Data Processing Agreement
1. Parties and scope
This Data Processing Agreement (“DPA”) is between PAC WEBHOSTING LTD, company number 06221654, of Suite 2 Albion House, 2 Etruria Office Village, Forge Lane, Etruria, Stoke-on-Trent, ST1 5RQ (“PAC”, “we”, “us”), and the customer named on the client account (“Customer”, “you”).
It forms part of our Terms of Service. It applies whenever we process Customer Personal Data on your behalf while providing our services: shared hosting, business hosting, WordPress hosting, VPS, email, domains, backups and related support (the “Services”). If this DPA conflicts with the Terms of Service on data protection, this DPA takes precedence.
2. Definitions
- Data Protection Law: the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and any law that amends or replaces them. Where relevant, it also includes the EU GDPR.
- Customer Personal Data: personal data that you, or your users, upload to, store on or send through the Services, such as website content, databases, mailboxes, files and backups.
- Sub-processor: a third party we engage to process Customer Personal Data.
- Personal Data Breach, controller, processor, data subject and processing have the meanings given in Data Protection Law.
3. Roles
- Your role. You are the controller (or a processor acting for your own client) of Customer Personal Data. We are the processor (or sub-processor).
- Our own records. For our own customer account, billing and support records, PAC is a controller. Those are covered by our Privacy Policy, not this DPA.
- Microsoft 365. Microsoft 365 services are provided under Microsoft’s own customer agreement and data protection terms. This DPA doesn’t cover Microsoft’s processing.
- Processing details. Annex 1 sets out the details of the processing.
4. Our obligations
We will:
- Follow your instructions. We process Customer Personal Data only on your documented instructions, unless the law requires otherwise. Your instructions are this DPA, the Terms of Service, your use and configuration of the Services, and support requests you make. If the law requires us to process data in another way, we’ll tell you first unless the law forbids it. If we think an instruction breaks Data Protection Law, we’ll tell you.
- Keep it confidential. Everyone we authorise to process Customer Personal Data is bound by confidentiality. Staff access it only when they need to, for example to answer a support request or keep the Services secure.
- Keep it secure. We apply appropriate technical and organisational measures (Annex 2), in line with Article 32 UK GDPR.
- Use approved sub-processors. We only use sub-processors as set out in clause 5.
- Help with data subject requests. Most requests can be handled by you through the control panel. If a data subject contacts us directly about Customer Personal Data, we’ll pass the request to you and won’t respond ourselves unless you tell us to.
- Help with your compliance. Taking into account the nature of the processing and the information we hold, we’ll give you reasonable help with security, breach notification, data protection impact assessments and consultation with the ICO. We may charge for help beyond the normal Services at our standard rates.
- Delete or return data. We’ll delete or return data at the end of the Services, as set out in clause 9.
- Show we comply. We’ll make information available to show we comply with this DPA, and allow audits, as set out in clause 8.
We won’t sell Customer Personal Data or use it for our own purposes. We don’t look at the contents of your websites, databases or mailboxes unless:
- you ask us to
- it’s needed to deal with a security incident, malware or abuse
- the law requires it
5. Sub-processors
- General authorisation. You give us general authorisation to use the sub-processors on our Sub-processor List.
- Notice of changes. We’ll give at least 30 days’ notice before adding or replacing a sub-processor. We’ll update the Sub-processor List and email the account holder’s primary contact.
- Your right to object. You can object on reasonable data protection grounds within those 30 days. If we can’t reasonably meet your concern, you can cancel the affected Services without an early termination charge. You’ll get a pro-rata refund of any prepaid, unused fees for those Services.
- Emergencies. In an emergency, for example to deal with a security threat or a supplier failure, we may appoint a sub-processor at shorter notice. We’ll tell you as soon as we can.
- Sub-processor terms. Each sub-processor is bound by written terms that give data protection at least equivalent to this DPA. We remain liable to you for each sub-processor’s performance.
6. International transfers
Customer Personal Data is hosted in the UK, with backups in the UK and the EEA. DNS records for hosted domains are served from DNS servers in the UK, Amsterdam (Netherlands) and the USA. VPS customers can choose London (UK), Amsterdam (Netherlands), New York or Phoenix (USA). If you choose a location outside the UK, that choice is your instruction to host the VPS and its data in that country, and you’re responsible for making sure it meets your own data protection obligations. We won’t transfer it outside the UK unless a lawful safeguard under Chapter V UK GDPR applies. That means UK adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework), or the ICO’s International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses. The Sub-processor List shows where each sub-processor processes data.
7. Personal data breaches
- Notification. We’ll notify you without undue delay, and in any case within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
- What we’ll tell you. The notice will say, as far as we know at the time:
- what happened
- the types of data and the approximate number of data subjects and records affected
- the likely consequences
- what we’ve done or plan to do
- a contact for more information
We’ll send further details as they become available.
- Containment. We’ll take reasonable steps to contain the breach and reduce its effects, and help you meet your own notification duties.
- No admission of fault. Telling you about a breach doesn’t mean we accept fault or liability.
- Your notification duties. You’re responsible for deciding whether to notify the ICO or data subjects, as controller.
8. Audits
- Information. When you ask, we’ll provide the information you reasonably need to check we comply with this DPA. This includes our Cyber Essentials certificate, this DPA’s security measures and answers to reasonable security questionnaires.
- On-site audits. If that isn’t enough, or a regulator requires it, you (or an independent auditor bound by confidentiality) may carry out an audit:
- with at least 30 days’ written notice
- no more than once in any 12 months, unless there has been a Personal Data Breach
- during business hours
- without disrupting other customers or giving access to their data
- at your cost
- Data centres. Audits of our infrastructure providers’ data centres are met through their own certifications and reports.
9. Deletion and return
- Getting a copy. Before your Services end, you can download your data at any time through the control panel, or ask us for a copy.
- Deletion. Within 30 days of the Services ending, we’ll delete Customer Personal Data from our live systems. Backup copies are overwritten on their normal cycle within a further 30 days.
- Legal retention. We don’t have to delete data that the law requires us to keep. Any data we keep stays protected by this DPA.
10. Your responsibilities
You’re responsible for:
- having a lawful basis and giving any required notices for the Customer Personal Data you process using the Services
- the security of what’s under your control, including:
- your passwords and user accounts, including turning on the two-factor authentication we provide
- your website software, plugins and themes, and keeping them updated
- software you install on a VPS where you have root access
- keeping your own backups of important data. Our backups are a safeguard, not a guarantee
- not asking us to process special category or criminal offence data unless you’ve told us and we’ve agreed suitable measures
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits liability that can’t be limited by law.
12. General
- Duration. This DPA lasts as long as we process Customer Personal Data for you. Clauses that by their nature should continue after it ends will continue.
- Changes. We may update this DPA to reflect changes in law or our Services. We’ll give 30 days’ notice of any material change that reduces your protection.
- Business continuity. If PAC is unable to continue trading and your Services transfer to our business continuity partner (see our Terms of Service, clause 17.3), this DPA transfers with them. Our partner becomes your processor on the same terms.
- Law and courts. This DPA is governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.
Annex 1 — Details of processing
| Item | Details |
|---|---|
| Subject matter | Providing shared, business and WordPress hosting, VPS, email, domain, backup and related support services |
| Duration | For as long as the Services are provided, plus the deletion periods in clause 9 |
| Nature of processing | Storage, hosting, transmission, backup and restoration, email relay and spam filtering, security scanning and firewalling, and support access when requested |
| Purpose | To provide, secure and support the Services under the Terms of Service |
| Types of personal data | Whatever you choose to store or send using the Services. Typically: names, contact details, account credentials, website user and order records, email contents and metadata, IP addresses and access logs |
| Special category data | Not expected. Only if you choose to store it (see clause 10) |
| Data subjects | Your staff, customers, website visitors, email correspondents and anyone else whose data you store using the Services |
| Location | UK (hosting), or for a VPS the location you choose: London, Amsterdam, New York or Phoenix; UK and EEA (backups); sub-processor locations as shown on the Sub-processor List |
Annex 2 — Security measures
| Area | Measures |
|---|---|
| Certification | Cyber Essentials certified (UK government-backed scheme) |
| Infrastructure | Servers on Krystal Cloud infrastructure in UK data centres, with physical security, power and network redundancy provided by the data centre operator |
| Network security | Hardware firewalls and hardware DDoS protection in front of our infrastructure; server firewalls, web application firewall and malware scanning (cPFence), Cloudflare and NitroPack on our own websites, and outbound spam filtering (MailChannels) |
| Account isolation | Each hosting account runs isolated from the others (CloudLinux / Enhance containerisation) |
| Patching | Operating systems, control panels and server software kept up to date. Security patches applied promptly |
| Access control | Staff access on a least-privilege basis. Multi-factor authentication on admin systems. Access removed promptly when no longer needed. Two-factor authentication available to customers on the client area and the Enhance hosting control panel |
| Encryption | TLS for the control panel, client area, email and websites (free SSL certificates). Encrypted admin connections (SSH) |
| Backups | Regular off-server backups kept for 30 days in the UK and EEA |
| Logging and monitoring | Server and security logs kept and monitored for suspicious activity. Network and infrastructure registered with the NCSC Early Warning service for threat and vulnerability alerts |
| People | Staff bound by confidentiality and trained in data protection and security |
| Incident response | A documented process for investigating security incidents and personal data breaches, and notifying customers within 48 hours |
| Suppliers | Sub-processors chosen for their security and bound by written data protection terms |