📄 GDPR Article 28 Compliant

Data Processing Agreement

A legally binding agreement between HostStack (Processor) and business customers (Controller), ensuring your users' data is handled in full compliance with GDPR Article 28.

✔ GDPR Art. 28 ✔ Standard Contractual Clauses ✔ UK GDPR

📩 Request Your DPA

We can issue a signed DPA for your business within 3 business days. Send an email to our privacy team with your company details.

✉ Email DPA Request

This page is the operative Data Processing Agreement for HostStack services. By using HostStack's hosting services as a business, you agree to the terms below, which govern how HostStack processes personal data on your behalf. For individual/consumer users, see our Privacy Policy and GDPR Statement.

1. Parties & Context

PartyDetails
Data Controller ("you")The legal entity or individual that has entered into a Service Agreement with HostStack and determines the purposes and means of processing personal data.
Data Processor ("HostStack")HostStack, operating from Bramapur Nath Para, Kolkata 700084, West Bengal, India. Email: [email protected]

This Data Processing Agreement ("DPA") supplements and forms part of HostStack's Terms of Service. In the event of any conflict, this DPA prevails with respect to data protection matters.

2. Scope of Processing

ItemDetail
Subject matterProvision of web hosting, email hosting, VPS, and related services
DurationFor the term of the Service Agreement, plus 90 days for data return/deletion
Nature of processingStorage, transmission, backup, and retrieval of data on hosted infrastructure
PurposeTo deliver the hosting services subscribed to by the Controller
Data typesAny personal data the Controller stores on HostStack's servers (e.g., website visitor data, customer databases, email correspondence)
Data subjectsThe Controller's end-users, customers, employees, or any individuals whose data is stored on HostStack infrastructure

3. HostStack's Obligations as Processor

HostStack shall:

4. Controller's Obligations

The Controller shall:

5. International Data Transfers

HostStack's primary data centre is in India, which the European Commission has not recognised as providing an adequate level of data protection. To ensure your data is lawfully transferred and processed, we rely on:

By signing or accepting this DPA, the Controller and HostStack agree to be bound by the SCCs/IDTA as set out above. HostStack completes Annex I (description of processing) and Annex II (technical/organisational measures) as detailed in Sections 2 and 6 of this DPA.

6. Technical & Organisational Measures (TOMs)

HostStack implements the following measures to protect personal data:

AreaMeasures
Encryption in transitTLS 1.2+ for all connections; free SSL certificates on all hosted domains
Encryption at restAES-256 encryption on storage volumes
Access controlPrinciple of least privilege; MFA on all admin systems; role-based access
BackupDaily automated backups; 30-day retention; off-site copies
Network securityDDoS protection (Imunify360), firewall, intrusion detection
Physical securityData centre physical access controls; 24/7 CCTV; biometric entry
Incident response72-hour breach notification; incident response plan; post-incident review
Staff trainingRegular data protection training for all staff with access to personal data

7. Authorised Sub-Processors

The Controller provides general authorisation for HostStack to engage the following sub-processors. HostStack will notify the Controller of any changes (additions or replacements) with 14 days' notice, giving the Controller opportunity to object.

Sub-processorPurposeLocationSafeguard
Razorpay Payment processing India Indian law applicable
Stripe International payments USA SCCs + DPA
PayPal International payments USA SCCs + DPA
Cloudflare DDoS / CDN USA SCCs + DPA
Google LLC Analytics (opt-in) USA SCCs + DPA
Tawk.to Live chat USA GDPR DPA
WHMCS Billing system India Indian law applicable

8. Data Breach Notification

In the event that HostStack becomes aware of a confirmed personal data breach affecting Controller's data, HostStack will:

For urgent security matters: [email protected] (Subject: "Security Incident")

9. Data Return & Deletion

Upon termination or expiry of the service agreement, HostStack will, at the Controller's written request:

Note: Billing records are retained for 7 years as required by Indian tax law. Anonymised usage statistics may be retained indefinitely.

10. Governing Law & Disputes

This DPA is governed by the laws of India (primarily IT Act 2000, IT Rules 2011, and DPDP Act 2023). However, where the processing involves EU/EEA personal data, the Standard Contractual Clauses referred to in Section 5 are also binding and take precedence over Indian law to the extent required by GDPR.

Disputes arising from this DPA shall first be attempted to be resolved by good-faith negotiation between the parties. If unresolved within 30 days, disputes shall be submitted to binding arbitration under the Arbitration and Conciliation Act 1996 of India.

Get Your Signed DPA

Email us with your company name, registration number, and HostStack account email. We'll issue a signed DPA within 3 business days.

✉ Request DPA via Email

Response within 3 business days · Free for all business customers

From ₹149/mo • Shared • Cloud • VPS

✔ 30-day money-back • Free migration

See plans
WhatsApp Support