Skip to main content
.com domains from $2.99 — WHOIS privacy at no extra charge

Data Processing Addendum

Revised July 30, 2026

Who this addendum covers

Host a site, store or mailbox with us that holds personal data about your own customers, members or users, and UK and EU data protection law makes you the controller of that data and us your processor. This addendum sets out the terms Article 28 of the UK and EU GDPR requires for that relationship.

It forms part of our terms of service and applies automatically — nothing needs signing for you to rely on it. If your organisation wants a countersigned copy for its own files, email info@hosting-seller.com and we will arrange it.

Data we hold about you as our customer — your account, billing and support records — is a different matter. There we are the controller, and our privacy policy governs it instead.

1. Subject matter and duration

Personal data inside your hosted content is processed for one reason: to provide the hosting, email, domain and support services you ordered. Processing runs for as long as your service is active, plus the short backup-retention period described in section 8.

2. Nature and purpose of processing

Storing, hosting, transmitting, backing up and restoring your content; running the servers, network and mail systems it sits on; and giving technical support when you ask for it.

3. Types of data and categories of data subject

You decide both, because you decide what goes on the platform. In practice that usually means the names, email addresses, contact details, order records and message content of your website visitors, customers or members.

The platform is not built for special-category data — health, biometric, political, religious and the like — nor for criminal-offence data. If that is your intended use, say so before you buy and we will give you a straight answer on whether we are the right shop for it.

4. What we undertake to do

  • We process personal data only on your documented instructions, your ordinary use of the platform included, unless the law requires otherwise — and then we tell you first, unless we are barred from doing so.
  • Everyone with access is under a duty of confidence, and access is limited to the people who need it to run the platform or answer your support requests.
  • We keep appropriate technical and organisational security measures in place; section 5 describes them.
  • We help you, so far as is reasonable, with data-subject requests, security-incident notification and any data protection impact assessment you carry out.
  • We notify you without undue delay once we become aware of a personal data breach affecting your data, with the detail you need to meet your own notification duties.

5. Security measures

Free auto-renewing TLS certificates, so traffic is encrypted in transit; account isolation on shared infrastructure; a web application firewall with network-level DDoS mitigation; Imunify360 malware scanning; daily automatic backups you can restore yourself; brute-force protection and optional two-factor authentication on your account; and platform software kept patched and current. Our security page lays all of it out, including a frank account of what stays your responsibility.

6. Sub-processors

You give general authorisation for us to engage the sub-processors listed in section 5 of our privacy policy, which we keep up to date. Each one is bound by data protection terms no less protective than those in this addendum.

Before we add or swap a sub-processor that handles your hosted content, you get reasonable notice. Object on reasonable data protection grounds and we will look for an alternative with you; if none is workable, you may terminate the affected service and take a pro-rata refund of any prepaid, unused fees.

7. International transfers

Your hosted content sits in a London datacentre. Where a transfer outside the UK or EEA happens through the sub-processors above, it rests on an appropriate safeguard — a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses.

8. Deletion and return

Export or delete your content yourself at any time from the control panel. On termination we remove it from active systems, and it ages out of backups within the normal backup-retention cycle. Need a final export before that happens? Ask before you cancel and we will help.

9. Audit and information

We will supply the information reasonably necessary to demonstrate compliance with this addendum, and answer reasonable written questions about our processing.

Plainly, on the question of our size: we are a small company, and we do not currently hold ISO 27001 or SOC 2 certification, so those reports are not ours to give. Where your own compliance programme strictly requires a certified processor, better you hear it now than after you have bought.

10. Liability and precedence

Liability under this addendum runs subject to the limitations in our terms of service. Where the two conflict on a data protection point, this addendum takes precedence. It is governed by the law of England and Wales.

Getting in touch

Data protection questions, sub-processor queries or a request for a countersigned copy: email info@hosting-seller.comwith “DPA” in the subject line.