Data Processing Agreement
Version 1.0. Last updated 1 August 2026.
This agreement is entered into between:
Hosting Me, of International House, London, EC1A 2BN (the Processor)
and
the customer identified in the Terms of Service (the Controller)
It forms part of our Terms of Service and satisfies the requirements of Article 28 of UK GDPR. Where it conflicts with the Terms of Service on data protection matters, this agreement prevails.
1. Definitions
Data Protection Law means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any successor or amending legislation.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing and Supervisory Authority have the meanings given in UK GDPR.
Customer Personal Data means Personal Data contained within Customer Data that we process on your behalf in providing the Services.
Sub-processor means any third party engaged by us to process Customer Personal Data.
2. Roles
2.1 You are the Controller of Customer Personal Data. We are the Processor.
2.2 This applies to Personal Data belonging to your website visitors, your customers, your staff and anyone else whose data ends up in your hosting account, databases, email or backups.
2.3 We are a separate Controller in relation to your own account, billing and support data. That is covered by our Privacy Policy, not by this agreement.
2.4 You confirm that you have a lawful basis for the processing you instruct us to carry out, that you have given the necessary privacy information to Data Subjects, and that your instructions do not require us to breach Data Protection Law.
3. Our obligations
We will:
3.1 Process Customer Personal Data only on your documented instructions, which consist of this agreement, the Terms of Service, and your use of the Services and control panels. If we are required by law to process for another reason, we will tell you first unless the law prohibits it.
3.2 Tell you immediately if we believe an instruction from you breaches Data Protection Law. We may suspend that processing until it is resolved.
3.3 Ensure that everyone authorised to process Customer Personal Data is bound by an appropriate duty of confidentiality.
3.4 Implement the technical and organisational measures set out in Annex B.
3.5 Respect the conditions in clause 4 for engaging Sub-processors.
3.6 Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights.
3.7 Assist you in complying with your obligations under Articles 32 to 36 of UK GDPR, covering security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of processing and the information available to us.
3.8 At your choice, delete or return Customer Personal Data at the end of the Services, and delete existing copies, unless we are legally required to retain it. Deletion happens at the point of termination, as set out in clause 10.5 of the Terms of Service, with backups overwritten within a further 30 days.
3.9 Make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits under clause 7.
4. Sub-processors
4.1 You give general authorisation for us to engage Sub-processors. The current list is at Annex C.
4.2 We will give you at least 30 days’ notice by email before adding or replacing a Sub-processor.
4.3 You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected Services without penalty and receive a pro rata refund of prepaid fees.
4.4 We will impose on each Sub-processor, by written contract, obligations equivalent to those in this agreement. We remain fully liable to you for the performance of each Sub-processor.
5. International transfers
5.1 We will not transfer Customer Personal Data outside the UK without an appropriate safeguard under Chapter V of UK GDPR.
5.2 Where a transfer takes place, we rely on UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or the International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, as applicable.
5.3 Annex C states the location of each Sub-processor and the safeguard relied on.
5.4 Where we offer a UK data location for your hosting and you choose it, primary processing remains in the UK, though certain support and monitoring functions may still involve access from other locations as set out in Annex C.
6. Personal data breaches
6.1 We will notify you without undue delay, and in any event within 24 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.
6.2 The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, the measures we have taken or propose to take, and a point of contact for further information. Where we cannot provide all of this at once, we will provide it in phases without undue further delay.
6.3 We will cooperate with you and take reasonable steps you direct to assist your investigation and remediation.
6.4 We will not notify a Supervisory Authority or Data Subjects on your behalf unless you ask us to or we are legally required to do so.
7. Audit
7.1 On reasonable written notice of at least 30 days, and no more than once in any 12 month period, you may audit our compliance with this agreement. We may also satisfy an audit request by providing a current third party certification or audit report held by us or our Sub-processors.
7.2 Audits must take place during business hours, must not unreasonably disrupt our operations, and must not involve access to other customers’ data or infrastructure.
7.3 You bear your own audit costs. Where an audit reveals material non-compliance, we bear our reasonable costs of remediation.
7.4 You may audit more frequently following a Personal Data Breach, or where a Supervisory Authority requires it.
8. Data subject requests
8.1 If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond to it directly, other than to confirm receipt and direct them to you. We will forward it to you promptly.
8.2 You have direct access to Customer Personal Data through your control panel, databases and email, so in most cases you can handle requests yourself. Where you need our assistance beyond that, we will provide reasonable help.
8.3 We may charge for assistance that goes materially beyond what is reasonable, at our standard rates, having told you the cost in advance.
9. Liability
Liability under this agreement is subject to the limits in clause 12 of the Terms of Service, except where Data Protection Law does not permit that limitation.
10. Term
This agreement takes effect when the Terms of Service take effect and continues until we stop processing Customer Personal Data on your behalf.
Annex A: Details of processing
Subject matter. Provision of web hosting, managed WordPress hosting, reseller hosting, email, domain and related services.
Duration. The term of the Terms of Service, plus the retention and deletion periods set out in clause 10.5 of those Terms.
Nature and purpose. Hosting, storage, transmission, backup, restoration and deletion of Customer Data, and technical support in relation to it.
Types of Personal Data. Whatever you choose to store or transmit. Typically this includes names, email addresses, postal addresses, telephone numbers, IP addresses, account credentials, order and transaction records, form submissions and email content.
Categories of Data Subject. Your website visitors, customers, prospects, staff, suppliers and any other individuals whose data you place on the Services.
Special category data. We do not expect you to store special category data or criminal offence data. If you intend to, tell us first so we can confirm whether the Services are appropriate and whether additional measures are needed.
Annex B: Technical and organisational measures
Access control
- Role based access, restricted to what each role requires
- Mandatory two factor authentication for all staff
- Key based SSH authentication, password authentication disabled
- Logging and monitoring of administrative access
- Prompt revocation of access when staff leave
Encryption
- TLS on all connections to websites, control panels and mail services
- Encryption at rest on backup storage
- Secure credential handling through the ticket system, never by email or chat
Infrastructure security
- Datacentres with physical access control, environmental monitoring and 24 hour security
- Network firewalling and intrusion detection
- Rate limiting and brute force protection on authentication endpoints
- Regular application of security patches, tracked against upstream advisories
Resilience and recovery
- Rolling backups retained for 30 days
- Documented restoration procedures
- Monitoring and alerting on service availability
Organisational
- Confidentiality obligations for all staff and contractors
- Data protection awareness training
- Documented incident response procedure
- Written contracts with all Sub-processors
We may update these measures, provided the level of protection is not reduced.
Annex C: Approved sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Hosting infrastructure partner | Physical web hosting, email and domain infrastructure | UK | N/A, UK |
| Cloud and VPS infrastructure partner | VPS and cloud compute platform | UK | N/A, UK |
| Client management and billing platform | Account management, invoicing and support ticketing | UK / EEA | UK adequacy |
| Stripe | Payment processing | US, EEA | UK Extension to EU-US DPF |
| PayPal | Payment processing | US, EEA | UK Extension to EU-US DPF |
| Live chat provider | Live chat support widget | EEA | UK adequacy |
Stripe and PayPal act as independent Controllers for payment data as well as processing on our behalf for account reconciliation.
The current version of this list is always available on this page.