hosting data processing agreement

Data Processing Agreement

Data Processing Agreement

This DPA applies where you use Techpullers Cloud services to process personal data of your own customers, users or staff and you require processor terms under the EU/UK GDPR, India's DPDP Act 2023, or similar law. Request a signed copy by ticket.

1. Roles

You are the controller of personal data on your hosted services. Techpullers Technology Solutions Pvt Ltd is the processor, acting only on your instructions as set out in the Terms of Service and your configuration of the services.

2. Scope of processing

Storage, transmission, backup and technical maintenance of data you upload to hosted services. We do not access the content of your data except as needed to provide support you request, to respond to security incidents, or as required by law.

3. Sub-processors

Sub-processor Purpose Location
OVHcloud (OVH SAS) Shared and Managed WordPress server infrastructure Gravelines, France
Hetzner Online GmbH Cloud, dedicated server and backup storage infrastructure Germany, Finland, Singapore, USA (customer's choice)
CloudLinux Inc. (Imunify360) Malware scanning on shared servers Server-side; threat data processed per CloudLinux policy
cPanel LLC Control panel software licensing Server-side
WHMCS / billing provider Billing and support portal location
Payment processors: Razorpay, Stripe/other Payment processing India / location
ResellerClub / Endurance Domain registration India

We will notify you of new sub-processors 30 days before engagement; you may object on reasonable grounds.

4. Data location and transfers

Shared, Managed WordPress and backup data is stored in the EU (France, Germany, Finland). Cloud and managed cloud data is stored in the location you select at order. Support access from India is subject to the security measures below and, for EU data, to standard contractual clauses on request.

5. Security measures

Account isolation (CloudLinux CageFS/LVE), malware scanning and WAF, encrypted transport (TLS), encrypted storage of credentials, access logging, role-based staff access, daily backups stored in a separate data centre, monthly restore testing, and the network and physical security of ISO/IEC 27001-certified facilities. Full list on the Security & Backups page.

6. Breach notification

We notify you without undue delay, and within 48 hours of becoming aware, of any personal data breach affecting your services, with the information we have at the time and updates as we learn more.

7. Assistance and rights

We assist you with data subject requests, impact assessments and regulator enquiries to the extent the request relates to our processing, at no charge for reasonable requests.

8. Deletion and return

On termination, data is retained 14 days for your retrieval, then deleted from live systems; backups expire per plan retention (14–60 days).

9. Audit

On reasonable notice, once per year, you may request evidence of our compliance: certifications of our sub-processors, our security policy, and a completed questionnaire. On-site audits of sub-processor facilities are governed by their terms.

Get started

Talk to an engineer about your site

GST invoice on every payment. Same price on renewal.