Data Processing Addendum
Revised July 30, 2026
Who this addendum covers
Where a site, store or mailbox you keep with us happens to carry personal data about your own customers, members or users, then under UK and EU data protection law you are the controller over that data, which leaves us your processor. What follows are the terms Article 28 of the UK and EU GDPR demands for a relationship of that kind.
It forms part of our terms of service and takes effect by itself; no signature is needed before you rely on it. Should your organisation want a countersigned copy to keep on its own file, email info@hosting-n-domains.com and one will be arranged.
Data we hold about you as our customer, meaning your account, billing and support records, falls under a separate heading. There we are the controller ourselves, and our privacy policy applies instead.
1. Subject matter and duration
Personal data sitting inside your hosted content is processed for a single purpose, which is to deliver the hosting, mail, domain and support services you ordered. That processing runs for as long as the service stays active, and then through the short copy-retention period set out in section 8.
2. What the processing is, and why
Holding, hosting, transmitting, copying and restoring what you put on the platform; running the servers, the network and the mail systems that carry it; and answering your technical support requests.
3. Which data, and whose data it is
You settle both, since you are the one deciding what goes onto the platform. In practice it tends to come down to names, email addresses, contact details, order records and message content belonging to your website visitors, your customers or your members.
The platform is not designed for special-category data, meaning health, biometric, political, religious and the like, and it is not designed for criminal-offence data either. Have that sort of use in mind? Say so before you buy, and you will get a straight answer on whether this platform suits it.
4. Our obligations to you
- Personal data is processed only on your documented instructions, and your everyday use of the platform counts as such an instruction. Where the law demands otherwise, we tell you before acting, save where telling you is itself forbidden by law.
- A duty of confidentiality binds every person who holds access, and that access reaches only the people who need it to run the platform or to answer a support request of yours.
- We keep appropriate technical and organisational security in place, and section 5 spells it out.
- So far as is reasonable, we help with data-subject requests, with security-incident notification, and with any data protection impact assessment you carry out.
- We notify you without undue delay once we become aware of a personal data breach touching your data, and we supply whatever detail your own notification duties call for.
5. Security measures
Free TLS certificates that renew on their own, encrypting traffic in transit; separation between accounts sharing infrastructure; a web application firewall with network-level DDoS mitigation behind it; Imunify360 malware scanning; a daily copy taken automatically that you can restore without help; brute-force protection, plus optional two-factor authentication on the account itself; and platform software held patched and current. Our security page lays all of that out in full, with a frank note on the parts that remain yours.
6. Sub-processors
You give general authorisation for us to engage the sub-processors named in section 5 of our privacy policy, and that list is kept up to date. Data protection terms bind every one of them, at a level no less protective than this addendum sets.
Before any sub-processor handling your hosted content is added or swapped out, reasonable notice comes to you first. Object on reasonable data protection grounds and we will look for an alternative with you. Where nothing workable turns up, you can terminate the affected service and take a pro-rata refund of any prepaid fees you have not used.
7. International transfers
Everything you host here sits inside a London datacentre. Where a transfer beyond the UK or EEA does occur by way of the sub-processors listed above, an appropriate safeguard covers it: a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses.
8. Deletion and return
Export or remove your content whenever you like, straight from the control panel. Once a service ends we take it off the active systems, and it expires from the copies inside the normal retention cycle. Wanting a final export before all that? Ask us while the account is still open and we will help you get it.
9. Audit and information
We hand over whatever information is reasonably needed to show compliance with this addendum, and we answer reasonable written questions about how we process.
Plainly on the question of scale: this is a small company, and we hold neither ISO 27001 nor SOC 2 certification at present, so those reports are not ours to hand over. Does your compliance programme insist on a certified processor? Better you learn that now than after you have bought.
10. Liability and precedence
Whatever liability arises under this addendum falls inside the limits set out in our terms of service. Should the two documents disagree on a point of data protection, this addendum takes precedence. Governing law is that of the Province of Ontario, together with the federal laws of Canada that apply there.
Getting in touch
Questions on data protection, queries about a sub-processor, or a request for a countersigned copy all go to info@hosting-n-domains.com putting “DPA” into the subject line.