Data Processing Agreement (DPA)
Last updated: 4 October 2026
This English version is provided for convenience. In case of doubt, the German version prevails.
between the customer (controller, hereinafter "client")
and
Lars Eppendahl, trading as CheapTopHost, Wasserstr. 496 (Bürocenter am Schlosspark), 44795 Bochum, Germany (processor, hereinafter "contractor")
1. Conclusion and subject matter
- This Data Processing Agreement (DPA) sets out the data protection obligations of the parties under Art. 28 GDPR. It is concluded upon acceptance of the terms and conditions and applies to all contracts between the parties under which the contractor processes personal data on behalf of the client. A separate signature is not required; on request we provide a countersigned version.
- The subject matter is the provision of hosting services (web hosting, managed cloud servers, email services, storage and databases), in the course of which the contractor may gain access to personal data stored by the client.
- For the client's own data (customer account, billing), the contractor is a controller in its own right; the Privacy Policy applies in this respect.
2. Duration
The term of this DPA follows the term of the respective main contract. It ends automatically when the last main contract ends, but continues to apply for as long as the contractor still processes personal data of the client.
3. Nature and purpose of processing
- Nature of processing: storing, holding, transmitting (delivering to website visitors and email recipients), backing up, restoring and deleting data, as well as technical maintenance and troubleshooting.
- Purpose: providing the hosting services booked by the client and support. The contractor does not process the data for its own purposes.
4. Categories of data and data subjects
- Data categories: all data the client stores or has processed on the systems, in particular website and database content, emails and mailbox content, form submissions, order and customer data of online shops, user accounts, log data (e.g. IP addresses in access and error logs).
- Special categories of personal data (Art. 9 GDPR) are only processed if the client stores them; the client is then responsible for their lawfulness and appropriate safeguards.
- Data subjects: visitors and users of the client's websites, the client's customers, prospects, employees, email correspondents and other persons whose data the client processes.
5. Instructions
- The contractor processes personal data only on documented instructions from the client, unless required to do so by Union or Member State law; in that case the contractor informs the client of that legal requirement before processing, unless the law prohibits this.
- Instructions result from the main contract, this DPA and the settings the client makes in the control panel. The client issues further instructions in text form.
- If the contractor considers that an instruction infringes data protection law, it informs the client without delay.
6. Obligations of the contractor
- The contractor ensures that persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.
- It takes the technical and organisational measures required under Art. 32 GDPR (section 7).
- Within its capabilities, it assists the client in responding to requests from data subjects (Art. 12–22 GDPR), in particular through the tools provided in the control panel for viewing, exporting and deleting data.
- It assists the client in complying with the obligations under Art. 32–36 GDPR (security, notification of personal data breaches, data protection impact assessment, prior consultation), taking into account the nature of processing and the information available to it.
- It informs the client without undue delay after becoming aware of a personal data breach affecting the client's data and provides the information required for a notification.
- For assistance going beyond the provision of the tools, the contractor may charge reasonable remuneration, unless the assistance is due to a breach by the contractor.
7. Technical and organisational measures (summary)
The contractor and its sub-processor implement the following measures in particular:
- Physical access control: servers operated in professional data centers with access control systems, video surveillance and security staff.
- System and data access control: password-protected, personal accounts; permissions based on need; separation of customer accounts; encrypted connections (SSH, SFTP, HTTPS/TLS) for administrative access.
- Transfer control: transport encryption (TLS) for website and email connections; free SSL certificates for customer domains.
- Input control: logging of administrative access and changes.
- Availability control: redundant infrastructure, uninterruptible power supply, DDoS protection, malware scans, firewall and bot protection; daily backups with defined retention where premium backups are booked.
- Separation control: logical separation of different customers' data.
- Review: regular system updates (security patches) and review of the effectiveness of the measures.
The contractor may adapt the measures to the state of the art provided the level of protection is not reduced. A detailed description is available on request.
8. Sub-processors
- The client grants general authorisation for the use of sub-processors.
- The contractor currently uses an infrastructure partner based in the United Kingdom that provides the servers and data centers. Depending on the client's choice, processing takes place in data centers in the United Kingdom or the United States. A current list of sub-processors with name and address is available on request by email to support@cheaptophost.com.
- The contractor informs the client in advance in text form of any intended changes (addition or replacement). The client may object to the change within 30 days for an important data protection reason. If the parties cannot agree, the client may terminate the affected services for good cause.
- The contractor contractually imposes on each sub-processor data protection obligations equivalent to those in this DPA.
- Third-country transfers: An adequacy decision exists for the United Kingdom (Art. 45 GDPR). For processing in the United States, the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR) have been agreed.
9. Rights and obligations of the client
- The client is responsible for the lawfulness of processing and for safeguarding the rights of data subjects.
- The client informs the contractor without delay if it detects errors or irregularities in the processing.
10. Audits and evidence
- The contractor makes available to the client all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR. Evidence may be provided in particular through current certificates, audit reports or confirmations from the sub-processor.
- The client may carry out audits, including inspections, itself or through an auditor bound to confidentiality. Inspections must be announced with reasonable notice (usually at least 30 days), carried out during normal business hours and must not disrupt operations disproportionately. As the contractor does not operate its own data centers, audits of the data centers are generally carried out by presenting the sub-processor's evidence.
- The contractor may charge reasonable remuneration for on-site inspections unless a data protection breach by the contractor is found.
11. Deletion and return
- After the main contract ends, the contractor deletes all personal data of the client unless there is a legal obligation to retain it. Backup copies are overwritten within 60 days as part of the regular backup rotation.
- The client can export its data at any time until the end of the contract via the control panel, FTP/SFTP or SSH. Return by the contractor in any other form requires a separate agreement.
12. Liability and final provisions
- Liability is governed by Art. 82 GDPR. Otherwise, the liability provisions of the terms apply.
- In the event of conflicts between this DPA and the main contract, the provisions of this DPA prevail with regard to data protection.
- German law applies. The final provisions of the terms apply in addition.