1. Introduction and Scope
Host360 ("Host360," "we," "us," or "our") operates enterprise cloud infrastructure — public cloud, private cloud, GPU and AI infrastructure, bare metal, colocation, storage, networking, disaster recovery and managed services — for organisations across India and international markets.
This Privacy Policy explains what personal data we collect when you visit www.host360.ai, interact with our sales and support teams, or use Host360 services and the Host360 Client Portal. It also explains how we handle the data our customers store and process on our infrastructure, and the rights available to you.
It applies to our website and documentation portals; the Client Portal used for provisioning, usage monitoring, billing and support; sales enquiries, consultations, demos and RFP processes; managed, migration and professional services engagements; colocation facility access including visitor and physical security records; and our marketing, events and partner programmes.
It does not apply to the content customers themselves upload, generate or process on Host360 infrastructure. That is governed by Section 3, your Master Services Agreement and, where applicable, a Data Processing Agreement.
By using our website or services, you acknowledge that you have read and understood this Policy.
2. Our Role: Data Fiduciary and Data Processor
Which role we occupy determines your rights and our obligations, so we state it plainly.
Host360 is the Data Fiduciary (Controller) for website visitor and marketing data, sales and prospect enquiries, Client Portal account, authentication and billing data, support ticket metadata and correspondence, vendor and partner records, employment applicant data, and physical access and CCTV records at our facilities. In these cases we determine why and how the data is processed.
Host360 is a Data Processor for personal data contained inside your workloads. When you deploy virtual machines, containers, databases, GPU clusters, storage buckets or backup replicas on our infrastructure, you remain the Data Fiduciary for the personal data within them. We process it solely on your documented instructions. We do not decide what you collect, why, how long you retain it, or how you respond to data principal requests. You are responsible for the lawfulness of the data you place on our infrastructure, for obtaining necessary consents, and for configuring encryption, access controls and retention appropriately.
Regulated customers — BFSI entities under RBI directives, insurers under IRDAI, healthcare organisations and government bodies — should execute a Data Processing Agreement with Host360. Request one at privacy@host360.ai
3. Customer Content and AI Workloads
Customer Content means the data, applications, databases, datasets, model weights, logs, media and backups you store or process on Host360 infrastructure. Our commitments are unambiguous.
We do not read, scan, index or analyse the contents of your virtual machines, storage buckets or GPU workloads. We do not sell, licence, share or monetise Customer Content. And we never use it to train, fine-tune, benchmark or evaluate any machine learning or AI model — ours or anyone else's.
Host360 engineers access customer environments only when you raise a support request and grant access, when a managed services contract authorises administration of your environment, when an incident affecting platform integrity requires investigation, or when we are legally compelled. All privileged access is authenticated, role-based, time-bound and logged, and those logs are available to enterprise customers as audit evidence.
When you run training, fine-tuning or inference on Host360 GPU infrastructure, your datasets, model weights, prompts, embeddings and outputs remain yours. We do not access, copy or retain them for any purpose beyond delivering the compute you provisioned.
Data placed in Indian regions stays in Indian data centres by default. Cross-border replication occurs only where you configure it.
Separately, Host360 does not make decisions producing legal or similarly significant effects about you through solely automated means. We use automation operationally — fraud and abuse detection, capacity forecasting, security anomaly detection, lead routing and chatbot triage — and a human reviews any outcome that materially affects service provision, such as account suspension.
4. Personal Data We Collect
Information you provide. When you enquire, register, contract or raise a support request, we collect your name, job title, business email, phone number, company name and country. Client Portal accounts additionally involve a username, hashed password, MFA settings, SSH public keys and API keys. Commercial engagement generates billing address, GSTIN, PAN, purchase orders, invoices and payment references, and — for regulated or high-capacity deployments — company registration documents and authorised signatory identification for KYC. During solution design we record the technical requirements you share: vCPU, RAM, storage, operating system, IP addressing, GPU model and workload description. Support interactions produce tickets, chat transcripts, email threads and call notes.
We do not require sensitive personal data such as health, biometric or financial account credentials, and ask that you do not submit it through enquiry or support channels.
Information collected automatically. Visiting our website or Portal generates connection and device data — IP address, browser and operating system, device type and language — alongside usage data such as pages viewed, referring URL, time on page and downloads. Portal use additionally generates login timestamps, source IP, actions performed, API calls and configuration changes, retained as security and audit evidence.
Service usage and metering data. To operate the platform and bill accurately we collect operational telemetry about your consumption: vCPU hours, RAM allocation, GPU hours by model type, block, object and backup storage consumed, network ingress and egress, public IP allocation, snapshot and replication counts, Kubernetes node hours, instance lifecycle events, and uptime and SLA metrics. This is infrastructure metadata, not workload content, and it underpins invoicing, capacity planning, SLA reporting and abuse detection.
Information from third parties. We may receive business contact data from channel partners, system integrators, resellers, event organisers, marketing platforms and compliance screening providers. We use it only for legitimate B2B outreach and due diligence, and honour opt-outs immediately.
Physical security data. Visitors to a Host360 or partner data centre are recorded by name, organisation, government ID reference, entry and exit time and escort details, and are captured on CCTV, as required for facility security and Tier III compliance.
5. Why We Process Your Data
We process personal data to respond to enquiries and quotations, to provision and operate your cloud, GPU and managed services, to meter usage and issue invoices, and to deliver technical support and incident response — all necessary to enter into or perform our contract with you.
We rely on legitimate interests, balanced against your rights, to monitor platform security, detect fraud and abuse, maintain audit logs, send service and outage notices, and improve platform capacity and reliability using aggregated, de-identified data.
We rely on legal obligation for statutory and tax record-keeping, KYC and sanctions screening, and regulatory reporting.
We rely on consent for analytics and marketing cookies, marketing communications to new prospects, and recruitment processing. Existing business customers may receive relevant marketing under legitimate interests, always with a clear opt-out. You may withdraw consent at any time; withdrawal does not affect processing already carried out and may limit certain services.
6. Cookies and Website Tracking
We use four categories of cookies. Strictly necessary cookies handle authentication, session management, load balancing and consent storage — these cannot be disabled without breaking the site and the Client Portal. Functional cookies remember language and region preferences, chat widget state and form entries. Analytics cookies measure aggregate traffic, page performance and conversion funnels. Marketing cookies support campaign attribution, retargeting and conversion measurement.
Non-essential cookies are set only with your consent. You can accept, reject or granularly configure them through the banner shown on your first visit, and change your choices at any time. We also honour browser-level controls and Global Privacy Control signals where technically supported. A current list of cookies with provider, purpose and duration is maintained at www.host360.ai/cookie-policy.
Our website and documentation also link to third-party sites, partner platforms and open-source projects whose privacy practices we do not control. Review their policies before providing personal data.
7. Zoho SalesIQ Live Chat
Our website chat and chatbot are powered by Zoho SalesIQ, provided by Zoho Corporation.
SalesIQ processes your chat transcript and any name, email or phone number you enter, together with your IP address and the approximate location derived from it, your browser, device and operating system, your referring source, and the pages you visit before, during and after the chat. It also stores visitor scoring and returning-visitor identifiers in cookies and local storage.
We use this to answer pre-sales questions in real time, qualify infrastructure requirements, route enquiries to the right solutions architect and maintain continuity across sessions. Transcripts are stored in Zoho SalesIQ, may be synchronised into our CRM as a record of the enquiry, and are retained as set out in Section 10.
Please do not enter passwords, API keys, payment card details, government identifiers or confidential workload information into the chat window. If you need to share sensitive material, ask and we will provide a secure channel.
Zoho Corporation acts as our processor under a data processing agreement; its privacy practices are described at https://www.zoho.com/privacy.html. You can avoid SalesIQ entirely by declining functional cookies or by contacting us at sales@host360.ai instead.
8. Client Portal, Billing and Payments
The Host360 Client Portal lets customers provision resources, monitor consumption, download invoices, manage payment methods, raise support tickets and administer team access.
It processes account credentials, MFA enrolment and session records; your organisation hierarchy, user roles and permissions; resource inventory and configuration; consumption metering and cost allocation data; invoices, payment history, credit notes and tax documents; support tickets and attachments; and a full audit trail of administrative actions.
Where the Portal supports online payment, card and bank details are captured and processed directly by PCI DSS compliant payment gateways. Host360 does not store full card numbers, CVV codes or bank credentials — only a payment reference, masked identifier and transaction status.
If your organisation's administrator created your account, they control your access rights and can view your activity within that tenancy; direct account queries to them first. You remain responsible for safeguarding credentials, enabling MFA, rotating API keys and removing access for departing personnel. Notify us immediately at sales@host360.ai if you suspect unauthorised access.
9. Sharing, Sub-Processors and Cross-Border Transfers
We do not sell, rent or trade personal data. We disclose it only as described here.
Service providers. These include cloud and hosting platforms used to deliver multi-cloud managed services (AWS, Microsoft Azure); virtualisation and platform vendors for licensing and support escalation (Nutanix, VMware, OpenStack ecosystem vendors); Tier III data centre and colocation operators; our CRM and sales engagement platform; Zoho SalesIQ for live chat; billing platforms and PCI DSS compliant payment gateways; transactional and marketing email providers; website analytics providers; and monitoring, ticketing, SIEM and ITSM tooling used in NOC and SOC operations. Each is bound by contractual confidentiality and data protection obligations and is assessed before onboarding. A current sub-processor list is available at privacy@host360.ai, and enterprise customers with a DPA receive advance notice of material changes.
Advisers and partners. Legal counsel, auditors, tax advisers and insurers where necessary, and channel partners or system integrators involved in delivering your engagement, who are named in the relevant contract.
Legal and protective disclosures. We may disclose data where required by applicable law, a binding court order or a lawful authority request; to enforce our agreements; to investigate suspected fraud, abuse or security incidents; or to protect the rights and safety of Host360, our customers or the public. Where legally permitted, we will notify the affected customer before disclosing their data and will challenge requests that appear overbroad or improperly issued.
Corporate transactions. In a merger, acquisition, restructuring or asset sale, personal data may transfer to the successor entity subject to this Policy, with notice of any material change in controllership.
Cross-border transfers. Host360 cloud, GPU, storage and colocation services are delivered from data centres in India, and customer workload data remains within Indian jurisdiction by default — supporting RBI data localisation directives, DPDP Act obligations and sovereign cloud requirements. Limited categories of corporate and operational data such as CRM records, chat transcripts, email and analytics may be processed by providers whose infrastructure sits outside India. Where that occurs we apply contractual data protection clauses, Standard Contractual Clauses where GDPR applies, and vendor security assessment. We do not transfer personal data to any country restricted by the Central Government under the DPDP Act, 2023. If you require a contractual guarantee of strict in-country processing across all data categories, contact privacy@host360.ai
10. Data Retention and Deletion
We retain personal data only as long as necessary for the purpose collected, or as required by law.
Website analytics and cookie data are held for up to 26 months, and chat transcripts for 24 months from your last interaction. Sales enquiries that do not convert are deleted 24 months after last engagement. Client Portal account records are retained for the contract duration plus 90 days, and support tickets for three years after closure. Security, audit and access logs are retained for a minimum of 12 months, or longer where contract or regulation requires, and CCTV footage for 90 days unless needed for an active investigation. Billing, invoicing and tax records are retained for eight years under Indian statutory requirements, and KYC documentation for the period mandated by applicable regulation. Recruitment records for unsuccessful applicants are held for 12 months unless you consent to a longer talent-pool period. Marketing suppression records are kept indefinitely so we can continue honouring your opt-out.
Customer Content is retained per your service agreement. On termination, and after any contractually agreed grace period, it is deleted using secure erasure procedures, with backup and DR replicas purged on the rotation cycle defined in your service configuration. Certified deletion attestations are available to enterprise customers on request.
11. Information Security and Breach Notification
Security is engineered into the platform rather than added afterwards.
Technically, we enforce encryption in transit using TLS 1.2 or higher and encryption at rest for supported storage services, alongside network segmentation, VPC isolation, private networking, stateful firewalling and DDoS mitigation at the network edge. Access is governed by role-based controls, least-privilege provisioning and multi-factor authentication, with centralised logging, SIEM correlation and 24x7 SOC monitoring, structured vulnerability and patch management, and immutable audit logging of privileged operations.
Organisationally, personnel with infrastructure access undergo background verification and are bound by confidentiality obligations and security awareness training. We maintain formal incident response, escalation and post-incident review processes, assess vendor security before onboarding sub-processors, and apply change management with segregation of duties.
Physically, our Tier III certified data centres operate 2N redundant power and N+1 precision cooling, with multi-factor access control, CCTV surveillance, 24x7 manned security, visitor escorting and lockable cabinet infrastructure.
Security is a shared responsibility. Host360 secures the underlying infrastructure; you are responsible for what you run on it — operating system hardening, application patching, credential hygiene, key management, IAM configuration, encryption choices and backup validation. No system is entirely immune to compromise, and we cannot guarantee absolute security.
If we become aware of a personal data breach, we will contain and investigate it without undue delay, notify the Data Protection Board of India as required under the DPDP Act, 2023, and report to CERT-In in accordance with applicable cyber incident directions. We will promptly notify affected customers and data principals, describing the nature of the breach, its likely consequences, the mitigation steps taken and any recommended protective action. Where GDPR applies, EU supervisory authorities are notified within 72 hours. Where Host360 acts as a Data Processor, we notify the affected customer without undue delay so they can meet their own obligations.
12. Your Rights and Grievance Redressal
Under the Digital Personal Data Protection Act, 2023, you may request a summary of the personal data we process and the parties it has been shared with, ask us to correct or complete inaccurate data, request erasure of data no longer necessary for its purpose, nominate someone to exercise your rights in the event of death or incapacity, withdraw consent as easily as it was given, and raise a grievance with our Grievance Officer before approaching the Data Protection Board of India.
Where GDPR applies, you additionally have rights to restriction of processing, data portability, objection to processing based on legitimate interests or direct marketing, freedom from solely automated decision-making with legal or similarly significant effects, and complaint to your supervisory authority. Residents of California, Virginia, Colorado and comparable US states may have rights to know, delete, correct and opt out of sale, sharing or targeted advertising — and again, Host360 does not sell personal information.
To exercise any right, email privacy@host360.ai with enough detail for us to verify your identity. We acknowledge within seven business days and respond substantively within 30 days, extending only where a request is complex and telling you if so. There is no charge, except for manifestly unfounded or repetitive requests. If your data sits inside a customer's workload, we will forward your request to that customer, who is the Data Fiduciary responsible for responding; we will assist them but cannot act unilaterally on their data.
To stop marketing, use the unsubscribe link in any marketing email or write to privacy@host360.ai. You will continue to receive essential service communications — outage notices, maintenance windows, security advisories, invoices and contractual notices — as these are necessary to the service relationship and are not marketing.
Children's data. Host360 provides business-to-business infrastructure services. Our website, Portal and services are not directed at children and we do not knowingly collect personal data of anyone under 18. If you believe a child has provided us personal data, contact privacy@host360.ai and we will delete it promptly.
Grievances are acknowledged within seven business days and resolved within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to your local supervisory authority where GDPR or other regional laws apply.
13. Policy Updates and Contact
We may update this Policy to reflect changes in our services, technology, sub-processors or legal obligations, and the "Last Updated" date shows the most recent revision. For material changes — new processing purposes, new categories of data or new international transfers — we will give at least 30 days' notice by email to Client Portal account holders and post a prominent notice on our website before the change takes effect. Continued use after the effective date constitutes acceptance. Superseded versions are archived and available on request.
For privacy enquiries and rights requests, write to privacy@host360.ai. To report a security incident or vulnerability, write to security@host360.ai. For sales and general enquiries, contact sales@host360.ai or visit www.host360.ai.