Data Processing Agreement
Between SIA "WS Group" (registration number 44103127763, Gustava Zemgala gatve 71, LV-1039, Rīga, Latvia) — the "Processor" — and the customer named in the hosting contract — the "Controller".
This agreement is concluded under Article 28 of Regulation (EU) 2016/679 (GDPR) and forms part of the hosting Terms and Conditions. It applies whenever the Controller stores personal data on services provided by the Processor.
1. Subject matter and duration
The Processor provides virtual servers, shared hosting, dedicated servers and related services. Personal data is processed for as long as the service is active, and deleted after termination as described in clause 7.
2. Nature and purpose of processing
The Processor stores and hosts data on the Controller's behalf. It does not access the content of that data except where necessary to deliver, maintain or secure the service, to comply with the law, or on the Controller's documented instruction.
3. Categories of data and data subjects
The categories are determined by the Controller. Typically they include the Controller's own customers, employees and website visitors, and data such as names, contact details, account credentials, order and billing records, IP addresses and log files.
4. Obligations of the Processor
- process personal data only on documented instructions from the Controller;
- ensure that persons authorised to process the data are bound by confidentiality;
- implement the technical and organisational measures set out in clause 5;
- assist the Controller in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR;
- notify the Controller without undue delay after becoming aware of a personal data breach;
- make available the information necessary to demonstrate compliance with this agreement.
5. Security measures
- data centre with controlled physical access, redundant power and cooling (CloudHosting, Rīga);
- segregation of customer environments; firewalling and access control;
- encrypted administrative access; credentials stored encrypted;
- logging and monitoring of administrative actions;
- daily backups where the service plan includes them;
- pseudonymisation where appropriate to the risk.
6. Sub-processors
The Controller authorises the Processor to engage sub-processors for infrastructure and connectivity. Current sub-processors are the data centre and network providers used to operate the platform. The Processor remains fully liable for their performance and will inform the Controller of intended changes, giving the Controller the opportunity to object.
7. Deletion and return of data
On termination the Processor deletes the Controller's data, including backups, within a reasonable period, unless retention is required by law. On written request made before deletion, the Processor will make the data available for export.
8. Audits
The Processor makes available the information necessary to demonstrate compliance and allows for audits, including inspections, conducted by the Controller or an auditor mandated by it, on reasonable notice and during business hours.
9. International transfers
Personal data is stored in the European Union (Latvia). Any transfer outside the EEA takes place only where a lawful transfer mechanism under Chapter V GDPR is in place.
10. Contact
Questions about data processing, requests for a signed copy of this agreement and data subject requests: [email protected].
This text is provided for review; a countersigned copy is issued on request.