Data Processing Addendum
Revised July 30, 2026
Who this addendum covers
Run a website, shop or mailbox on our platform that carries personal data about your own customers, members or ordinary visitors, and under UK and EU data protection law you become the controller of all that data, and leaves us your processor. What follows is the addendum that puts down the terms Article 28 of the UK and EU GDPR demands for that particular relationship.
It forms part of our terms of service and it applies on its own; no signature is needed anywhere before you can rely on it. Should your organisation want a countersigned copy for its own paper records, email info@hosting-seller.com and we will arrange it.
Data we hold about you as our customer, meaning your account details, billing and support records, is a wholly separate matter. On that data we act as the controller, and our privacy policy governs it instead.
1. Subject matter and duration
One reason only explains why we touch the personal data sitting inside your hosted content: to deliver the hosting, email, domain and support services you ordered. That processing carries on for as long as your service stays active, and then for the short backup-retention window set out in section 8.
2. What the processing involves and why
Holding, hosting, transmitting, backing up and restoring whatever you put on the platform; keeping the servers, network and mail systems underneath it running; answering technical support requests whenever you raise one.
3. Kinds of data, and the categories of data subject
Both are your call, since you choose whatever gets uploaded. Most of the time it comes down to names, email addresses, contact particulars, order histories and the wording of messages left behind by people visiting your website, your customers or your members.
The platform is not built for special-category data (health, biometric, political, religious and the rest of that list), nor for criminal-offence data. If that is what you have in mind, tell us before you pay for anything, and you will get a straight answer about whether this is the right shop for that particular job.
4. What we commit ourselves to
- Personal data gets processed only on your documented instructions, and your everyday use of the platform counts as such an instruction. Where the law compels something else, we say so beforehand, unless we are expressly forbidden from telling you first.
- A duty of confidence binds everyone who can reach the data, and the reach itself stops at the people required to keep the platform running or to answer the support tickets you send in.
- Appropriate technical and organisational security measures stay in place throughout; section 5 spells out what they are.
- So far as is reasonable, we assist with data-subject requests, with notifying a security incident, and with any data protection impact assessment your organisation happens to carry out.
- We notify you without undue delay once a personal data breach touching your data comes to our attention, together with the detail your own notification duties will require you to have on hand.
5. Security measures
TLS certificates at no charge that renew themselves, so traffic travels encrypted; isolation between accounts living on shared infrastructure; a web application firewall carrying network-level DDoS mitigation; Imunify360 malware scanning; daily backups taken without prompting that you can restore on your own; brute-force protection plus optional two-factor authentication on the account itself; and platform software kept patched and reasonably current. Our security page sets the whole lot out, including a blunt description of the parts that remain yours to handle.
6. Sub-processors
You give us general authorisation to engage whichever sub-processors happen to be listed in section 5 of our privacy policy, kept current as things change. Every one of them is tied to data protection terms at least as protective as the ones written here.
Adding a sub-processor that handles your hosted content, or swapping one out, means reasonable notice to you first. Raise an objection on sensible data protection grounds and we will hunt for an alternative alongside you. If nothing workable turns up, you can end the affected service and claim a pro-rata refund on any prepaid fees you have not yet used.
7. International transfers
Content you host with us sits inside a London datacentre. Should any personal data move beyond the borders of the UK or EEA through one of the sub-processors named above, an appropriate safeguard has to carry it across: a UK adequacy decision, the UK International Data Transfer Agreement or its Addendum, or the European Commission's own Standard Contractual Clauses.
8. Deletion and return
From the control panel you can export or delete your content whenever you like. Once a service terminates, we take it off the active systems, and it ages out of the backups within the usual backup-retention cycle. Want one last export before that point? Ask us before you cancel and we will help you get it done.
9. Audit and information
Whatever information is reasonably necessary to demonstrate compliance with this addendum, we will supply, and reasonable written questions about our processing will receive an answer.
On the question of size, without dressing it up: this is a small company, and it holds neither ISO 27001 nor SOC 2 certification at present, so those reports are simply not ours to hand over. If your own compliance programme insists on a certified processor, far better that you learn it here than once the money has already changed hands.
10. Liability and precedence
Any liability arising under this addendum remains subject to the limits set in our terms of service. Should the two disagree on anything touching data protection, what is written here carries the day. The law of England and Wales governs this addendum.
Getting in touch
Questions on data protection, queries about a sub-processor, or a request for a countersigned copy: email info@hosting-seller.com and put “DPA” somewhere in the subject line.