Sub-processing Agreement
Version: April 2026
This sub-processing agreement, including its annexes, is entered into between my.host (hereinafter: the “sub-processor”) and the customer who purchases services from my.host as a processor (hereinafter: the “processor”) and sets out the arrangements between the Parties regarding the processing of personal data carried out by the sub-processor on behalf of and for the benefit of the processor in the context of the services provided by the sub-processor to the processor.
This sub-processing agreement applies exclusively to the processing of personal data by the sub-processor for the benefit of the processor in the context of the services that my.host provides to the processor under the main agreement. The sub-processor processes personal data on the basis of documented instructions from the processor. To the extent my.host processes personal data as an independent data controller or as (main) processor for its own customers, that processing falls outside the scope of this sub-processing agreement.
Parties
This sub-processing agreement applies between my.host (Pietersbergweg 291, 1105 BM Amsterdam, Chamber of Commerce: 89592514), hereinafter the “sub-processor”, and the processor who purchases services from my.host for the benefit of its data controller(s). Collectively referred to as the “Parties” and individually as a “Party”.
1. General
- The Parties agree that this sub-processing agreement replaces all previously agreed (sub)processing agreements and/or privacy or data protection provisions between the Parties relating to the same services, unless the Parties have expressly agreed otherwise in writing.
- This sub-processing agreement applies only if and to the extent that the processing of personal data is governed by the GDPR. Terms from the GDPR used in this sub-processing agreement, including “personal data”, “processing”, “data controller”, “processor” and “sub-processor”, have the meaning assigned to them in the GDPR.
- This sub-processing agreement is deemed to form an integral part of the main agreement between the sub-processor and the processor. For the purposes of this sub-processing agreement, the term “sub-sub-processor” means: a third party engaged by the sub-processor for (part of) the processing of personal data.
2. Annexes
The following annexes form an integral part of this sub-processing agreement:
- Annex A: Details of the data processing
- Annex B: Sub-sub-processors
- Annex C: Security measures (technical and organisational measures)
3. Purpose of the processing
- The sub-processor undertakes, in accordance with the terms of this sub-processing agreement, to carry out the processing of personal data on behalf of the processor.
- The processing of personal data by the sub-processor takes place exclusively in the context of performing the main agreement, strictly in accordance with the documented instructions of the processor, and relates to one or more of the services as further described in Annex A. The sub-processor shall not use the personal data for any other purpose or in any other manner than for the purpose communicated by the processor.
- Additional or deviating instructions apply only if the Parties have agreed them in writing, whereby the sub-processor is entitled to charge any (reasonable) costs associated with carrying out such instructions to the processor.
4. Obligations
- The processor declares and warrants that it will at all times comply with applicable data protection legislation (including the GDPR) with regard to (i) the personal data it provides to the sub-processor or has processed via the services and (ii) the (processing) instructions it gives to the sub-processor. The processor warrants that the processing of personal data via the services is lawful, that it is authorised to do so on the basis of a data processing agreement with the relevant data controller(s), and that the sub-processor may process the personal data on the basis of the main agreement and this sub-processing agreement in accordance with applicable data protection legislation.
- The processor warrants that it is authorised to engage the sub-processor and that the instructions it gives are lawful.
- The sub-processor is not responsible for assessing whether the instructions of the processor (or the underlying instructions of the data controller(s)) comply with applicable laws and regulations.
- The details of the processing are set out in Annex A (Details of the data processing).
- The processor shall inform the sub-processor in writing and with reasonable prior notice if it intends to make changes to the processing referred to above, including (but not limited to) changes in the nature, purposes, categories of personal data or categories of data subjects. If necessary, the Parties shall amend Annex A accordingly.
5. Term of the sub-processing agreement and termination
- This sub-processing agreement is entered into for the term set out in the main agreement. The Parties remain bound by obligations under this sub-processing agreement that by their nature continue to apply after termination.
- This sub-processing agreement terminates automatically when the main agreement is terminated.
- After termination of the main agreement, the sub-processor deletes all personal data in accordance with the retention periods set out in Annex A, unless Union law or Member State law requires retention.
- If the sub-processor is unable to delete personal data for technical or other reasons, the sub-processor shall take reasonable measures to ensure that the personal data are blocked from further processing and, to the extent technically possible, anonymised.
6. Sub-sub-processors
- The processor hereby authorises the sub-processor to use sub-sub-processors in the processing of personal data, subject to applicable data protection legislation. A current list of sub-sub-processors is included in Annex B.
- The sub-processor ensures that sub-sub-processors are bound by written agreements to data processing obligations that offer at least an equivalent level of protection as the obligations under this sub-processing agreement.
- The sub-processor ensures that each sub-sub-processor it engages complies with the obligations that apply to the sub-processor under this sub-processing agreement and applicable data protection legislation. The sub-processor remains fully responsible and liable towards the processor for processing by sub-sub-processors, as if the sub-processor carried out the processing itself.
7. Data breach
- In the event of a data breach, the sub-processor shall notify the processor without undue delay after discovery of the data breach. The notification shall include, to the extent available, at least:
- a description of the nature of the breach, including – where possible – how it occurred and the (presumed) date and time of the incident and of discovery;
- the (categories of) personal data affected by the breach;
- the (categories of) data subjects and, to the extent reasonably possible, an estimate of the number of affected data subjects;
- the likely consequences and risks of the breach; and
- the measures the sub-processor has taken or proposes to take to address the breach and limit possible adverse consequences.
- If the sub-processor cannot provide all information referred to in Article 7.1 within the period mentioned in that article, the sub-processor shall provide the information available at that time within that period, while simultaneously stating the reasons why additional information is still missing. The sub-processor shall provide additional information subsequently without undue delay once it becomes available.
- The sub-processor shall provide the processor with reasonable assistance in fulfilling its obligations under the GDPR in connection with the breach (including its obligations towards data controller(s)), including – where applicable – assistance with (i) notifications to the competent supervisory authority(ies) and (ii) communication to data subjects.
8. Security and confidentiality
- The sub-processor has implemented appropriate technical and organisational measures for the security of personal data.
- These security measures are designed at an appropriate level of security, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing and the varying likelihood and severity of risks to the rights and freedoms of natural persons. The (current) security measures are further described in Annex C.
- The sub-processor monitors compliance with the security measures periodically and is entitled to adjust the security measures if this is reasonably necessary for the security, continuity or further development of the services.
- The sub-processor limits access to personal data to those persons for whom access is necessary for the performance of the services. The sub-processor ensures that persons who process personal data under its authority are bound by an appropriate confidentiality obligation and have received appropriate instructions and training regarding data protection and information security.
9. Rights of data subjects
- The sub-processor shall provide the processor, to the extent reasonably possible and taking into account the nature of the processing, with assistance in fulfilling its obligations regarding requests from data subjects to exercise their rights under the GDPR.
- The sub-processor shall promptly forward requests from data subjects submitted directly to the sub-processor to the processor and shall not handle such requests independently, unless the processor has expressly given permission to do so.
- The sub-processor may charge reasonable costs for assistance that goes beyond standard functionality of the services.
10. Transfer outside the EU/EEA
- The sub-processor may process or transfer personal data outside the EU/EEA, provided that the requirements of Chapter V of the GDPR are met. The sub-processor ensures that a valid transfer mechanism applies, such as an adequacy decision, Standard Contractual Clauses (SCCs) adopted by the European Commission, or another instrument recognised by the GDPR.
- Where Standard Contractual Clauses apply, they are deemed to form an integral part of this sub-processing agreement.
11. Data protection impact assessment and prior consultation
- The sub-processor shall provide the processor, upon request and to the extent reasonably possible, with assistance in carrying out a data protection impact assessment (DPIA) and, where applicable, in prior consultation with the supervisory authority.
12. Audit
- The sub-processor shall make available to the processor all information reasonably necessary to demonstrate compliance with the obligations under this sub-processing agreement, and shall enable audits – including inspections – by or on behalf of the processor, subject to the provisions of this article.
- Audits are carried out at the expense of the processor, with reasonable prior written notice (at least 30 days), and are limited to what is necessary and proportionate to verify compliance with this sub-processing agreement.
- The processor ensures that the audit is conducted professionally, does not disproportionately disrupt the sub-processor’s operations and does not jeopardise the confidentiality and security of the sub-processor’s data and those of its other customers.
- The sub-processor is entitled to impose reasonable conditions on the audit, including (but not limited to) prior agreement on scope and planning, confidentiality obligations for auditors and restriction of access to data of other customers.
- If the sub-processor has a current certificate, report or statement from an independent auditor (for example SOC 2 Type II, ISO 27001), this constitutes sufficient evidence of compliance with the relevant security obligations under this sub-processing agreement, unless the processor demonstrates in a motivated and written manner that additional investigation is necessary.
13. Liability
- The liability of the sub-processor under or in connection with this sub-processing agreement is subject to the liability provisions and limitations as set out in the main agreement and the applicable general terms and conditions, to the extent permitted under mandatory law.
14. Miscellaneous
- In the event of conflict between the provisions of this sub-processing agreement and the main agreement, this sub-processing agreement prevails to the extent it concerns the processing of personal data.
- This sub-processing agreement is governed by Dutch law. Disputes arising from or in connection with this sub-processing agreement shall be submitted to the competent court in Amsterdam, unless otherwise prescribed by mandatory law.
- If any provision of this sub-processing agreement is void, annulled or otherwise unenforceable, or if this sub-processing agreement contains a gap, the remaining provisions shall remain in full force and effect. In that case, the Parties shall consult to agree a replacement or supplementary provision that is legally valid and that aligns as closely as possible with the intent of the original provision, taking into account the requirements of Article 28 GDPR.
Annex A: Details of the data processing
| Name and contact details of the sub-processor |
my.host Pietersbergweg 291, 1105 BM Amsterdam Email: privacy@my.host |
| Data protection officer |
Not appointed. |
| Representative of the sub-processor |
Not applicable. |
| Duration of the processing |
Processing starts on the effective date of the main agreement (between processor and sub-processor) and ends upon expiry or termination of that main agreement. |
| Services |
The sub-processor processes personal data in the context of one or more of the following services:
- Web hosting (including storage and provision of customer content)
- Email hosting
- DNS hosting and nameserver management
- Back-ups and disaster recovery
- Management and support of customer environments
- Monitoring and security of customer environments
- Domain name registration
|
| Nature and purposes of the processing |
The sub-processor processes personal data solely for and on the instruction of the processor for the provision of the services. |
| Data subjects |
Depending on the services purchased by the processor and the content of customer data, the following categories of data subjects may be involved:
- Employees and contact persons of the processor (including administrators and other authorised users)
- End users and visitors of the processor (including customers/contacts of the processor, website visitors and application users)
- Senders and recipients of email (to the extent email services are provided)
- Other natural persons whose personal data are processed by or on behalf of the processor in the customer environment(s) (e.g. prospects/leads, suppliers and their contact persons)
|
| Categories of personal data |
Depending on the service(s) purchased by the processor, the sub-processor may process the following categories of personal data:
Web hosting (including customer content)
- Content, application data and databases provided or generated by the processor
- User account data (such as username and email address)
- IP addresses and technical metadata
Email hosting
- Content of email messages and associated attachments
- Header and routing data (including sender, recipient, timestamp, subject lines and email headers)
- Mailbox metadata and configuration data
DNS hosting and nameserver management
- DNS records and zone files, hostnames and technical IP addresses
Back-ups and disaster recovery
- Copies of customer content, databases and system configurations (including all categories of personal data stored therein by the processor)
Monitoring, performance and security logging
- IP addresses, timestamps and user-agent data
- Login and system events, event logs, error messages and performance logs
Management and support (including change management)
- Ticket content, contact details of requesters and contextual information relating to incidents or change requests
- Screenshots or log fragments provided by the processor or necessary for troubleshooting and problem resolution
Malware scanning, abuse detection and notice-and-take-down support
- Scan results, URLs, file names and IP addresses
- Communication data and metadata relating to reports and handling of abuse incidents
The nature, scope and specific content of the processed personal data are largely determined by the processor and depend on the data that the processor uploads, stores or otherwise makes available to the sub-processor in or via the services.
|
| Special categories of data |
The sub-processor has no knowledge of whether special categories of personal data are processed. The nature and content of the processed data are determined by the processor. If special categories of personal data are processed, the processor is responsible for a lawful basis for this. |
| Frequency of transfer |
Continuously throughout the term of the main agreement. |
| Retention periods |
The sub-processor does not retain personal data longer than necessary for the performance of the services. Unless the Parties agree otherwise in writing or the processor gives other written instructions, the following retention periods apply:
- Active customer data (web hosting, email, databases and other customer content): throughout the term of the main agreement. After termination, the sub-processor enables the processor to export or migrate customer data for 30 days. After this period, the sub-processor deletes customer data from production and management systems.
- Back-ups and disaster recovery: retained in accordance with the sub-processor’s regular back-up rotation, with a maximum retention period of 90 days, unless otherwise agreed in writing. Deletion from back-ups takes place through rotation.
- Logging and monitoring (e.g. access logs, server logs, security logs): maximum 12 months, to the extent necessary for security, incident investigation, abuse prevention, availability and troubleshooting.
- Support and ticket data (incl. communication and attachments/log fragments): maximum 48 months after closure of the ticket.
|
Annex B: Sub-sub-processors
A current overview of all sub-sub-processors engaged by the sub-processor is available under the Sub-processors tab.
Annex C: Security measures
The sub-processor implements and maintains appropriate technical and organisational security measures to protect personal data.
Organisational measures
- Periodic monitoring, evaluation and assessment of the effectiveness of organisational and technical measures.
- Procedure for compliance with retention periods and deletion in accordance with agreements/instructions.
- Confidentiality obligations for employees (contractual and/or via internal policy).
- Awareness and training of employees in the field of information security and privacy.
Technical measures
- Physical and network security: secured server rooms, network segmentation, firewalls, hardening.
- Encryption and secure transfer: TLS/STARTTLS (where applicable), encryption “in transit”.
- Email security: anti-spam/anti-virus, rate limiting, DMARC/DKIM/SPF (where applicable).
- DNS security: DNSSEC (where possible).
- Logging and monitoring: access logging, monitoring/alerting, SIEM/IDS (where appropriate), time synchronisation.
- Access security: MFA, least-privilege (where possible), jump host/bastion.
- Back-up/continuity: segregated storage, integrity checks.
- Malware/abuse: endpoint/malware scans, quarantines, controlled access to samples/logging.