Skip to content
PIVIHOST
  • Hosting
  • VPS
  • Domains
  • Knowledge Base
  • Contact
Client Login Order Now
Menu
  • Hosting
  • VPS
  • Domains
  • Knowledge Base
  • Contact
  • Client Login
  • Order Now
  1. Home
  2. Data Processing Terms
DATA PROCESSING

Data Processing Terms

A real Article 28 processor agreement for personal data you store with us — not a generic template, and separate from how we handle your own account data.

Effective
2026-09-17
Last updated
2026-09-17

On this page

  1. Scope and purpose
  2. Roles: you are the controller, we are the processor
  3. Subject matter and duration of processing
  4. Nature and purpose of the processing
  5. Types of personal data and categories of data subjects
  6. Processing only on your instructions
  7. Confidentiality
  8. Security measures
  9. Sub-processors
  10. Assisting with data subject rights
  11. Assisting with security, breach, and DPIA obligations
  12. Deletion or return of data
  13. Audit and information rights
  14. Contact

Scope and purpose

These Data Processing Terms apply whenever personal data is contained within Content you store, transmit, or make available using our hosting, VPS, or related Services ("Customer Content") — for example, personal data about your own customers, subscribers, or website visitors that you choose to keep in a database, mailbox, or application we host for you. They form part of our Terms of Service and give effect to Article 28(3) of the UK GDPR for that specific relationship.

They do not apply to your own account, billing, and support data — that's covered by our Privacy Notice as ordinary controller-role processing, not an Article 28 relationship, because that's data about you as our customer, not data you're asking us to process on someone else's behalf.

Roles: you are the controller, we are the processor

For Customer Content, you are the data controller — you decide what personal data to store with us and why — and we are the data processor, acting only on your instructions as set out here. If your own use of the Services means you're processing personal data on behalf of your own customers (for example, you run an online shop and we host your customer database), you remain responsible for your own lawful basis and your own privacy notice to your users — we have no visibility into, and make no decisions about, that relationship.

Subject matter and duration of processing

The subject matter is the storage, transmission, and (where your plan includes it) backup of Customer Content, for as long as you have an active Service with us. Processing ends when your Service ends, subject to §Deletion or return of data below.

Nature and purpose of the processing

The processing is purely infrastructural: storing Customer Content on our servers, transmitting it as needed to serve your website or application, and — only where your plan includes backup functionality — creating and retaining backup copies. We don't process Customer Content for any purpose of our own (no analytics on it, no use for our own marketing, no disclosure to third parties) beyond providing the Service, securing it, and enforcing our Acceptable Use Policy.

Types of personal data and categories of data subjects

You control what personal data Customer Content contains and whose it is — we don't dictate or restrict this beyond what our Acceptable Use Policy already prohibits (for example, no unlawfully obtained data). Customer Content may include any category of personal data or data subject you choose to store using the Services, ordinarily limited only by the storage and resource allocations of your plan.

Processing only on your instructions

We process Customer Content only on your documented instructions — which means these Data Processing Terms, the rest of our Terms of Service, and your own configuration and use of the Services (for example, what you choose to store, and any support request you make to us) — unless we're required to do otherwise by UK law. If a legal requirement obliges us to process Customer Content beyond your instructions, we'll tell you first, unless that law prohibits us from doing so on important grounds of public interest.

Confidentiality

Anyone we authorise to process Customer Content — our own staff, or anyone working for us — is subject to a duty of confidentiality over it, whether contractual or statutory.

Security measures

We apply the security measures described in our Terms §Security and Hosting page (including CloudLinux resource isolation and Imunify360 malware protection on hosting plans) to Customer Content in the same way as the rest of the Service — we don't apply a lower standard to data because it's a customer's rather than our own.

Sub-processors

You give us general written authorisation to engage the infrastructure provider that physically hosts our servers (currently located in Poland — see our Company Details page for the current, factual location) as a sub-processor for Customer Content, since storing Customer Content on physical infrastructure is inherent to providing the Service at all. We'll impose data-protection obligations on that sub-processor equivalent to these Data Processing Terms, and we remain responsible to you for its performance. If we ever intend to add a materially different category of sub-processor for Customer Content specifically (not merely the infrastructure host itself), we'll give you reasonable notice and the opportunity to object on reasonable data-protection grounds before that change takes effect.

Assisting with data subject rights

Because we don't inspect or index Customer Content, we generally can't identify or act on a data subject's request about it ourselves — that's your responsibility as controller. Where you need our help (for example, technical assistance locating or deleting specific data within your own hosted application), we'll provide reasonable assistance, which may be chargeable if it requires meaningful engineering time beyond standard support.

Assisting with security, breach, and DPIA obligations

If we become aware of a personal data breach affecting Customer Content, we'll notify you without undue delay. We'll provide reasonable assistance with any data protection impact assessment or prior consultation with the ICO you need to carry out in relation to your use of the Services, based on the factual information we can reasonably provide about how the Services process data.

Deletion or return of data

At the end of your Service, you can export or download Customer Content through your control panel before it ends, or request a copy from us. Once the Service has ended, we delete Customer Content within 30 days as described in Terms §Your data after a Service ends, unless we're legally required to keep it for longer — we don't offer indefinite retention of Customer Content on request, since that would work against your own data-minimisation obligations as controller, not just ours.

Audit and information rights

We'll make available to you the information reasonably necessary to demonstrate our compliance with these Data Processing Terms — in practice, a summary of the security and processing measures described above and in our Terms and Privacy Notice. Given the realities of shared and virtualised hosting infrastructure, we satisfy this through documentation rather than on-site inspection by default; if you reasonably need something more (for example, because your own regulatory obligations require it), contact us and we'll discuss what's practical.

Contact

Questions about these Data Processing Terms, or about a specific processing arrangement for your Service, can be sent to admin@pivihost.com.

PIVIHOST

Pivi Website Ltd · company no. 13138238

Products

  • Shared Hosting
  • Hosting — Unlimited Domains
  • VPS
  • Domains

Support

  • Knowledge Base
  • Submit a Ticket
  • Contact

Company

  • About / Contact
  • Company Details

Legal

  • Terms of Service
  • Privacy Notice
  • Acceptable Use Policy
  • Domain Terms
  • Cookie Notice
  • Data Processing Terms
© 2026 Pivi Website Ltd. All rights reserved. Client Login