HOSTRY Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms an integral part of the Hostry Terms and Conditions and applies to the processing of personal data by Hostry on behalf of the Customer in connection with the provision of hosting services.
Scope and Applicability (Territorial Limitation)
This DPA applies exclusively to the processing of Personal Data of data subjects located within the European Economic Area (EEA) and the United Kingdom (UK), or where the processing of Personal Data by the Customer is otherwise legally subject to the EU General Data Protection Regulation 2016/679 ("GDPR") or the UK GDPR. For Customers whose processing activities do not fall under the territorial scope of the GDPR or UK GDPR, the provisions of this DPA do not apply, and data will be handled in accordance with Hostry’s standard operational procedures and Privacy Policy.
Roles and Instructions
In the context of this DPA, the Customer acts as the Data Controller and Hostry acts as the Data Processor. Hostry shall process personal data only on documented instructions from the Controller, unless required to do so by European Union or Member State law. The Controller is solely responsible for determining the lawful basis for collecting and processing such data and ensuring that no illegal content is hosted on Hostry's infrastructure.
Sub-processors
The Controller grants Hostry general written authorization to engage third-party data centers, infrastructure partners, and other sub-processors to fulfill its obligations. Hostry shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object to such changes. Hostry remains fully liable for the acts and omissions of its sub-processors in relation to data protection.
Personal Data Breach Notification
In the event of a confirmed Personal Data Breach affecting the Controller's data covered by this DPA on Hostry's infrastructure, Hostry shall notify the Controller without undue delay, and where feasible, not later than 48 hours after having become aware of it. The notification will provide sufficient information to allow the Controller to meet any obligations to report or inform regulatory authorities and data subjects in the EU/UK.
Return or Deletion of Data
Upon termination or expiration of the hosting services, Hostry shall, at the choice of the Controller, securely delete or return all personal data processed on behalf of the Controller under this DPA. Hostry may retain backup copies for a limited, strictly defined retention period as part of its standard backup rotation cycle, after which the data will be permanently overwritten and destroyed.
Technical and Organizational Measures
Hostry shall implement and maintain appropriate technical and organizational security measures to ensure a level of security appropriate to the risk, including protection against unauthorized or unlawful processing and against accidental or unlawful loss, destruction, or damage of personal data.