This Data Processing Agreement (“DPA”) forms part of the agreement between Host2Go Ltd, a company registered in England and Wales (“Processor”), and the customer (“Controller”) who uses Host2Go’s services.
Processor: Host2Go Ltd, registered in England and Wales (Company No. 13279820)
Contact: [email protected]
This DPA is entered into in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR”), as applicable. This DPA serves as a Data Processing Agreement under Article 28 of the GDPR, equivalent to an “Auftragsverarbeitungsvertrag” (AVV) under German data protection law (BDSG). For German-speaking customers, a German version of this DPA is available upon request.
Host2Go processes personal data on behalf of the Controller solely for the purpose of providing hosting, domain, email, backup, security, and technical support services for the duration of the service agreement.
Processing activities may include:
– website and database hosting
– email hosting and filtering
– backups and disaster recovery
– system monitoring and logging
– customer support and migrations
– domain name registration and management
– payment processing (via authorised payment sub-processors)
– website visitors
– customers and account users
– domain registrants
– employees or contractors of the Controller
Depending on the service, data may include:
– names, email addresses, phone numbers
– IP addresses and logs
– website content and databases
– domain registration data (WHOIS)
– authentication credentials (hashed or encrypted where applicable)
– payment-related data (processed by authorised payment sub-processors only)
Host2Go shall:
(a) process personal data only on documented instructions from the Controller, unless required to do so by applicable law;
(b) ensure that all persons authorised to process personal data are bound by appropriate confidentiality obligations;
(c) implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (see Section 11);
(d) not engage another processor (Sub-Processor) without prior general authorisation of the Controller. The current list of Sub-Processors is set out in Section 7 below;
(e) assist the Controller, insofar as is possible, in fulfilling its obligations to respond to data subject access requests and other rights under GDPR;
(f) assist the Controller in ensuring compliance with obligations relating to data security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities;
(g) at the choice of the Controller, delete or return all personal data after the end of the provision of services, unless retention is required by applicable law;
(h) make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, within reasonable scope and upon reasonable notice.
In the event of a personal data breach, Host2Go shall:
(a) notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach;
(b) provide the Controller with sufficient information to enable them to meet their own obligations to report the breach to the relevant supervisory authority and, where applicable, to affected data subjects;
(c) cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
Host2Go’s ability to meet the 72-hour notification timeline depends, in part, on timely notification from its sub-processors. Host2Go undertakes to notify the Controller as soon as reasonably practicable after becoming aware of any breach, including breaches notified to Host2Go by its sub-processors.
The Controller provides general authorisation for Host2Go to engage Sub-Processors as necessary to provide the services. Host2Go currently uses the following Sub-Processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Host2Go UK Infrastructure Partner (StackCP and WordPress hosting platform) Registered office: Hawthorn House, Southwell Road West, Mansfield, Nottinghamshire, NG21 0HJ, United Kingdom Full sub-processor identity available upon written request to [email protected] | Managed hosting infrastructure, web servers, backups, email delivery, DNS | United Kingdom (London data centre) |
| Host2Go cPanel Infrastructure Partner Registered office: 5 Sydney Street, Chelsea, London, SW3 6PU, United Kingdom Full sub-processor identity available upon written request to [email protected] | cPanel managed hosting infrastructure, web servers, backups, email delivery, DNS | Customer’s choice at provisioning: Frankfurt (Germany), Amsterdam (Netherlands), or London (United Kingdom) |
| Cloudflare, Inc. 101 Townsend Street, San Francisco, CA 94107, USA | CDN, DNS, DDoS protection, SSL, web application firewall | Global. EU/UK traffic is processed by Cloudflare’s EU/UK edge locations. Cloudflare is certified under the EU-US Data Privacy Framework (DPF). |
| Stripe Payments Europe Ltd 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland | Credit/debit card payment processing | Ireland (EEA), with global payment infrastructure |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. 22-24 Boulevard Royal, L-2449 Luxembourg | PayPal payment processing | Luxembourg (EEA) |
Host2Go’s infrastructure providers (as identified above) may engage their own sub-processors (e.g., domain registrars, SSL certificate authorities, payment processors). Details of these are available in the respective infrastructure provider’s own Data Processing Agreement.
Host2Go will inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 30 days in advance, giving the Controller the opportunity to object to such changes. If no objection is raised within 14 days of notification, consent is deemed granted.
Host2Go ensures that all Sub-Processors are bound by data processing obligations no less protective than those set out in this DPA and applicable data protection law. Host2Go remains fully liable to the Controller for the performance of its Sub-Processors’ obligations in accordance with Article 28(4) of the GDPR.
Host2Go’s hosting services are delivered through managed infrastructure hosted in secure, enterprise-grade data centres. The data centre location depends on the service selected:
WordPress and StackCP Hosting: United Kingdom (London)
cPanel Hosting: Customer’s choice — Frankfurt (Germany), Amsterdam (Netherlands), or London (United Kingdom)
VPS, Cloud, and Dedicated Servers: Multiple locations available; please refer to the service specification at the time of provisioning
For customers requiring strict EU/EEA-only data residency (e.g., German customers subject to BDSG requirements), Host2Go offers cPanel hosting in Frankfurt (Germany) or Amsterdam (Netherlands). Please specify your preferred data centre location at the time of provisioning.
Transfers of personal data shall comply with Chapter V of the EU GDPR and Chapter V of the UK GDPR, as applicable:
– EU → UK transfers rely on the European Commission’s adequacy decision for the United Kingdom, renewed on 19 December 2025. This confirms that the UK provides an adequate level of data protection, and transfers from the EU/EEA to the UK are permitted without the need for additional safeguards such as Standard Contractual Clauses (SCCs) or the International Data Transfer Agreement (IDTA).
– UK → EU transfers, where applicable, rely on the UK’s recognition of the EU as providing an adequate level of protection.
– Transfers to the United States (Cloudflare) are covered by Cloudflare’s certification under the EU-US Data Privacy Framework (DPF), as recognised by the European Commission’s adequacy decision of 10 July 2023.
– Onward transfers to third countries outside the UK or EEA are subject to appropriate safeguards under Article 46 EU GDPR and UK GDPR, including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), as applicable.
If the EU adequacy decision for the UK is revoked or modified, Host2Go will, at the Controller’s choice:
(a) implement the European Commission’s Standard Contractual Clauses (SCCs) Module 2 (Controller to Processor) and Module 3 (Processor to Processor for Sub-Processors), as adopted by Commission Implementing Decision (EU) 2021/914;
(b) for cPanel hosting customers, offer migration to an EEA-based hosting location (Frankfurt or Amsterdam) at no additional cost within 90 days; or
(c) for WordPress and StackCP hosting customers, offer migration to Host2Go’s cPanel hosting on an EEA-based location, subject to technical compatibility and a reasonable migration period.
Host2Go shall assist the Controller in responding to requests from data subjects exercising their rights under GDPR, including the right of access, rectification, erasure, restriction of processing, data portability, and the right to object.
Where Host2Go receives a request from a data subject directly, we will promptly refer the request to the Controller unless we are legally required to respond directly.
Host2Go processes and retains personal data for the duration of the hosting service agreement. Upon termination or expiry of the service:
(a) the Controller may request the return or export of their data prior to termination;
(b) following termination, data will be handled in accordance with the data retention terms set out in our Terms and Conditions (see Clauses 5.16 and 6.7);
(c) after the retention period specified in the Terms and Conditions, all data — including website files, databases, emails, and backups — will be permanently deleted.
Backup data held by sub-processors may persist in isolated, encrypted backup systems for the duration of the sub-processor’s backup retention cycle (typically up to 30 days), after which it is permanently deleted in accordance with the sub-processor’s data retention policies.
In accordance with Article 32 of the GDPR, Host2Go implements the following technical and organisational security measures:
Encryption: all data in transit is encrypted using SSL/TLS. Free SSL certificates are provided with all hosting accounts. Passwords and authentication credentials are stored using industry-standard hashing algorithms.
Pseudonymisation: where technically feasible, personal data is pseudonymised in logs and monitoring systems to reduce exposure in the event of unauthorised access.
Backups and Recovery: automated daily backups stored in the same geographical region as the primary server. Recovery Time Objective (RTO): 24 hours. Recovery Point Objective (RPO): 24 hours.
Access Control: access to hosting infrastructure is restricted to authorised personnel only, using secure authentication methods and least-privilege permissions. Multi-factor authentication is used where available.
Firewalls and Intrusion Detection: web application firewalls (WAF), DDoS protection, and intrusion detection systems are deployed across our infrastructure.
Malware Monitoring: automated malware scanning and monitoring is in place across shared and managed hosting platforms.
Logging and Monitoring: system and access logs are maintained and monitored for security events and anomalies.
Incident Response: documented incident response procedures are in place for identifying, containing, and remediating security incidents.
Physical Security: all data centres used by Host2Go and its infrastructure providers maintain appropriate physical security measures, including access controls, surveillance, and environmental protections.
Data Separation: logical separation of customer data is maintained to prevent unauthorised cross-access between accounts.
Testing and Evaluation: security measures are reviewed and tested on a regular basis to ensure their continued effectiveness. Updates and patches are applied promptly to address known vulnerabilities.
The Controller may request reasonable information to verify Host2Go’s compliance with this DPA.
The Controller may conduct audits no more than once per calendar year, with at least 30 days’ written notice, during normal business hours. Audit costs are borne by the Controller. Host2Go may charge reasonable reimbursement for staff time and resources required to support the audit.
Where Host2Go’s underlying infrastructure providers conduct independent third-party audits (such as ISO 27001, SOC 2, or Cyber Essentials), Host2Go will, upon written request, make available the most recent audit attestation or summary report (subject to confidentiality obligations imposed by the relevant sub-processor).
Where a third-party auditor is engaged by the Controller, such auditor must be bound by appropriate confidentiality obligations and must not be a competitor of Host2Go.
The Controller is responsible for:
(a) ensuring that the collection and processing of personal data through their website or service complies with applicable data protection laws, including having a lawful basis for processing;
(b) providing appropriate privacy notices (such as a Privacy Policy or Datenschutzerklärung) to their website visitors and end users;
(c) obtaining any necessary consents from data subjects where required;
(d) ensuring that any instructions given to Host2Go regarding the processing of personal data comply with applicable law;
(e) where the Controller is established in the EU/EEA, the Controller acts as the primary point of contact for EU data protection authorities. Host2Go does not act as an EU Article 27 representative for the Controller;
(f) selecting an appropriate data centre location for their hosting service in line with their own data residency requirements (see Section 8).
The liability of each party under this DPA shall be subject to the limitation of liability provisions set out in Host2Go’s Terms and Conditions.
Host2Go remains liable to the Controller for the performance of its sub-processors’ obligations in accordance with Article 28(4) of the GDPR. Nothing in this DPA shall limit any liability that cannot be excluded under applicable law.
Host2Go may update this DPA from time to time to reflect changes in applicable law, our Sub-Processors, or our data processing practices. The current version will always be available at this page. Material changes will be communicated to affected customers.
This DPA is governed by the laws of England and Wales and is subject to the jurisdiction of the courts of England and Wales.
Notwithstanding the above, where the Controller is established in the European Union or European Economic Area, data subjects shall retain their right to pursue claims before the supervisory authority and courts of their Member State as provided by EU GDPR Article 79. Nothing in this DPA shall limit any rights that data subjects may have under applicable data protection law, including the BDSG (Bundesdatenschutzgesetz) and the TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz).
For any questions regarding this Data Processing Agreement or our data processing practices, please contact us at:
Host2Go Ltd
Email: [email protected]
Client Area: https://clients.host2goo.com
We use cookies to make our website work smoothly, improve your experience, and show you relevant content and ads in collaboration with trusted third parties. By clicking "Allow all," you agree to these uses, including helping us with analytics and support. You can customize your cookie preferences in the settings and adjust them anytime.