a money-back guarantee?+
Every plan is protected by a 7-day money-back guarantee, no questions asked. Domain registration fees are non-refundable but everything else is.
What payment methods do you accept in India?+
UPI, all major credit & debit cards, Netbanking, Wallets, Razorpay and international cards. VPS and Cloud can be invoiced.
How secure are Ceohost servers?+
Every plan includes Imunify360, WAF, DDoS mitigation, wildcard SSL, isolated CloudLinux containers and daily off-site backups. and we run regular external penetration testing.
Can I upgrade my plan later without downtime?+
Absolutely. Shared / WordPress plans upgrade instantly (in the same container). VPS & Cloud can vertically scale with a 30-second reboot.
Do you offer domain registration?+
Yes — .in from ₹399, .com from ₹749, and 480+ other TLDs. Free ID protection on every domain.
What if I need help — how do I contact support?+
24/7 live chat, WhatsApp, tickets, phone and email. Median first response is 47 seconds. Real engineers — never bots.
Where are your datacenters located?+
Primary DC in Mumbai (Tier-4), edge PoP in Bengaluru, plus Singapore, Frankfurt, London, New York, Dallas, Sao Paulo and Sydney.
Get started

Privacy questions?

Email privacy@ceohost.in — our Data Protection Officer replies personally within a reasonable timeframe.

7-day money back Free migration 24/7 support No hidden fees
Fastest to activate
< 2 minutes

From payment to cPanel access — most orders activate in under two minutes, 24/7.

Privacy, plainly

A little more — What we collect.

The context

Account: name, email, phone, GSTIN. Billing: transaction IDs (never full card numbers). Service: DNS zones, mailbox size. Support: tickets, chat transcripts.

What we don't do

We do not sell data. We do not run tracking pixels. We do not use Google Ads or Facebook pixels. Analytics are self-hosted Plausible with no personal data.
Security

Enterprise security for
₹39-a-month customers.

Every plan — from Starter Cloud to Enterprise bare-metal — ships with the same paranoid, defence-in-depth security stack.

Imunify360 real-time

Signature + behavioural malware detection with automatic quarantine and healing.

Free wildcard SSL

Let's Encrypt on every domain and subdomain — auto-renewed, HSTS pre-loaded.

20 Gbps DDoS shield

Anycast network with automatic mitigation of Layer 3/4 attacks and behavioural L7 rules.

Off-site backups

Daily JetBackup snapshots stored in a separate DC for 30 days. Restore in one click.

Isolated containers

Every account runs inside a CloudLinux LVE — one hacked site can't touch another.

Serious about security

Background-checked staff, isolated containers, and quarterly external penetration tests.

Regions

9 regions, real latencies.

Median TTFB from a Mumbai visitor to each region — measured continuously from our public monitoring nodes.

RegionCodeTierPeeringMedian from MumbaiSLARole
Mumbai · India IN-MUM Tier-4 Airtel · Jio · VI 35 ms 99.99% Primary
Bengaluru · India IN-BLR Tier-3 Jio · ACT · Airtel 48 ms 99.99% Edge
Singapore SG-SIN Tier-4 Equinix SG3 65 ms 99.99% Cloud + CDN
Frankfurt DE-FRA Tier-4 Interxion FRA5 140 ms 99.99% Bare-metal
London GB-LON Tier-4 LD5 150 ms 99.99% CDN + Edge
New York US-NYC Tier-4 Equinix NY9 230 ms 99.99% Cloud
Dallas US-DAL Tier-3 Dallas Infomart 220 ms 99.99% CDN
Sao Paulo BR-GRU Tier-3 Equinix SP4 290 ms 99.99% CDN
Sydney AU-SYD Tier-3 Global Switch 195 ms 99.99% Edge
Privacy

DPDP + GDPR aligned.

No data sales · no tracking pixels · self-hosted analytics.

Zero data sales
No ad pixels
DPO email
30-day requests
Data residency
Mumbai · default
Rights

What you can request.

Under DPDP + GDPR — reply in 30 days from dpo@ceohost.in.

Access

Full copy of your data.

Correction

Fix any inaccuracy.

Portability

Export in JSON.

Deletion

Right to be forgotten.

Objection

Opt out of processing.

Grievance

Escalate to grievance@.

Related legal pages

Other legal pages.