Privacy Policy
What personal information Squid IP Hosting collects, why we process it, who we share it with, how long we keep it, and the rights available to you.
This notice explains how we handle personal information. We are a business-to-business infrastructure provider, so most of the personal information we hold is the contact details of people acting for the organizations we deal with.
1. Who is responsible
Squid Ventures LLC, trading as Squid IP Hosting, is the controller of the personal information described in this notice. Our office is at 3960 Howard Hughes Parkway Paradise, #500, Las Vegas, NV 89169, United States.
Privacy questions and requests should go to [email protected]. We aim to respond within five business days and to resolve substantive requests within thirty days.
2. What we collect
Information you give us
- Inquiry details. Name, work email address, company, telephone number, country, the services and regions you are interested in, expected capacity and timeline, and the content of your message.
- Partner applications. The above plus your company website, the partnership model you are interested in, target markets, and background on your business.
- Account details. For customers: administrative, technical, billing, and abuse contacts, along with the entity details needed to contract and invoice.
- Billing information. Billing address, purchase order references, and tax identifiers.
- Correspondence. Support tickets, maintenance correspondence, and notes from calls and meetings.
Information we collect automatically
- Web server logs. IP address, request time, page requested, HTTP status, referrer, and user agent.
- Inquiry form metadata. The IP address and user agent from which a form was submitted, and the time of submission. We retain this to investigate abuse of the forms.
- Session cookie. A single functional cookie set when you use a form, described in clause 9.
Information from third parties
- Payment processors. Confirmation that a payment succeeded or failed, and limited card metadata such as the last four digits and expiry. We do not receive or store full card numbers.
- Credit and verification checks. For customers taking services on credit terms, we may obtain a business credit report or verify entity details against public registers.
- Abuse reports. Where a third party reports abuse, their report may contain personal information such as IP addresses and log extracts.
We do not buy marketing lists, and we do not enrich our records with data purchased from data brokers.
3. Why we process it
- To respond to inquiries and prepare quotes.
- To assess and administer partner applications.
- To provide, provision, and support the services, including notifying you of maintenance and incidents.
- To invoice you and collect payment, and to manage credit risk.
- To keep the network secure, investigate abuse, and comply with our Acceptable Use Policy.
- To keep records required for accounting, tax, and audit.
- To comply with legal obligations, including sanctions screening and lawful requests from authorities.
- To establish, exercise, or defend legal claims.
We do not use personal information for automated decision-making that produces legal effects, and we do not profile individuals for marketing.
4. Legal basis
Where the UK GDPR or EU GDPR applies, we rely on the following bases:
- Contract. Processing necessary to enter or perform a contract with you or your organization.
- Legitimate interests. Responding to business inquiries, securing our network, preventing abuse and fraud, and managing our commercial relationships. We balance these against your interests and rights.
- Legal obligation. Accounting and tax records, sanctions compliance, and responses to lawful requests.
- Consent. Where we ask for it, for example to be added to a mailing list. You can withdraw consent at any time without affecting other processing.
5. Who we share it with
We share personal information with the following categories of recipient:
| Recipient | Purpose | Information |
|---|---|---|
| Payment processors | Taking payment (PayPal, Stripe) | Billing contact and transaction details |
| Facility operators | Physical access authorization at facilities | Names of authorized personnel |
| Carriers and upstreams | Circuit delivery and fault resolution | Technical contact details |
| Registries and registrars | Address space assignment and routing records | Entity and technical contact details, where publication is required |
| Professional advisers | Legal, accounting, and audit | As necessary for the engagement |
| IT and hosting suppliers | Email, ticketing, and monitoring | As necessary to operate the systems |
| Authorities | Compliance with lawful requests | Only what the request lawfully requires |
A current list of sub-processors is available on request from [email protected] and is summarized on our security and compliance page.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. International transfers
We are established in the United States and operate infrastructure in multiple countries, so personal information may be transferred outside the country in which you are located.
Where we transfer personal information out of the United Kingdom or the European Economic Area, we rely on an adequacy decision where one applies, or otherwise on the appropriate Standard Contractual Clauses or the UK International Data Transfer Addendum, together with a transfer risk assessment. Copies of the relevant mechanism are available on request.
7. How long we keep it
| Category | Retention period |
|---|---|
| Inquiries that do not become customers | 24 months from last contact |
| Partner applications not taken forward | 24 months from decision |
| Customer account records | Duration of the relationship plus 7 years |
| Invoices and accounting records | 7 years, as required by tax law |
| Support and maintenance correspondence | 3 years from closure |
| Web server logs | 90 days |
| Inquiry form metadata | 12 months |
| Abuse reports and investigations | 3 years from closure |
| Network flow and routing telemetry | 13 months, aggregated after 90 days |
We may keep information longer where necessary to establish, exercise, or defend a legal claim, or where a legal hold applies.
8. How we protect it
- Transport encryption on this website and on our administrative systems.
- Encryption at rest for backups of business systems.
- Role-based access on a least-privilege basis, with multi-factor authentication on administrative accounts.
- Separate credentials and change control for network devices, with configuration changes logged.
- Logging and monitoring of administrative access.
- Background-appropriate vetting and confidentiality obligations for personnel with access to customer data.
No system is perfectly secure. If a breach affects your personal information and presents a risk to you, we will notify you and the relevant regulator where we are required to do so, without undue delay.
9. Cookies
This site uses one cookie. PHPSESSID is a session cookie set when you use an
inquiry form. It links your browser to the verification code shown in the form so that the
submission can be validated, and it expires when you close your browser.
We do not use advertising cookies, cross-site trackers, or third-party analytics on this site. Fonts and scripts are served from our own domain rather than from a content delivery network, so using the site does not disclose your visit to a third party.
10. Your rights
Depending on where you are located, you may have the right to:
- Ask what personal information we hold about you and receive a copy.
- Have inaccurate information corrected.
- Have information deleted where we no longer have a lawful reason to keep it.
- Restrict processing while a concern is being resolved.
- Object to processing carried out on the basis of legitimate interests.
- Receive information you provided in a portable format.
- Withdraw consent where we relied on it.
Send requests to [email protected]. We may ask for information to verify your identity. We do not charge for responding, and we will not treat you differently for making a request.
If you are in the United Kingdom or the European Economic Area and are unhappy with our response, you may complain to your local supervisory authority. In the UK that is the Information Commissioner's Office. We would appreciate the chance to resolve the matter first.
11. United States privacy rights
Residents of California and of other states with comprehensive privacy laws have rights to know, delete, and correct personal information, and to opt out of its sale or of sharing for cross-context behavioral advertising.
We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. The rights to know, delete, and correct can be exercised by contacting [email protected]. You may use an authorized agent, in which case we will ask for evidence of their authority.
We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
12. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under sixteen. If you believe we have, contact [email protected] and we will delete it.
13. Customer traffic
As a network operator we carry traffic that may contain personal information belonging to our customers' own users. We do not inspect the content of customer traffic as a matter of course. Where we process such data, we act as a processor on our customer's instructions, and a data processing agreement is available.
We inspect traffic only to the minimum extent necessary to investigate an abuse report, to protect the network from attack, or where we are legally required to do so. We retain flow telemetry, which records the parties and volume of a connection rather than its contents, for the period stated in clause 7.
14. Changes to this notice
We may update this notice. The version number and dates at the top of this page show when it last changed. Where a change materially affects how we handle your information we will notify the contacts on affected accounts. Earlier versions are available on request.
Contacting us about this document
Questions about this document should go to [email protected]. Written notice under it may be sent to that address or by post to:
Squid Ventures LLC
3960 Howard Hughes Parkway Paradise, #500
Las Vegas, NV 89169
United States
Questions before you sign?
Our team can walk your counsel or procurement team through any of these documents before a service order is raised.