Legal
Data Processing Addendum
Last updated: 9 July 2026
1. Roles of the parties
This Data Processing Addendum (DPA) applies where you use IntoClouds to store or process the personal data of your own end users or contacts. For that data:
- You are the controller — you decide why and how the data is processed.
- We are the processor — we process that data only to provide the service, and only on your documented instructions.
This DPA forms part of, and is governed by, our Terms of Service. Our handling of your own account data as a controller is covered by the Privacy Policy.
2. Subject matter, duration, nature & purpose
- Subject matter
- Providing VPS, domain, DNS and email hosting to you.
- Duration
- For as long as you use the service, plus the retention periods in section 7.
- Nature & purpose
- Hosting, storing, transmitting and processing the data as needed to operate the resources you create — running your servers, resolving your DNS, and delivering your email.
- Types of personal data
- Whatever you choose to place on your infrastructure. You control this; we do not require any particular category and ask you not to store special-category data unless you have implemented appropriate safeguards for it.
- Categories of data subjects
- The individuals whose data you store — typically your own customers, users, employees or contacts.
3. Our obligations as processor
We will:
- process the personal data only on your documented instructions, including for transfers, unless the law requires otherwise (in which case we will tell you, unless the law forbids it);
- ensure that people authorised to process the data are bound by an appropriate duty of confidentiality;
- implement the technical and organisational security measures set out in section 4, as required by Article 32 of the GDPR;
- respect the conditions in section 5 for engaging sub-processors;
- assist you, as far as we reasonably can, with your obligations towards data subjects and supervisory authorities (section 6).
4. Security measures
We apply security measures appropriate to the risk. We describe them honestly — we claim only what we actually do:
- Password hashing — account passwords are stored using argon2id and never in plain text.
- Session security — sessions use random tokens stored only as hashes; session cookies are
HttpOnlyandSameSite. - Encryption in transit — customer-facing traffic is served over TLS.
- Least-privilege access — every API route is scoped to the requesting organisation, so one customer cannot reach another's resources; the credentials we hold for our own providers are scoped to the minimum privilege each integration needs.
- Secret handling — provider credentials are kept as environment configuration outside our source code, not committed to the repository.
- Abuse controls — API rate limiting, and cryptographic signature verification on incoming payment webhooks.
- Audit logging — every action that changes account state is recorded with the actor, the target and the time.
What we do not claim. We do not currently hold ISO 27001, SOC 2 or any equivalent third-party certification, and we do not represent that we do. If that changes, we will say so.
5. Sub-processors
You authorise us to engage the sub-processors below to help deliver the service. They process personal data only as needed for their role:
- Hetzner Online GmbH (Germany) — cloud hosting infrastructure. Our own systems are in the EU; the servers you create run in the region you pick, which may be in the United States or Singapore.
- Polar — merchant of record and payment processing (handles billing data directly).
- Domain registrar and registries — for domain registration, transfer and renewal.
We will give you reasonable prior notice before adding or replacing a sub-processor, so you can object. If you object on reasonable data-protection grounds and we cannot resolve it, you may stop using the affected part of the service.
6. Assistance & breach notification
Taking account of the nature of the processing, we will assist you with reasonable measures to respond to data-subject requests (access, rectification, erasure, portability, objection) relating to data you host with us, and to meet your obligations under Articles 32–36 of the GDPR.
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, and within 72 hours where feasible, with the information you reasonably need to meet your own notification duties.
7. Deletion & return on termination
On termination of the service, or on your written request, we will delete or return the personal data we process on your behalf, and delete existing copies, unless the law requires us to keep them. In practice, deleting your resources removes the data they hold; the non-payment lifecycle in the Terms of Service also results in deletion after the stated period.
8. Audit rights
We will make available the information reasonably necessary to demonstrate our compliance with this DPA. Given our size and setup, audit rights are satisfied primarily through this documentation and written responses to reasonable questions, rather than on-site inspections. If a supervisory authority specifically requires an on-site audit, we will cooperate to arrange one on reasonable terms.