Skip to content

NOFOH Ltd · Registered in England and Wales · Company No. 14279361

Remote delivery, United Kingdom ·  [email protected]

NOFOH
  • Capabilities
  • Who we serve
  • Group structure
  • Entities
  • Enquire
Enquiry routes

Operating entities

  • BBC Cloud
  • NHostn
  • NameTLS
  • 02Host
  • DukanKSA
  • URLemail

Six companies, one standard of delivery

  1. NOFOH
  2. Privacy notice

Document Privacy notice · Version 1.0

Privacy notice

This notice explains what personal information NOFOH Ltd holds, why we hold it, who we share it with, how long we keep it and what rights you have. It covers this website and correspondence with the group. Where we process personal data on behalf of a client under a service contract, the client's own data processing terms and instructions take precedence for that data.

Data controller
NOFOH Ltd
Company number
14279361
Contact
[email protected]
Last updated
21 September 2026

On this page

  1. Who we are
  2. Scope of this notice
  3. The two roles we take
  4. Information we collect
  5. How we collect it
  6. Cookies, analytics and storage
  7. Server and security logs
  8. Purposes and lawful bases
  9. Disclosure and recipients
  10. Processing locations and transfers
  11. Retention
  12. Security
  13. Your rights
  14. Automated decisions and profiling
  15. Children
  16. Data we handle for clients
  17. Other sources of information
  18. Changes to this notice
  19. Complaints and how to reach us

Read with our terms of use and the legal and corporate information page.

1 · Who we are

NOFOH Ltd ("NOFOH", "we", "us") is a private limited company registered in England and Wales, company number 14279361, incorporated on 5 August 2022, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. For the information described in this notice we are the data controller.

NOFOH is the parent of several operating companies — BBC Cloud · NHostn · NameTLS · 02Host · DukanKSA · URLemail. Each entity is a separate controller for the account and service records it holds about its own clients. This notice is written for the group as a whole; where an entity's own privacy terms apply to a service, they are provided with that service.

Enquiries and data-subject requests should be sent to [email protected]. We handle them from the United Kingdom, in English or Arabic.

2 · Scope of this notice

It applies to personal information about individuals who visit this website, correspond with us, represent a client or prospective client, act for a supplier, or otherwise deal with the group. It does not apply to personal data that we host, process or administer on a client's instructions — for example mailboxes on a client's domain or records inside a client's website — where the client is the controller and we act as their processor.

3 · The two roles we take

As controller, we decide why and how personal information about our contacts, prospects, suppliers and website users is processed — this notice governs that processing.

As processor, we handle personal data belonging to our clients' systems on their documented instructions under a data processing agreement. In that role the client's lawful basis, retention schedule and instructions control what happens to the data, and our obligations are those in section 16.

4 · Information we collect

  • Identity and business contact data — name, job title, organisation, work email address, work telephone number and postal address where supplied.
  • Correspondence data — the content of messages you send us, attachments, subject lines, and our replies and internal notes about the matter.
  • Commercial data — invoicing details, bank or card reference identifiers needed to pay or be paid, purchase order numbers, contract records and credit-control information.
  • Service and support data — ticket descriptions, system and account identifiers, diagnostic records, change requests and the history of a service arrangement.
  • Technical data — request metadata generated when this website is visited, described in section 7.

We do not ask for, and do not expect, special category information (health, biometrics, religion, political opinion, sexual orientation or trade-union membership), criminal-offence data, or any information about children. Please do not send it to us; if it reaches us in correspondence we delete it once noticed.

5 · How we collect it

Almost all of the information we hold is given to us directly — by email, in a tender or due-diligence exchange, through a contract, or when you contact support for a service. Some is generated automatically when this website is used (section 7), and some comes from publicly available sources when we research an organisation that has contacted us (section 17).

This website asks nothing of you: there is no account to create, no form to complete and no checkout. You reach us by email at [email protected] or through whichever operating company you need, so the personal information we receive is only what you choose to send us. That is deliberate — data minimisation is easier to honour when collection starts at a conversation.

6 · Cookies, analytics and third-party scripts

This site uses one analytics tool: Google Analytics 4, provided by Google Ireland Limited and Google LLC. It is switched off by default: no request is made to Google at all until you choose Allow analytics in the notice shown at the bottom of your first visit. A visitor who never interacts with that notice is not tracked, no analytics cookie is written, and Google's servers never see their browser. Analytics storage is additionally declared denied at consent level, so the measurement cannot resume silently.

Your choice is kept in your browser's own storage, not in a cookie, and we ask again after about six months. You can change it at any time through Analytics settings in the footer of every page. Where your browser sends a Global Privacy Control signal, we treat it as a refusal and do not measure the visit.

Storage used by this website
Storage Set by Purpose Duration
_ga and _ga_G-QY7XB35VCL Google Analytics, after you allow it Distinguish returning visitors and attribute a session to a page path 13 months by default
__cf_bm Cloudflare, which delivers and protects this site Strictly necessary: bot mitigation and session stability 30 minutes
Browser storage nofoh.consent Us Remember your analytics choice so we do not ask again About 6 months

The analytics cookie is not exempt from consent, so we ask for it; the Cloudflare cookie is strictly necessary to deliver the page you requested, which is why it needs no consent. There are no advertising cookies, no social plug-ins, no marketing pixels, no session recording and no heatmaps — advertising and remarketing features of Google Analytics are switched off at configuration level, and ad_storage remains denied for every visitor.

When Google Analytics is enabled by you, it receives the page you are on, the referring page, your device and browser type, and an approximate location derived from a truncated IP address. Google states that GA4 does not retain or store IP addresses and does not associate your activity on this site with other Google products. Two destinations are contacted from your browser — www.googletagmanager.com for the tag and www.google-analytics.com for the measurement payload; our Content-Security-Policy allows no other third-party destination, and the tag is loaded by a single line of code in our own scripts.

Google processes that data as our processor under a data processing agreement, on the lawful basis of your consent. Where Google processes data outside the UK, we rely on the UK adequacy regulations for the UK Extension to the EU–US Data Privacy Framework or on the International Data Transfer Agreement / Addendum, as applicable. You may also block Google Analytics permanently using Google's opt-out browser add-on ↗, which we honour and cannot override.

7 · Server and security logs

Delivering a web page necessarily involves processing the request. For security, abuse prevention and capacity management, the delivery platform records request metadata that can include the IP address, the browser and device string, the requested path, a timestamp and the referring address.

We use that data only to keep the site available, to investigate disruption or attack, and to apply proportionate network controls. We do not build profiles of visitors, we do not join log data to correspondence, and we do not sell or share it for advertising. Security logs are kept for a limited period and retained longer only where an incident requires it.

8 · Purposes and lawful bases

The table below sets out why we process personal information and the lawful basis we rely on.

Processing purposes, data categories and lawful bases
Purpose Information used Lawful basis
Answering an enquiry, proposal or tender question Identity, business contact, correspondence Necessary for steps at your request before entering a contract; legitimate interests
Performing a contract and delivering a service Identity, business contact, commercial, service and support data Performance of a contract
Billing, payment and credit control Commercial data, correspondence Performance of a contract; legal obligation (accounting and tax)
Protecting our systems, clients and network Technical and log data, service data Legitimate interests (security of our services)
Complying with law, regulators and lawful requests Relevant records Legal obligation; legitimate interests
Keeping a corporate record of who we contracted with Contract and correspondence records Legitimate interests (accountability and audit)
Supplier and sub-contractor administration Business contact, commercial data Performance of a contract; legitimate interests
Measuring which pages of this corporate record are read Page, referrer, device and approximate region Consent — sought before any analytics storage is enabled

Where we rely on legitimate interests, they are the interests of running a reliable technology services business and dealing properly with the organisations that contact us. We have considered whether our use is necessary and whether it affects your rights and freedoms, and we consider the balance to be reasonable in every case listed above.

9 · Disclosure and recipients

We disclose personal information only where we must, or where it is necessary to deliver what you asked for:

  • Within the group — the operating company performing your work, and the group functions (support, finance, governance) that need the record.
  • Service providers acting for us — Cloudflare for delivery and network security, Google Analytics for the aggregated measurement described in section 6, plus email, cloud infrastructure, accounting software, document storage and professional advisers. Each is bound by written confidentiality and data-protection terms and receives only what it needs.
  • Our clients — where you raise a matter concerning a service, the relevant client is given what they need to resolve it.
  • Regulators, courts and law enforcement — to the extent required or permitted by law, including a public authority exercising statutory powers.
  • A buyer of a business — if the group or a company within it is reorganised or sold, records may transfer as part of that transaction, under obligations equivalent to this notice.

We do not sell personal information, and we do not disclose it for advertising or marketing to third parties.

10 · Processing locations and international transfers

Our own processing takes place in the United Kingdom. Some of the platforms and infrastructure we use operate data centres outside the UK, and a client's service may be hosted in a region the client has chosen — for example in-Kingdom hosting for Saudi-facing services through DukanKSA.

Where personal information leaves the UK, we rely on regulations made by the Secretary of State approving a territory as adequate, or on the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, together with technical and organisational safeguards such as encryption in transit and at rest and restricted access. For client data, the processing locations and any transfer mechanism are recorded in the contract or data processing terms, and we will not move client data to a new location without the client's agreement where the contract requires it.

11 · Retention

We keep personal information only as long as the purpose for holding it lasts, within these limits:

  • Unsuccessful enquiries and proposals — up to 24 months from our last substantive contact, then deleted unless a procurement record must be preserved.
  • Contracts, orders and invoices — 6 years from the end of the accounting period in which the contract ended, to meet UK company and tax record-keeping requirements.
  • Correspondence about a live matter — for the life of the matter, then as above.
  • Support and change records — for the life of the service arrangement and the following limitation period, because they evidence what was agreed and done.
  • Security logs — a limited rolling period, extended only where an investigation requires it.

Records we must keep are not deleted on request while the retention period runs, and data hosted on a client's behalf is returned or deleted according to the client's instructions and the contract.

12 · Security

We apply proportionate technical and organisational measures: access on a need-to-know basis with unique credentials and multi-factor authentication for administrative access, encryption of data in transit and of sensitive data at rest, hardened and monitored infrastructure, tested backups, documented change control, device management, and confidentiality obligations in every contract with staff and suppliers.

No system is perfectly secure. Where a personal-data breach affecting information we control is likely to result in a risk to individuals, we will investigate, take steps to mitigate the impact, notify the Information Commissioner's Office where the law requires it, and tell affected individuals without undue delay where the risk is high. Where we are a processor, we notify the controlling client so that it can meet its own obligations.

13 · Your rights

You have the right, under the UK GDPR and the Data Protection Act 2018, to:

  • access the personal information we hold about you and receive a copy of it;
  • have it corrected where it is inaccurate or incomplete;
  • have it erased, where we have no compelling lawful reason to keep it;
  • restrict or object to processing based on legitimate interests or performed for a task in the public interest, and object to direct marketing at any time;
  • data portability — receive information you gave us in a structured, commonly used, machine-readable form;
  • withdraw consent at any time where consent is the basis, without affecting processing already carried out — for analytics this is the Analytics settings control in the footer of every page, which takes effect immediately.

To exercise a right, email [email protected] with the subject line "Data subject request". We will confirm receipt, ask only for what we need to verify your identity and the account concerned, and respond within one month. That period may be extended by two further months for complex or numerous requests, in which case we will tell you within the first month. Requests are free, unless they are manifestly unfounded or excessive.

14 · Automated decisions and profiling

We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not profile individuals. Standard traffic handling by our content-delivery and security providers applies network rules to requests, not to people.

15 · Children

Our services are directed at organisations and business users, and this website is not intended for children. We do not knowingly collect personal information from anyone under 18. If you believe a child's information has reached us, contact us and we will remove it.

16 · Data we handle on a client's behalf

Where the group hosts, administers or supports a client's systems, we process the personal data in those systems as the client's processor. In that capacity we will: act only on the client's documented instructions; keep information confidential; apply the security measures in section 12; engage sub-processors only as the contract allows and remain responsible for them; assist the client with access, rectification, erasure, restriction, portability and objection requests made to us; assist with data protection impact assessments and consultation where processing is high risk; notify the client without undue delay on becoming aware of a relevant personal-data breach; and return or delete the data at the end of the service as the client instructs.

The detailed terms, sub-processor list and security schedule for a specific service are provided with that service's contract or data processing agreement, and are available on request before signature.

17 · Other sources of information

When an organisation contacts us, we may look at information it has published about itself — its website, tender documents, or entries in public registers such as Companies House — so that we address the enquiry correctly and can complete supplier or counter-party checks. We also receive a contact's business details from the message they send and from the signature block of their organisation.

18 · Changes to this notice

We review this notice at least annually and whenever our services, suppliers or obligations change. The version number and date at the head of the page record each revision; the version published on this site is the one currently in force. Material changes affecting an existing engagement will be communicated through the contract's notice provisions rather than by this page alone.

19 · Complaints and how to reach us

Please tell us first: write to [email protected] marked "Data protection", and a named person at the group office will deal with it. We will respond within one month.

If you are not satisfied with our response, or you believe our processing breaches the UK GDPR, you can complain to the supervisory authority in Great Britain:

Information Commissioner's Office

Wycliffe Hall, 2–14 Underwood Street, London N1 7JQ, United Kingdom

Telephone: 0303 123 1113 · ico.org.uk ↗

You may also contact the ICO directly without raising the matter with us first.

NOFOH

Remote digital services and solutions for government and enterprise. Registered in England and Wales, operating since 2022, and working remotely with public-sector and enterprise clients.

Registered office

71–75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom

Private limited company · No. 14279361 · Companies House record ↗

Correspondence

[email protected]

English and Arabic. Every message reaches a named person who can act on it — a first question, a tender invitation or a supplier request are all equally welcome.

This site

  • Capabilities
  • Who we serve
  • Group structure
  • Entity index
  • Enquiry routes
  • Return to top

Operating entities

  • BBC Cloudbbccloud.com
  • NHostnnhostn.com
  • NameTLSnametls.com
  • 02Host02host.com
  • DukanKSAdukanksa.com
  • URLemailurlemail.com

How to reach us

  • General enquiry
  • Public sector & tenders
  • Supplier due diligence
  • Existing service support

Or engage any operating entity directly through its own site — each carries its own plans, terms and support desk.

NOFOH uses a single analytics cookie to see which pages of this corporate record are read. Everything else on this site — including the fonts — is served from this origin.

How this works

© 2026 NOFOH Ltd. Registered in England and Wales, company No. 14279361. Incorporated 5 August 2022.

NOFOH is the parent identity of the operating entities named on this page. Each entity trades under its own brand and terms. Company, product and service names are the property of their respective owners.

Documents

  • Privacy notice
  • Terms of use
  • Legal & corporate information

nofoh.com · Built and maintained in the United Kingdom