20% off your first order with code APEX20 00:00:00 See deals

Legal

Data Processing Agreement

Version 1.0  ·  Effective: 1 January 2025  ·  GDPR Article 28 Compliant

1. Introduction

This Data Processing Agreement ("DPA") is entered into between HOSTSTACK (OPC) PVT LTD ("Processor", "Hoststack") and the customer entity identified in the associated Hoststack account ("Controller", "Customer"). This DPA supplements and forms part of the Hoststack Terms of Service.

This DPA applies where Hoststack processes personal data on behalf of the Customer in the course of providing its hosting, VPS, game server, email hosting, and domain registration services. It is intended to satisfy the requirements of GDPR Article 28 for controller-processor arrangements.

Need a countersigned DPA?

Business customers requiring a formally signed DPA for compliance purposes may request one by emailing [email protected]. We typically turn around signed DPAs within 5 business days.

2. Definitions

Personal Data

Any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).

Controller

The entity (Customer) that determines the purposes and means of processing personal data.

Processor

HOSTSTACK (OPC) PVT LTD, which processes personal data on behalf of the Controller.

Processing

Any operation performed on personal data, including collection, storage, retrieval, use, disclosure and deletion.

Sub-Processor

A third party engaged by the Processor to carry out processing activities on the Controller's behalf.

Data Breach

A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

GDPR

Regulation (EU) 2016/679 of the European Parliament and of the Council.

3. Subject Matter and Duration

This DPA governs the processing of personal data by Hoststack in connection with the services provided under the Customer's active Hoststack account. The DPA commences upon the date the Customer first accesses Hoststack's services and remains in force for the duration of the service agreement, including any renewal periods. Upon termination or expiry, the provisions governing deletion and return of data (Section 10) continue to apply.

4. Nature and Purpose of Processing

Hoststack processes personal data solely for the purpose of providing the contracted services. Specific processing activities include:

  • Hosting and storing website files, databases, emails, and other customer content
  • Provisioning and managing VPS, VDS, or game server instances
  • Delivering domain registration and DNS management services
  • Providing control panel access (DirectAdmin, Plesk) and related administration tools
  • Sending transactional service notifications and billing communications
  • Monitoring server health and infrastructure security
  • Processing support requests and incident responses

Hoststack shall not process personal data for any purpose other than those set out in this DPA and the Terms of Service without the Controller's prior written instruction, except where required by law.

5. Types of Personal Data and Data Subjects

The following categories of personal data may be processed depending on the services used:

Category Data Subjects Examples
Account data Customer (Controller) Name, email, phone, billing address
End-user data Website visitors and customers of the Controller Email addresses, names, form submissions stored in hosted databases
Technical data All users IP addresses, access logs, error logs
Email content Email account holders Emails stored on Hoststack mail servers
File data Controller and their end-users Files, images, media uploaded to hosting accounts

6. Controller and Processor Obligations

Hoststack (Processor) shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure that persons authorised to process the data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 8)
  • Assist the Controller in responding to data subject rights requests
  • Delete or return all personal data upon termination of services (see Section 10)
  • Provide all information necessary to demonstrate compliance with this DPA and GDPR Article 28
  • Notify the Controller of any data breach without undue delay (see Section 9)

The Controller shall:

  • Ensure it has a lawful basis for processing before instructing Hoststack to process personal data
  • Provide clear and accurate instructions for processing activities
  • Ensure that data subjects are informed about processing through the Controller's own privacy notices
  • Comply with applicable data protection laws in respect of data the Controller uploads or processes through our infrastructure

7. Sub-Processors

Hoststack engages the following categories of sub-processors. By entering into this DPA, the Controller provides general authorisation for Hoststack to engage sub-processors within these categories. Hoststack will provide notice of any intended change to sub-processors via email or our website, giving the Controller an opportunity to object.

Data Centre & Cloud Infrastructure

Physical and virtual infrastructure providers located in India where customer data is hosted and processed.

India

Payment Processors

PCI-DSS compliant payment gateway providers used for billing (e.g. Razorpay, PayU). Payment data is processed under their own DPA.

India / Global

Email Delivery Services

Transactional email providers used to send service notifications and billing emails.

India / EEA

Customer Support Platforms

Ticketing and live chat systems used to manage and respond to support requests.

India / Global

Analytics Providers

Website analytics tools used in anonymised, aggregated form to improve service quality.

EEA / USA

8. Security Measures

In accordance with GDPR Article 32, Hoststack implements the following technical and organisational security measures:

Encryption in Transit

All connections secured via TLS 1.2/1.3. HTTPS enforced across all customer-facing and administrative interfaces.

Encryption at Rest

Sensitive account data and credentials encrypted at rest using industry-standard encryption.

Access Control

Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication for all administrative access.

Network Security

Enterprise-grade firewall protection, DDoS mitigation, intrusion detection and prevention systems.

Physical Security

Data centres with restricted physical access, CCTV surveillance, and environmental controls.

Vulnerability Management

Regular security assessments, patch management processes, and vulnerability scanning of infrastructure.

Incident Response

Defined incident response procedures with documented escalation paths and breach notification protocols.

Staff Training

Data protection training for all staff with access to personal data.

9. Data Breach Notification

In the event of a data breach affecting personal data processed under this DPA, Hoststack shall:

  • Notify the Controller within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33(2)
  • Provide the Controller with information regarding: the nature of the breach; approximate number of data subjects affected; categories and approximate number of records affected; likely consequences of the breach; measures taken or proposed to address the breach
  • Assist the Controller in meeting its own notification obligations to supervisory authorities and data subjects under GDPR Articles 33 and 34
  • Preserve evidence relating to the breach for investigation purposes

Breach notifications should be directed to the email address associated with the Customer's Hoststack account. Please ensure your contact details are kept up to date in the client area.

10. Deletion on Termination

Upon termination or expiry of the service agreement, or upon written request by the Controller, Hoststack shall:

  • Delete all personal data held on behalf of the Controller within 30 days of termination, subject to any legal retention obligations
  • Provide written confirmation of deletion upon request
  • Where return of data is requested before termination, export it in a standard format (SQL dump, file archive) at no additional charge within 5 business days

Note that certain data may be retained beyond this period where required by law (e.g., billing records for tax compliance), in which case Hoststack will limit processing to the minimum necessary to fulfil the legal obligation.

11. Requesting a Signed DPA

Business customers requiring a countersigned DPA for their own compliance purposes (e.g., for GDPR accountability or enterprise procurement requirements) may request one. We support customised DPA schedules on request.

Request a Countersigned DPA

Email us with your company name, account email, and any specific schedule requirements.

[email protected]

Typical turnaround: 5 business days. We cover EU SCCs and UK IDTA schedules.

Deploy today

Online in 60 seconds. Supported around the clock.

Hosting, VPS and game servers on Mumbai infrastructure — INR billing, GST invoices, and code APEX20 for 20% off your first order.

5,000+ customers served
99.9% uptime SLA
<8ms ping across India
24/7 expert support
WhatsApp Discord