Data Processing Agreement (DPA)
Data Processing Agreement (DPA)
This Data Processing Agreement (“DPA“) forms part of the Terms of Service between VeerHost (“Processor“, “we“, “our“, or “us“) and the customer purchasing or using VeerHost services (“Controller“, “Customer“, or “you“).
This DPA governs the processing of Personal Data by VeerHost on behalf of the Customer in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR where applicable, and other applicable data protection laws.
By using VeerHost services, the Customer agrees to the terms of this DPA.
1. Purpose
The purpose of this DPA is to define the obligations and responsibilities of both parties regarding the processing of Personal Data while VeerHost provides hosting and related services.
This Agreement applies whenever VeerHost processes Personal Data on behalf of a Customer in connection with:
Shared Hosting
WordPress Hosting
VPS Hosting
Cloud Hosting
Reseller Hosting
Domain-related services
Email hosting
Backup services
Website migration services
Technical support
Any additional services where Personal Data is processed on behalf of the Customer.
2. Definitions
For the purposes of this Agreement:
Personal Data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on Personal Data including collection, storage, organization, transmission, retrieval, deletion, or destruction.
Controller means the Customer who determines the purposes and means of processing Personal Data.
Processor means VeerHost, acting on behalf of the Controller.
Subprocessor means any third party engaged by VeerHost to process Personal Data in connection with providing the Services.
Applicable Data Protection Law means the GDPR, UK GDPR, and any applicable privacy legislation governing the processing of Personal Data.
3. Scope of Processing
VeerHost processes Personal Data solely for the purpose of providing the Services requested by the Customer.
Processing activities may include:
Hosting websites and applications
Storing databases
Delivering email services
Maintaining server infrastructure
Creating backups
Restoring customer data
Monitoring system performance
Providing technical support
Troubleshooting service issues
Maintaining platform security
Detecting abuse, fraud, or malicious activity
VeerHost does not determine the purposes for which Customer Personal Data is collected or used. Those decisions remain solely with the Customer.
4. Categories of Data
Depending on how the Services are used, Personal Data processed by VeerHost may include:
Names
Email addresses
Phone numbers
Postal addresses
IP addresses
User account information
Website content
Uploaded files
Databases
Authentication records
Application logs
Customer support communications
Business records
Customer-generated content
The exact categories of Personal Data processed are determined by the Customer.
5. Categories of Data Subjects
Data subjects may include:
Website visitors
Customers
Employees
Contractors
Subscribers
Business contacts
End users
Members
Clients of the Customer
Other individuals whose Personal Data is submitted to the Services by the Customer.
6. Instructions from the Customer
VeerHost shall process Personal Data only on documented instructions from the Customer unless required to do otherwise by applicable law.
The Customer is responsible for ensuring that all Personal Data submitted to VeerHost has been collected and processed lawfully.
The Customer remains responsible for determining:
The legal basis for processing
Data retention periods
Privacy notices
Cookie compliance
Responding to data subject requests
Compliance with applicable privacy laws
7. Confidentiality
VeerHost ensures that all personnel authorized to process Personal Data are bound by confidentiality obligations.
Access to Personal Data is limited strictly to personnel who require access to perform their assigned duties.
VeerHost maintains internal policies governing:
Employee confidentiality
Access management
Security awareness
Information handling
Incident reporting
8. Security Measures
VeerHost implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
These measures include, where applicable:
Encryption of data in transit using modern TLS protocols
Encrypted administrative connections
Network firewalls
DDoS mitigation
Infrastructure monitoring
Intrusion detection and prevention measures
Malware detection
Server hardening
Access control based on the principle of least privilege
Strong authentication mechanisms
Security logging
Vulnerability management
Timely security updates
Backup procedures
Disaster recovery planning
Physical security controls provided by data center operators
VeerHost regularly reviews and improves its security practices to address evolving threats and industry best practices.
9. Subprocessors
The Customer authorizes VeerHost to engage carefully selected Subprocessors where necessary to deliver the Services.
Subprocessors may include providers of:
Cloud infrastructure
Data center facilities
Payment processing
Email delivery
Domain registration
DNS services
Monitoring and observability
Security services
Customer support platforms
VeerHost requires its Subprocessors to maintain appropriate security measures and contractual obligations consistent with applicable data protection laws.
VeerHost remains responsible for the performance of its Subprocessors in accordance with applicable law.
10. International Data Transfers
VeerHost operates infrastructure in multiple geographic regions.
Where Personal Data is transferred outside the European Economic Area (EEA), the United Kingdom, or Switzerland, VeerHost implements appropriate safeguards as required by applicable data protection law.
Such safeguards may include:
Standard Contractual Clauses (SCCs)
Adequacy decisions issued by competent authorities
Other legally recognized transfer mechanisms
11. Assistance with Data Subject Requests
Where technically feasible, VeerHost shall assist the Customer in responding to requests from data subjects, including requests relating to:
Access
Rectification
Erasure
Restriction of processing
Data portability
Objection to processing
The Customer remains responsible for determining whether such requests should be fulfilled.
12. Security Incident and Breach Notification
VeerHost maintains documented procedures for identifying, investigating, and responding to security incidents.
Where VeerHost becomes aware of a Personal Data Breach affecting Customer Personal Data, VeerHost shall notify the Customer without undue delay after confirming the breach and gathering sufficient information to provide a meaningful notification.
Where possible, the notification will include:
Nature of the incident
Categories of affected data
Likely consequences
Measures taken or proposed
Contact information for further communication
13. Assistance with Compliance
Taking into account the nature of the processing and the information available, VeerHost shall provide reasonable assistance to the Customer regarding:
Data protection impact assessments
Security obligations
Breach response
Regulatory compliance
Supervisory authority inquiries
14. Audit Rights
Where required by applicable law, the Customer may request reasonable information demonstrating VeerHost’s compliance with this DPA.
Any audit request must:
Be reasonable in scope
Minimize operational disruption
Protect the confidentiality of other customers
Be subject to appropriate confidentiality obligations
VeerHost may satisfy audit requests through documentation, certifications, questionnaires, or other appropriate evidence where suitable.
15. Data Retention and Deletion
Upon termination of the Services, and subject to applicable law and any agreed retention periods, VeerHost shall delete or return Customer Personal Data where technically feasible and in accordance with its operational procedures.
Certain information may be retained where necessary to:
Comply with legal obligations
Resolve disputes
Enforce contractual rights
Maintain security records
Prevent fraud
16. Customer Responsibilities
The Customer is responsible for:
Ensuring a lawful basis for processing Personal Data.
Providing appropriate privacy notices to data subjects.
Obtaining any required consents.
Configuring and using the Services in a compliant manner.
Maintaining the security of Customer credentials.
Managing content uploaded to the Services.
Responding to requests from data subjects.
17. Liability
Each party shall remain responsible for its own compliance with applicable data protection laws.
Nothing in this DPA limits or excludes liability where such limitation is prohibited by applicable law or by the Terms of Service.
18. Governing Agreement
This DPA forms part of the VeerHost Terms of Service.
If there is any conflict between this DPA and the Terms of Service regarding the processing of Personal Data, the provisions of this DPA shall prevail to the extent of that conflict.
19. Changes to This Agreement
VeerHost may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, security practices, or the Services.
Material changes will become effective upon publication or as otherwise communicated to Customers.
20. Contact Information
For questions regarding this Data Processing Agreement or VeerHost’s privacy practices, please contact:
VeerHost
Privacy Team
Email: [email protected]
Support: [email protected]
Website: https://veerhost.com
VeerHost is committed to protecting Personal Data and maintaining compliance with applicable data protection laws while providing secure, reliable, and privacy-focused hosting services.