Public testing phase We’re in a public testing phase — feel free to look around, but we’re not taking orders yet. Ordering opens 1 October 2026. Reserve your place →

Legal

Data Processing Agreement

GDPR Article 28(3) · Last reviewed: 16 September 2026 · Sub-processor register v1.2, updated 16 September 2026

In force — version 2.0, 16 September 2026. This Data Processing Agreement forms part of the Veldhost Paid Hosting Terms of Service and is incorporated into your contract by reference (Terms §2). It is drafted to meet GDPR Article 28(3). The service provider and sub-processor register below is version v1.2. If you need a countersigned copy for your records, write to legal@veldhost.eu.

1. Parties and roles

This Data Processing Agreement ("DPA") forms part of, and is governed by, the Veldhost Paid Hosting Terms of Service (the "Agreement") between:

  • Processor: Veldhost, the registered trade name of a Dutch sole proprietorship (eenmanszaak) of Janis Berzins, KvK 98167820, VAT NL005311289B72, registered office and contacts as stated in the "Who we are" panel above, legal contact legal@veldhost.eu ("veldhost", "we", "Processor"); and
  • Controller: the customer identified in the account/order ("Customer", "you", "Controller").

For Customer Content — the websites, applications, files, databases, mailboxes, backups, DNS records and any personal data you host with us — you are the controller and veldhost is your processor. For account, billing, support, security and abuse-prevention data, veldhost is an independent controller under the separate Privacy Policy, and this DPA does not apply to that data.

Where you are yourself a processor for a third party, you act here as controller toward us and warrant you have authority to instruct us on that third party's behalf.

2. Subject-matter, duration, nature and purpose

  • Subject-matter: processing of personal data contained in Customer Content in the course of providing the managed hosting service.
  • Duration: for the term of the Agreement, plus the retention/return/deletion period in §11.
  • Nature and purpose: hosting, storing, transmitting, backing up, serving, securing and operating Customer Content and the associated managed services (compute, DNS, TLS, storage, email when enabled, monitoring, backups, support) solely to deliver the service you ordered.
  • Type of personal data: determined by you as controller. Typically may include website/app users' names, email addresses, contact details, account credentials, order/transaction data, IP addresses, support content, and any other personal data you choose to place in your hosted content. You must not place special-category data (GDPR Art. 9) or criminal-offence data in Customer Content without a separate written agreement.
  • Categories of data subjects: determined by you — typically your website/app visitors, users, customers, employees and contacts.

3. Processor obligations (Art. 28(3))

veldhost shall:

  1. Process only on documented instructions. Process Customer Content personal data only on your documented instructions (including the Agreement, portal configuration, and support requests), including for international transfers, unless required by EU/Member-State law — in which case we inform you first unless the law prohibits it.
  2. Confidentiality. Ensure persons authorised to process the data (currently the owner; any future staff/contractors) are bound by confidentiality.
  3. Security. Implement the technical and organisational measures in §7 (Art. 32).
  4. Sub-processors. Engage sub-processors only under §6.
  5. Assist with data-subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection) — see §8.
  6. Assist with compliance. Assist you in ensuring compliance with Art. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the information available to us.
  7. Deletion/return. At the end of the service, delete or return Customer Content per §11.
  8. Demonstrate compliance. Make available information necessary to demonstrate Art. 28 compliance and allow for and contribute to audits per §9.
  9. Flag unlawful instructions. Immediately inform you if, in our opinion, an instruction infringes the GDPR or other EU/Member-State data-protection law.

4. Controller obligations

You warrant that: you have a lawful basis for the processing; you are responsible for the accuracy, content and legality of Customer Content; you will not instruct us to process data unlawfully; you have provided any required notices and obtained any required consents from your data subjects; and you will not place special-category or criminal-offence data in the service without a prior written agreement.

5. International transfers

veldhost's product promise is EU/EEA data residency for Customer Content. We do not intentionally place Customer Content, production compute, or backups outside the EU/EEA, and any new sub-processor that will carry Customer Content is pinned to an EU location before use.

Domain registration is not a self-serve product: Customers normally keep their domain at their own registrar and only point its DNS at us, in which case no registrant data passes through us at all. Where a Customer asks us to register a domain, the Customer is the registrant, and the registrant's identity and contact details — name, address, email, telephone, and a VAT number or identity-verification result where the registry demands one — are passed to Openprovider (Hosting Concepts B.V., Netherlands) and onward to the registry. Openprovider is in the EEA. The registry is not always: registries for .nl, .eu and most European extensions are in the EU, while the registries for generic extensions such as .com, .net and .org — and the data-escrow agents ICANN requires for them — sit outside the EEA. Where a Customer asks for such an extension, passing their registrant data on is a Chapter V transfer made in reliance on Article 49(1)(b), because it is necessary to perform the registration the Customer asked us to arrange. Registrant data is processed by veldhost as a controller for the registration relationship, not as a processor of Customer Content. A small number of veldhost's own domains registered before mid-2026 remain with our previous registrar, OpenSRS / Tucows Inc. (Canada), and are being migrated to Openprovider; that bounded path — which carries no Customer personal data, though veldhost's own business contact is the personal data of its owner, an eenmanszaak having no separate legal personality — relies on the European Commission adequacy decision for PIPEDA-regulated commercial organisations (Commission Decision 2002/2/EC) until migration completes. If any future flow requires Customer Content personal data to leave the EEA, we will implement an appropriate Chapter V safeguard (adequacy decision or the EU Standard Contractual Clauses) and update the sub-processor list before enabling it.

6. Sub-processors

You give general written authorisation for veldhost to engage the sub-processors listed below. We will notify you at least 14 days before adding or replacing a sub-processor (via the portal or email), and you may object on reasonable data-protection grounds. If we cannot resolve your objection within 30 days, you may terminate the affected Service without penalty with effect from the date the sub-processor would begin processing, and we refund the prepaid fees for the unused remainder of your billing period on a pro-rata basis. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain fully liable for their performance. The table below is the single, versioned source of truth for our sub-processor register.

Service providers and sub-processors (v1.2)

This table is the single, versioned source of truth for every third party that touches personal data in connection with the service. Rows marked Sub-processor (Customer Content) are engaged under Art. 28(2)/(4) GDPR: your general written authorisation, the notice period and the objection right in this section apply to them. Rows marked Recipient — veldhost as controller fall outside this DPA; we process that data as controller under the Privacy Policy, and we list them here so you can see the whole picture in one place.

Provider Role / processing Location of processing Transfer basis
Hetzner Online GmbH Sub-processor (Customer Content). Core EU hosting infrastructure: compute (customer containers), block/object/file storage, backups, authoritative DNS nodes Germany / Finland (EU/EEA) Within EEA
Stripe Payments Europe, Ltd. Recipient — veldhost as controller (billing data). Payment processing + billing/tax metadata. Stripe acts as an independent controller for card/payment data under its own terms; as our sub-processor it handles billing identifiers only (no full card numbers reach us) Ireland (EU) + Stripe global EEA; Stripe DPA + SCCs/DPF for any onward transfer
Openprovider (Hosting Concepts B.V.) Recipient — veldhost as controller (registrant data); Openprovider is our processor for the registration request and an independent controller for its own registrar obligations. Domain registration/management (current registrar), used only where a Customer asks us to register a domain for them. Receives that Customer's registrant details (name, address, email, telephone, VAT number or identity-check result) as the registries require, and passes them to the registry Netherlands (EU); registry per extension Within the EEA (EU registries); Art. 49(1)(b) derogation where you ask us to register a non-EEA extension such as .com
OpenSRS / Tucows Inc. (legacy, migrating) Recipient — veldhost's own business data only; no Customer personal data. Previous registrar, now holding veldhost's own domains only, being migrated to Openprovider. Receives the domain-name string + veldhost's own business WHOIS/RDAP contact — not Customer personal data Canada Adequacy (Commission Decision 2002/2/EC, PIPEDA scope)
Mail-in-a-Box (self-hosted) Sub-processor (Customer Content). Mailbox/email service when enabled — runs on veldhost-controlled Hetzner EU infrastructure, not a third-party SaaS Germany/Finland (EU/EEA) Within EEA (self-operated)

Register change log

  • v1.2 — 16 September 2026. Corrected, not changed: the register previously described Openprovider as receiving only the domain-name string and veldhost's own business contact. Since 15 July 2026 the Customer is the registrant of record, so where a Customer asks us to register a domain their registrant details (name, address, email, telephone, VAT number or identity-check result) are passed to Openprovider and onward to the registry, as the registries require. Openprovider is within the EEA; a registry for a generic extension such as .com is not, and a transfer there relies on Art. 49(1)(b). Domains are no longer sold self-serve; OpenSRS / Tucows now holds veldhost's own domains only. No new sub-processor was added and none was removed.
  • v1.1 — 9 September 2026. Removed: Cloudflare, Inc. (edge/CDN + DNS for the portal and marketing domain). veldhost.eu and the Manage portal have been served directly from our own EU infrastructure and our own authoritative nameservers (ns1/ns2.veldhost.eu) since July 2026; no edge, CDN or third-party DNS provider remains in front of any veldhost property. Removing a sub-processor requires no notice period under §6.
  • v1.0 — 4 July 2026. Initial register.

7. Security measures (Art. 32)

Taking into account the state of the art, costs, and the nature/scope/context/purposes of processing and the risks to data subjects, veldhost applies technical and organisational measures including:

  • Encryption in transit (TLS for all customer-facing and management traffic); TLS certificates managed and auto-renewed.
  • Access control: multi-factor authentication, role-based access, least-privilege operator access via a separate console (bastion + mTLS), disabled root SSH, and audit logging of privileged actions.
  • Tenant isolation: per-customer LXD containers; localhost-only customer databases; separation of customer workloads.
  • Network/abuse controls: rate limiting, egress controls, malware/phishing/spam signals, monitoring.
  • Patching: fleet-wide automated security updates (daily OS-update sweep + auto-restart of affected services) and CVE scanning with alerting.
  • Backups: scheduled backups (weekly baseline; daily with add-on) to EU storage; restore testing is being brought to a routine cadence (see the SLA).
  • Secrets management: environment secrets stored encrypted; production config rebuilt under controlled privilege.
  • Logging & monitoring: security/audit logs and health monitoring; retention per the Privacy Policy.
  • Organisational: confidentiality obligations; incident-response process; sub-processor due diligence.

These measures may evolve; veldhost will not materially reduce the overall level of security during the term.

8. Assistance with data-subject rights

Because you control Customer Content, you can generally fulfil access/rectification/erasure/portability requests directly through your hosted application, database and files. Where you cannot do so with the tools provided and reasonably require our help, we will provide reasonable assistance within a reasonable time, taking into account the nature of the processing. If a data subject contacts us directly about Customer Content, we will refer them to you and (unless legally prohibited) not respond substantively ourselves.

9. Audits

veldhost will make available the information necessary to demonstrate compliance with Art. 28 and, on reasonable prior written notice and no more than once per 12 months (or after a personal-data breach affecting you), allow and contribute to an audit — satisfied first by providing existing documentation (security overview, sub-processor register, relevant certifications/reports if available), and only where genuinely insufficient by a proportionate on-site/remote audit under reasonable confidentiality and cost-allocation terms.

10. Breach notification

veldhost will notify you without undue delay and in any event within 48 hours after becoming aware of a personal-data breach affecting Customer Content, providing (as available): the nature of the breach, categories/approximate numbers of data subjects and records, likely consequences, measures taken/proposed, and a contact point. We assist you in meeting your own Art. 33/34 obligations. As controller, you are responsible for notifying the supervisory authority (e.g. Autoriteit Persoonsgegevens) and affected data subjects where required; we notify our own authority only for data where we are controller.

11. Return and deletion on termination

On expiry or termination of the service, and at your choice, veldhost will return Customer Content (via export of files, database and DNS information, where technically and legally possible) and/or delete it. The export remains available for 30 days after the service ends. We delete live Customer Content within 30 days of the end of that export window, or within 5 business days of you confirming sooner that you have your export. Copies held in backups are not erased individually: they are overwritten as the backup rotation runs, including the nightly second-region replica, and are gone no later than 35 days after deletion of the live data. Until then they remain subject to the security measures in §7 and are not used for any other purpose. Account deletion triggers automated teardown of the customer's container and hosting resources. We may retain the minimum data required by law (e.g. invoices for the 7-year Dutch fiscal retention period, security/abuse evidence) beyond service termination, unless EU/Member-State law requires longer storage.

12. Liability, term, governing law

Liability under this DPA is subject to the limitations in the Agreement (Terms §14) and to mandatory law that cannot be limited (including non-waivable data-subject rights). This DPA takes effect when the Agreement does and terminates with it (subject to §11). It is governed by Dutch law; disputes go to the competent Dutch courts, without prejudice to mandatory consumer rights.

13. Order of precedence

If this DPA conflicts with the Agreement on the processing of Customer Content personal data, this DPA prevails for that subject-matter. Otherwise the Agreement governs.

Requesting a signed copy

This DPA is incorporated into your contract by reference from the Terms and is surfaced here for you to read and retain. If you require a countersigned copy for your own records, email legal@veldhost.eu.