How WebOps Hosting processes personal data on your behalf, including security measures, sub-processors, and your rights as a data controller.
Document Purpose
This Data Processing Addendum ("DPA") establishes the legal framework and obligations concerning the processing of Personal Data between WebOps Hosting and its customers, ensuring full compliance with prevailing data protection regulations including the GDPR and CCPA.
1. Introduction
This Data Processing Addendum is an addendum to the main Agreement between Ryan Davis LLC, operating as WebOps Hosting (acting as the Data Processor), and the customer (acting as the Data Controller). This DPA applies exclusively to the extent that WebOps processes Personal Data on behalf of the Controller in the course of providing its services.
By engaging WebOps Hosting for services, you agree to be bound by the terms detailed in this DPA.
2. Definitions
For the purposes of this Data Processing Addendum, the following terms shall have the specified meanings:
- Data Subject: An identified or identifiable natural person whose personal data is being processed.
- Personal Data: Any information relating to a Data Subject, including but not limited to names, email addresses, IP addresses, location data, or online identifiers.
- Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processor: WebOps Hosting, processing personal data on behalf of the Controller.
- Processing: Any operation or set of operations performed on Personal Data, whether or not by automated means.
3. Categories of Data Subjects
The processing of Personal Data under this DPA generally concerns the following categories of Data Subjects:
- Customers and clients of the Controller.
- Employees, contractors, agents, and representatives of the Controller.
- Visitors navigating the Controller's websites hosted on our infrastructure.
- End-users of services provided by the Controller.
4. Types of Personal Data
The Personal Data processed on behalf of the Controller may encompass, but is not limited to, the following types:
- Contact Information: Names, postal addresses, email addresses, and telephone numbers.
- Account Data: Usernames, passwords, and account preferences.
- Payment & Transaction Data: Billing details, purchase history, and subscription information (processed securely through compliance gateways).
- Online Identifiers: IP addresses, browser types, device information, and cookie data.
- Communication Data: Content of emails (when utilizing our email hosting services) and support ticketing details.
- Usage Data: Server logs, application telemetry, and performance metrics generated during the use of our hosting infrastructure.
5. Purposes of Data Processing
WebOps Hosting processes Personal Data solely for the following objective purposes:
- Providing, managing, and maintaining our web hosting, VPS, and email hosting services.
- Delivering technical customer support and resolving infrastructure issues.
- Ensuring the security, stability, and integrity of our networks and servers.
- Conducting necessary usage analysis to optimize performance and prevent abuse.
- Complying with applicable legal and regulatory obligations.
6. Security Measures
We implement robust technical and organizational measures to safeguard Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Access Control: Restricting access to Personal Data solely to authorized personnel requiring such access to perform their duties.
- Encryption: Utilizing industry-standard encryption protocols for data in transit (TLS) and data at rest on our secure storage arrays.
- Data Minimization: Limiting the collection and retention of data to what is strictly necessary for service provision.
- Regular Audits: Conducting periodic security assessments and vulnerability scans of our infrastructure.
- Incident Response Plan: Maintaining an active protocol to swiftly identify, mitigate, and report any data breaches or security incidents.
7. Use of Sub-processors
The Controller grants WebOps Hosting general authorization to engage sub-processors to assist in delivering our services. We maintain a current list of our sub-processors, accessible at our designated Sub-processors page.
WebOps Hosting ensures that all engaged sub-processors are bound by written agreements imposing data protection obligations that are at least as stringent as those set forth in this DPA.
8. Rights and Obligations of Controller
As the Controller of the Personal Data, you possess specific rights and bear essential obligations:
- The Controller retains full rights and ultimate control over the Personal Data hosted on WebOps infrastructure.
- The Controller must ensure that all Personal Data provided for processing is collected and processed in strict compliance with applicable data protection laws.
- The Controller is responsible for providing lawful, documented instructions regarding the processing of Personal Data to WebOps Hosting.
- The Controller is solely responsible for determining the legal basis for processing operations.
9. Data Subject Rights
WebOps Hosting, considering the nature of the processing, will assist the Controller through appropriate technical and organizational measures in fulfilling the Controller's obligations to respond to requests from Data Subjects exercising their rights. This includes, but is not limited to, requests for:
- Data access and portability.
- Correction or rectification of inaccurate data.
- Erasure or deletion of data ("Right to be Forgotten").
- Restriction or objection to processing activities.
If WebOps receives a direct request from a Data Subject, we will promptly forward the request to the Controller without responding directly to the Data Subject, unless legally required.
10. International Data Transfers
Any transfer of Personal Data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries outside these regions will be conducted in strict compliance with applicable data protection laws.
Where required, such transfers are safeguarded through the execution of Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an adequate level of data protection equivalent to domestic standards.
11. Termination and Deletion
Upon the termination or expiration of the main Agreement or the cessation of services, WebOps Hosting shall, at the choice of the Controller, securely return or permanently delete all corresponding Personal Data from its systems.
Deletion will be carried out within a standard commercial timeframe, provided that WebOps is not required by applicable law, regulation, or legally binding order to retain specific Personal Data.
12. Governing Law
This Data Processing Addendum and any disputes arising out of or in connection with it shall be governed by and construed in accordance with the laws of the State of Delaware, without giving effect to any principles of conflicts of law.
Privacy & Legal Contact
If you have any questions, concerns, or require assistance regarding this Data Processing Addendum or your data protection obligations, please reach out to our dedicated legal team.
- Email: legal[at]webops.host
- Support: Via the secure Client Portal
- Hours: 9:00 AM - 5:00 PM (7 Days a week) • 24/7 for critical security emergencies