Skip to content
intoclouds.io
Back to siteLog in

Legal

Data Processing Addendum

Last updated: 9 July 2026

In plain English

When you store your own users' personal data on IntoClouds, you are the controller and we are your processor. We only act on your instructions, keep your data confidential, and protect it with the security measures listed below.

We are honest about what we have: we use argon2id password hashing, TLS, org-scoped access control and audit logging — but we do not hold ISO 27001 or SOC 2 certification. We notify you of a personal-data breach without undue delay.

On this page

  1. 1. Roles
  2. 2. Subject matter & scope
  3. 3. Our obligations
  4. 4. Security measures
  5. 5. Sub-processors
  6. 6. Assistance & breaches
  7. 7. Deletion & return
  8. 8. Audit rights

1. Roles of the parties

This Data Processing Addendum (DPA) applies where you use IntoClouds to store or process the personal data of your own end users or contacts. For that data:

  • You are the controller — you decide why and how the data is processed.
  • We are the processor — we process that data only to provide the service, and only on your documented instructions.

This DPA forms part of, and is governed by, our Terms of Service. Our handling of your own account data as a controller is covered by the Privacy Policy.

2. Subject matter, duration, nature & purpose

Subject matter
Providing VPS, domain, DNS and email hosting to you.
Duration
For as long as you use the service, plus the retention periods in section 7.
Nature & purpose
Hosting, storing, transmitting and processing the data as needed to operate the resources you create — running your servers, resolving your DNS, and delivering your email.
Types of personal data
Whatever you choose to place on your infrastructure. You control this; we do not require any particular category and ask you not to store special-category data unless you have implemented appropriate safeguards for it.
Categories of data subjects
The individuals whose data you store — typically your own customers, users, employees or contacts.

3. Our obligations as processor

We will:

  • process the personal data only on your documented instructions, including for transfers, unless the law requires otherwise (in which case we will tell you, unless the law forbids it);
  • ensure that people authorised to process the data are bound by an appropriate duty of confidentiality;
  • implement the technical and organisational security measures set out in section 4, as required by Article 32 of the GDPR;
  • respect the conditions in section 5 for engaging sub-processors;
  • assist you, as far as we reasonably can, with your obligations towards data subjects and supervisory authorities (section 6).

4. Security measures

We apply security measures appropriate to the risk. We describe them honestly — we claim only what we actually do:

  • Password hashing — account passwords are stored using argon2id and never in plain text.
  • Session security — sessions use random tokens stored only as hashes; session cookies are HttpOnly and SameSite.
  • Encryption in transit — customer-facing traffic is served over TLS.
  • Least-privilege access — every API route is scoped to the requesting organisation, so one customer cannot reach another's resources; the credentials we hold for our own providers are scoped to the minimum privilege each integration needs.
  • Secret handling — provider credentials are kept as environment configuration outside our source code, not committed to the repository.
  • Abuse controls — API rate limiting, and cryptographic signature verification on incoming payment webhooks.
  • Audit logging — every action that changes account state is recorded with the actor, the target and the time.

What we do not claim. We do not currently hold ISO 27001, SOC 2 or any equivalent third-party certification, and we do not represent that we do. If that changes, we will say so.

5. Sub-processors

You authorise us to engage the sub-processors below to help deliver the service. They process personal data only as needed for their role:

  • Hetzner Online GmbH (Germany) — cloud hosting infrastructure. Our own systems are in the EU; the servers you create run in the region you pick, which may be in the United States or Singapore.
  • Polar — merchant of record and payment processing (handles billing data directly).
  • Domain registrar and registries — for domain registration, transfer and renewal.

We will give you reasonable prior notice before adding or replacing a sub-processor, so you can object. If you object on reasonable data-protection grounds and we cannot resolve it, you may stop using the affected part of the service.

6. Assistance & breach notification

Taking account of the nature of the processing, we will assist you with reasonable measures to respond to data-subject requests (access, rectification, erasure, portability, objection) relating to data you host with us, and to meet your obligations under Articles 32–36 of the GDPR.

If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, and within 72 hours where feasible, with the information you reasonably need to meet your own notification duties.

7. Deletion & return on termination

On termination of the service, or on your written request, we will delete or return the personal data we process on your behalf, and delete existing copies, unless the law requires us to keep them. In practice, deleting your resources removes the data they hold; the non-payment lifecycle in the Terms of Service also results in deletion after the stated period.

8. Audit rights

We will make available the information reasonably necessary to demonstrate our compliance with this DPA. Given our size and setup, audit rights are satisfied primarily through this documentation and written responses to reasonable questions, rather than on-site inspections. If a supervisory authority specifically requires an on-site audit, we will cooperate to arrange one on reasonable terms.

Terms of ServiceAcceptable UsePrivacy PolicyData Processing Addendum
intoclouds.io

Servers, domains, DNS and email — one panel, one billing page.

Cloud serversBusiness emailDomains & DNSAbout IntoCloudsContactLog inCreate accountPricingStatusGuidesTermsPrivacyAcceptable UseData Processing Addendumabuse@intoclouds.iohello@intoclouds.io

© 2026 IntoClouds · Data centers in the EU, the US & Asia