Application
Roles and incorporation
This DPA applies where the customer is a controller or processor and FastVPS processes customer personal data as processor or sub-processor. It is incorporated into an order that references it and continues while related processing exists.
For account, billing, security and compliance data, FastVPS may act as an independent controller under the Privacy Notice.
Instructions
Subject and documented instructions
FastVPS processes data only to deliver, secure, support, back up/restore and terminate the agreed service under the order and lawful documented instructions. It informs the customer where it considers an instruction to breach applicable law unless prohibited from doing so.
The customer is responsible for lawful instructions, notices to data subjects, legal bases, retention and suitable configuration/encryption.
Annex
Processing details
| Subject | Hosting, transmission, storage, monitoring, support and, if purchased, backup/restore. |
|---|---|
| Duration | Service term and agreed return/deletion period. |
| Nature | Storage, occasional access, transmission, organisation, backup, recovery and deletion. |
| Data subjects | Users, employees, customers, partners or other people determined by the customer. |
| Data categories | Data uploaded or created by the customer. Special-category data is permitted only where the order and security measures expressly cover it. |
| Frequency | Continuous for active hosting and periodic for backup/monitoring as stated in the order. |
The final order completes or limits this annex for the specific workload.
Access
Confidentiality and personnel
Access is limited to authorised people bound by confidentiality and provided with appropriate security awareness. Customer data is accessed only where required for the agreed scope, incident response or a legal duty.
Measures
Technical and organisational measures
- access control, least privilege and administrative logging where supported,
- encryption in transit and, where agreed/supported, at rest,
- patching, hardening, firewall, anti-malware/anti-spam and vulnerability management by service,
- monitoring, alerting, incident response and availability protection,
- backup, restore testing and continuity only within purchased scope,
- secure deletion and access-change procedures.
Specific measures, RPO/RTO and location are documented in the order or technical annex.
Sub-processors
Sub-processors and changes
The customer gives general written authorisation for necessary datacentre, network, backup, domain, email or support providers bound by equivalent data-protection duties. FastVPS remains responsible for its sub-processors to the extent required by the GDPR.
A material new sub-processing arrangement affecting customer data is notified before use, allowing a reasonable, documented data-protection objection.
Transfers
Location and third countries
The primary hosting location is stated in the order. Personal data is transferred outside the EEA only under a valid mechanism such as an adequacy decision or approved Standard Contractual Clauses, with supplementary measures where required.
Assistance
Rights, DPIA and authorities
Taking account of the processing, FastVPS provides reasonable assistance with data-subject requests, impact assessments, prior consultation, compliance evidence and lawful authority requests. Work beyond ordinary support may be charged if disclosed and not caused by FastVPS breach.
Breach
Personal data breach
FastVPS informs the customer without undue delay after becoming aware of a confirmed customer personal-data breach and provides available information on nature, categories, likely consequences and mitigation. Notice is not an admission of liability.
Expiry
Return, deletion and audit
On expiry, data is returned or deleted according to the order unless law requires retention. Backups are removed through their normal cycle and remain protected and unused for another purpose.
Available compliance information is provided on reasonable request. Audits are arranged to protect other customers, security and confidentiality, avoid unreasonable disruption and prefer independent assurance or remote evidence where sufficient.