Data Processing Addendum
Revised July 30, 2026
Who this addendum covers
If you host a site, store or mailbox with us that contains personal data about your own customers, members or users, UK and EU data protection law makes you the controller of that data and us your processor. This addendum sets out the terms Article 28 of the UK and EU GDPR requires for that relationship.
It forms part of our terms of service and applies automatically — no signature is needed for you to rely on it. If your organisation requires a countersigned copy for its own records, email info@hostingfastnet.com and we will arrange one.
Data we hold about you as our customer — your account, billing and support records — is treated separately. For that data we are the controller, and our privacy policy applies instead.
1. Subject matter and duration
Personal data within your hosted content is processed for a single purpose: delivering the hosting, email, domain and support services you ordered. Processing continues for as long as your service remains active, plus the short backup-retention period described in section 8.
2. Nature and purpose of processing
Storing, hosting, transmitting, backing up and restoring your content; operating the servers, network and mail systems that carry it; and providing technical support when you request it.
3. Types of data and categories of data subject
Both are determined by you, because you decide what is placed on the platform. In practice this usually means the names, email addresses, contact details, order records and message content of your website visitors, customers or members.
The platform is not designed for special-category data — health, biometric, political, religious and similar — nor for criminal-offence data. If that is your intended use, tell us before you buy and we will give you a clear answer on whether the platform is suitable for it.
4. Our obligations to you
- We process personal data only on your documented instructions, which include your ordinary use of the platform, unless the law requires otherwise — in which case we inform you first, unless we are legally prevented from doing so.
- Everyone with access is bound by a duty of confidentiality, and access is restricted to the people who need it to operate the platform or respond to your support requests.
- We maintain appropriate technical and organisational security measures; section 5 describes them.
- We assist you, so far as is reasonable, with data-subject requests, security-incident notification and any data protection impact assessment you undertake.
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, providing the detail you need to satisfy your own notification obligations.
5. Security measures
Free auto-renewing TLS certificates, encrypting traffic in transit; account isolation on shared infrastructure; a web application firewall backed by network-level DDoS mitigation; Imunify360 malware scanning; daily automatic backups you can restore yourself; brute-force protection and optional two-factor authentication on your account; and platform software kept patched and up to date. Our security page describes all of it, including an honest statement of what remains your responsibility.
6. Sub-processors
You grant general authorisation for us to engage the sub-processors listed in section 5 of our privacy policy, a list we keep current. Each one is bound by data protection terms at least as protective as those in this addendum.
You receive reasonable advance notice before we add or replace a sub-processor that handles your hosted content. If you object on reasonable data protection grounds, we will work with you to find an alternative; where none is workable, you may terminate the affected service and receive a pro-rata refund of any prepaid, unused fees.
7. International transfers
Your hosted content is stored in a London datacentre. Where a transfer outside the UK or EEA occurs through the sub-processors above, it is covered by an appropriate safeguard — a UK adequacy decision, the UK International Data Transfer Agreement or Addendum, or the European Commission's Standard Contractual Clauses.
8. Deletion and return
You can export or delete your content yourself at any time through the control panel. On termination we delete it from active systems, and it expires from backups within the normal backup-retention cycle. If you need a final export before that happens, ask before you cancel and we will assist.
9. Audit and information
We will provide the information reasonably necessary to demonstrate compliance with this addendum, and will answer reasonable written questions about our processing.
To be plain about our size: we are a small company, and we do not currently hold ISO 27001 or SOC 2 certification, so those reports are not ours to supply. If your compliance programme strictly requires a certified processor, it is better you know that now than after you have bought.
10. Liability and precedence
Liability under this addendum is subject to the limitations set out in our terms of service. Where the two documents conflict on a data protection point, this addendum prevails. It is governed by the law of England and Wales.
Getting in touch
For data protection questions, sub-processor queries or a request for a countersigned copy, email info@hostingfastnet.com with “DPA” in the subject line.