Article 28 (EU GDPR + UK GDPR)

Data Processing Agreement DPA

web development

This Data Processing Agreement (“DPA”) forms part of the agreement between Host2Go Ltd, a company registered in England and Wales (“Processor”), and the customer (“Controller”) who uses Host2Go’s services.

Processor: Host2Go Ltd, registered in England and Wales (Company No. 13279820)
Contact: [email protected]

This DPA is entered into in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR”), as applicable. This DPA serves as a Data Processing Agreement under Article 28 of the GDPR, equivalent to an “Auftragsverarbeitungsvertrag” (AVV) under German data protection law (BDSG). For German-speaking customers, a German version of this DPA is available upon request.

1. Subject and Duration of Processing

Host2Go processes personal data on behalf of the Controller solely for the purpose of providing hosting, domain, email, backup, security, and technical support services for the duration of the service agreement.

2. Nature and Purpose of Processing

Processing activities may include:

– website and database hosting
– email hosting and filtering
– backups and disaster recovery
– system monitoring and logging
– customer support and migrations
– domain name registration and management
– payment processing (via authorised payment sub-processors)

3. Categories of Data Subjects

– website visitors
– customers and account users
– domain registrants
– employees or contractors of the Controller

4. Categories of Personal Data

Depending on the service, data may include:

– names, email addresses, phone numbers
– IP addresses and logs
– website content and databases
– domain registration data (WHOIS)
– authentication credentials (hashed or encrypted where applicable)
– payment-related data (processed by authorised payment sub-processors only)

5. Processor Obligations

Host2Go shall:

(a) process personal data only on documented instructions from the Controller, unless required to do so by applicable law;

(b) ensure that all persons authorised to process personal data are bound by appropriate confidentiality obligations;

(c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 11);

(d) not engage another processor (Sub-Processor) without prior general authorisation of the Controller. The current list of Sub-Processors is set out in Section 7 below;

(e) assist the Controller, insofar as is possible, in fulfilling its obligations to respond to data subject access requests and other rights under GDPR;

(f) assist the Controller in ensuring compliance with obligations relating to data security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities;

(g) at the choice of the Controller, delete or return all personal data after the end of the provision of services, unless retention is required by applicable law;

(h) make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, within reasonable scope and upon reasonable notice.

6. Data Breach Notification

In the event of a personal data breach, Host2Go shall:

(a) notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach;

(b) provide the Controller with sufficient information to enable them to meet their own obligations to report the breach to the relevant supervisory authority and, where applicable, to affected data subjects;

(c) cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

Host2Go’s ability to meet the 72-hour notification timeline depends, in part, on timely notification from its sub-processors. Host2Go undertakes to notify the Controller as soon as reasonably practicable after becoming aware of any breach, including breaches notified to Host2Go by its sub-processors.

7. Sub-Processors

The Controller provides general authorisation for Host2Go to engage Sub-Processors as necessary to provide the services. Host2Go currently uses the following Sub-Processors:

Sub-Processor Purpose Location
Host2Go UK Infrastructure Partner (StackCP and WordPress hosting platform)
Registered office: Hawthorn House, Southwell Road West, Mansfield, Nottinghamshire, NG21 0HJ, United Kingdom
Full sub-processor identity available upon written request to [email protected]
Managed hosting infrastructure, web servers, backups, email delivery, DNS United Kingdom (London data centre)
Host2Go cPanel Infrastructure Partner
Registered office: 5 Sydney Street, Chelsea, London, SW3 6PU, United Kingdom
Full sub-processor identity available upon written request to [email protected]
cPanel managed hosting infrastructure, web servers, backups, email delivery, DNS Customer’s choice at provisioning: Frankfurt (Germany), Amsterdam (Netherlands), or London (United Kingdom)
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA 94107, USA
CDN, DNS, DDoS protection, SSL, web application firewall Global. EU/UK traffic is processed by Cloudflare’s EU/UK edge locations. Cloudflare is certified under the EU-US Data Privacy Framework (DPF).
Stripe Payments Europe Ltd
1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
Credit/debit card payment processing Ireland (EEA), with global payment infrastructure
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal, L-2449 Luxembourg
PayPal payment processing Luxembourg (EEA)

Host2Go’s infrastructure providers (as identified above) may engage their own sub-processors (e.g., domain registrars, SSL certificate authorities, payment processors). Details of these are available in the respective infrastructure provider’s own Data Processing Agreement.

Host2Go will inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 30 days in advance, giving the Controller the opportunity to object to such changes. If no objection is raised within 14 days of notification, consent is deemed granted.

Host2Go ensures that all Sub-Processors are bound by data processing obligations no less protective than those set out in this DPA and applicable data protection law. Host2Go remains fully liable to the Controller for the performance of its Sub-Processors’ obligations in accordance with Article 28(4) of the GDPR.

8. International Data Transfers

Host2Go’s hosting services are delivered through managed infrastructure hosted in secure, enterprise-grade data centres. The data centre location depends on the service selected:

WordPress and StackCP Hosting: United Kingdom (London)
cPanel Hosting: Customer’s choice — Frankfurt (Germany), Amsterdam (Netherlands), or London (United Kingdom)
VPS, Cloud, and Dedicated Servers: Multiple locations available; please refer to the service specification at the time of provisioning

For customers requiring strict EU/EEA-only data residency (e.g., German customers subject to BDSG requirements), Host2Go offers cPanel hosting in Frankfurt (Germany) or Amsterdam (Netherlands). Please specify your preferred data centre location at the time of provisioning.

Transfers of personal data shall comply with Chapter V of the EU GDPR and Chapter V of the UK GDPR, as applicable:

– EU → UK transfers rely on the European Commission’s adequacy decision for the United Kingdom, renewed on 19 December 2025. This confirms that the UK provides an adequate level of data protection, and transfers from the EU/EEA to the UK are permitted without the need for additional safeguards such as Standard Contractual Clauses (SCCs) or the International Data Transfer Agreement (IDTA).

– UK → EU transfers, where applicable, rely on the UK’s recognition of the EU as providing an adequate level of protection.

– Transfers to the United States (Cloudflare) are covered by Cloudflare’s certification under the EU-US Data Privacy Framework (DPF), as recognised by the European Commission’s adequacy decision of 10 July 2023.

– Onward transfers to third countries outside the UK or EEA are subject to appropriate safeguards under Article 46 EU GDPR and UK GDPR, including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), as applicable.

If the EU adequacy decision for the UK is revoked or modified, Host2Go will, at the Controller’s choice:

(a) implement the European Commission’s Standard Contractual Clauses (SCCs) Module 2 (Controller to Processor) and Module 3 (Processor to Processor for Sub-Processors), as adopted by Commission Implementing Decision (EU) 2021/914;

(b) for cPanel hosting customers, offer migration to an EEA-based hosting location (Frankfurt or Amsterdam) at no additional cost within 90 days; or

(c) for WordPress and StackCP hosting customers, offer migration to Host2Go’s cPanel hosting on an EEA-based location, subject to technical compatibility and a reasonable migration period.

9. Data Subject Rights

Host2Go shall assist the Controller in responding to requests from data subjects exercising their rights under GDPR, including the right of access, rectification, erasure, restriction of processing, data portability, and the right to object.

Where Host2Go receives a request from a data subject directly, we will promptly refer the request to the Controller unless we are legally required to respond directly.

10. Data Retention and Deletion

Host2Go processes and retains personal data for the duration of the hosting service agreement. Upon termination or expiry of the service:

(a) the Controller may request the return or export of their data prior to termination;

(b) following termination, data will be handled in accordance with the data retention terms set out in our Terms and Conditions (see Clauses 5.16 and 6.7);

(c) after the retention period specified in the Terms and Conditions, all data — including website files, databases, emails, and backups — will be permanently deleted.

Backup data held by sub-processors may persist in isolated, encrypted backup systems for the duration of the sub-processor’s backup retention cycle (typically up to 30 days), after which it is permanently deleted in accordance with the sub-processor’s data retention policies.

11. Technical and Organisational Measures (TOMs)

In accordance with Article 32 of the GDPR, Host2Go implements the following technical and organisational security measures:

Encryption: all data in transit is encrypted using SSL/TLS. Free SSL certificates are provided with all hosting accounts. Passwords and authentication credentials are stored using industry-standard hashing algorithms.

Pseudonymisation: where technically feasible, personal data is pseudonymised in logs and monitoring systems to reduce exposure in the event of unauthorised access.

Backups and Recovery: automated daily backups stored in the same geographical region as the primary server. Recovery Time Objective (RTO): 24 hours. Recovery Point Objective (RPO): 24 hours.

Access Control: access to hosting infrastructure is restricted to authorised personnel only, using secure authentication methods and least-privilege permissions. Multi-factor authentication is used where available.

Firewalls and Intrusion Detection: web application firewalls (WAF), DDoS protection, and intrusion detection systems are deployed across our infrastructure.

Malware Monitoring: automated malware scanning and monitoring is in place across shared and managed hosting platforms.

Logging and Monitoring: system and access logs are maintained and monitored for security events and anomalies.

Incident Response: documented incident response procedures are in place for identifying, containing, and remediating security incidents.

Physical Security: all data centres used by Host2Go and its infrastructure providers maintain appropriate physical security measures, including access controls, surveillance, and environmental protections.

Data Separation: logical separation of customer data is maintained to prevent unauthorised cross-access between accounts.

Testing and Evaluation: security measures are reviewed and tested on a regular basis to ensure their continued effectiveness. Updates and patches are applied promptly to address known vulnerabilities.

12. Audit Rights

The Controller may request reasonable information to verify Host2Go’s compliance with this DPA.

The Controller may conduct audits no more than once per calendar year, with at least 30 days’ written notice, during normal business hours. Audit costs are borne by the Controller. Host2Go may charge reasonable reimbursement for staff time and resources required to support the audit.

Where Host2Go’s underlying infrastructure providers conduct independent third-party audits (such as ISO 27001, SOC 2, or Cyber Essentials), Host2Go will, upon written request, make available the most recent audit attestation or summary report (subject to confidentiality obligations imposed by the relevant sub-processor).

Where a third-party auditor is engaged by the Controller, such auditor must be bound by appropriate confidentiality obligations and must not be a competitor of Host2Go.

13. Controller Obligations

The Controller is responsible for:

(a) ensuring that the collection and processing of personal data through their website or service complies with applicable data protection laws, including having a lawful basis for processing;

(b) providing appropriate privacy notices (such as a Privacy Policy or Datenschutzerklärung) to their website visitors and end users;

(c) obtaining any necessary consents from data subjects where required;

(d) ensuring that any instructions given to Host2Go regarding the processing of personal data comply with applicable law;

(e) where the Controller is established in the EU/EEA, the Controller acts as the primary point of contact for EU data protection authorities. Host2Go does not act as an EU Article 27 representative for the Controller;

(f) selecting an appropriate data centre location for their hosting service in line with their own data residency requirements (see Section 8).

14. Liability

The liability of each party under this DPA shall be subject to the limitation of liability provisions set out in Host2Go’s Terms and Conditions.

Host2Go remains liable to the Controller for the performance of its sub-processors’ obligations in accordance with Article 28(4) of the GDPR. Nothing in this DPA shall limit any liability that cannot be excluded under applicable law.

15. Amendments

Host2Go may update this DPA from time to time to reflect changes in applicable law, our Sub-Processors, or our data processing practices. The current version will always be available at this page. Material changes will be communicated to affected customers.

16. Governing Law

This DPA is governed by the laws of England and Wales and is subject to the jurisdiction of the courts of England and Wales.

Notwithstanding the above, where the Controller is established in the European Union or European Economic Area, data subjects shall retain their right to pursue claims before the supervisory authority and courts of their Member State as provided by EU GDPR Article 79. Nothing in this DPA shall limit any rights that data subjects may have under applicable data protection law, including the BDSG (Bundesdatenschutzgesetz) and the TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz).

17. Contact

For any questions regarding this Data Processing Agreement or our data processing practices, please contact us at:

Host2Go Ltd
Email: [email protected]
Client Area: https://clients.host2goo.com