Data Processing Agreement v2 Archive

How we process data on your behalf

This agreement sets out how Pladinum processes personal data on your behalf as your data processor under Article 28 of the GDPR, including security, sub-processors, and transfers.

Last revised: 17 June 2026

We want to make sure you have all the information you need. While we provide translations of our legal agreements and policies for your ease, please keep in mind that the English version is the official and most accurate one. Translations are just here to help you read and understand better, but they don’t have any legal weight. If there’s ever a misunderstanding, the English version will be the one that counts.

Introduction

This Data Processing Agreement (“DPA”) forms part of the Agreement between Pladinum Group SL (“Pladinum”, the “Processor”) and the customer (the “Customer”, the “Controller”) and sets out the terms on which Pladinum processes personal data on the Customer’s behalf in providing the Services. It reflects the requirements of Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”). Where the Customer is itself a processor, Pladinum acts as a sub-processor and this DPA applies accordingly.

1. Definitions

1.1 The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given to them in the GDPR. “Services” means the hosting and related services Pladinum provides under the Agreement. “Sub-processor” means any third party engaged by Pladinum to process personal data on the Customer’s behalf.

2. Roles and Scope

2.1 The Customer is the controller (or, where applicable, a processor) of the personal data processed through the Services, and Pladinum is the processor (or sub-processor). Each party shall comply with its respective obligations under applicable data protection law.

2.2 Annex 1 sets out the subject matter and duration of the processing, its nature and purpose, the types of personal data, and the categories of data subjects.

3. Processing Instructions

3.1 Pladinum shall process personal data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless required to process by EU or Member State law to which Pladinum is subject; in that case, Pladinum shall inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

3.2 The Agreement, this DPA, and the Customer’s use and configuration of the Services constitute the Customer’s complete documented instructions. Pladinum shall inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

4. Confidentiality

4.1 Pladinum shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited on a need-to-know basis.

5. Security

5.1 Pladinum shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures in place are described in Annex 2 and are reviewed and updated to address evolving risks.

6. Sub-processing

6.1 The Customer grants Pladinum general written authorisation to engage sub-processors to process personal data, subject to this Section. The sub-processors engaged at the date of this DPA are listed in Annex 3.

6.2 Pladinum shall impose on each sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA, and shall remain fully liable to the Customer for the performance of each sub-processor’s obligations.

6.3 Pladinum shall inform the Customer of any intended addition or replacement of a sub-processor, thereby giving the Customer a reasonable opportunity to object on reasonable data protection grounds.

7. Data Subject Rights

7.1 Taking into account the nature of the processing, Pladinum shall assist the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer’s obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.

7.2 If Pladinum receives a request directly from a data subject in relation to the Customer’s personal data, it shall, where lawful, forward the request to the Customer without undue delay and shall not otherwise respond except on the Customer’s documented instructions.

8. Assistance to the Controller

8.1 Pladinum shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security of processing, notification of personal data breaches, communication to data subjects, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Pladinum.

9. Personal Data Breach

9.1 Pladinum shall notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s personal data, and shall provide the Customer with sufficient information to enable the Customer to meet its own obligations to notify the supervisory authority and, where required, affected data subjects.

10. International Transfers

10.1 Pladinum primarily processes personal data within the European Economic Area. Where a transfer of personal data to a third country occurs, it shall be safeguarded by an appropriate transfer mechanism under Chapter V GDPR, such as the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or a European Commission adequacy decision.

11. Audits

11.1 Pladinum shall make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits are subject to reasonable prior notice, confidentiality undertakings, and reasonable limits on scope and frequency, and shall be conducted in a manner that does not compromise the security or confidentiality of other customers.

12. Return and Deletion

12.1 On termination of the Services, Pladinum shall, at the Customer’s choice, delete or return all personal data processed on the Customer’s behalf and delete existing copies, unless EU or Member State law requires storage. Residual copies contained in routine encrypted backups are deleted in the ordinary course in accordance with Pladinum’s backup retention cycle.

13. Liability

13.1 Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement and the General Terms and Conditions.

14. Term and Precedence

14.1 This DPA takes effect on acceptance of the Agreement and remains in force for as long as Pladinum processes personal data on the Customer’s behalf. In the event of any conflict between this DPA and the Agreement on data protection matters, this DPA prevails.

15. Governing Law

15.1 This DPA is governed by and construed in accordance with the laws of Spain, consistent with the General Terms and Conditions.

Annex 1 — Details of the Processing

Subject matter: Processing of personal data in the course of providing the hosting and related Services to the Customer.
Duration: For the term of the Agreement and until deletion or return of the personal data in accordance with Section 12.
Nature and purpose: Hosting, storage, transmission, backup, security, and support in connection with the Customer’s websites, applications, email, and related services.
Categories of data subjects: The Customer’s own customers, employees, contacts, website visitors, and end users whose personal data is contained in the Customer’s content.
Categories of personal data: Any personal data contained in the Customer’s content, which may include identification and contact data, account credentials, billing data, communications, and technical data such as IP addresses and logs.
Special categories: Pladinum does not require special category data. Any such data present in the Customer’s content is processed only as part of the hosting Services and remains the Customer’s responsibility.

Annex 2 — Technical and Organisational Measures

Access control: SSH key-based authentication on non-standard ports, role-based access on a least-privilege basis, and two-factor authentication on key administrative accounts.
Account isolation: Per-account isolation between hosting accounts (CloudLinux CageFS) to prevent unauthorised cross-account access.
Network security: A host firewall (FirewallD) with an intrusion prevention system (CrowdSec), together with a web application firewall, malware scanning, and proactive defence (Imunify360).
Encryption: Encryption in transit via TLS (HTTPS) with automated certificate management; encrypted backups; and DNSSEC on key zones.
Backups and resilience: Daily encrypted backups held both locally and offsite within the European Economic Area, with defined retention, on redundant (RAID) storage.
Monitoring and logging: Continuous availability monitoring, system logging, and administrative alerting.
Email security: Inbound and outbound spam and malware filtering, with SPF, DKIM, and DMARC authentication.
Physical security: Services are hosted in Tier III data centres in the European Economic Area (Germany and the Netherlands) with physical access controls and power and network redundancy.
Organisational measures: Confidentiality obligations for personnel, a defined incident-response process, and regular patching and updates.

Annex 3 — Sub-processors

Leaseweb (Leaseweb Deutschland GmbH / Leaseweb B.V.): Server hosting and encrypted backup storage. Location: Germany and the Netherlands (EEA). Transfer safeguard: within EEA.
SpamExperts (N-able): Inbound and outbound email filtering. Location: European Economic Area. Transfer safeguard: within EEA.
QUIC.cloud (LiteSpeed Technologies Inc.): Content delivery and caching. Location: global edge network (US parent). Transfer safeguard: EU Standard Contractual Clauses.

This list is indicative and current as at the “Last revised” date above. The up-to-date list of sub-processors is available from Pladinum on request.

History