# Data Processing Agreement | my.host

> Read the my.host data processing agreement: terms on how we process personal data on your behalf as data controller.

# Trust

Transparency about how my.host handles personal data

    At my.host we take the protection of personal data seriously. On this page you find all the information about how we handle the processing of personal data, which sub-processors we engage, and which technical and organizational security measures we take.

If you use our hosting, email, domain or server services, we process personal data on your behalf as the controller. The arrangements about this are laid down in our [data processing agreement](/trust/data-processing-agreement). If you (also) use our services to process personal data on behalf of your own customers &amp;mdash; for example as a reseller, web builder, agency or managed service provider &amp;mdash; then you act as the processor and my.host as the sub-processor. For that situation our [sub-processing agreement](/trust/sub-processing-agreement). For the transfer of personal data to third parties that we engage in delivering our services, we refer to our [sub-processor list](/trust/subprocessors).

#####  Organizational measures

- Periodic monitoring, evaluation and assessment of the effectiveness of measures
- Procedure for compliance with retention periods and deletion
- Confidentiality obligations for employees
- Awareness and training in the field of information security and privacy

#####  Technical measures

- Physical and network security: closed server rooms, network segmentation, firewalls, hardening
- Encryption and secure transfer: TLS/STARTTLS
- Email security: anti-spam/anti-virus, DMARC, DKIM and SPF
- DNS security: DNSSEC
- Logging and monitoring: access logging, SIEM/IDS, time synchronization
- Access security: MFA, least-privilege, jump-host/bastion
- Backup/continuity: separated storage, integrity checks
- Malware/abuse: endpoint/malware scans, quarantines

#####  Privacy contact

**my.host**

Pietersbergweg 291

1105 BM Amsterdam

The Netherlands

KvK: 89592514

<privacy@my.host>

#####  Documents

[Privacy policy](/privacy-policy) [Data processing agreement](/trust/data-processing-agreement) [Sub-processing agreement](/trust/sub-processing-agreement) [Sub-processors](/trust/subprocessors)

## Sub-processors

When delivering our services, we engage sub-processors that process personal data on our behalf. Below you find an overview of all sub-processors that we currently use, including their location and the purpose for which they are used. This list serves as Annex B to both the [data processing agreement](/trust/data-processing-agreement) (sub-processors of my.host) and the [sub-processing agreement](/trust/sub-processing-agreement) (sub-sub-processors of my.host when my.host acts as a sub-processor).

Last updated: April 2026

Voxility • Infrastructure

Dedicated servers

EU

Worldstream • Infrastructure

Dedicated servers

Netherlands

Leaseweb • Backup infrastructure

Dedicated servers (backups)

Netherlands

Hostcircle • Backup infrastructure

Dedicated servers (backups)

Netherlands

Oneprovider • Backup infrastructure

Dedicated servers (backups)

EU

SIDN • Domain registration (.nl)

Registry

Netherlands

DNS Belgium • Domain registration (.be)

Registry

Belgium

OpenProvider • Domain registration

Registrar

EU

Pax8 • Microsoft 365 distribution

Distributor

EU / US

Anthropic • AI-supported ticket handling

Support questions via Claude. Transfer to the US on the basis of SCCs. Zero data retention (ZDR).

United States

## Data Processing Agreement

Version: April 2026

This data processing agreement, including its annexes, is entered into between my.host (hereinafter: the “processor”) and the Customer (hereinafter: the “data controller”) and sets out the arrangements between the Parties regarding the processing of personal data carried out by the processor on behalf of the data controller in the context of the services that my.host provides to the Customer under the main agreement. This data processing agreement applies exclusively to the processing of personal data by the processor on behalf of the data controller and does not cover activities that do not involve the processing of personal data. Where my.host processes personal data as an independent data controller, that processing falls outside the scope of this data processing agreement.

### Parties

This data processing agreement applies between **my.host** (Pietersbergweg 291, 1105 BM Amsterdam, Chamber of Commerce: 89592514), hereinafter the “processor”, and the customer purchasing services from my.host, hereinafter the “data controller”. Collectively referred to as the “Parties” and individually as a “Party”.

### 1. General

1. The Parties agree that this data processing agreement replaces all previously agreed data processing agreements and/or privacy or data protection provisions between the Parties relating to the same services and the same processing relationship (namely: Customer as data controller and my.host as processor), unless the Parties have expressly agreed otherwise in writing. This data processing agreement does not affect any sub-processing agreement concluded between the Parties; both agreements coexist and each relates to a different processing relationship.
2. This data processing agreement applies only if and to the extent that the processing of personal data is governed by the GDPR. Terms from the GDPR used in this data processing agreement, including “personal data”, “processing”, “data controller” and “processor”, have the meaning assigned to them in the GDPR.
3. This data processing agreement is deemed to form an integral part of the main agreement between the Parties.

### 2. Annexes

The following annexes form an integral part of this data processing agreement:

- Annex A: Details of the data processing
- Annex B: Sub-processors
- Annex C: Security measures (technical and organisational measures)

### 3. Purpose of the processing

1. The processor undertakes, in accordance with the terms of this data processing agreement, to carry out the processing of personal data on behalf of the data controller.
2. The processor processes personal data solely in the context of performing the main agreement, strictly in accordance with the documented instructions of the data controller, and relates to one or more of the services as further described in Annex A. The processor shall not use the personal data for any other purpose or in any other manner than for the purpose determined by the data controller.
3. The data controller agrees that this data processing agreement, the main agreement and any further (agreed in writing) work arrangements, as well as the configurations and settings chosen by the data controller or its authorised users for the services (in accordance with the documentation), together constitute the full instructions of the data controller to the processor regarding the processing of personal data.
4. Additional or deviating instructions apply only if the Parties have agreed them in writing, whereby the processor is entitled to charge any (reasonable) costs associated with carrying out such instructions.

### 4. Obligations

1. The data controller declares and warrants that it will at all times comply with applicable data protection legislation (including the GDPR) with regard to (i) the personal data it provides to the processor or has processed via the services and (ii) the (processing) instructions it gives to the processor. The data controller warrants that the processing of personal data via the services is lawful, so that the processor may process the personal data on the basis of the main agreement and this data processing agreement and in accordance with applicable data protection legislation.
2. The data controller warrants that it has all necessary rights, consents, legal bases and authorisations to (a) provide personal data to the processor and (b) authorise the processor to process the personal data as provided for in the main agreement, this data processing agreement and the documented instructions of the data controller. The data controller is responsible for the origin, accuracy, quality and lawfulness of the personal data and the manner in which it obtained them.
3. To the extent third parties bring claims against the processor relating to personal data or processing for which the data controller is responsible, the data controller shall indemnify the processor upon first request against such claims, damages, fines and costs, to the extent permitted under mandatory law and to the extent not caused by intent or wilful recklessness on the part of the processor.
4. The processor is not responsible for assessing whether the instructions of the data controller comply with applicable laws and regulations. If the processor considers that an instruction from the data controller infringes applicable data protection legislation, the processor shall promptly inform the data controller thereof and is not obliged to comply with such unlawful instruction. The processor shall suspend execution of the relevant instruction until the data controller has withdrawn or amended the instruction or has confirmed in writing that the instruction is lawful, all to the extent reasonably possible without disproportionate disruption to service continuity.
5. The details of the processing, including the categories of personal data uploaded or otherwise made available by the data controller in the services and processed by the processor on behalf of the data controller, are set out in Annex A (Details of the data processing).
6. The data controller shall inform the processor in writing and with reasonable prior notice if it intends to make changes to the processing referred to above, including (but not limited to) changes in the nature, purposes, categories of personal data or categories of data subjects. If necessary, the Parties shall amend Annex A accordingly.
7. The data controller warrants that it maintains a complete and up-to-date record of processing activities in accordance with Article 30 of the GDPR.
8. The data controller is obliged to inform the processor promptly in writing if it (intends to) use the services to process personal data (also) on behalf of one or more of its own data controller(s), or if such processing ends. The data controller is itself responsible for the correct qualification of its role under the GDPR and for promptly informing the processor of any changes thereto. In such a situation, the sub-processing agreement between the Parties also applies, to the extent the actual processing gives rise to it.

### 5. Term of the data processing agreement and termination

1. This data processing agreement is entered into for the term set out in the main agreement. The Parties remain bound by obligations under this data processing agreement that by their nature continue to apply after termination.
2. This data processing agreement terminates automatically when the main agreement is terminated.
3. After termination of the main agreement, the processor deletes all personal data in accordance with the retention periods set out in Annex A, unless Union law or Member State law requires retention.
4. If the processor is unable to delete personal data for technical or other reasons, the processor shall take reasonable measures to ensure that the personal data are blocked from further processing and, to the extent technically possible, anonymised.

### 6. Sub-processors

1. The data controller agrees that the processor may engage sub-processors to process personal data of the data controller in order to provide the services. The processor maintains a list of its authorised sub-processors on its website and the data controller authorises the processor to use these sub-processors. The list of sub-processors applicable on the effective date of the main agreement is attached to this data processing agreement as Annex B.
2. The processor may engage sub-processors within and outside the EU/EEA and may transfer personal data outside the EU/EEA or otherwise process them there. The processor ensures that sub-processors are bound by written agreements to data processing obligations that, to the extent appropriate to the nature of the services provided by the sub-processor, offer at least an equivalent level of protection as the obligations under this data processing agreement with regard to data protection.
3. The processor ensures that each sub-processor it engages complies with the obligations that apply to the processor under this data processing agreement and applicable data protection legislation. The processor remains fully responsible and liable towards the data controller for processing by sub-processors, as if the processor carried out the processing itself.
4. The processor shall inform the data controller in writing at least fourteen (14) days in advance if it intends to make changes to the list of sub-processors. The data controller may object in writing within this period to the engagement of a new sub-processor (or a material change regarding an existing sub-processor), provided that such objection is based on reasonable grounds relating to data protection.

### 7. Data breach

1. In the event of a data breach, the processor shall notify the data controller without undue delay, and no later than 48 hours after discovery of the data breach. The notification shall include, to the extent available, at least:
    - a description of the nature of the breach, including – where possible – how it occurred and the (presumed) date and time of the incident and of discovery;
    - the (categories of) personal data affected by the breach;
    - the (categories of) data subjects and, to the extent reasonably possible, an estimate of the number of affected data subjects;
    - the likely consequences and risks of the breach; and
    - the measures the processor has taken or proposes to take to address the breach and limit possible adverse consequences.
2. If the processor cannot provide all information referred to in Article 7.1 within the period mentioned in that article, the processor shall provide the information available at that time within that period, while simultaneously stating the reasons why additional information is still missing. The processor shall provide additional information subsequently without undue delay once it becomes available.
3. The processor shall provide the data controller with reasonable assistance in fulfilling its obligations under the GDPR in connection with the breach, including – where applicable – assistance with (i) notifications to the competent supervisory authority(ies) and (ii) communication to data subjects.

### 8. Security and confidentiality

1. The processor has implemented appropriate technical and organisational measures for the security of personal data.
2. These security measures are designed at an appropriate level of security, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing and the varying likelihood and severity of risks to the rights and freedoms of natural persons. The (current) security measures are further described in Annex C.
3. The processor monitors compliance with the security measures periodically and is entitled to adjust the security measures if this is reasonably necessary for the security, continuity or further development of the services.
4. The processor limits access to personal data to those persons for whom access is necessary for the performance of the services. The processor ensures that persons who process personal data under its authority are bound by an appropriate confidentiality obligation and have received appropriate instructions and training regarding data protection and information security.

### 9. Rights of data subjects

1. The processor shall provide the data controller, to the extent reasonably possible and taking into account the nature of the processing, with assistance in fulfilling its obligations regarding requests from data subjects to exercise their rights under the GDPR (such as the right of access, rectification, erasure, restriction, portability and objection).
2. The processor shall promptly forward requests from data subjects submitted directly to the processor to the data controller and shall not handle such requests independently, unless the data controller has expressly given permission to do so.
3. The processor may charge reasonable costs for assistance that goes beyond standard functionality of the services.

### 10. Transfer outside the EU/EEA

1. The processor may process or transfer personal data outside the EU/EEA, provided that the requirements of Chapter V of the GDPR are met. The processor ensures that a valid transfer mechanism applies, such as an adequacy decision, Standard Contractual Clauses (SCCs) adopted by the European Commission, or another instrument recognised by the GDPR.
2. Where Standard Contractual Clauses apply, they are deemed to form an integral part of this data processing agreement.

### 11. Data protection impact assessment and prior consultation

1. The processor shall provide the data controller, upon request and to the extent reasonably possible, with assistance in carrying out a data protection impact assessment (DPIA) and, where applicable, in prior consultation with the supervisory authority.

### 12. Audit

1. The processor shall make available to the data controller all information reasonably necessary to demonstrate compliance with the obligations under this data processing agreement, and shall enable audits – including inspections – by or on behalf of the data controller, subject to the provisions of this article.
2. Audits are carried out at the expense of the data controller, with reasonable prior written notice (at least 30 days), and are limited to what is necessary and proportionate to verify compliance with this data processing agreement.
3. The data controller ensures that the audit is conducted professionally, does not disproportionately disrupt the processor’s operations and does not jeopardise the confidentiality and security of the processor’s data and those of its other customers.
4. The processor is entitled to impose reasonable conditions on the audit, including (but not limited to) prior agreement on scope and planning, confidentiality obligations for auditors and restriction of access to data of other customers.
5. If the processor has a current certificate, report or statement from an independent auditor (for example SOC 2 Type II, ISO 27001), this constitutes sufficient evidence of compliance with the relevant security obligations under this data processing agreement, unless the data controller demonstrates in a motivated and written manner that additional investigation is necessary.

### 13. Liability

1. The liability of the processor under or in connection with this data processing agreement is subject to the liability provisions and limitations as set out in the main agreement and the applicable general terms and conditions, to the extent permitted under mandatory law.

### 14. Miscellaneous

1. In the event of conflict between the provisions of this data processing agreement and the main agreement, this data processing agreement prevails to the extent it concerns the processing of personal data.
2. This data processing agreement is governed by Dutch law. Disputes arising from or in connection with this data processing agreement shall be submitted to the competent court in Amsterdam, unless otherwise prescribed by mandatory law.
3. If any provision of this data processing agreement is void, annulled or otherwise unenforceable, or if this data processing agreement contains a gap, the remaining provisions shall remain in full force and effect. In that case, the Parties shall consult to agree a replacement or supplementary provision that is legally valid and that aligns as closely as possible with the intent of the original provision, taking into account the requirements of Article 28 GDPR.

---

## Annex A: Details of the data processing

    Name and contact details of the processor my.host
Pietersbergweg 291, 1105 BM Amsterdam
Email: privacy@my.host   Data protection officer Not appointed.   Representative of the processor Not applicable.   Duration of the processing Processing starts on the effective date of the main agreement and ends upon expiry or termination of the main agreement.   Services  The processor processes personal data in the context of one or more of the following services: - Web hosting (including storage and provision of customer content)
- Email hosting
- DNS hosting and nameserver management
- Back-ups and disaster recovery
- Management and support of customer environments
- Monitoring and security of customer environments
- Domain name registration

    Nature and purposes of the processing The processor processes personal data solely for and on the instruction of the data controller for the provision of the services.   Data subjects  Depending on the services purchased by the Customer and the content of customer data, the following categories of data subjects may be involved: - Employees and contact persons of the Customer (including administrators and other authorised users)
- End users and visitors of the Customer (including the Customer’s customers/contacts, website visitors and application users)
- Senders and recipients of email (to the extent email services are provided)
- Other natural persons whose personal data are processed by or on behalf of the Customer in the customer environment(s) (e.g. prospects/leads, suppliers and their contact persons)

    Categories of personal data  Depending on the service(s) purchased by the data controller, the processor may process the following categories of personal data: ##### Web hosting (including customer content)

- Content, application data and databases provided or generated by the data controller
- User account data (such as username and email address)
- IP addresses and technical metadata

##### Web hosting, email hosting and VPS/server services

- Content of email messages and associated attachments
- Header and routing data (including sender, recipient, timestamp, subject lines and email headers)
- Mailbox metadata and configuration data

##### DNS hosting and nameserver management

- DNS records and zone files, hostnames and technical IP addresses

##### Back-ups and disaster recovery

- Copies of customer content, databases and system configurations (including all categories of personal data stored therein by the data controller)

##### Monitoring, performance and security logging

- IP addresses, timestamps and user-agent data
- Login and system events, event logs, error messages and performance logs

##### Management and support (including change management)

- Ticket content, contact details of requesters and contextual information relating to incidents or change requests
- Screenshots or log fragments provided by the data controller or necessary for troubleshooting and problem resolution

##### Malware scanning, abuse detection and notice-and-take-down support

- Scan results, URLs, file names and IP addresses
- Communication data and metadata relating to reports and handling of abuse incidents

The nature, scope and specific content of the processed personal data are largely determined by the data controller and depend on the data that the data controller uploads, stores or otherwise makes available to the processor in or via the services.

    Special categories of data The processor has no knowledge of whether special categories of personal data are processed. The nature and content of the processed data are determined by the data controller. If special categories of personal data are processed, the data controller is responsible for a lawful basis for this.   Frequency of transfer Continuously throughout the term of the main agreement.   Retention periods  The processor does not retain personal data longer than necessary for the performance of the services. Unless the Parties agree otherwise in writing or the data controller gives other written instructions, the following retention periods apply: - **Active customer data** (web hosting, email, databases and other customer content): throughout the term of the main agreement. After expiry or termination, the processor deletes customer data from production and management systems. Back-ups are deleted no later than 30 days after termination of the agreement. The data controller must export or migrate all customer data itself before the end date.
- **Back-ups and disaster recovery**: retained in accordance with the processor’s regular back-up rotation, with a maximum retention period of 90 days, unless otherwise agreed in writing. Deletion from back-ups takes place through rotation.
- **Logging and monitoring** (e.g. access logs, server logs, security logs): maximum 12 months, to the extent necessary for security, incident investigation, abuse prevention, availability and troubleshooting.
- **Support and ticket data** (incl. communication and attachments/log fragments): during your customer relationship for as long as needed for our service delivery, and thereafter maximum 24 months after the end of the customer relationship. For correspondence from persons without a customer relationship, we retain the data for a maximum of 48 months after closure of the ticket.

### Annex B: Sub-processors

A current overview of all sub-processors engaged by the processor is available at [https://my.host/trust/subprocessors](https://my.host/trust/subprocessors).

### Annex C: Security measures

The processor implements and maintains appropriate technical and organisational security measures to protect personal data.

#### Organisational measures

- Periodic monitoring, evaluation and assessment of the effectiveness of organisational and technical measures.
- Procedure for compliance with retention periods and deletion in accordance with agreements/instructions.
- Confidentiality obligations for employees (contractual and/or via internal policy).
- Awareness and training of employees in the field of information security and privacy.

#### Technical measures

- Physical and network security: secured server rooms, network segmentation, firewalls, hardening.
- Encryption and secure transfer: TLS/STARTTLS (where applicable), encryption “in transit”.
- Email security: anti-spam/anti-virus, rate limiting, DMARC/DKIM/SPF (where applicable).
- DNS security: DNSSEC (where possible).
- Logging and monitoring: access logging, monitoring/alerting, SIEM/IDS (where appropriate), time synchronisation.
- Access security: MFA, least-privilege (where possible), jump host/bastion.
- Back-up/continuity: segregated storage, integrity checks.
- Malware/abuse: endpoint/malware scans, quarantines, controlled access to samples/logging.

## Sub-processing Agreement

Version: April 2026

This sub-processing agreement, including its annexes, is entered into between my.host (hereinafter: the “sub-processor”) and the customer who purchases services from my.host as a processor (hereinafter: the “processor”) and sets out the arrangements between the Parties regarding the processing of personal data carried out by the sub-processor on behalf of and for the benefit of the processor in the context of the services provided by the sub-processor to the processor.

This sub-processing agreement applies exclusively to the processing of personal data by the sub-processor for the benefit of the processor in the context of the services that my.host provides to the processor under the main agreement. The sub-processor processes personal data on the basis of documented instructions from the processor. To the extent my.host processes personal data as an independent data controller or as (main) processor for its own customers, that processing falls outside the scope of this sub-processing agreement.

### Parties

This sub-processing agreement applies between **my.host** (Pietersbergweg 291, 1105 BM Amsterdam, Chamber of Commerce: 89592514), hereinafter the “sub-processor”, and the processor who purchases services from my.host for the benefit of its data controller(s). Collectively referred to as the “Parties” and individually as a “Party”.

### 1. General

1. The Parties agree that this sub-processing agreement replaces all previously agreed (sub)processing agreements and/or privacy or data protection provisions between the Parties relating to the same services, unless the Parties have expressly agreed otherwise in writing.
2. This sub-processing agreement applies only if and to the extent that the processing of personal data is governed by the GDPR. Terms from the GDPR used in this sub-processing agreement, including “personal data”, “processing”, “data controller”, “processor” and “sub-processor”, have the meaning assigned to them in the GDPR.
3. This sub-processing agreement is deemed to form an integral part of the main agreement between the sub-processor and the processor. For the purposes of this sub-processing agreement, the term “sub-sub-processor” means: a third party engaged by the sub-processor for (part of) the processing of personal data.

### 2. Annexes

The following annexes form an integral part of this sub-processing agreement:

- Annex A: Details of the data processing
- Annex B: Sub-sub-processors
- Annex C: Security measures (technical and organisational measures)

### 3. Purpose of the processing

1. The sub-processor undertakes, in accordance with the terms of this sub-processing agreement, to carry out the processing of personal data on behalf of the processor.
2. The processing of personal data by the sub-processor takes place exclusively in the context of performing the main agreement, strictly in accordance with the documented instructions of the processor, and relates to one or more of the services as further described in Annex A. The sub-processor shall not use the personal data for any other purpose or in any other manner than for the purpose communicated by the processor.
3. Additional or deviating instructions apply only if the Parties have agreed them in writing, whereby the sub-processor is entitled to charge any (reasonable) costs associated with carrying out such instructions to the processor.

### 4. Obligations

1. The processor declares and warrants that it will at all times comply with applicable data protection legislation (including the GDPR) with regard to (i) the personal data it provides to the sub-processor or has processed via the services and (ii) the (processing) instructions it gives to the sub-processor. The processor warrants that the processing of personal data via the services is lawful, that it is authorised to do so on the basis of a data processing agreement with the relevant data controller(s), and that the sub-processor may process the personal data on the basis of the main agreement and this sub-processing agreement in accordance with applicable data protection legislation.
2. The processor warrants that it is authorised to engage the sub-processor and that the instructions it gives are lawful.
3. The sub-processor is not responsible for assessing whether the instructions of the processor (or the underlying instructions of the data controller(s)) comply with applicable laws and regulations.
4. The details of the processing are set out in Annex A (Details of the data processing).
5. The processor shall inform the sub-processor in writing and with reasonable prior notice if it intends to make changes to the processing referred to above, including (but not limited to) changes in the nature, purposes, categories of personal data or categories of data subjects. If necessary, the Parties shall amend Annex A accordingly.

### 5. Term of the sub-processing agreement and termination

1. This sub-processing agreement is entered into for the term set out in the main agreement. The Parties remain bound by obligations under this sub-processing agreement that by their nature continue to apply after termination.
2. This sub-processing agreement terminates automatically when the main agreement is terminated.
3. After termination of the main agreement, the sub-processor deletes all personal data in accordance with the retention periods set out in Annex A, unless Union law or Member State law requires retention.
4. If the sub-processor is unable to delete personal data for technical or other reasons, the sub-processor shall take reasonable measures to ensure that the personal data are blocked from further processing and, to the extent technically possible, anonymised.

### 6. Sub-sub-processors

1. The processor hereby authorises the sub-processor to use sub-sub-processors in the processing of personal data, subject to applicable data protection legislation. A current list of sub-sub-processors is included in Annex B.
2. The sub-processor ensures that sub-sub-processors are bound by written agreements to data processing obligations that offer at least an equivalent level of protection as the obligations under this sub-processing agreement.
3. The sub-processor ensures that each sub-sub-processor it engages complies with the obligations that apply to the sub-processor under this sub-processing agreement and applicable data protection legislation. The sub-processor remains fully responsible and liable towards the processor for processing by sub-sub-processors, as if the sub-processor carried out the processing itself.

### 7. Data breach

1. In the event of a data breach, the sub-processor shall notify the processor without undue delay after discovery of the data breach. The notification shall include, to the extent available, at least:
    - a description of the nature of the breach, including – where possible – how it occurred and the (presumed) date and time of the incident and of discovery;
    - the (categories of) personal data affected by the breach;
    - the (categories of) data subjects and, to the extent reasonably possible, an estimate of the number of affected data subjects;
    - the likely consequences and risks of the breach; and
    - the measures the sub-processor has taken or proposes to take to address the breach and limit possible adverse consequences.
2. If the sub-processor cannot provide all information referred to in Article 7.1 within the period mentioned in that article, the sub-processor shall provide the information available at that time within that period, while simultaneously stating the reasons why additional information is still missing. The sub-processor shall provide additional information subsequently without undue delay once it becomes available.
3. The sub-processor shall provide the processor with reasonable assistance in fulfilling its obligations under the GDPR in connection with the breach (including its obligations towards data controller(s)), including – where applicable – assistance with (i) notifications to the competent supervisory authority(ies) and (ii) communication to data subjects.

### 8. Security and confidentiality

1. The sub-processor has implemented appropriate technical and organisational measures for the security of personal data.
2. These security measures are designed at an appropriate level of security, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing and the varying likelihood and severity of risks to the rights and freedoms of natural persons. The (current) security measures are further described in Annex C.
3. The sub-processor monitors compliance with the security measures periodically and is entitled to adjust the security measures if this is reasonably necessary for the security, continuity or further development of the services.
4. The sub-processor limits access to personal data to those persons for whom access is necessary for the performance of the services. The sub-processor ensures that persons who process personal data under its authority are bound by an appropriate confidentiality obligation and have received appropriate instructions and training regarding data protection and information security.

### 9. Rights of data subjects

1. The sub-processor shall provide the processor, to the extent reasonably possible and taking into account the nature of the processing, with assistance in fulfilling its obligations regarding requests from data subjects to exercise their rights under the GDPR.
2. The sub-processor shall promptly forward requests from data subjects submitted directly to the sub-processor to the processor and shall not handle such requests independently, unless the processor has expressly given permission to do so.
3. The sub-processor may charge reasonable costs for assistance that goes beyond standard functionality of the services.

### 10. Transfer outside the EU/EEA

1. The sub-processor may process or transfer personal data outside the EU/EEA, provided that the requirements of Chapter V of the GDPR are met. The sub-processor ensures that a valid transfer mechanism applies, such as an adequacy decision, Standard Contractual Clauses (SCCs) adopted by the European Commission, or another instrument recognised by the GDPR.
2. Where Standard Contractual Clauses apply, they are deemed to form an integral part of this sub-processing agreement.

### 11. Data protection impact assessment and prior consultation

1. The sub-processor shall provide the processor, upon request and to the extent reasonably possible, with assistance in carrying out a data protection impact assessment (DPIA) and, where applicable, in prior consultation with the supervisory authority.

### 12. Audit

1. The sub-processor shall make available to the processor all information reasonably necessary to demonstrate compliance with the obligations under this sub-processing agreement, and shall enable audits – including inspections – by or on behalf of the processor, subject to the provisions of this article.
2. Audits are carried out at the expense of the processor, with reasonable prior written notice (at least 30 days), and are limited to what is necessary and proportionate to verify compliance with this sub-processing agreement.
3. The processor ensures that the audit is conducted professionally, does not disproportionately disrupt the sub-processor’s operations and does not jeopardise the confidentiality and security of the sub-processor’s data and those of its other customers.
4. The sub-processor is entitled to impose reasonable conditions on the audit, including (but not limited to) prior agreement on scope and planning, confidentiality obligations for auditors and restriction of access to data of other customers.
5. If the sub-processor has a current certificate, report or statement from an independent auditor (for example SOC 2 Type II, ISO 27001), this constitutes sufficient evidence of compliance with the relevant security obligations under this sub-processing agreement, unless the processor demonstrates in a motivated and written manner that additional investigation is necessary.

### 13. Liability

1. The liability of the sub-processor under or in connection with this sub-processing agreement is subject to the liability provisions and limitations as set out in the main agreement and the applicable general terms and conditions, to the extent permitted under mandatory law.

### 14. Miscellaneous

1. In the event of conflict between the provisions of this sub-processing agreement and the main agreement, this sub-processing agreement prevails to the extent it concerns the processing of personal data.
2. This sub-processing agreement is governed by Dutch law. Disputes arising from or in connection with this sub-processing agreement shall be submitted to the competent court in Amsterdam, unless otherwise prescribed by mandatory law.
3. If any provision of this sub-processing agreement is void, annulled or otherwise unenforceable, or if this sub-processing agreement contains a gap, the remaining provisions shall remain in full force and effect. In that case, the Parties shall consult to agree a replacement or supplementary provision that is legally valid and that aligns as closely as possible with the intent of the original provision, taking into account the requirements of Article 28 GDPR.

---

## Annex A: Details of the data processing

    Name and contact details of the sub-processor my.host
Pietersbergweg 291, 1105 BM Amsterdam
Email: privacy@my.host   Data protection officer Not appointed.   Representative of the sub-processor Not applicable.   Duration of the processing Processing starts on the effective date of the main agreement (between processor and sub-processor) and ends upon expiry or termination of that main agreement.   Services  The sub-processor processes personal data in the context of one or more of the following services: - Web hosting (including storage and provision of customer content)
- Email hosting
- DNS hosting and nameserver management
- Back-ups and disaster recovery
- Management and support of customer environments
- Monitoring and security of customer environments
- Domain name registration

    Nature and purposes of the processing The sub-processor processes personal data solely for and on the instruction of the processor for the provision of the services.   Data subjects  Depending on the services purchased by the processor and the content of customer data, the following categories of data subjects may be involved: - Employees and contact persons of the processor (including administrators and other authorised users)
- End users and visitors of the processor (including customers/contacts of the processor, website visitors and application users)
- Senders and recipients of email (to the extent email services are provided)
- Other natural persons whose personal data are processed by or on behalf of the processor in the customer environment(s) (e.g. prospects/leads, suppliers and their contact persons)

    Categories of personal data  Depending on the service(s) purchased by the processor, the sub-processor may process the following categories of personal data: ##### Web hosting (including customer content)

- Content, application data and databases provided or generated by the processor
- User account data (such as username and email address)
- IP addresses and technical metadata

##### Email hosting

- Content of email messages and associated attachments
- Header and routing data (including sender, recipient, timestamp, subject lines and email headers)
- Mailbox metadata and configuration data

##### DNS hosting and nameserver management

- DNS records and zone files, hostnames and technical IP addresses

##### Back-ups and disaster recovery

- Copies of customer content, databases and system configurations (including all categories of personal data stored therein by the processor)

##### Monitoring, performance and security logging

- IP addresses, timestamps and user-agent data
- Login and system events, event logs, error messages and performance logs

##### Management and support (including change management)

- Ticket content, contact details of requesters and contextual information relating to incidents or change requests
- Screenshots or log fragments provided by the processor or necessary for troubleshooting and problem resolution

##### Malware scanning, abuse detection and notice-and-take-down support

- Scan results, URLs, file names and IP addresses
- Communication data and metadata relating to reports and handling of abuse incidents

The nature, scope and specific content of the processed personal data are largely determined by the processor and depend on the data that the processor uploads, stores or otherwise makes available to the sub-processor in or via the services.

    Special categories of data The sub-processor has no knowledge of whether special categories of personal data are processed. The nature and content of the processed data are determined by the processor. If special categories of personal data are processed, the processor is responsible for a lawful basis for this.   Frequency of transfer Continuously throughout the term of the main agreement.   Retention periods  The sub-processor does not retain personal data longer than necessary for the performance of the services. Unless the Parties agree otherwise in writing or the processor gives other written instructions, the following retention periods apply: - **Active customer data** (web hosting, email, databases and other customer content): throughout the term of the main agreement. After termination, the sub-processor enables the processor to export or migrate customer data for 30 days. After this period, the sub-processor deletes customer data from production and management systems.
- **Back-ups and disaster recovery**: retained in accordance with the sub-processor’s regular back-up rotation, with a maximum retention period of 90 days, unless otherwise agreed in writing. Deletion from back-ups takes place through rotation.
- **Logging and monitoring** (e.g. access logs, server logs, security logs): maximum 12 months, to the extent necessary for security, incident investigation, abuse prevention, availability and troubleshooting.
- **Support and ticket data** (incl. communication and attachments/log fragments): maximum 48 months after closure of the ticket.

## Annex B: Sub-sub-processors

A current overview of all sub-sub-processors engaged by the sub-processor is available under the [Sub-processors](#subverwerkers) tab.

## Annex C: Security measures

The sub-processor implements and maintains appropriate technical and organisational security measures to protect personal data.

#### Organisational measures

- Periodic monitoring, evaluation and assessment of the effectiveness of organisational and technical measures.
- Procedure for compliance with retention periods and deletion in accordance with agreements/instructions.
- Confidentiality obligations for employees (contractual and/or via internal policy).
- Awareness and training of employees in the field of information security and privacy.

#### Technical measures

- Physical and network security: secured server rooms, network segmentation, firewalls, hardening.
- Encryption and secure transfer: TLS/STARTTLS (where applicable), encryption “in transit”.
- Email security: anti-spam/anti-virus, rate limiting, DMARC/DKIM/SPF (where applicable).
- DNS security: DNSSEC (where possible).
- Logging and monitoring: access logging, monitoring/alerting, SIEM/IDS (where appropriate), time synchronisation.
- Access security: MFA, least-privilege (where possible), jump host/bastion.
- Back-up/continuity: segregated storage, integrity checks.
- Malware/abuse: endpoint/malware scans, quarantines, controlled access to samples/logging.

---

## Can we help you?

We offer the best hardware, speed, support, service and the fairest price. Get in touch with no obligation to find out what the best solution is for you!

- Best-in-class customer service
- 24/7 monitoring
- Personal service

[Get in touch](/contact)

  ##### All services

[Domain name](/domain-names)

[Website Builder](/website-builder)

[Virtual Private Server](/vps)

[Dedicated server](/dedicated-server)

[Microsoft 365](/microsoft-365)

[SSL certificates](/ssl-certificate)

##### Domain name

[Register a domain name](/domain-names)

[Transfer a domain name](/domain-names/transfer)

[Domain name pricing](/domain-names/pricing)

[New domain extensions](/domain-names/new-extensions)

##### Hosting

[Web hosting](/web-hosting)

[WordPress hosting](/wordpress-hosting)

[Reseller hosting](/reseller-hosting)

##### Information

[About us](/about-us)

[Blog](/blog)

[Sustainability](/green-hosting)

[Affiliate program](/affiliate)

##### Legal

[Trust Center](/trust)

[Privacy policy](/privacy-policy)

[Report abuse](/report-abuse)

[Terms and conditions](/terms-and-conditions)

##### Support

[Customer service](/contact)

[Knowledge base](/kb/)

[API documentation](/api/doc/)

[Control panel](/cp/)

<a id="hyperping-badge"></a>

   © 2026 my.host

-

Hosting, Cloud &amp; Domains

-

All prices shown exclude VAT

-

[Nederlands](https://mijn.host/)

All prices shown exclude VAT

© 2026 my.host
