Legal

GDPR – Data Processing Agreement

Last updated: March 25, 2026

Introduction

This Data Processing Agreement ("DPA") is an addendum to the Terms & Conditions between HostGrower Limited ("HostGrower Limited") and you ("Customer"). This DPA has been effective from 25th May 2018 and will remain in force for as long as HostGrower Limited provides services as described in its Terms & Conditions.

Definitions

  • Customer Data – Data provided by or on behalf of the Customer or the Customer's end users via the Services under the account.
  • Data Controller – The entity that determines the purposes and means of the processing of Personal Data.
  • Data Processor – The entity that processes Personal Data on behalf of the Data Controller.
  • Data Protection Laws – All applicable data protection and privacy laws, including the UK GDPR and the Data Protection Act 2018.
  • Data Subject – The individual to whom the Personal Data relates.
  • EEA – The European Economic Area.
  • GDPR – The UK General Data Protection Regulation, as retained in UK law by the European Union (Withdrawal) Act 2018, and the EU General Data Protection Regulation 2016/679 where applicable.
  • Personal Data – Any Customer Data relating to an identified or identifiable natural person that is protected as personal data under the GDPR.
  • Processing – As defined in the GDPR, including all associated variations: "process", "processes", and "processed".
  • Sub-Processor – Any third party authorised under this DPA to process Customer Data as part of the Services.
  • Services – Any product or service provided to the Customer, as described in HostGrower Limited's Terms & Conditions.

1. Data Processing

HostGrower Limited will only process Customer Data in accordance with documented instructions from the Customer (the "Instruction"), unless required by law to act otherwise. At the time of entering into this DPA, the Instruction is that HostGrower Limited may only process Customer Data for the purpose of delivering services as described in its Terms & Conditions and any product-specific agreements.

Subject to the terms of this DPA, the Customer may issue additional written instructions, provided they align with this agreement. The Customer is responsible for ensuring that individuals issuing such instructions are authorised to do so. If HostGrower Limited believes any instruction violates the GDPR, it will notify the Customer and not proceed until clarification or modification is received.

When Customer Data is processed by HostGrower Limited, both parties acknowledge:

  • HostGrower Limited is the Data Processor of Customer Data under the GDPR.
  • The Customer is the Data Controller of Customer Data under the GDPR.

2. Legal Basis for Processing

HostGrower Limited processes Customer Data on the following legal bases under the UK GDPR:

  • Contractual necessity – Processing required to perform the services described in the Terms & Conditions.
  • Legal obligation – Processing required to comply with applicable UK law.
  • Legitimate interests – Processing necessary for fraud prevention, network security, and service improvement, provided such interests are not overridden by the rights of Data Subjects.

3. Confidentiality

HostGrower Limited will treat all Customer Data as strictly confidential. Customer Data shall not be copied, transferred, or processed in violation of Customer instructions, unless required by law. All HostGrower Limited employees handling Customer Data are bound by confidentiality obligations and will only process data in accordance with Customer instructions.

4. Sub-Processing

The Customer authorises HostGrower Limited to engage third-party Sub-Processors for processing Customer Data. HostGrower Limited will:

  • Restrict Sub-Processor access to only what is necessary to provide the Services.
  • Enter into a written agreement with each Sub-Processor, ensuring GDPR compliance.
  • Remain accountable for Sub-Processors as if performing the services itself.

HostGrower Limited will notify the Customer at least 30 days in advance before engaging any new Sub-Processor. Notifications will be sent via email and/or through the control panel interface. If a Customer objects to a Sub-Processor, they may terminate this DPA and the related Services in accordance with the Terms & Conditions.

A current list of authorised Sub-Processors is provided in Annex 1 of this agreement.

5. Security

HostGrower Limited will implement appropriate technical and organisational measures to protect Customer Data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, and from cyber threats, as required by GDPR Article 32. Security measures will evolve with technical advancements and will not degrade the overall level of protection afforded to Customer Data. HostGrower Limited also provides controls within the control panel to enable Customers to enhance the security of their own data.

6. Data Breach Notifications

If HostGrower Limited detects a personal data breach, it will notify the Customer without undue delay via their registered email address and take all necessary steps to identify, contain, and resolve the breach. HostGrower Limited is not required to report unsuccessful security incidents that do not result in a risk to Customer Data, such as failed login attempts or port scans.

Where a breach is likely to result in a high risk to the rights and freedoms of individuals, HostGrower Limited will cooperate with the Customer to support any required notification to the Information Commissioner's Office (ICO) within the 72-hour timeframe stipulated by the UK GDPR.

7. Data Subject Rights

If HostGrower Limited receives a request directly from a Data Subject, it will forward the request to the Customer promptly. The Customer is responsible for responding within the timeframe required under the UK GDPR. HostGrower Limited will provide reasonable assistance via control panel tools where applicable to help the Customer fulfil its obligations.

8. Data Transfers

HostGrower Limited stores and processes Customer Data in secure data centres within the United Kingdom and/or the EEA. Where data is transferred outside these regions in connection with Sub-Processor operations, HostGrower Limited ensures that all such transfers comply with applicable UK GDPR requirements, including the use of appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms where required.

9. Compliance & Audit Rights

HostGrower Limited agrees to maintain records of its data protection and security practices. Upon written request, HostGrower Limited will provide relevant documentation to demonstrate GDPR compliance. Independent audits may be conducted with a minimum of 30 days' written notice, no more than once per calendar year, and at the Customer's expense unless a breach of this DPA is established.

10. Return or Deletion of Data

Customer Data will be retained only for as long as is necessary for the delivery of the Services. Upon termination of the Services, all Customer Data will be securely deleted, unless retention is required by applicable law. Data stored in backups will be securely isolated and permanently removed within a reasonable timeframe following termination.

11. Data Protection Contact

For all data protection enquiries, requests, or concerns relating to this DPA, please contact HostGrower Limited at:

  • Email: privacy@hostgrower.com
  • Post: HostGrower Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

12. Limitation of Liability

The total liability of each party under this DPA is subject to the limitations set out in the Terms & Conditions. HostGrower Limited shall not be liable for losses resulting from the Customer's misuse of the Services or failure to comply with its own obligations as Data Controller.

13. Value Added Tax (VAT)

All pricing for services excludes VAT at 20%, in accordance with UK regulations. VAT will be applied automatically at checkout where applicable. VAT Registration Number: GB 458 9261 48. Customers outside the UK may be eligible for VAT exemption or reclaim, subject to the provision of valid supporting documentation.

14. Governing Law

This DPA is governed by and construed in accordance with the laws of England and Wales. Any disputes arising in connection with this agreement shall be subject to the exclusive jurisdiction of the courts of England and Wales.

15. Changes to This Agreement

HostGrower Limited reserves the right to update this DPA at any time to reflect changes in law, regulation, or our data processing practices. Customers will be notified of any material changes via email or through the control panel at least 30 days prior to the changes taking effect. Continued use of the Services following notification constitutes acceptance of the revised DPA.

Annex 1 – Authorised Sub-Processors

  • Stripe – Credit/debit card payment processing
  • Nominet – Domain name registration and management
  • JISC – Domain name registration and management
  • Tucows (OpenSRS) – Domain name registration and management
  • Openprovider – Domain name registration and management
  • InternetX – Domain name registration and management
  • Sectigo – SSL/TLS certificate issuance and management
  • Google Analytics – Anonymised control panel analytics and reporting
  • MoneyPenny – Telephone answering service
HostGrower Support
Loading…