Data Processing Addendum
Applies to: host.yt, the customer panel, billing portal, support channels, and services provided by Marko Omelyash VARSOFIA.
Plain-language summary
This summary is for convenience only. The full provisions below form the legally relevant text.
1. Parties
This Data Processing Addendum forms part of the agreement between the customer as controller and Marko Omelyash VARSOFIA as processor where Hostyt processes personal data on behalf of the customer through hosting, VPS, email, domain, support, or related services.
2. Subject matter and duration
The subject matter is the processing of customer personal data needed to provide the Services. Processing continues for the duration of the Services and any retention period needed for deletion, backup expiry, legal obligations, security, or dispute handling.
3. Nature and purpose
Processing may include hosting, storage, transmission, retrieval, backup, restoration, technical support, security monitoring, malware mitigation, incident response, migration, maintenance, and deletion.
4. Categories of data
Customer personal data may include any personal data uploaded, stored, transmitted, or otherwise processed by the customer through the Services, such as website visitor data, account data, contact data, emails, database records, logs, files, and application data.
5. Categories of data subjects
Data subjects may include the customer’s employees, contractors, clients, website visitors, end users, subscribers, leads, support contacts, and other individuals whose data is processed through the Services.
6. Customer instructions
We process customer personal data only on documented instructions from the customer, including instructions in the agreement, account settings, service configuration, support requests, and lawful customer actions in the panel, unless law requires otherwise.
7. Customer obligations
The customer is responsible for lawful collection, transparency, legal bases, consent where needed, data subject rights, data minimisation, retention decisions, and the content of data processed through the Services.
8. Confidentiality
Personnel authorised to process customer personal data are bound by confidentiality obligations or equivalent professional duties.
9. Security measures
We maintain technical and organisational measures designed to protect customer personal data, including access controls, logical segregation, network security, monitoring, backup processes, secure administration, incident handling, and supplier controls.
10. Sub-processors
The customer gives general authorisation for us to use sub-processors needed to provide the Services, including data centres, cloud infrastructure, registries, registrars, payment/security tools, support systems, email systems, and monitoring providers.
We will impose data protection obligations on sub-processors that are appropriate to the processing. We remain responsible for sub-processor performance as required by applicable data protection law.
11. International transfers
Where customer personal data is transferred outside the EEA or another protected jurisdiction, we will use appropriate safeguards where required, such as adequacy decisions, standard contractual clauses, or other lawful transfer mechanisms.
12. Data subject requests
Where legally required and technically possible, we will assist the customer with data subject requests relating to customer personal data processed by us as processor. The customer remains responsible for responding to the data subject.
13. Security incidents
We will notify the customer without undue delay after becoming aware of a personal data breach affecting customer personal data processed by us as processor. The customer is responsible for assessing notification duties to authorities and data subjects unless law requires otherwise.
14. Deletion and return
After termination, we will delete or make unavailable customer personal data in accordance with service deletion processes, backup expiry, legal obligations, and technical constraints. The customer must export data before termination where continued access is required.
15. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, confidential, non-disruptive, and subject to prior written agreement on scope, timing, security, and costs.
16. Liability
Liability under this DPA is subject to the limitations in the Terms of Service unless mandatory data protection law requires otherwise.
Updates
We may update this document from time to time. The version published on host.yt is the current version. If a change materially affects active paid services, we may notify affected customers by email, account notice, ticket, or another reasonable channel.