Data Processing Agreement
The short version
- A Data Processing Agreement (DPA) is the contract that, under EU data-protection law, must be in place whenever one party handles personal data on another party’s behalf. When you host data with us, you decide what that data is and why; we simply process it to run the Services. That makes you the controller and us the processor.
- This DPA is in force by default for every paid account — you do not need to sign anything separately. It forms part of our Terms of Service.
- We process your data only on your instructions, keep it within the EU/EEA, and apply the security measures set out in Annex 2.
- We give you at least 30 days’ notice before adding or replacing a subprocessor, so you can object.
- If there is ever a personal-data breach affecting your data, we notify you without undue delay so you can meet your own 72-hour duty.
- Resold Email (Microsoft 365 / Google Workspace) lives in your own tenant, not on our infrastructure, and is governed by Microsoft’s or Google’s own terms and DPAs — not this one.
This summary is for convenience only. The numbered clauses below are the binding agreement.
1. Background, scope & order of precedence
This DPA (Data Processing Agreement) records the terms on which Maxinodes (“we”, “us”, “our” — Maxinodes Ltd, a private company limited by shares registered in Ireland, registered office 1 Ballycoolin Road, Dublin 15, Ireland) processes personal data on behalf of the Customer (“you”, “your”) in connection with the Services.
It is concluded under and gives effect to Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Irish Data Protection Act 2018.
This DPA forms part of, and is incorporated into, our Terms of Service (the “Terms”). It is in force by default for every paid account from the moment you place an Order; no separate signature is required, although a signed counterpart is available on request to [email protected].
This DPA applies only where, and to the extent that, we process personal data on your behalf as a processor in providing the Services. It does not apply to personal data for which we are the controller in our own right (for example, your account, billing and contact data, and our own operational logs); that processing is governed by our Privacy Policy.
Order of precedence. In the event of any conflict on data-protection matters, the documents prevail in this order: (a) this DPA; (b) the rest of the Terms; (c) any other Maxinodes policy. On all matters other than data protection, the Terms prevail over this DPA. Mandatory provisions of applicable data-protection law prevail over all of them.
Duration. This DPA takes effect when you first place an Order and continues for as long as we process personal data on your behalf. It terminates automatically with the main contract under the Terms, save that any provisions which by their nature should survive (including confidentiality and the return-or-deletion obligations in clause 11) survive termination.
2. Definitions & roles
Capitalised terms not defined here have the meaning given to them in the Terms. The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “special categories of personal data”, “personal data breach” and “supervisory authority” have the meanings given to them in the GDPR.
2.1 Roles of the parties
In respect of personal data contained in the Content / Customer Data that you store on, or transmit through, the Services:
- the Customer is the controller (or, where the Customer itself acts as a processor for a third party, the processor); and
- Maxinodes is the processor (or, where applicable, the sub-processor) acting on the Customer’s behalf.
You confirm that you are entitled to transfer the Customer Data to us so that we may lawfully process it in accordance with this DPA and your instructions, and that you have a lawful basis for that processing and have provided all required notices to data subjects.
2.2 Resold Email carve-out
Resold Email (Microsoft 365 or Google Workspace mailboxes resold by us) is hosted in the Customer’s own tenant with Microsoft or Google. The personal data in those mailboxes does not sit on Maxinodes infrastructure and is outside the scope of our processing under this DPA. For Resold Email, the relevant provider (Microsoft or Google) is your processor, under that provider’s own terms, DPA and security commitments. Our only role is to resell the licences; we do not access mailbox content as part of that role.
3. Details of the processing
The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1 (Details of the processing), which forms part of this DPA. Because the Services are general-purpose hosting, the precise personal data processed depends on what you choose to store and transmit; Annex 1 describes the typical, default position and the categories within which your actual use will fall.
4. Processing on documented instructions
We process personal data only on your documented instructions, including with regard to transfers, unless required to do otherwise by EU or Irish law to which we are subject; in that case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (GDPR Art. 28(3)(a)).
Your documented instructions are made up of: (a) this DPA and the Terms; (b) your configuration and use of the Services through the Client Area and the Services themselves; and (c) any further written instructions you give us (for example by ticket or to [email protected]) that are consistent with the Terms. Instructions that go beyond the standard functionality of the Services may be subject to a separate agreement, including on cost.
We will inform you without undue delay if, in our opinion, an instruction infringes the GDPR or other EU or Irish data-protection law. We may suspend performance of the affected instruction until you confirm, amend or withdraw it; we are not obliged to carry out an instruction we reasonably believe to be unlawful.
5. Confidentiality
We ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR Art. 28(3)(b)). That obligation survives the end of their engagement with us.
Access to personal data processed under this DPA is granted on a need-to-know basis only, under the principle of least privilege, and is limited to personnel and subprocessors who need it to provide, secure or support the Services.
6. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (GDPR Art. 28(3)(c) and Art. 32).
The measures we maintain are set out in Annex 2 (Technical & organisational measures), which forms part of this DPA. We may update these measures from time to time provided the level of protection is not materially reduced. You are responsible for assessing whether those measures meet your requirements and for the security of anything within your own control (including your application code, credentials, access management and the configuration choices you make in the Client Area and within your environment).
7. Subprocessors
You give us a general written authorisation to engage subprocessors to carry out specific processing activities on your behalf (GDPR Art. 28(2) and (4)). A current list of our subprocessors is maintained on the Subprocessors page.
7.1 Notice and right to object
We will give you at least 30 days’ prior notice of any intended addition or replacement of a subprocessor, by updating the Subprocessors page and, where you have subscribed to change notifications, by email. Within that notice period you may object on reasonable, data-protection-related grounds by writing to [email protected]. If we cannot accommodate a well-founded objection, you may terminate the affected Services on written notice as your sole remedy, in accordance with the Terms.
7.2 Flow-down of obligations
Where we engage a subprocessor, we do so under a written contract that imposes on it data-protection obligations equivalent in substance to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a subprocessor fails to fulfil its data-protection obligations, we remain fully liable to you for the performance of that subprocessor’s obligations.
8. Assisting with data-subject requests
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR — access, rectification, erasure, restriction, data portability, and objection (GDPR Art. 28(3)(e)).
If we receive a request directly from a data subject relating to personal data we process on your behalf, we will not respond directly (except to confirm that the request should be directed to you) and will, unless legally prohibited, forward the request to you without undue delay. The Client Area also gives you self-service tools to access, export and delete much of the Customer Data directly.
9. Assisting with security, breaches & DPIAs
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under GDPR Articles 32 to 36 (GDPR Art. 28(3)(f)), namely:
- Security of processing (Art. 32) — by maintaining the measures in Annex 2 and making available the information described in clause 12;
- Personal-data-breach notification (Arts. 33–34) — by notifying you and providing the information described in clause 10;
- Data-protection impact assessments and prior consultation (Arts. 35–36) — by providing, on reasonable request, the information about the Services within our possession that you reasonably need to carry out a DPIA or to consult the supervisory authority.
Where the assistance you request goes beyond the standard information and tooling we make available, we may charge our reasonable costs, notified to you in advance.
10. Personal-data-breach notification
We notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf (GDPR Art. 33(2)). Our notification will, to the extent then known and to help you meet your own 72-hour duty under Art. 33(1), describe:
- the nature of the breach, including, where possible, the categories and approximate number of data subjects and of personal-data records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- a contact point from whom you can obtain more information.
Where it is not possible to provide all of this information at once, we may provide it in phases without further undue delay. Notifications are routed through [email protected], and, for abuse- or security-incident reports, [email protected]. It remains your responsibility as controller to assess the breach and to notify the supervisory authority and, where required, affected data subjects; we do not make those notifications on your behalf unless separately agreed in writing.
11. Return or deletion on termination
On termination of the Services to which the processing relates, we will, at your choice, either return the Customer Data to you or delete it, and delete existing copies, unless EU or Irish law requires storage of the personal data (GDPR Art. 28(3)(g)).
You may make your choice through the Client Area or by writing to [email protected]. In the absence of a documented instruction, and following a reasonable retrieval window after termination, we will delete the Customer Data.
Two practical limits apply, both consistent with the GDPR:
- Legal retention. Where we are required by law to retain certain data (for example, records needed for tax or accounting purposes), we will retain only that data, only for as long as required, and continue to protect it under this DPA.
- Backup cycle. Encrypted backups, which are stored within the EU/EEA, are overwritten on their normal rotation cycle. Data persisting only in those backups is isolated from active processing and is deleted in the ordinary course as the backups expire.
12. Audits & information
We make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you (GDPR Art. 28(3)(h)).
In the first instance, we satisfy this obligation by providing the documentation we maintain about the Services, including the measures in Annex 2 and answers to your reasonable written security questionnaires. Where that is not sufficient for your demonstrable compliance, you may carry out an audit on the following basis:
- on reasonable prior written notice (normally at least 30 days);
- at most once per calendar year, unless a more frequent audit is required by a competent supervisory authority or following a personal-data breach affecting your data;
- during European business hours, in a manner that does not unreasonably disrupt our operations or compromise the confidentiality or security of other customers’ data;
- under an obligation of confidentiality, with any third-party auditor not being a competitor of ours and bound to confidentiality; and
- with each party bearing its own costs, save that we may charge our reasonable costs for audit support that goes materially beyond providing existing documentation.
13. International transfers
We process and store the Customer Data within the EU/EEA only. Our primary infrastructure is in enterprise data centres in the Netherlands, and encrypted backups are stored within the EU/EEA only. We do not transfer hosted service data to third countries (countries outside the EU/EEA).
If, in the future, providing the Services were to require a transfer to a non-EU/EEA subprocessor, we would not make that transfer without first updating the Subprocessors page in accordance with clause 7 and putting in place an appropriate transfer mechanism — in particular the European Commission’s Standard Contractual Clauses (SCCs) together with any supplementary measures required — on which basis the SCCs are reserved.
For the avoidance of doubt, the Resold Email path (clause 2.2) is separate: any transfer of mailbox data is carried out by Microsoft or Google under their own terms, DPAs and transfer mechanisms (including SCCs), not by us.
14. Liability
Each party’s liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the Terms. Nothing in this DPA increases or extends those limits; this DPA does not create a separate liability cap.
Nothing in this DPA or the Terms limits any liability that cannot be limited or excluded under applicable law, including liability under Article 82 of the GDPR towards data subjects. As elsewhere in our documents, nothing in this DPA affects your mandatory statutory rights as a Consumer; where you are a Consumer, the consumer-protective provisions of the Terms (including any narrower liability framework that applies in your favour) prevail over any provision of this DPA that would otherwise be less favourable to you.
15. Annex 1 — Details of the processing
This Annex sets out the details of the processing as required by GDPR Art. 28(3). Because the Services are general-purpose hosting, your actual personal data depends on what you choose to store and transmit; the table below describes the default position and the categories within which your use will fall.
| Item | Details |
|---|---|
| Subject-matter | Provision of the Services — Self-Managed Services (Lite, Plus, Pro) and Managed Services (Starter, Growth, Business, Enterprise) — comprising the hosting, storage, processing, transmission and backup of the Customer Data that the Customer stores on, or transmits through, the Services. |
| Duration | For the term of the main contract under the Terms, and thereafter until the Customer Data is returned or deleted in accordance with clause 11 (subject to legal-retention and backup-cycle exceptions). |
| Nature & purpose | Hosting and operating the Customer’s websites, applications, databases and files; storing and transmitting the Customer Data; creating and storing encrypted backups within the EU/EEA; providing technical support; and maintaining the security, integrity and availability of the Services. For Managed Services we additionally operate the underlying environment on the Customer’s behalf; Self-Managed Services are self-managed by the Customer. |
| Types of personal data | Any personal data the Customer includes in the Customer Data, the precise nature of which is determined and controlled by the Customer. Typically this may include identification and contact data, account and login data, transactional and order data, communications, technical identifiers (such as IP addresses and device data) and usage data of the Customer’s own users and contacts. The Customer must not store special categories of personal data or other high-risk data on the Services unless it has implemented the additional safeguards its own risk assessment requires and remains responsible for the lawfulness of doing so. |
| Categories of data subjects | The data subjects whose personal data is contained in the Customer Data, as determined by the Customer. Typically this may include the Customer’s own customers, end users, website visitors, employees, contractors, suppliers and other contacts. |
| Controller / processor | Customer = controller (or processor for a third party). Maxinodes = processor (or sub-processor). |
16. Annex 2 — Technical & organisational measures
This Annex describes the technical and organisational measures we maintain under Article 32 of the GDPR, organised by security goal. These are the ordinary, good-practice measures appropriate for our Services; we may update them provided the level of protection is not materially reduced. We make no certification claims of any kind.
16.1 Confidentiality
- Encryption in transit using current TLS for connections to the Services and the Client Area.
- Encryption at rest for stored data and for encrypted backups, which are kept within the EU/EEA only.
- Access controls on a least-privilege, need-to-know basis, with multi-factor authentication (MFA) required for administrative access.
- Physical security at enterprise data centres in the Netherlands, operated by our infrastructure subprocessor under its own access-control regime.
- Personnel bound to confidentiality (clause 5) and granted access only as needed for their role.
16.2 Integrity
- Separation and logical isolation of customer environments.
- Change management and the use of secure administrative channels for system access.
- Logging and monitoring of access to, and changes within, the infrastructure to support accountability and to detect unauthorised processing.
16.3 Availability & resilience
- Operation in enterprise data centres with resilient power, cooling and network connectivity.
- Continuous monitoring of the platform, network and facilities; incidents are communicated via the SLA process and on the Status Page (status.maxinodes.com), with our monitoring systems as the authoritative measurement source.
- Regular encrypted backups, stored within the EU/EEA only.
16.4 Restore
- The ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident, from the encrypted backups described above.
16.5 Regular testing & evaluation
- A process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures, including reviewing access rights, applying security updates, and verifying that backups can be restored.
17. Annex 3 — Subprocessors
We engage subprocessors as authorised under clause 7. The current list of subprocessors — including the infrastructure / data-centre operator in the Netherlands, our payment processor, and our monitoring provider, together with the processing each performs and its location — is maintained on the Subprocessors page. Where you purchase Resold Email, Microsoft or Google acts in respect of your own tenant under its own terms and DPA, as described in clause 2.2, rather than as our subprocessor under this DPA.
Contact
Data-protection and DPA enquiries: [email protected].
By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.
If you have a concern about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the supervisory authority in Ireland:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence.