Data Processing Agreement

  1. Valid as of 12 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between JustHostMe Limited ("JustHostMe", "we", "us") and the customer identified in the applicable order, account or service agreement ("Customer", "you") where JustHostMe processes Personal Data on the Customer's behalf as a processor.

1. DEFINITIONS AND INTERPRETATION

  1. 1.1 Definitions. In this DPA:
    1. Data Protection Laws means the UK GDPR, the Data Protection Act 2018 and any other applicable law relating to the protection of personal data, as amended or replaced from time to time.
    2. Data Subject means an identified or identifiable natural person whose Personal Data is processed.
    3. Personal Data has the meaning given in applicable Data Protection Laws.
    4. Processing and Process have the meanings given in applicable Data Protection Laws.
    5. Services means the hosting, email, website, backup, domain and related services supplied by JustHostMe under the applicable Agreement, but only to the extent that JustHostMe processes Personal Data on the Customer's behalf.
    6. Sub-processor means another processor appointed by JustHostMe to Process Personal Data on behalf of the Customer in connection with the Services.
  2. 1.2 Order of precedence. If there is a conflict between this DPA and the Terms of Service in relation to the Processing of Personal Data, this DPA will prevail to the extent necessary to comply with applicable Data Protection Laws. All other terms of the Agreement continue to apply.
  3. 1.3 Role of the parties. For the Personal Data covered by this DPA, the Customer is the Controller and JustHostMe is the Processor, except where the parties have separately agreed or applicable law requires a different role for a particular Processing activity.

2. SCOPE, SUBJECT MATTER AND DURATION

  1. 2.1 Scope. This DPA applies only where and to the extent JustHostMe Processes Personal Data on behalf of the Customer in providing the Services.
  2. 2.2 Subject matter. The subject matter of the Processing is the storage, transmission, hosting, backup, security, maintenance, support and other technical Processing of Personal Data necessary to provide the Services requested by the Customer.
  3. 2.3 Duration. Processing will continue for the duration of the relevant Services and any period during which JustHostMe is required or permitted to retain the relevant Personal Data in accordance with the Agreement, applicable law or legitimate technical backup and disaster-recovery processes.
  4. 2.4 Details of Processing. The nature and purpose of the Processing, categories of Personal Data and categories of Data Subjects are described in Schedule 1.

3. CUSTOMER INSTRUCTIONS AND RESPONSIBILITIES

  1. 3.1 Documented instructions. JustHostMe will Process Personal Data only on the Customer's documented instructions, including the instructions contained in the Agreement, this DPA, the Customer's use of the Services and any further written instructions agreed between the parties, unless required to do otherwise by applicable law.
  2. 3.2 Lawful basis. The Customer is responsible for determining the purposes and means of its Processing and for ensuring that it has a lawful basis for its Processing and has provided any required notices to Data Subjects.
  3. 3.3 Instructions and use of Services. The Customer is responsible for ensuring that its use of the Services and its instructions to JustHostMe do not require unlawful Processing. The Customer must not knowingly instruct JustHostMe to Process Personal Data in a manner contrary to applicable Data Protection Laws.
  4. 3.4 Special category and criminal offence data. The Customer remains responsible for ensuring that any Processing of special category data or personal data relating to criminal convictions or offences is lawful and appropriately protected. JustHostMe will apply the security measures described in Schedule 2 to Personal Data without regard to the particular category of Personal Data unless a different level of protection has been agreed.

4. JUSTHOSTME'S OBLIGATIONS

  1. 4.1 Compliance. JustHostMe will comply with its obligations as a Processor under applicable Data Protection Laws in relation to the Services.
  2. 4.2 Confidentiality. JustHostMe will ensure that persons authorised to Process Customer Personal Data are subject to a duty of confidentiality or an appropriate statutory obligation of confidentiality.
  3. 4.3 Instructions from the Customer. JustHostMe will not use Customer Personal Data for its own independent purposes except where necessary to comply with applicable law or where the parties have separately agreed that JustHostMe is acting as a Controller for a particular Processing activity.
  4. 4.4 Data Protection Officer. Where applicable, each party will provide the contact details of its Data Protection Officer or other relevant privacy contact. Nothing in this DPA requires a party to appoint a Data Protection Officer where it is not legally required to do so.

5. SECURITY OF PERSONAL DATA

  1. 5.1 Technical and organisational measures. Taking into account the state of technical development, the costs of implementation and the nature, scope, context and purposes of the Processing, as well as the risk to the rights and freedoms of Data Subjects, JustHostMe will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
  2. 5.2 Security measures. The measures used by JustHostMe are described in Schedule 2. JustHostMe may update its security measures from time to time where the overall level of protection is not materially reduced.
  3. 5.3 Access control. Access to Customer Personal Data by JustHostMe personnel is restricted to authorised personnel who require access for service provision, administration, support, security, maintenance, troubleshooting or other legitimate service purposes. Access will be subject to appropriate authentication and confidentiality controls.
  4. 5.4 Customer security responsibilities. The Customer is responsible for account credentials, user permissions, application security, website code, databases and other security measures under the Customer's control. The Customer should use appropriate passwords, access controls, software updates and independent backups where appropriate.

6. SUB-PROCESSORS

  1. 6.1 General authorisation. The Customer generally authorises JustHostMe to appoint Sub-processors as necessary to provide the Services, including the Sub-processors identified in Schedule 3.
  2. 6.2 Sub-processor obligations. JustHostMe will enter into a written agreement with each Sub-processor which requires the Sub-processor to provide appropriate safeguards and to comply with data protection obligations appropriate to the nature of the Processing, including obligations equivalent to those applicable to JustHostMe under this DPA where required by law.
  3. 6.3 Changes to Sub-processors. JustHostMe may appoint or replace Sub-processors where reasonably necessary to provide or improve the Services. We will maintain an up-to-date list of material Sub-processors and will provide information about material changes on reasonable notice or by updating our published Sub-processor information where available.
  4. 6.4 Objection. Where required by applicable Data Protection Laws, the Customer may object on reasonable data-protection grounds to the appointment of a new Sub-processor. The parties will work in good faith to address the objection. If the parties cannot reasonably resolve the objection, the Customer may exercise any rights available under the Agreement and applicable law in relation to the affected Service.
  5. 6.5 Responsibility. JustHostMe remains responsible to the Customer for the performance of its obligations under this DPA and will remain liable for the acts and omissions of its Sub-processors to the extent required by applicable law.

7. DATA SUBJECT RIGHTS

  1. 7.1 Assistance. Taking into account the nature of the Processing and the information available to JustHostMe, we will provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under applicable Data Protection Laws.
  2. 7.2 Requests received by JustHostMe. If JustHostMe receives a request from a Data Subject relating to Customer Personal Data, we will not respond to the request except where authorised by the Customer or where required by law. Where legally permitted, we will promptly inform the Customer of the request and provide reasonable assistance.
  3. 7.3 Technical assistance. Assistance may include providing access to, exporting, correcting, restricting or deleting Customer Personal Data where those functions are reasonably available through the Services and consistent with the Customer's instructions.

8. PERSONAL DATA BREACHES

  1. 8.1 Notification. JustHostMe will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by JustHostMe on the Customer's behalf.
  2. 8.2 Information provided. Taking into account the information available to us, the notification will provide reasonably available information about the nature of the breach, categories of data and Data Subjects affected where known, likely consequences, measures taken or proposed to address the breach and relevant contact information.
  3. 8.3 Cooperation. JustHostMe will provide reasonable assistance to the Customer in meeting its obligations concerning notification of a Personal Data Breach to the Information Commissioner's Office or Data Subjects where required by law.
  4. 8.4 Security incidents. Not every security alert, attempted attack or unsuccessful intrusion constitutes a Personal Data Breach. Where an incident does not involve a Personal Data Breach, JustHostMe may handle it under its ordinary security and incident-management procedures.

9. DATA PROTECTION IMPACT ASSESSMENTS AND REGULATORY ASSISTANCE

  1. 9.1 DPIAs and consultations. Taking into account the nature of the Processing and the information available to JustHostMe, we will provide reasonable assistance to the Customer with data protection impact assessments and, where applicable, prior consultation with the ICO.
  2. 9.2 Reasonable scope. Assistance under this clause is limited to information and measures relating to the Services and does not make JustHostMe responsible for the Customer's overall compliance, processing purposes, lawful bases or risk assessments.

10. INTERNATIONAL TRANSFERS

  1. 10.1 UK hosting. Standard JustHostMe hosting services are provided using infrastructure located in London, United Kingdom, subject to the operation of applicable third-party services, support arrangements and technical infrastructure.
  2. 10.2 Restricted transfers. Where JustHostMe or a Sub-processor makes a restricted transfer of Customer Personal Data outside the United Kingdom, JustHostMe will ensure that the transfer is made in accordance with applicable Data Protection Laws and using an appropriate safeguard where required.
  3. 10.3 Transfer safeguards. Depending on the circumstances, appropriate safeguards may include an adequacy regulation, the UK International Data Transfer Agreement, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another mechanism recognised under applicable law.
  4. 10.4 Transfer assessments. Where required by applicable law, JustHostMe will take reasonable steps to assess the transfer and implement supplementary measures identified as necessary to maintain an appropriate level of protection.

11. DOMAIN REGISTRATION AND OTHER INDEPENDENT PROCESSING

  1. 11.1 Separate processing roles. Not all Personal Data processed in connection with the Services is processed by JustHostMe as a Processor on the Customer's behalf. For example, JustHostMe may process account, billing, support, security and transactional information as an independent Controller where we determine the purposes and means of that Processing.
  2. 11.2 Domain registration. Where a Customer requests registration, renewal, transfer or management of a domain, personal data may be submitted to the relevant registry, registrar or reseller, including Nominet for .UK domains and ResellerClub for other TLDs. Those organisations may process registrant and administrative data under their own contractual, regulatory and legal obligations. The precise legal role of each organisation depends on the relevant domain service and applicable registry or registrar arrangements.
  3. 11.3 Payment processing. Payment and payment-method information may be processed by Stripe or another payment provider in accordance with the applicable payment arrangements and JustHostMe's Privacy Policy. Such processing is distinct from the Processing of Customer Personal Data covered by this DPA where JustHostMe acts as Processor.
  4. 11.4 Scope of this DPA. Clauses 11.1 to 11.3 do not remove or reduce any obligation that applies to JustHostMe as a Processor where JustHostMe is processing Personal Data on the Customer's documented instructions.

12. AUDITS AND COMPLIANCE INFORMATION

  1. 12.1 Information. JustHostMe will make available to the Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the UK GDPR and this DPA, taking into account the nature of the Services and information available to JustHostMe.
  2. 12.2 Audit requests. The Customer may request an audit where reasonably necessary to verify JustHostMe's compliance with this DPA and applicable Data Protection Laws. The parties will agree the scope, timing and method of any audit in advance.
  3. 12.3 Reasonable limitations. Audits must be conducted during normal business hours, on reasonable notice and in a manner that does not materially disrupt JustHostMe's operations or compromise the security, confidentiality or data protection rights of other customers. The Customer will bear its own audit costs unless applicable law requires otherwise.
  4. 12.4 Alternative evidence. Where reasonably sufficient, JustHostMe may satisfy an audit request by providing relevant policies, certifications, security documentation, questionnaire responses, independent audit reports or other appropriate evidence instead of permitting an on-site audit.

13. RETURN AND DELETION OF PERSONAL DATA

  1. 13.1 During the Services. The Customer can generally access, export, modify or delete Customer Personal Data through the Services where the applicable functionality is provided.
  2. 13.2 On termination. Following termination or expiry of the relevant Service, JustHostMe will delete or return Customer Personal Data in accordance with the Customer's instructions, unless applicable law requires continued retention or the data remains in routine backups for a limited period.
  3. 13.3 Backups. Customer Personal Data contained in backups may remain until those backups are overwritten or securely deleted in accordance with JustHostMe's ordinary backup and retention processes. While retained, the data will remain subject to the confidentiality and security obligations in this DPA and will not be restored or used except for legitimate disaster recovery, security, legal or operational purposes.
  4. 13.4 Legal retention. Nothing in this DPA requires JustHostMe to delete Personal Data where retention is required by law, a competent authority or a legitimate legal obligation. Where permitted, retained data will be isolated from further Processing for other purposes.

14. CONFIDENTIALITY AND COMMERCIAL TERMS

  1. 14.1 Confidentiality. Customer Personal Data will be treated as confidential information of the Customer, subject to the permissions and rights expressly provided by the Agreement and applicable law.
  2. 14.2 Fees for assistance. Where legally permitted, JustHostMe may charge reasonable fees for extraordinary assistance, audits or requests which are materially beyond the ordinary operation of the Services, particularly where the request is manifestly unfounded, excessive or repetitive. We will normally discuss any material charge with the Customer before carrying out the additional work.

15. TERM AND TERMINATION

  1. 15.1 Term. This DPA will take effect when the Customer starts using a Service to which this DPA applies and will continue for so long as JustHostMe Processes Customer Personal Data as a Processor.
  2. 15.2 Termination. Termination of the Agreement or the affected Service will not remove any obligation to protect Personal Data that remains in JustHostMe's possession or control.

16. LIABILITY AND GENERAL PROVISIONS

  1. 16.1 Liability. The parties' liability in connection with this DPA is subject to the liability provisions of the Agreement, except to the extent that applicable Data Protection Laws impose liability which cannot lawfully be excluded or limited.
  2. 16.2 Changes required by law. The parties will cooperate in good faith to make amendments reasonably necessary to keep this DPA compliant with changes in applicable Data Protection Laws or binding regulatory requirements.
  3. 16.3 No reduction of statutory rights. Nothing in this DPA is intended to exclude or restrict any right or remedy which cannot lawfully be excluded or restricted.
  4. 16.4 Governing law. This DPA is governed by the law of England and Wales and is subject to the jurisdiction provisions in the Terms of Service, unless applicable law requires otherwise.

SCHEDULE 1: DETAILS OF PROCESSING

  1. Subject matter. Hosting, storing, transmitting, securing, backing up, maintaining and providing technical services in relation to Customer Personal Data contained within websites, files, databases, email accounts and other services supplied by JustHostMe.
  2. Duration. For the duration of the applicable Service and any limited period required for backup, disaster recovery or legal retention after termination.
  3. Nature and purpose. Provision and operation of hosting and related services; storage and transmission of data; email delivery and filtering where selected; backup and recovery where selected; maintenance and technical support; security and abuse prevention; troubleshooting; and other Processing reasonably necessary to provide the Services in accordance with the Customer's instructions.
  4. Categories of Personal Data. Depending on the Customer's use of the Services, this may include names, contact details, addresses, account identifiers, online identifiers, communications, IP addresses, login information, website content, email contents and attachments, transaction-related information, employment-related information, customer or member records, uploaded documents, photographs and other information placed into hosted systems by or on behalf of the Customer.
  5. Special categories. The Services may be capable of storing special category data and criminal offence data where lawfully required by the Customer. Customers remain responsible for ensuring that such Processing is lawful and appropriate to the Service selected.
  6. Categories of Data Subjects. Depending on the Customer's use of the Services, Data Subjects may include the Customer's customers, clients, website visitors, users, members, employees, contractors, suppliers, business contacts and other individuals whose Personal Data is uploaded, transmitted or otherwise processed through the Services.

SCHEDULE 2: TECHNICAL AND ORGANISATIONAL MEASURES

  1. Infrastructure and access control. Standard hosting infrastructure is provided using OVH infrastructure located in London, United Kingdom. Access to server systems is restricted to authorised JustHostMe personnel with a legitimate business need for access.
  2. Authentication and permissions. Administrative access is controlled through account credentials and appropriate permissions. Access is granted according to operational need and is removed or amended when access is no longer required.
  3. Transport security. Appropriate encryption mechanisms, including TLS where supported and appropriate, are used for network connections and the transmission of Personal Data.
  4. Network and system security. JustHostMe uses appropriate firewalling, server hardening, operating-system and software updates, malware and abuse controls, monitoring and other security measures appropriate to the Services supplied.
  5. Backups and resilience. JustHostMe operates backup and disaster-recovery processes for applicable Services. Standard JustHostMe-managed backups are stored using OVH infrastructure. Customers may also purchase optional third-party backup services such as CodeGuard.
  6. Email security. Email services may be protected by spam, malware and abuse controls. Customers who purchase the optional SpamExperts service may route email through SpamExperts/N-able infrastructure for filtering and related email-security purposes.
  7. Confidentiality. Personnel authorised to access Customer Personal Data are subject to confidentiality obligations and are provided with access only where required for their role.
  8. Incident management. JustHostMe maintains operational procedures for identifying, investigating and responding to security incidents and Personal Data Breaches.
  9. Data minimisation and retention. JustHostMe seeks to limit access to Personal Data to what is required for the applicable Service and retains data in accordance with the Agreement, applicable law and operational retention requirements.
  10. Review. Security measures are reviewed and may be updated from time to time to address changes in technology, threats, legal requirements and operational needs, without materially reducing the overall level of protection.

SCHEDULE 3: SUB-PROCESSORS AND OTHER THIRD-PARTY PROCESSING

  1. OVH
    Purpose: Underlying hosting infrastructure and storage, including infrastructure used for JustHostMe-managed backups.
    Use: Standard hosting services.
    Location: Standard JustHostMe hosting infrastructure is located in London, United Kingdom.
    Role: Sub-processor/infrastructure provider where OVH processes or stores Customer Personal Data on JustHostMe's behalf.
  2. SpamExperts / N-able
    Purpose: Optional email filtering, routing, spam and malware protection.
    Use: Only where the Customer purchases or enables the optional SpamExperts service.
    Location: Processing may involve infrastructure outside the UK depending on the service configuration. N-able maintains its own data-processing arrangements for SpamExperts services.
    Role: Sub-processor where it processes Customer Personal Data on JustHostMe's behalf.
  3. CodeGuard
    Purpose: Optional website and database backup and recovery services.
    Use: Only where the Customer purchases or enables the optional CodeGuard service.
    Location: Processing and storage locations are determined by the CodeGuard service and its applicable infrastructure and data-processing arrangements; processing may occur outside the UK.
    Role: Sub-processor where it processes Customer Personal Data on JustHostMe's behalf.
  4. Domain registries, registrars and resellers
    Purpose: Domain registration, renewal, transfer and management.
    Examples: Nominet for .UK domains and ResellerClub for other TLDs.
    Use: Only where the Customer purchases or uses the relevant domain service.
    Role: The applicable registry, registrar or reseller may process registrant and administrative Personal Data under its own contractual, regulatory and legal obligations. The precise role is determined by the applicable domain service and registry/registrar arrangements and is not necessarily that of a Sub-processor under this DPA.
  5. Other suppliers
    JustHostMe may from time to time appoint or replace other Sub-processors reasonably necessary to provide the Services. Any such appointment will be subject to clause 6 and applicable Data Protection Laws.

Important: The Customer should review Schedule 3 and the applicable JustHostMe Terms of Service and Privacy Policy before entering into this DPA. Optional services may involve additional third-party Processing and international transfers as described above.