Data Processing Agreement
Terms governing our processing of personal data on your behalf.
This Data Processing Agreement ("DPA") forms an integral part of the Master Service Agreement between Hostry Compute LLC ("Hostry", "Processor") and the customer ("Customer", "Controller"), and applies to the processing of personal data by Hostry on behalf of the Customer in connection with the provision of hosting and infrastructure services.
This DPA is a standalone agreement between the parties. Where its terms conflict with the Master Service Agreement in respect of the processing of personal data covered by it, this DPA prevails.
1. Scope and Applicability
This DPA applies exclusively to the processing of personal data:
- of data subjects located within the European Economic Area or the United Kingdom; or
- where the Customer's processing is otherwise subject to Regulation (EU) 2016/679 ("GDPR") or the UK GDPR.
For Customers whose processing does not fall within the territorial scope of the GDPR or UK GDPR, this DPA does not apply, and data is handled in accordance with the Master Service Agreement and the Privacy Policy.
This DPA does not apply to personal data that Hostry processes as a controller in its own right — account, billing, identity verification and security data relating to the Customer itself. That processing is described in the Privacy Policy.
2. Roles of the Parties
The Customer acts as the Controller and Hostry as the Processor in respect of personal data contained in Customer Content hosted on Hostry infrastructure.
The Customer is solely responsible for:
- determining the purposes and means of processing;
- establishing and documenting a lawful basis for the processing;
- providing all notices and obtaining all consents required from data subjects;
- ensuring that no illegal content is hosted on Hostry infrastructure;
- responding to data subject requests concerning data it controls.
3. Subject Matter and Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of hosting, virtualization, storage and network infrastructure services |
| Duration | For the term of the Master Service Agreement, plus the retention periods set out in Section 8 |
| Nature and purpose | Storage, hosting, transmission and technical processing of Customer Content, as instructed by the Customer through its use and configuration of the services |
| Types of personal data | Determined solely by the Customer. Hostry does not control and does not inspect what categories of data the Customer stores |
| Categories of data subjects | Determined solely by the Customer, typically the Customer's own customers, employees and website visitors |
4. Processing Instructions
Hostry processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do otherwise by applicable law. Where Hostry is required by law to process without instructions, it will inform the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
The Customer's instructions are given through:
- this DPA and the Master Service Agreement;
- the Customer's configuration and use of the services through the Portal and its own systems.
Hostry will inform the Controller if, in its opinion, an instruction infringes the GDPR or UK GDPR.
5. Confidentiality
Hostry ensures that all personnel authorized to process personal data are bound by confidentiality obligations, have received appropriate data protection training, and access personal data only to the extent necessary to perform their duties.
6. Sub-processors
The Controller grants Hostry general written authorization to engage third-party datacenter operators, connectivity providers, infrastructure partners and other sub-processors to fulfil its obligations.
Hostry shall:
- impose on each sub-processor data protection obligations no less protective than those in this DPA;
- inform the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance, giving the Controller the opportunity to object on reasonable data protection grounds;
- remain fully liable to the Controller for the acts and omissions of its sub-processors.
Where the Controller objects on reasonable grounds and the parties cannot agree a resolution, the Controller may terminate the affected services without penalty, with pro-rated credit for the unused prepaid period.
The current list of sub-processors is available on request from dp@hostry.com, where Controllers may also subscribe to advance notification of any change.
7. Personal Data Breach
Hostry shall notify the Controller of a confirmed personal data breach affecting the Controller's data on Hostry infrastructure without undue delay, and where feasible no later than 48 hours after becoming aware of it.
The notification will include, to the extent available:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address it and mitigate its effects;
- a contact point for further information.
Where full information is not available at the time of notification, it will be provided in phases without undue further delay. Hostry will provide reasonable assistance to enable the Controller to meet its own notification obligations to supervisory authorities and data subjects.
8. Return or Deletion of Data
Upon termination or expiration of the services, Hostry shall, at the Controller's choice, securely delete or return all personal data processed on the Controller's behalf, and delete existing copies, unless retention is required by applicable law.
Deletion timelines follow the Service Suspension & Retention Policy. Hostry may retain backup copies for a limited period as part of its standard backup rotation, after which they are permanently overwritten and destroyed. Data held in such backups remains subject to this DPA until destroyed.
9. Technical and Organizational Measures
Hostry implements and maintains technical and organizational measures appropriate to the risk, including:
- encryption of data in transit;
- physical security of the facilities in which the infrastructure is located, provided either by Hostry or by the operator of the facility under contractual obligations no less protective than those in this DPA;
- logical segregation of customer environments;
- access control, authentication and role separation for personnel;
- network security monitoring and intrusion detection;
- logging and audit trails;
- secure wiping of storage media on service deletion;
- business continuity and incident response procedures.
The Controller remains responsible for security measures within its own environment, including encryption of data at rest, application-level access controls, patching of its own operating systems and applications, and maintaining backups outside the Hostry infrastructure. Hostry does not manage or audit Customer application security.
10. Assistance to the Controller
Taking into account the nature of the processing and the information available to it, Hostry shall provide reasonable assistance to the Controller with:
- responding to requests from data subjects exercising their rights. Since Hostry does not have visibility into the structure of Customer Content, this assistance is limited to providing access to the infrastructure and tools necessary for the Controller to act on such requests itself;
- data protection impact assessments and prior consultation with supervisory authorities;
- notification of personal data breaches to authorities and data subjects;
- demonstrating compliance with the obligations in Article 32 of the GDPR.
Hostry may charge a reasonable fee for assistance that goes materially beyond what is described above, on notice to the Controller.
11. Audits
Hostry shall make available to the Controller the information necessary to demonstrate compliance with this DPA.
Audit rights are satisfied in the first instance by Hostry providing available documentation on its security measures and, where held, third-party certifications or audit reports.
Where that is insufficient to demonstrate compliance, the Controller may conduct an audit no more than once per calendar year, on at least 30 days' written notice, during business hours, subject to confidentiality undertakings, and in a manner that does not disrupt the operation of Hostry infrastructure or compromise the security or confidentiality of other customers' data. The Controller bears the cost of such audits.
An audit under this Section covers systems and processes under Hostry's control. In respect of infrastructure operated by sub-processors, Hostry will provide the documentation and certifications made available to it by those sub-processors.
12. International Transfers
Hostry is established in the United States and operates infrastructure in multiple jurisdictions. Where personal data is transferred out of the EEA or the UK, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference and take effect on the transfer.
For the purposes of the Standard Contractual Clauses:
- the data exporter is the Customer, the data importer is Hostry;
- the details of processing in Section 3 populate Annex I;
- the measures in Section 9 populate Annex II;
- the sub-processors referenced in Section 6 populate Annex III;
- the governing law and forum clauses are completed with Ireland.
Hostry does not maintain an establishment in the European Union and has not appointed a representative under Article 27 of the GDPR. See Section 11 of the Privacy Policy.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Master Service Agreement, except to the extent that applicable data protection law does not permit such limitation.
14. Term
This DPA takes effect when the Customer accepts the Master Service Agreement and remains in force for as long as Hostry processes personal data on the Customer's behalf.
15. Contact
Data protection matters: dp@hostry.com