Privacy Notice
DUHosting respects your privacy and handles personal data in accordance with Tanzania's Personal Data Protection Act, 2022 (Cap. 44), the Personal Data Collection and Processing Regulations, 2023, and other applicable laws.
To provide domains, hosting, email, VPS, security, billing and customer support.
You may request access, correction, deletion, restriction or object to certain processing.
1. Who we are and our data-protection roles
DUHosting Tanzania provides domain registration and transfer, shared and reseller hosting, VPS hosting, business email, Google Workspace, Microsoft 365, SSL certificates, SiteLock, backups and related support services.
DUHosting acts as a data controller when deciding how personal data is used for accounts, orders, billing, service administration, security, communications and legal compliance. We may act as a data processor when hosting websites, databases, email, backups or other content that a customer controls. In that processor role, the customer remains responsible for having a lawful basis, giving required notices and responding to the rights of people whose data the customer uploads or processes.
2. Data-protection principles
We aim to process personal data lawfully, fairly and transparently; collect it for specified and legitimate purposes; limit it to what is necessary; keep it accurate; retain it only as long as needed; protect it with appropriate safeguards; and remain accountable for our processing.
3. Personal data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, company, postal address, email, telephone number, country and account identifiers. | You, an authorized account user or reseller. |
| Account and authentication | Username, password hash, login history, security preferences, support PIN and multi-factor authentication status. | You and our systems. |
| Orders and billing | Products, invoices, transaction references, payment status, account credit, tax information and TIN where supplied. | You, WHMCS and payment providers. We do not intentionally store full payment-card details when a payment provider processes them. |
| Domain-registration data | Registrant, administrative and technical contact details, domain name, nameservers, transfer data and registry-required records. | You, a reseller, registry or registrar. |
| Service and customer content | Website files, databases, DNS records, mailboxes, email metadata and content, backups, logs and VPS data. | You, your users and systems using your services. |
| Support and communications | Tickets, AI-assistant chats, calls, emails, attachments, service instructions, complaints and helpful/unhelpful response ratings. | You, our support channels and our support systems. |
| Technical and security | IP address, device/browser data, timestamps, cookies, server and access logs, malware or abuse indicators and fraud signals. | Your device, our infrastructure and security providers. |
| Marketing preferences | Subscription status, campaign interaction and communication preferences. | You and our communication tools. |
We do not seek sensitive personal data unless it is necessary and lawful. Please do not place sensitive data in support tickets or hosted services unless it is required, lawful and appropriately protected.
4. Why we process personal data and our legal bases
- Contract: to create and administer accounts, register or transfer domains, provision services, issue invoices, take payments, provide support, renew or terminate services and communicate service notices.
- Legal obligation: to maintain business and tax records, respond to lawful requests, meet domain-registry and telecommunications requirements, prevent unlawful use and comply with data-protection duties.
- Legitimate interests: to secure networks, prevent fraud and abuse, troubleshoot services, improve reliability and support quality, evaluate de-identified response ratings, review generalized resolutions, defend legal claims and understand service performance, where those interests do not override your rights.
- Consent: for optional direct marketing, non-essential cookies or other processing where consent is required. Consent may be withdrawn without affecting earlier lawful processing.
- Vital or public interests: only in exceptional circumstances where the law permits or requires it.
5. How we use personal data
- Verify customers and authorized users and protect account access.
- Search, register, renew, transfer and manage domain names and nameservers.
- Provision and operate hosting, VPS, email, certificates, security and backup products.
- Process orders, invoices, refunds, account credit and payment status.
- Provide technical, billing and abuse support and maintain service records.
- Provide AI-assisted answers using public DUHosting information, redacted customer questions and staff-approved generalized support examples, with human escalation where appropriate.
- Monitor availability, capacity, security, fraud, spam, malware and acceptable-use compliance.
- Send operational, renewal, security, billing and policy notices.
- Improve our website and services using proportionate analytics and feedback.
- Meet legal, regulatory, audit, reporting and dispute-resolution requirements.
6. Domain registration and public registry records
Domain registration requires information to be provided to the relevant registry, registrar, Tanzania Network Information Centre or other domain authority. Some registration data may be disclosed through lawful domain-registration data services, depending on registry rules and available privacy protection. We may also share information needed to process transfers, resolve domain disputes, investigate abuse or comply with a lawful registry request.
7. When we share personal data
We do not sell personal data. We disclose it only when necessary and lawful, including to:
- Domain registries, registrars and domain-dispute authorities.
- Data centres, network, cloud, control-panel, security, certificate and backup providers.
- Email and productivity-service providers when you order services such as Google Workspace, Microsoft 365 or other third-party email products.
- Payment gateways, banks, mobile-money operators and fraud-prevention providers.
- WHMCS and other account, billing, support, communication and analytics providers acting under appropriate terms.
- Our configured AI service provider, where necessary to generate an assistant response. We minimize and redact submitted content and do not intentionally send passwords, API keys, payment-card details or complete private account records for response generation.
- Professional advisers, auditors, insurers and a purchaser or successor in a lawful business transaction.
- Courts, regulators, law-enforcement bodies and other authorities where disclosure is required or permitted by law.
Providers are expected to process data only for agreed purposes, protect it and comply with applicable law. A current list of material subprocessors may be requested using the contact details below.
8. International and cross-border processing
International processing can include account and service identifiers, IP addresses, DNS and domain configuration, website files, databases, email and email metadata, VPS data, backups, security logs and support information. The exact data depends on the products a customer activates and the content placed in those services.
| Location or recipient type | Why data may be processed there | Data that may be involved |
|---|---|---|
| European data centres and infrastructure providers | Primary or backup hosting, VPS infrastructure, network delivery, monitoring, security, disaster recovery and technical support. | Hosted websites and databases, service configuration, IP and security logs, backups and account/service identifiers. |
| United States data centres, cloud, software and AI providers | Cloud or software services, email/productivity products, security, analytics, AI-assisted support, backup, registry or infrastructure functions. | Account/contact data and service metadata where required by the selected service; redacted support questions for AI assistance; support records, logs and, where the purchased service requires it, customer-hosted content. |
| Domain registries, registrars and global service providers | Domain registration and transfer, certificates, DNS, email, collaboration and other products selected by the customer. | Registry-required contact data, domain and DNS data, service identifiers and operational records. |
These providers act as independent controllers or processors depending on the service. DUHosting limits disclosures to data reasonably required to deliver, secure, support or comply with legal obligations for the service. We do not authorize an infrastructure provider to use customer-hosted content for its own advertising.
Where Tanzanian law requires it, DUHosting will use appropriate contracts, confidentiality and security requirements, transfer assessments, regulatory approvals or cross-border transfer permits. The laws and government-access rules of another country may differ from those of Tanzania. Customers should consider data-location and sector-specific requirements before uploading regulated, sensitive or restricted information.
Customers may contact info@duhosting.tz before ordering, or while a service is active, to request available information about the hosting region and safeguards applicable to that service. A particular country or data centre is not guaranteed unless it is expressly stated in the order or a written service agreement.
9. Retention and deletion
We keep personal data only for as long as necessary for the purposes described in this notice. Retention depends on the service term, account status, backup cycle, security needs, dispute or limitation periods and applicable tax, accounting, registry and regulatory requirements.
- Active account and service data is retained while the service is provided.
- Billing, transaction and statutory records are retained for the period required by applicable law.
- Support, security and abuse records are retained for a proportionate period needed to resolve issues, prevent recurrence and defend claims.
- AI chat transcripts are normally retained for up to 90 days. Anonymous response-rating metadata and unapproved or rejected learning candidates are normally retained for up to 180 days, subject to the configured privacy limits.
- Only staff-approved, generalized support examples may be used for future answer retrieval. They contain no client ID or plain source-ticket identifier and remain until staff retire them or they are no longer needed.
- Service content is deleted or rendered inaccessible after termination in accordance with the service and backup cycle, unless law or a preservation request requires longer retention.
- Backups may retain residual copies until the normal backup rotation completes.
When retention ends, data is securely deleted, anonymized or isolated from further use.
10. Security and personal-data breaches
We use risk-appropriate technical and organizational safeguards, which may include access controls, authentication, encryption in transit, network protection, logging, monitoring, backups, malware controls, staff confidentiality and incident procedures. No internet service can guarantee absolute security; customers must also protect passwords, devices, applications and authorized users.
We investigate suspected personal-data breaches, take containment and recovery steps, document incidents and notify affected parties and the Personal Data Protection Commission when required by law. Customers using DUHosting as a processor must notify us promptly of incidents affecting hosted services and cooperate with investigation and legal notification duties.
11. Your rights
Subject to the Act and lawful limitations, you may have the right to:
- Be informed about processing and request access to your personal data.
- Request correction of inaccurate or incomplete data.
- Request erasure where there is no lawful reason to retain the data.
- Request restriction or object to harmful or unlawful processing.
- Withdraw consent and object to direct marketing.
- Raise concerns about automated decisions and request appropriate human review.
- Complain to DUHosting and lodge a complaint with the Personal Data Protection Commission.
To protect accounts and third parties, we may verify your identity and authority before acting. We will respond within the period required by applicable law. Some requests may be limited where retention or processing is required by law, necessary to provide a requested service or needed to protect another person's rights.
12. Cookies, analytics and communications
Our website and client area use necessary cookies for sessions, authentication, security, cart contents, language and currency preferences. We may use analytics or advertising technologies where lawful to measure performance and understand campaigns. Non-essential cookies should be controlled through the available consent choices and browser settings.
Operational messages about services, invoices, renewals, outages, security and policy changes are part of providing the service. Optional marketing communications may be declined through the message controls or by contacting us.
13. Automated decisions, children and third-party links
DUHosting uses AI assistance to answer common questions and help route support. Customer ratings help us measure response quality. When a ticket is closed after a genuine human-admin resolution, the system may create a privacy-filtered candidate that staff can review, generalize, approve or reject. Pending and rejected candidates do not influence assistant answers, and customer content never changes the assistant automatically.
Approved examples are retrieval guidance rather than permission to perform an account action or claim that an action has been completed. High-risk matters, uncertain information, refunds, account changes, credentials, security incidents and server-side actions should be escalated to a person. AI responses can be incomplete or incorrect, so customers should use checkout, the Client Area or human support to confirm account-specific facts and consequential actions.
Security and fraud tools may automatically flag activity for review, but DUHosting does not intend to make solely automated decisions that produce legal or similarly significant effects without appropriate safeguards and human involvement.
Our services are intended for adults and organizations able to enter contracts. We do not knowingly invite children to create accounts. A parent or guardian who believes a child provided personal data should contact us.
Our website may link to third-party sites. Their privacy practices are governed by their own notices.
14. Complaints and the Personal Data Protection Commission
Please contact DUHosting first so we can investigate and respond. You may also lodge a complaint with Tanzania's Personal Data Protection Commission through pdpc.go.tz or the Commission's published complaint channels.
15. Changes to this notice
We may update this notice when services, providers, laws or processing activities change. Material changes will be posted here and, where appropriate, communicated through the client area or registered contact details. The effective date above identifies the current version.
Privacy contact
DUHosting Tanzania
2nd Floor, Nyuki House, Bagamoyo Road, Tegeta, Dar es Salaam, Tanzania
Email: info@duhosting.tz
Telephone: +255 768 816 728
Use the subject Privacy Request and identify the account or service concerned. Do not send passwords or full payment-card details.