Legal
Data Processing Addendum
Data Processing Addendum (DPA)
Company details: Legal entity name, company number, registered office, VAT number, and ICO registration (if applicable) are configured by administrators and shown when available. Until configured, treat references to the controller identity as incomplete placeholders — not invented registrations.
1. When this DPA applies
This DPA applies where you are a controller and Rackstead processes personal data on your behalf in providing hosting Services (for example, personal data stored inside your VPS by your applications). It does not automatically replace Rackstead's role as controller of account, billing, and platform logs.
If your use case does not involve Rackstead processing personal data on your documented instructions as a processor, this DPA may not create a processor relationship for that activity.
2. Subject matter and duration
Processing of customer content/personal data stored or transmitted via the Services, for the duration of the service term and any deletion/return window.
3. Nature and purpose
Hosting, storage, transmission, backup (where enabled), security monitoring of infrastructure, and support access strictly as needed to provide the Services.
4. Types of personal data and data subjects
Determined by your use of the Services (you control what you place on the server). Rackstead does not decide the categories of end-user data you choose to process.
5. Instructions
Rackstead processes such data on your documented instructions (including configuration in the control panel and support tickets), unless required by law to act otherwise.
6. Confidentiality and security
Personnel authorised to access customer environments are subject to confidentiality obligations. Security measures are described at a high level in our Security Policy.
7. Sub-processors
Infrastructure and platform sub-processors are listed in /legal/subprocessors. We will maintain that register; material additions should be reviewed under your contract process once supplier notification mechanics are finalised by legal review.
8. Assistance
We will provide reasonable assistance with data-subject requests, breach notification, and DPIAs to the extent related to platform capabilities, subject to technical feasibility and cost for disproportionate requests.
9. Deletion / return
On termination, you may export data using available tools before deletion windows expire. Residual backups expire according to retention practices. Exact deletion timelines for processor data require operational confirmation and are not invented as fixed statutory periods here.
10. Audits
Reasonable information necessary to demonstrate compliance may be provided (e.g. security summaries). On-site audits require prior written agreement and confidentiality.
11. International transfers
See Privacy Policy and subprocessor register — transfer tools require legal confirmation per supplier.
12. Precedence
If there is a signed custom DPA between you and Rackstead, that signed document prevails over this public framework for that relationship.