Who We Are
VoloWeb Internet Services ("VoloWeb", "we", "us", or "our") operates the website at voloweb.io and provides web hosting, domain registration, cloud VPS, business email, and related digital services.
For the purposes of applicable data protection laws — including the Indian Information Technology Act, 2000 (amended 2008), the IT (Amendment) Rules 2011, and, where applicable, the EU General Data Protection Regulation (GDPR) — VoloWeb acts as the data controller of personal information submitted through our website and services.
This Privacy Policy applies to all visitors, customers, and users of VoloWeb's websites and services. By accessing our platform you agree to the practices described here.
Information We Collect
We collect information you provide directly, information collected automatically when you use our services, and information from third-party sources.
2.1 Information You Provide
- Account registration: Name, email address, phone number, billing address, and password (hashed, never stored in plaintext).
- Payment information: Billing name, address, and payment card details — processed securely through PCI-DSS compliant payment gateways (Razorpay, PayPal, Stripe). VoloWeb does not store full card numbers.
- Domain registration: WHOIS contact details (name, organization, address, email, phone) required by ICANN regulations. Free WHOIS privacy protection is included for eligible TLDs.
- Support communications: Messages, ticket content, chat transcripts, and attachments you send to our support team.
- Survey and feedback forms: Optional responses to satisfaction surveys or feature requests.
- Identity verification: Government-issued ID may be requested for high-risk account verification or domain dispute processes.
2.2 Information Collected Automatically
- Log data: IP address, browser type and version, operating system, referring URL, pages visited, timestamps, and HTTP response codes.
- Cookies and similar technologies: Session cookies, persistent cookies, local storage, and web beacons. See Section 5 for full details.
- Device information: Device type, screen resolution, and language preference.
- Usage analytics: Pages viewed, features used, click patterns, and session duration via analytics tools.
- Server performance data: Resource usage (CPU, RAM, bandwidth, disk I/O) for services you have purchased.
2.3 Information from Third Parties
- Payment confirmation and fraud signals from payment processors.
- Domain ownership and transfer eligibility data from registries.
- Public social profile data if you connect a social account for sign-in.
How We Use Your Data
We use your personal data only for purposes that are clearly defined and proportionate.
| Purpose | Data Used | Basis |
|---|---|---|
| Provision of hosting, domain, and email services | Account info, payment info | Contract |
| Processing payments and invoicing | Billing info, payment details | Contract / Legal obligation |
| Customer support and ticket resolution | Account info, communications | Contract / Legitimate interest |
| Account security and fraud prevention | IP address, login data | Legitimate interest |
| Service communications (outages, renewals, policy changes) | Email address | Contract / Legal obligation |
| Marketing emails and promotional offers | Email, name | Consent (opt-in) |
| Analytics and service improvement | Usage data, log data | Legitimate interest |
| Legal compliance and regulatory reporting | All categories as required | Legal obligation |
| WHOIS / domain registration compliance | Contact details | Legal obligation (ICANN) |
We will never sell your personal data to third parties for their own marketing purposes.
Legal Basis for Processing
Where the GDPR applies to you (for example, if you are located in the European Economic Area), we rely on the following legal bases:
- Contract performance: Processing necessary to deliver the services you have purchased.
- Legitimate interests: Fraud detection, system security, internal analytics, and improving our platform — where those interests are not overridden by your rights.
- Legal obligation: Compliance with Indian tax law, ICANN domain registration requirements, and applicable financial regulations.
- Consent: Marketing communications and non-essential cookies, which you may withdraw at any time.
Cookies & Tracking Technologies
We use cookies and similar technologies to operate our website, remember your preferences, and understand how visitors interact with our content.
Types of Cookies We Use
| Category | Purpose | Examples | Consent Required |
|---|---|---|---|
| Strictly Necessary | Core site functionality, login sessions, shopping cart | session_id, XSRF-TOKEN | No |
| Performance / Analytics | Aggregate usage stats, page performance | Google Analytics (_ga) | Yes |
| Functional | Remember language, region, and chat preferences | locale, live_chat_ref | Yes |
| Marketing | Retargeting ads and conversion tracking | _fbp, Google Ads | Yes |
You can control cookies through our cookie consent banner or via your browser settings. Disabling non-essential cookies will not impair core service functionality.
We use Google Analytics with IP anonymisation enabled. No personally identifiable information is sent to Google as part of analytics tracking.
Data Sharing & Third Parties
We share your data only where necessary to provide the service or where required by law. We never sell personal data.
Service Providers (Data Processors)
- Payment gateways: Razorpay, PayPal, Stripe — for secure payment processing.
- Data centres & infrastructure: Our hosting infrastructure partners who hold ISO 27001 certification.
- Email delivery: Transactional email via SMTP providers (invoices, password resets, service alerts).
- Analytics: Google Analytics (pseudonymised data only).
- Live chat and support: Help-desk software to manage customer tickets.
- Domain registries: ICANN-accredited registries and registrars for domain registration and WHOIS purposes.
Legal Disclosures
We may disclose personal data if required by a court order, subpoena, or regulatory authority, or if we believe disclosure is necessary to protect rights, safety, or property of VoloWeb, our customers, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction. We will notify affected users by email or a prominent notice before data is transferred and becomes subject to a different privacy policy.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.
| Data Category | Retention Period |
|---|---|
| Active account data | Duration of account + 3 years after closure |
| Payment records and invoices | 7 years (Indian GST compliance) |
| Support ticket history | 3 years from ticket closure |
| Server and access logs | 90 days rolling |
| Marketing consent records | Until consent is withdrawn + 2 years |
| Domain WHOIS data | As required by ICANN policy (typically 2 years post-expiry) |
| Fraud and security incident records | 5 years |
When data is no longer required, it is securely deleted or anonymised in accordance with our data destruction policy.
Your Rights
Depending on your location, you have the following rights regarding your personal data. We will respond to all verifiable requests within 30 days.
To exercise any of these rights, contact us at privacy@voloweb.io. We may need to verify your identity before actioning your request.
Security
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure.
- Encryption in transit: All data transmitted between your browser and our servers is protected by TLS 1.2/1.3 (HTTPS). Free SSL certificates are provided for all hosting accounts.
- Encryption at rest: Sensitive data including passwords (bcrypt) and payment tokens are encrypted at rest.
- Access controls: Role-based access controls (RBAC), two-factor authentication (2FA) for staff, and principle of least privilege.
- Firewalls & DDoS protection: Enterprise-grade firewall rules, intrusion detection, and multi-layer DDoS mitigation.
- Regular audits: Periodic penetration testing, vulnerability scanning, and security reviews.
- Backups: Daily automated backups with offsite replication and tested restore procedures.
No method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. Please use strong, unique passwords and enable two-factor authentication on your account.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware.
International Transfers
VoloWeb is headquartered in India. Your data may be processed by our team or service providers located outside India. When transferring personal data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where applicable.
- Data processing agreements with all sub-processors.
- Adherence to the requirements of the Indian IT Act and applicable cross-border data transfer regulations.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@voloweb.io and we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Send an email notification to registered customers at least 14 days before changes take effect.
- Display a prominent notice on our website.
Your continued use of VoloWeb services after the effective date of any changes constitutes acceptance of the revised Policy. If you do not agree, you may close your account before the changes take effect.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, our dedicated Privacy team is here to help.
Email: privacy@voloweb.io
Address: VoloWeb Internet Services, India
Support Portal: voloweb.io/client