Website Hosting Policy
Effective: 28 August 2026.
Why this policy exists
Com Technology hosts multiple client websites on shared infrastructure. Automated scanners actively target hosted websites looking for vulnerabilities.
We maintain the hosting layer on a managed patching cycle and 10 minute cycles of activity analysis, at our cost. The operating system receives automated security updates daily and full patch-and-reboot cycle when required. PHP, the web server, the database, the firewall and server-level malware scanning are maintained on the same basis. That protection stops at the application layer: we cannot patch a plugin whose vendor has not released a patch, and we cannot patch a plugin that has no vendor left to release one.
This policy sets the condition on which shared hosting can be offered safely at all. It applies to every site we host, without exception.
1. Supported software only
All applications, themes and plugins installed on a hosted site must be vendor-supported and receiving security updates.
2. No abandoned or withdrawn software
A component (defined as a software script) must be updated, replaced or removed where any of the following applies:
- it has been closed or removed from the WordPress plugin directory;
- it has been discontinued, withdrawn or marked end-of-life by its vendor; or
- it has had no release of any kind to resolve security breaches.
3. Commercial plugins must hold an active licence
Without an active licence a commercial plugin cannot receive security patches, and WordPress cannot even report that an update exists. A site showing “no update available” for an unlicensed plugin is not evidence that the plugin is current — it is evidence that the update channel is closed.
4. Remediation is development work
Identifying replacements, migrating data and resolving breaking changes is development work and sits with the site’s developer, not with hosting. We will identify the problem and provide our evidence for it. We do not carry the fix.
5. Notice and remediation window
Where we find a site non-compliant we will advise you in writing, identifying the specific components, the versions installed, and the evidence relied on — the directory listing, vendor notice, advisory reference or release history, as applicable.
You then have 30 days from the date of that notice to remediate.
If you consider a finding to be wrong, tell us within the remediation window and we will review it and provide our evidence in full. Where a component is genuinely maintained under a name, fork or channel we have not accounted for, the finding is withdrawn. Where remediation is demonstrably underway but cannot complete inside 30 days, ask us and we will extend the window by agreement rather than escalate.
6. Immediate action on active exploitation
Where a vulnerability is being actively exploited, or a component carries a known unauthenticated exploit, we may disable that component immediately and without prior notice in order to protect the platform.
Where we do so:
- we will disable only the specific component that presents the risk, and only for as long as the risk persists;
- we will notify you in writing as soon as practicable and in any event within one business day, telling you what was disabled and why;
- we will restore the component as soon as a patched version is installed, or assist you to identify a safe replacement; and
- we will not charge you for the act of disabling it.
This is a containment measure of last resort, not a substitute for the notice process in clause 5.
7. Continued non-compliance
A site still non-compliant after the remediation window, and after any extension agreed under clause 5, may have hosting terminated on 30 days’ written notice.
Where we terminate under this clause:
- the 30 days is your migration window, and the site remains live throughout it unless clause 6 applies;
- we will provide a complete export of your site data and files in a standard, portable format, at no charge;
- we will refund any prepaid hosting fees for the period after service ends, on a pro-rata basis; and
- no termination penalty or exit fee applies.
8. Your data
In hosting your website, Com Technology holds and processes personal information on your behalf — you determine what is collected and why; we store and protect it. Under the Privacy Act 2020 that makes the information yours, held by us as your agent. Where the UK or EU General Data Protection Regulation applies to your site, we act as your processor and you as controller.
This policy forms part of the technical and organisational security measures we maintain to protect that information, as required by principle 5 of the Privacy Act 2020 and Article 32 of the GDPR. Running a site on abandoned or unpatched software undermines those measures directly, which is why currency is a condition of hosting rather than a recommendation.
Where we become aware of a security incident affecting personal information held on your site, we will notify you without undue delay, and in any event within 24 hours of becoming aware of it, so that you can meet your own notification obligations to the Office of the Privacy Commissioner or your supervisory authority.
On termination under clause 7, we will return your data as described above, and will then delete it from active hosting. Copies persisting in encrypted backup media are retained for the remainder of the applicable backup retention cycle and are then destroyed in the ordinary course. We do not retain or use your data for any other purpose.
9. Status of this policy, and the law that applies
This policy forms part of your hosting agreement with Com Technology Ltd. It is published here so that its terms are available to you in full at any time.
We may amend this policy. Where an amendment materially affects your obligations we will give you at least 30 days’ written notice before it takes effect, and you may terminate hosting without penalty within that period if you do not accept the change.
Governing law
Com Technology Ltd is a New Zealand company and your hosting agreement is governed by New Zealand law. The statutes referred to in this policy are New Zealand Acts:
- the Consumer Guarantees Act 1993 (New Zealand)
- the Fair Trading Act 1986 (New Zealand)
- the Privacy Act 2020 (New Zealand)
Nothing in this policy limits any right or remedy you have under those Acts that cannot lawfully be excluded or limited. Where you acquire hosting for the purposes of a business, and to the extent permitted by section 43 of the Consumer Guarantees Act 1993, the guarantees in that Act do not apply.
If you are outside New Zealand
These Acts still reach us, and in most cases still protect you.
The Fair Trading Act 1986 applies to the conduct of a New Zealand business, including conduct directed at customers overseas. Its prohibitions on misleading and deceptive conduct, and its regime governing unfair terms in standard form contracts, apply to how we describe this service and to what we may enforce against you, wherever you are located.
The Privacy Act 2020 applies to us because we are a New Zealand agency. It governs personal information we hold on your behalf regardless of where you, or the people that information is about, are located.
The Consumer Guarantees Act 1993 applies to services supplied from New Zealand. Depending on where you are, your local consumer law may give you further rights. We do not seek to displace them: where the law of your own country gives you a right that cannot be contracted out of, that right stands alongside this policy rather than being replaced by it.
Where your site is subject to the GDPR
Where the European Union or United Kingdom General Data Protection Regulation applies to your website — because you offer goods or services to people in the EU or UK, or monitor their behaviour — you are the controller and we are your processor, as described in clause 8. Two points of detail matter.
Where your data is held. Our hosting infrastructure is located in Singapore, with encrypted backups held on separate offsite storage. Singapore is not the subject of a European Commission adequacy decision. Where personal data subject to the GDPR is held on our platform, that transfer therefore relies on appropriate safeguards under Article 46 rather than on adequacy. We will enter into Standard Contractual Clauses with you on request, at no charge.
New Zealand’s adequacy status. New Zealand holds an adequacy decision from the European Commission, and equivalent recognition under the United Kingdom regime. That decision covers New Zealand as a destination for personal data. It does not by itself cover the physical location of the servers your site runs on, which is why the paragraph above applies.
If you require your site’s data to be held in a specific jurisdiction, tell us and we will confirm whether we can meet that requirement.
Questions
If you are unsure whether a component on your site meets this policy, ask us and we will check it for you.