Skip to main content
.com from $2.99, and WHOIS privacy costs nothing

Data Processing Addendum

Last updated: July 30, 2026

Who this is for

Where a website, an online store or a mailbox you keep with us happens to hold personal data about your own customers, members or the users of your service, then UK and EU data protection law makes you the controller for that data, and we act as your processor. What follows is the addendum which sets out precisely the terms Article 28 of the UK and EU GDPR requires for that relationship.

It forms part of our terms of service and it applies on its own, with nothing for you to sign before you can rely on it. Should your organisation want a countersigned copy for its own records, then email info@hostingally.com and we will arrange it.

For data we hold about you as our own customer, meaning your account records, your billing and your support history, we are the controller, and our privacy policy governs that instead.

1. Subject matter and duration

Personal data held inside your hosted content is processed by us for one purpose only: delivering the hosting, email, domain and support services you ordered. That processing runs for as long as the service stays active, and then for the short backup-retention period set out in section 8.

2. What the processing involves, and why

Storing your content, hosting it, transmitting it, backing it up and restoring it; running the servers, the network and the mail systems it sits on; and giving you technical support whenever you ask for some.

3. Which data, and which categories of data subject

You determine this completely, because you decide what goes onto the platform in the first place. In practice it tends to mean names, email addresses, contact details, order records and message content belonging to your website visitors, your customers or your members.

Our platform is not designed for special-category data, meaning health, biometric, political or religious data and the like, and it is not designed for criminal-offence data either. If what you plan involves any of that, tell us before you buy, so we can be straight with you about whether we suit you at all.

4. Our obligations

  • Personal data gets processed only on your documented instructions, and your ordinary use of the platform counts as those instructions. The exception is where the law requires something else, in which case we tell you first, unless we are prohibited from telling you.
  • Anyone here with access is bound by confidentiality obligations, and that access reaches only the people who need it in order to run the platform or answer a support request from you.
  • Appropriate technical and organisational security measures are maintained throughout, and section 5 describes them.
  • So far as is reasonable, we help you with data-subject requests, with security-incident notifications, and with any data protection impact assessment that you undertake yourself.
  • We notify you without undue delay after we become aware of a personal data breach touching your data, and with detail enough for you to discharge your own notification duties in turn.

5. Security measures

Traffic encrypted in transit by free auto-renewing TLS certificates; each account isolated from its neighbours on shared infrastructure; a web application firewall backed by network-level DDoS mitigation; Imunify360 malware scanning; daily backups taken automatically, with restore you run yourself; brute-force protection plus optional two-factor authentication on the account; and platform software kept current and patched. Our security page sets every one of those out in full, including a frank account of what remains your own responsibility.

6. Sub-processors

General authorisation is given by you for us to engage each of the sub-processors listed in section 5 of our privacy policy, which we keep up to date. Each is bound by data protection terms that are no less protective than the ones in this addendum.

Before we add or replace a sub-processor that touches your hosted content, you get reasonable notice of it. Object on data protection grounds, with reasons, and we will work with you to find an alternative. Where no alternative turns out to be workable, you may terminate the affected service, and any prepaid fees you have not used come back to you pro-rata.

7. International transfers

The content you host with us sits in a London datacentre. Data does sometimes travel beyond the UK or EEA through one of those sub-processors. When it does, an approved safeguard has to sit behind the move: the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or a UK adequacy decision.

8. Deletion and return

Through the control panel you can export or delete your own content whenever you like. When the service ends, we remove that content from active systems, and it then ages out of the backups across the normal backup-retention cycle. Want a final export before anything is deleted? Ask us before you cancel and we will sort it out with you.

9. Audit and information

Information reasonably necessary to demonstrate compliance with this addendum will be made available to you, and we answer reasonable written questions about how we process your data.

Being straightforward about our size: this is a small company, and we do not currently hold ISO 27001 or SOC 2 certification, which means those reports are not ours to supply. If your own compliance programme insists on a certified processor, we would sooner say so now than have you find out about it after you have paid us.

10. Liability and precedence

Liability arising under this addendum sits subject to the limits set in our terms of service. Where a conflict arises between this addendum and those terms on any data protection matter, this addendum is the one that wins. The law of England and Wales governs it.

Contact

Questions about data protection, queries about sub-processors, or a request for a countersigned copy: email info@hostingally.commaking sure “DPA” appears in the subject line.