Data Processing Addendum
Last updated: July 30, 2026
Who this is for
If you host a website, store or mailbox with us that holds personal data about your own customers, members or users, then under UK and EU data protection law you are the controller of that data and we are your processor. This addendum sets out the terms required by Article 28 of the UK and EU GDPR for that relationship.
It forms part of our terms of service and applies automatically — there is nothing to sign to rely on it. If your organisation needs a countersigned copy for its own records, email info@hostingally.com and we will arrange it.
For data we hold about you as our customer — your account, billing and support records — we are the controller, and our privacy policy governs that instead.
1. Subject matter and duration
We process personal data contained in your hosted content only to provide the hosting, email, domain and support services you have ordered. Processing lasts for as long as your service is active, plus the short backup-retention period described in section 8.
2. Nature and purpose of processing
Storing, hosting, transmitting, backing up and restoring your content; operating the servers, network and mail systems it runs on; and providing technical support when you ask for it.
3. Types of data and categories of data subject
Determined entirely by you, since you decide what to put on the platform. Typically this means the names, email addresses, contact details, order records and message content of your website visitors, customers or members.
Our platform is not designed for special-category data — health, biometric, political or religious data and similar — nor for criminal-offence data. If your intended use involves those, tell us before you buy so we can be straight with you about whether we are a suitable choice.
4. Our obligations
- We process personal data only on your documented instructions, which includes your normal use of the platform, unless the law requires otherwise — in which case we will tell you first unless prohibited from doing so.
- Staff with access are bound by confidentiality obligations, and access is limited to those who need it to run the platform or answer your support requests.
- We maintain appropriate technical and organisational security measures, described in section 5.
- We assist you, so far as is reasonable, with data-subject requests, security-incident notifications and any data protection impact assessment you carry out.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the detail you need to meet your own notification duties.
5. Security measures
Encryption in transit through free auto-renewing TLS certificates; account isolation on shared infrastructure; a web application firewall and network-level DDoS mitigation; Imunify360 malware scanning; automatic daily backups with self-service restore; brute-force protection and optional two-factor authentication on your account; and current, patched platform software. Our security page sets these out in full, including an honest account of what remains your responsibility.
6. Sub-processors
You give general authorisation for us to engage the sub-processors listed in section 5 of our privacy policy, which we keep current. Each is bound by data protection terms no less protective than those in this addendum.
We will give you reasonable notice before adding or replacing a sub-processor that handles your hosted content. If you reasonably object on data protection grounds, tell us and we will work with you to find an alternative; if none is workable, you may terminate the affected service and receive a pro-rata refund of any prepaid, unused fees.
7. International transfers
Your hosted content is stored in a London datacentre. Where any transfer outside the UK or EEA occurs through the sub-processors above, it relies on an appropriate safeguard — a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses.
8. Deletion and return
You can export or delete your content yourself at any time through the control panel. On termination we delete your content from active systems, and it ages out of backups within the normal backup-retention cycle. If you need a final export before deletion, ask us before cancelling and we will help.
9. Audit and information
We will make available the information reasonably necessary to demonstrate compliance with this addendum, and respond to reasonable written questions about our processing.
To be straightforward with you about our size: we are a small company and we do not currently hold ISO 27001 or SOC 2 certification, so we cannot supply those reports. Where your own compliance programme strictly requires a certified processor, we would rather tell you now than after you have bought.
10. Liability and precedence
Liability under this addendum is subject to the limitations in our terms of service. Where this addendum conflicts with those terms on a data protection matter, this addendum takes precedence. It is governed by the law of England and Wales.
Contact
Data protection questions, sub-processor queries or a request for a countersigned copy: email info@hostingally.comwith “DPA” in the subject line.