Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA“) forms part of the Terms of Service between VeerHost (“Processor“, “we“, “our“, or “us“) and the customer purchasing or using VeerHost services (“Controller“, “Customer“, or “you“).

This DPA governs the processing of Personal Data by VeerHost on behalf of the Customer in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR where applicable, and other applicable data protection laws.

By using VeerHost services, the Customer agrees to the terms of this DPA.

1. Purpose

The purpose of this DPA is to define the obligations and responsibilities of both parties regarding the processing of Personal Data while VeerHost provides hosting and related services.

This Agreement applies whenever VeerHost processes Personal Data on behalf of a Customer in connection with:

  • Shared Hosting

  • WordPress Hosting

  • VPS Hosting

  • Cloud Hosting

  • Reseller Hosting

  • Domain-related services

  • Email hosting

  • Backup services

  • Website migration services

  • Technical support

  • Any additional services where Personal Data is processed on behalf of the Customer.

2. Definitions

For the purposes of this Agreement:

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on Personal Data including collection, storage, organization, transmission, retrieval, deletion, or destruction.

Controller means the Customer who determines the purposes and means of processing Personal Data.

Processor means VeerHost, acting on behalf of the Controller.

Subprocessor means any third party engaged by VeerHost to process Personal Data in connection with providing the Services.

Applicable Data Protection Law means the GDPR, UK GDPR, and any applicable privacy legislation governing the processing of Personal Data.

3. Scope of Processing

VeerHost processes Personal Data solely for the purpose of providing the Services requested by the Customer.

Processing activities may include:

  • Hosting websites and applications

  • Storing databases

  • Delivering email services

  • Maintaining server infrastructure

  • Creating backups

  • Restoring customer data

  • Monitoring system performance

  • Providing technical support

  • Troubleshooting service issues

  • Maintaining platform security

  • Detecting abuse, fraud, or malicious activity

VeerHost does not determine the purposes for which Customer Personal Data is collected or used. Those decisions remain solely with the Customer.

4. Categories of Data

Depending on how the Services are used, Personal Data processed by VeerHost may include:

  • Names

  • Email addresses

  • Phone numbers

  • Postal addresses

  • IP addresses

  • User account information

  • Website content

  • Uploaded files

  • Databases

  • Authentication records

  • Application logs

  • Customer support communications

  • Business records

  • Customer-generated content

The exact categories of Personal Data processed are determined by the Customer.

5. Categories of Data Subjects

Data subjects may include:

  • Website visitors

  • Customers

  • Employees

  • Contractors

  • Subscribers

  • Business contacts

  • End users

  • Members

  • Clients of the Customer

  • Other individuals whose Personal Data is submitted to the Services by the Customer.

6. Instructions from the Customer

VeerHost shall process Personal Data only on documented instructions from the Customer unless required to do otherwise by applicable law.

The Customer is responsible for ensuring that all Personal Data submitted to VeerHost has been collected and processed lawfully.

The Customer remains responsible for determining:

  • The legal basis for processing

  • Data retention periods

  • Privacy notices

  • Cookie compliance

  • Responding to data subject requests

  • Compliance with applicable privacy laws

7. Confidentiality

VeerHost ensures that all personnel authorized to process Personal Data are bound by confidentiality obligations.

Access to Personal Data is limited strictly to personnel who require access to perform their assigned duties.

VeerHost maintains internal policies governing:

  • Employee confidentiality

  • Access management

  • Security awareness

  • Information handling

  • Incident reporting

8. Security Measures

VeerHost implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

These measures include, where applicable:

  • Encryption of data in transit using modern TLS protocols

  • Encrypted administrative connections

  • Network firewalls

  • DDoS mitigation

  • Infrastructure monitoring

  • Intrusion detection and prevention measures

  • Malware detection

  • Server hardening

  • Access control based on the principle of least privilege

  • Strong authentication mechanisms

  • Security logging

  • Vulnerability management

  • Timely security updates

  • Backup procedures

  • Disaster recovery planning

  • Physical security controls provided by data center operators

VeerHost regularly reviews and improves its security practices to address evolving threats and industry best practices.

9. Subprocessors

The Customer authorizes VeerHost to engage carefully selected Subprocessors where necessary to deliver the Services.

Subprocessors may include providers of:

  • Cloud infrastructure

  • Data center facilities

  • Payment processing

  • Email delivery

  • Domain registration

  • DNS services

  • Monitoring and observability

  • Security services

  • Customer support platforms

VeerHost requires its Subprocessors to maintain appropriate security measures and contractual obligations consistent with applicable data protection laws.

VeerHost remains responsible for the performance of its Subprocessors in accordance with applicable law.

10. International Data Transfers

VeerHost operates infrastructure in multiple geographic regions.

Where Personal Data is transferred outside the European Economic Area (EEA), the United Kingdom, or Switzerland, VeerHost implements appropriate safeguards as required by applicable data protection law.

Such safeguards may include:

  • Standard Contractual Clauses (SCCs)

  • Adequacy decisions issued by competent authorities

  • Other legally recognized transfer mechanisms

11. Assistance with Data Subject Requests

Where technically feasible, VeerHost shall assist the Customer in responding to requests from data subjects, including requests relating to:

  • Access

  • Rectification

  • Erasure

  • Restriction of processing

  • Data portability

  • Objection to processing

The Customer remains responsible for determining whether such requests should be fulfilled.

12. Security Incident and Breach Notification

VeerHost maintains documented procedures for identifying, investigating, and responding to security incidents.

Where VeerHost becomes aware of a Personal Data Breach affecting Customer Personal Data, VeerHost shall notify the Customer without undue delay after confirming the breach and gathering sufficient information to provide a meaningful notification.

Where possible, the notification will include:

  • Nature of the incident

  • Categories of affected data

  • Likely consequences

  • Measures taken or proposed

  • Contact information for further communication

13. Assistance with Compliance

Taking into account the nature of the processing and the information available, VeerHost shall provide reasonable assistance to the Customer regarding:

  • Data protection impact assessments

  • Security obligations

  • Breach response

  • Regulatory compliance

  • Supervisory authority inquiries

14. Audit Rights

Where required by applicable law, the Customer may request reasonable information demonstrating VeerHost’s compliance with this DPA.

Any audit request must:

  • Be reasonable in scope

  • Minimize operational disruption

  • Protect the confidentiality of other customers

  • Be subject to appropriate confidentiality obligations

VeerHost may satisfy audit requests through documentation, certifications, questionnaires, or other appropriate evidence where suitable.

15. Data Retention and Deletion

Upon termination of the Services, and subject to applicable law and any agreed retention periods, VeerHost shall delete or return Customer Personal Data where technically feasible and in accordance with its operational procedures.

Certain information may be retained where necessary to:

  • Comply with legal obligations

  • Resolve disputes

  • Enforce contractual rights

  • Maintain security records

  • Prevent fraud

16. Customer Responsibilities

The Customer is responsible for:

  • Ensuring a lawful basis for processing Personal Data.

  • Providing appropriate privacy notices to data subjects.

  • Obtaining any required consents.

  • Configuring and using the Services in a compliant manner.

  • Maintaining the security of Customer credentials.

  • Managing content uploaded to the Services.

  • Responding to requests from data subjects.

17. Liability

Each party shall remain responsible for its own compliance with applicable data protection laws.

Nothing in this DPA limits or excludes liability where such limitation is prohibited by applicable law or by the Terms of Service.

18. Governing Agreement

This DPA forms part of the VeerHost Terms of Service.

If there is any conflict between this DPA and the Terms of Service regarding the processing of Personal Data, the provisions of this DPA shall prevail to the extent of that conflict.

19. Changes to This Agreement

VeerHost may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, security practices, or the Services.

Material changes will become effective upon publication or as otherwise communicated to Customers.

20. Contact Information

For questions regarding this Data Processing Agreement or VeerHost’s privacy practices, please contact:

VeerHost

Privacy Team

Email: [email protected]

Support: [email protected]

Website: https://veerhost.com

VeerHost is committed to protecting Personal Data and maintaining compliance with applicable data protection laws while providing secure, reliable, and privacy-focused hosting services.

Launchpad