Customer-site data

Data Processing Addendum.

The commitments and customer-specific schedule that accompany an agreed hosting service.

Published and last updated September 9, 2026 · Version 1.0 · Applies when incorporated into your accepted order

1. Scope and instructions

This Data Processing Addendum is between the customer identified in an accepted service order and iHosting LLC. It applies when that order incorporates this version and iHosting processes personal data for the customer in providing hosting, migration, maintenance and backups. It supplements the service agreement and controls a conflict about that processing. It does not replace a different processing agreement already in force.

The customer acts as controller, or as a processor authorized by its controller to appoint iHosting as a subprocessor. iHosting acts as processor or subprocessor for the instructed work. The Privacy notice separately describes information iHosting handles for its own customer administration, billing and security purposes.

We process the customer data only on documented instructions, including the accepted order and authorized support instructions, unless law requires otherwise. We will inform the customer of a legal requirement before processing unless prohibited, and tell the customer if an instruction appears to infringe applicable data-protection law. The customer is responsible for its collection, legal bases, notices and authority to instruct us.

2. Confidentiality, security and assistance

We restrict access to personnel who need it for the services and are subject to confidentiality obligations. We maintain technical and organizational safeguards appropriate to the risk, including access control, secure transport, site isolation, backup and recovery measures, and the controls in the accepted care schedule. The customer retains responsibility for the access, content, plugins and systems it controls and for coordinating changes with us.

If we become aware of a personal-data breach affecting data processed under this Addendum, we notify the customer without undue delay. As information becomes available, we describe the nature of the breach, affected data and people where known, likely consequences, action taken or proposed, and a contact for follow-up. We cooperate with investigation and mitigation. The customer determines its notices to individuals and regulators; our assistance does not transfer that responsibility.

Taking account of the nature of processing and information available to us, we assist with data-subject requests, security obligations, breach assessments, impact assessments and regulator consultations required by applicable law. We forward relevant requests to the customer rather than disclose its data on an unverified request. We provide information reasonably necessary to demonstrate compliance and allow appropriately scoped audits by the customer or a mandated independent auditor, subject to confidentiality and protection of other customers. We do not use audit arrangements to prevent a right required by law.

3. Subprocessors and international transfers

The order's processing schedule identifies the infrastructure providers authorized for the customer's workload and their functions and locations. Standard care uses Cloudflare for network delivery/security and Backblaze B2 for offsite backups; the origin-hosting supplier and any other customer-specific provider must be identified in that schedule before processing begins. Providers used only for iHosting's own billing or enquiry handling are described separately in the Privacy notice.

The customer gives general written authorization for the subprocessors identified in its schedule. Before adding or replacing a subprocessor that handles customer data, we provide advance notice sufficient for the customer to raise a reasonable data-protection objection. We work to address an objection before that provider handles the affected data, including an alternative arrangement or an orderly end to the affected service if no reasonable solution is available. We impose equivalent data-protection obligations on subprocessors and remain responsible for their performance of those obligations.

Customer data may be processed only in the locations and under the transfer arrangements documented in the schedule. Where applicable law requires safeguards for a restricted international transfer, the parties must establish the appropriate mechanism before that transfer, including the applicable standard contractual clauses or other valid safeguard where needed. This Addendum alone does not execute standard contractual clauses, establish an adequacy decision or treat the customer's use of hosting as transfer consent.

4. Duration, return and deletion

Processing lasts for the agreed service and transition period. At the customer's choice, we return or delete customer personal data when the affected services end, and delete remaining copies unless law requires their retention. The order's schedule identifies the format, export window, cutoff, backup retention and deletion arrangements. We confirm completion on request and explain any legally required retention.

A live-data deletion may remain in an existing backup until that backup expires under the agreed schedule. Such copies remain protected and are used only for necessary recovery or legal retention. If recovery restores data subject to an agreed deletion, we reapply the deletion before returning that data to ordinary use. The customer must preserve any data it needs after the agreed export window.

5. Processing schedule required with your order

The following particulars must be completed in the accepted order or an attached written schedule before customer personal data is processed. They are specific to the customer's site; this public page does not supply a location or deletion period that has not been agreed.

  1. Parties and contacts: customer legal identity, controller/processor role, authorized instructions and privacy/security contacts.
  2. Subject matter and duration: covered sites, hosting and migration scope, maintenance, backups, service term and transition period.
  3. Purpose and operations: storing, transmitting, copying, restoring, troubleshooting, securing and deleting site data as needed for the agreed services.
  4. Data and people: the site's actual data categories, such as visitor/member/customer identifiers, contact details, account and order records and submitted content; categories of people; any sensitive or regulated information requiring special agreement.
  5. Safeguards and providers: applicable care/security schedule, each infrastructure subprocessor and function, processing/backup locations, access arrangements and any required international-transfer mechanism.
  6. Lifecycle and assistance: backup frequency and retention, export format/window, live and backup deletion periods, lawful retention exceptions, request/incident contacts and any separately scoped assistance charges agreed in advance.

Ask hello@ihosting.biz for the schedule for your site or to agree a requirement before work begins. No form submission on this website creates or completes a processing agreement.