Legal
Data Processing Agreement
Version 1.0 · Effective: 1 January 2025 · GDPR Article 28 Compliant
1. Introduction
This Data Processing Agreement ("DPA") is entered into between HOSTSTACK (OPC) PVT LTD ("Processor", "Hoststack") and the customer entity identified in the associated Hoststack account ("Controller", "Customer"). This DPA supplements and forms part of the Hoststack Terms of Service.
This DPA applies where Hoststack processes personal data on behalf of the Customer in the course of providing its hosting, VPS, game server, email hosting, and domain registration services. It is intended to satisfy the requirements of GDPR Article 28 for controller-processor arrangements.
Need a countersigned DPA?
Business customers requiring a formally signed DPA for compliance purposes may request one by emailing [email protected]. We typically turn around signed DPAs within 5 business days.
2. Definitions
Personal Data
Any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
Controller
The entity (Customer) that determines the purposes and means of processing personal data.
Processor
HOSTSTACK (OPC) PVT LTD, which processes personal data on behalf of the Controller.
Processing
Any operation performed on personal data, including collection, storage, retrieval, use, disclosure and deletion.
Sub-Processor
A third party engaged by the Processor to carry out processing activities on the Controller's behalf.
Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
GDPR
Regulation (EU) 2016/679 of the European Parliament and of the Council.
3. Subject Matter and Duration
This DPA governs the processing of personal data by Hoststack in connection with the services provided under the Customer's active Hoststack account. The DPA commences upon the date the Customer first accesses Hoststack's services and remains in force for the duration of the service agreement, including any renewal periods. Upon termination or expiry, the provisions governing deletion and return of data (Section 10) continue to apply.
4. Nature and Purpose of Processing
Hoststack processes personal data solely for the purpose of providing the contracted services. Specific processing activities include:
- Hosting and storing website files, databases, emails, and other customer content
- Provisioning and managing VPS, VDS, or game server instances
- Delivering domain registration and DNS management services
- Providing control panel access (DirectAdmin, Plesk) and related administration tools
- Sending transactional service notifications and billing communications
- Monitoring server health and infrastructure security
- Processing support requests and incident responses
Hoststack shall not process personal data for any purpose other than those set out in this DPA and the Terms of Service without the Controller's prior written instruction, except where required by law.
5. Types of Personal Data and Data Subjects
The following categories of personal data may be processed depending on the services used:
| Category | Data Subjects | Examples |
|---|---|---|
| Account data | Customer (Controller) | Name, email, phone, billing address |
| End-user data | Website visitors and customers of the Controller | Email addresses, names, form submissions stored in hosted databases |
| Technical data | All users | IP addresses, access logs, error logs |
| Email content | Email account holders | Emails stored on Hoststack mail servers |
| File data | Controller and their end-users | Files, images, media uploaded to hosting accounts |
6. Controller and Processor Obligations
Hoststack (Processor) shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process the data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures (see Section 8)
- Assist the Controller in responding to data subject rights requests
- Delete or return all personal data upon termination of services (see Section 10)
- Provide all information necessary to demonstrate compliance with this DPA and GDPR Article 28
- Notify the Controller of any data breach without undue delay (see Section 9)
The Controller shall:
- Ensure it has a lawful basis for processing before instructing Hoststack to process personal data
- Provide clear and accurate instructions for processing activities
- Ensure that data subjects are informed about processing through the Controller's own privacy notices
- Comply with applicable data protection laws in respect of data the Controller uploads or processes through our infrastructure
7. Sub-Processors
Hoststack engages the following categories of sub-processors. By entering into this DPA, the Controller provides general authorisation for Hoststack to engage sub-processors within these categories. Hoststack will provide notice of any intended change to sub-processors via email or our website, giving the Controller an opportunity to object.
Data Centre & Cloud Infrastructure
Physical and virtual infrastructure providers located in India where customer data is hosted and processed.
Payment Processors
PCI-DSS compliant payment gateway providers used for billing (e.g. Razorpay, PayU). Payment data is processed under their own DPA.
Email Delivery Services
Transactional email providers used to send service notifications and billing emails.
Customer Support Platforms
Ticketing and live chat systems used to manage and respond to support requests.
Analytics Providers
Website analytics tools used in anonymised, aggregated form to improve service quality.
8. Security Measures
In accordance with GDPR Article 32, Hoststack implements the following technical and organisational security measures:
Encryption in Transit
All connections secured via TLS 1.2/1.3. HTTPS enforced across all customer-facing and administrative interfaces.
Encryption at Rest
Sensitive account data and credentials encrypted at rest using industry-standard encryption.
Access Control
Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication for all administrative access.
Network Security
Enterprise-grade firewall protection, DDoS mitigation, intrusion detection and prevention systems.
Physical Security
Data centres with restricted physical access, CCTV surveillance, and environmental controls.
Vulnerability Management
Regular security assessments, patch management processes, and vulnerability scanning of infrastructure.
Incident Response
Defined incident response procedures with documented escalation paths and breach notification protocols.
Staff Training
Data protection training for all staff with access to personal data.
9. Data Breach Notification
In the event of a data breach affecting personal data processed under this DPA, Hoststack shall:
- Notify the Controller within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33(2)
- Provide the Controller with information regarding: the nature of the breach; approximate number of data subjects affected; categories and approximate number of records affected; likely consequences of the breach; measures taken or proposed to address the breach
- Assist the Controller in meeting its own notification obligations to supervisory authorities and data subjects under GDPR Articles 33 and 34
- Preserve evidence relating to the breach for investigation purposes
Breach notifications should be directed to the email address associated with the Customer's Hoststack account. Please ensure your contact details are kept up to date in the client area.
10. Deletion on Termination
Upon termination or expiry of the service agreement, or upon written request by the Controller, Hoststack shall:
- Delete all personal data held on behalf of the Controller within 30 days of termination, subject to any legal retention obligations
- Provide written confirmation of deletion upon request
- Where return of data is requested before termination, export it in a standard format (SQL dump, file archive) at no additional charge within 5 business days
Note that certain data may be retained beyond this period where required by law (e.g., billing records for tax compliance), in which case Hoststack will limit processing to the minimum necessary to fulfil the legal obligation.
11. Requesting a Signed DPA
Business customers requiring a countersigned DPA for their own compliance purposes (e.g., for GDPR accountability or enterprise procurement requirements) may request one. We support customised DPA schedules on request.
Request a Countersigned DPA
Email us with your company name, account email, and any specific schedule requirements.
[email protected]Typical turnaround: 5 business days. We cover EU SCCs and UK IDTA schedules.
Related Legal Documents