WEB HOSTING

For personal sites and professionals

WORDPRESS HOSTING

AI-powered WordPress hosting

BUSINESS HOSTING

For demanding, business-critical websites

VIRTUAL PRIVATE SERVERS

Dedicated resources and full control

BUY DOMAIN NAMES

Register the perfect domain from over 1,100 extensions

TRANSFER YOUR DOMAIN NAME

Bring your domains together and manage them in one place

sales support Call Us!
Perfecting UK hosting since 2007
FOLLOW PAC
Client login
PAC UK Web Hosting
  • Hosting Packages
  • Microsoft 365
  • Domain Names
  • Contact us

Data Processing Agreement

PAC WEBHOSTING LTD · Registered in England and Wales, company number 06221654 · Last updated: 28 September 2026

Contents

  1. 1. Parties and scope
  2. 2. Definitions
  3. 3. Roles
  4. 4. Our obligations
  5. 5. Sub-processors
  6. 6. International transfers
  7. 7. Personal data breaches
  8. 8. Audits
  9. 9. Deletion and return
  10. 10. Your responsibilities
  11. 11. Liability
  12. 12. General
  13. Annex 1 — Details of processing
  14. Annex 2 — Security measures

1. Parties and scope

This Data Processing Agreement (“DPA”) is between PAC WEBHOSTING LTD, company number 06221654, of Suite 2 Albion House, 2 Etruria Office Village, Forge Lane, Etruria, Stoke-on-Trent, ST1 5RQ (“PAC”, “we”, “us”), and the customer named on the client account (“Customer”, “you”).

It forms part of our Terms of Service. It applies whenever we process Customer Personal Data on your behalf while providing our services: shared hosting, business hosting, WordPress hosting, VPS, email, domains, backups and related support (the “Services”). If this DPA conflicts with the Terms of Service on data protection, this DPA takes precedence.

2. Definitions

  • Data Protection Law: the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that amends or replaces them. Where relevant, it also includes the EU GDPR.
  • Customer Personal Data: personal data that you, or your users, upload to, store on or send through the Services, such as website content, databases, mailboxes, files and backups.
  • Sub-processor: a third party we engage to process Customer Personal Data.
  • Personal Data Breach, controller, processor, data subject and processing have the meanings given in Data Protection Law.

3. Roles

  1. Your role. You are the controller (or a processor acting for your own client) of Customer Personal Data. We are the processor (or sub-processor).
  2. Our own records. For our own customer account, billing and support records, PAC is a controller. Those are covered by our Privacy Policy, not this DPA.
  3. Microsoft 365. Microsoft 365 services are provided under Microsoft’s own customer agreement and data protection terms. This DPA doesn’t cover Microsoft’s processing.
  4. Processing details. Annex 1 sets out the details of the processing.

4. Our obligations

We will:

  1. Follow your instructions. We process Customer Personal Data only on your documented instructions, unless the law requires otherwise. Your instructions are this DPA, the Terms of Service, your use and configuration of the Services, and support requests you make. If the law requires us to process data in another way, we’ll tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law, we’ll tell you.
  2. Keep it confidential. Everyone we authorise to process Customer Personal Data is bound by confidentiality. Staff access it only when they need to, for example to answer a support request or keep the Services secure.
  3. Keep it secure. We apply appropriate technical and organisational measures (Annex 2), in line with Article 32 UK GDPR.
  4. Use approved sub-processors. We only use sub-processors as set out in clause 5.
  5. Help with data subject requests. Most requests can be handled by you through the control panel. If a data subject contacts us directly about Customer Personal Data, we’ll pass the request to you and won’t respond ourselves unless you tell us to.
  6. Help with your compliance. Taking into account the nature of the processing and the information we hold, we’ll give you reasonable help with security, breach notification, data protection impact assessments and consultation with the ICO. We may charge for help beyond the normal Services at our standard rates.
  7. Delete or return data. We’ll delete or return data at the end of the Services, as set out in clause 9.
  8. Show we comply. We’ll make information available to show we comply with this DPA, and allow audits, as set out in clause 8.

We won’t sell Customer Personal Data or use it for our own purposes. We don’t look at the contents of your websites, databases or mailboxes unless:

  • you ask us to
  • it’s needed to deal with a security incident, malware or abuse
  • the law requires it

5. Sub-processors

  1. General authorisation. You give us general authorisation to use the sub-processors on our Sub-processor List.
  2. Notice of changes. We’ll give at least 30 days’ notice before adding or replacing a sub-processor. We’ll update the Sub-processor List and email the account holder’s primary contact.
  3. Your right to object. You can object on reasonable data protection grounds within those 30 days. If we can’t reasonably meet your concern, you can cancel the affected Services without an early termination charge. You’ll get a pro-rata refund of any prepaid, unused fees for those Services.
  4. Emergencies. In an emergency, for example to deal with a security threat or a supplier failure, we may appoint a sub-processor at shorter notice. We’ll tell you as soon as we can.
  5. Sub-processor terms. Each sub-processor is bound by written terms that give data protection at least equivalent to this DPA. We remain liable to you for each sub-processor’s performance.

6. International transfers

Customer Personal Data is hosted in the UK, with backups in the UK and the EEA. DNS records for hosted domains are served from DNS servers in the UK, Amsterdam (Netherlands) and the USA. VPS customers can choose London (UK), Amsterdam (Netherlands), New York or Phoenix (USA). If you choose a location outside the UK, that choice is your instruction to host the VPS and its data in that country, and you’re responsible for making sure it meets your own data protection obligations. We won’t transfer it outside the UK unless a lawful safeguard under Chapter V UK GDPR applies. That means UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework), or the ICO’s International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. The Sub-processor List shows where each sub-processor processes data.

7. Personal data breaches

  1. Notification. We’ll notify you without undue delay, and in any case within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
  2. What we’ll tell you. The notice will say, as far as we know at the time:
    • what happened
    • the types of data and the approximate number of data subjects and records affected
    • the likely consequences
    • what we’ve done or plan to do
    • a contact for more information

    We’ll send further details as they become available.

  3. Containment. We’ll take reasonable steps to contain the breach and reduce its effects, and help you meet your own notification duties.
  4. No admission of fault. Telling you about a breach doesn’t mean we accept fault or liability.
  5. Your notification duties. You’re responsible for deciding whether to notify the ICO or data subjects, as controller.

8. Audits

  1. Information. When you ask, we’ll provide the information you reasonably need to check we comply with this DPA. This includes our Cyber Essentials certificate, this DPA’s security measures and answers to reasonable security questionnaires.
  2. On-site audits. If that isn’t enough, or a regulator requires it, you (or an independent auditor bound by confidentiality) may carry out an audit:
    • with at least 30 days’ written notice
    • no more than once in any 12 months, unless there has been a Personal Data Breach
    • during business hours
    • without disrupting other customers or giving access to their data
    • at your cost
  3. Data centres. Audits of our infrastructure providers’ data centres are met through their own certifications and reports.

9. Deletion and return

  1. Getting a copy. Before your Services end, you can download your data at any time through the control panel, or ask us for a copy.
  2. Deletion. Within 30 days of the Services ending, we’ll delete Customer Personal Data from our live systems. Backup copies are overwritten on their normal cycle within a further 30 days.
  3. Legal retention. We don’t have to delete data that the law requires us to keep. Any data we keep stays protected by this DPA.

10. Your responsibilities

You’re responsible for:

  • having a lawful basis and giving any required notices for the Customer Personal Data you process using the Services
  • the security of what’s under your control, including:
    • your passwords and user accounts, including turning on the two-factor authentication we provide
    • your website software, plugins and themes, and keeping them updated
    • software you install on a VPS where you have root access
  • keeping your own backups of important data. Our backups are a safeguard, not a guarantee
  • not asking us to process special category or criminal offence data unless you’ve told us and we’ve agreed suitable measures

11. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits liability that can’t be limited by law.

12. General

  1. Duration. This DPA lasts as long as we process Customer Personal Data for you. Clauses that by their nature should continue after it ends will continue.
  2. Changes. We may update this DPA to reflect changes in law or our Services. We’ll give 30 days’ notice of any material change that reduces your protection.
  3. Business continuity. If PAC is unable to continue trading and your Services transfer to our business continuity partner (see our Terms of Service, clause 17.3), this DPA transfers with them. Our partner becomes your processor on the same terms.
  4. Law and courts. This DPA is governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.

Annex 1 — Details of processing

Item Details
Subject matter Providing shared, business and WordPress hosting, VPS, email, domain, backup and related support services
Duration For as long as the Services are provided, plus the deletion periods in clause 9
Nature of processing Storage, hosting, transmission, backup and restoration, email relay and spam filtering, security scanning and firewalling, and support access when requested
Purpose To provide, secure and support the Services under the Terms of Service
Types of personal data Whatever you choose to store or send using the Services. Typically: names, contact details, account credentials, website user and order records, email contents and metadata, IP addresses and access logs
Special category data Not expected. Only if you choose to store it (see clause 10)
Data subjects Your staff, customers, website visitors, email correspondents and anyone else whose data you store using the Services
Location UK (hosting), or for a VPS the location you choose: London, Amsterdam, New York or Phoenix; UK and EEA (backups); sub-processor locations as shown on the Sub-processor List

Annex 2 — Security measures

Area Measures
Certification Cyber Essentials certified (UK government-backed scheme)
Infrastructure Servers on Krystal Cloud infrastructure in UK data centres, with physical security, power and network redundancy provided by the data centre operator
Network security Hardware firewalls and hardware DDoS protection in front of our infrastructure; server firewalls, web application firewall and malware scanning (cPFence), Cloudflare and NitroPack on our own websites, and outbound spam filtering (MailChannels)
Account isolation Each hosting account runs isolated from the others (CloudLinux / Enhance containerisation)
Patching Operating systems, control panels and server software kept up to date. Security patches applied promptly
Access control Staff access on a least-privilege basis. Multi-factor authentication on admin systems. Access removed promptly when no longer needed. Two-factor authentication available to customers on the client area and the Enhance hosting control panel
Encryption TLS for the control panel, client area, email and websites (free SSL certificates). Encrypted admin connections (SSH)
Backups Regular off-server backups kept for 30 days in the UK and EEA
Logging and monitoring Server and security logs kept and monitored for suspicious activity. Network and infrastructure registered with the NCSC Early Warning service for threat and vulnerability alerts
People Staff bound by confidentiality and trained in data protection and security
Incident response A documented process for investigating security incidents and personal data breaches, and notifying customers within 48 hours
Suppliers Sub-processors chosen for their security and bound by written data protection terms
Contact our sales team today

And We'll reply within 24 hours

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Your name*
Before contacting us you may find your answers are already covered in our frequently asked questions.
The fastest way to get help regarding your account is to log into your account and open a billing support ticket there.
The fastest way to get technical support is to log into your account and open a technical support ticket there.
We respond within 1 hour 24/7 to tickets.

Hosting Solutions

  • Web Hosting
  • WordPress Hosting
  • Business Hosting
  • Virtual private servers
  • Buy a domain name
  • Transfer your Domain Name
  • VPS Hosting

HELP AND SUPPORT

  • Control Panel Login
  • Knowledge Base
  • Submit a support ticket
  • Contact Support
  • Call Sales/Support
  • Blog Articles
  • Cookie Settings

The legal stuff

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Complaints & Abuse
  • Domain Registration Terms
  • Data Processing Agreement
  • Sub Processors
PAC has been delivering UK Web Hosting since 2007. Our primary goal is to offer top-notch hosting and support, always infused with a personalised approach
PAC Web Hosting partner and technology logos
Copyright 2007-2026 PAC Web Hosting Ltd | All Rights Reserved. | All pricing excluding UK VAT charged at 20%
Suite 2 Albion House 2 Etruria Office Village, Forge Lane, Etruria, Stoke-On-Trent, ST1 5RQ, UK | UK Limited Company Number 06221654
WE ACCEPT PAC Web Hosting Accept the following payment methods
  • Hosting Packages
    • Web Hosting
    • WordPress Hosting
    • Business Hosting
    • Virtual private servers
  • Microsoft 365
  • Domain Names
    • Buy domain names
    • Transfer your Domain Name
  • Contact Us
FOLLOW US
Facebook X tiktok Instagram