Trust centre

The important details.
Out in the open.

Security, compliance and privacy only build confidence when the scope is clear. Here’s what DX3 covers, what remains your responsibility, and where to ask for evidence.

Accredited PCI service provider.
Evidence available.

DX3 states that it maintains PCI DSS v4.0.1 compliance for SAQ-A-equivalent service provision. Our Attestation of Compliance is available on request.

Scope matters

This model is intended for card-not-present businesses where all cardholder-data processing is outsourced to validated payment providers and payment-page elements originate directly from those providers.

Shared responsibility, clearly stated

DX3

Hosting platform

  • Operating system and service patching
  • Hosting-platform access controls
  • Resolution of hosting issues flagged by ASV scans
  • Relevant service-provider policies and controls
Customer

Your store and payment flow

  • Magento, WooCommerce, extensions and custom-code patching
  • CMS users, passwords and access
  • Validated payment provider and correct integration
  • Your own SAQ, policies, scans and evidence
Important payment limitation

Do not store card details on the hosting service. Direct or API-based integrations that bring cardholder data into your environment require consultation and may fall outside the supported PCI scope.

Practical privacy information.

We use personal information to answer enquiries, set up and support services, administer contracts, invoice customers and meet legal obligations.

Information

Contact, company, billing and service details; correspondence; support information; and basic website/device data where analytics or security tools are enabled.

Legal bases

Contract and pre-contract steps, legitimate interests in running and securing the service, legal obligations, and consent where required for marketing or non-essential cookies.

Service providers

Email, telephony, accounting, infrastructure and analytics providers may process limited information where needed. Appropriate contractual and transfer safeguards must apply.

Your rights

You may request access, correction, deletion, restriction, portability or objection where applicable, and complain to the UK Information Commissioner’s Office.

Order-form privacy

This prototype does not send or store order details on the website. Its email button prepares a message in the customer’s email application. A production submission service must add an appropriate privacy notice, retention rules, processor contract and security controls.

Review before launch

The existing policy mentions providers and practices that may have changed since it was written. Confirm the current email, analytics, newsletter, telephony, accounting and hosting providers before publishing the final legal policy.

Fair expectations on both sides.

Service use

Application-specific shared hosting is for one installation of the application purchased. Additional applications or uses require DX3’s consent.

Email use

Hosting servers are intended for normal transactional application email, not bulk or general mailbox use. Separate email services are available.

Refunds

The current terms provide a seven-day initial period in which an account holder may request closure and a refund. After that period, hosting payments are non-refundable and service is provided for the paid period.

Security and customer responsibility

Customers remain responsible for their CMS, extensions, content, users and credentials, and must use the service lawfully without attempting unauthorised access or harming third parties.

Data processing

The existing Data Processing Agreement identifies the customer as controller and DX3 as processor for hosted personal data, with confidentiality, security, assistance, deletion/return and subprocessor obligations.

Contract notice

This page is a readable summary, not a replacement contract. The full terms and Data Processing Agreement should be reviewed for current UK law, current PCI wording and present-day suppliers before launch.

Common questions.

Why DX3?

We have specialised in ecommerce hosting since 2009, supporting stores from small catalogues to large, high-traffic operations. Every customer receives the same security-first platform and access to specialist support.

How do I choose the right package?

Use the order page to select a plan or ask for a recommendation. We can assess your store, traffic and growth plans, and arrange a trial or migration discussion where appropriate.

What is the hosting built on?

The existing service specification describes Dell PowerEdge infrastructure, Intel Xeon processors and Samsung SSD storage, with the exact resources varying by package.

Do you host anything besides Magento?

Yes. DX3 provides WooCommerce and other application hosting alongside Magento shared, cloud, dedicated and clustered services.

What is an SSL certificate?

An SSL certificate enables encrypted communication between a customer’s browser and your server. It protects information in transit, but it is only one layer of ecommerce security.

Does DX3 make my store PCI compliant automatically?

No host can complete every customer responsibility. DX3 provides an in-scope hosting service; your payment integration, store software, access, policies and validation remain part of your own compliance work.