Legal
Data Processing Agreement
UK GDPR Article 28 controller-processor terms governing personal data you process via our services.
Effective Date
This Data Processing Agreement ("DPA") is effective as of July 12, 2026.
1. Scope and Application
This DPA forms part of the agreement between Nova Grid Hosting LLC ("Nova Grid", "we", or "Processor") and the customer ("Customer", "you", or "Controller") for the provision of hosting, domain registration, and related services as set out in our Terms of Service and SLA.
This DPA applies whenever you process personal data of UK or European Economic Area data subjects via our services and we, in providing those services, process that personal data on your behalf. It does not apply to personal data we collect directly from you about you (such as your billing details), which is governed by our Privacy Policy.
In the event of any conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails.
2. Definitions
Terms used in this DPA have the meanings given to them in the UK GDPR, including: personal data, processing, controller, processor, data subject, personal data breach, and special categories of personal data. "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended. "EU GDPR" means Regulation (EU) 2016/679. "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
3. Subject Matter, Duration, Nature, and Purpose of Processing
Subject matter: the provision of web hosting (including WordPress, WooCommerce, Joomla, and static-site hosting), Professional Email mailbox hosting, game-server hosting, domain registration, DNS management, and related customer support services.
Duration: for the term of your account with us, plus any retention period set out in our Privacy Policy and applicable law.
Nature and purpose: hosting, storing, transmitting, and rendering content uploaded by you, including any personal data therein, on our infrastructure for the purpose of operating your website, application, mailbox, or other service.
Type of personal data: any personal data you elect to upload, store, or transmit through your hosting account. This may include, depending on your use case, names, email addresses, postal addresses, phone numbers, IP addresses, account credentials, transactional records, message content, and uploaded files.
Categories of data subjects: your end users, customers, employees, contacts, or any other natural persons whose data you process via our services.
4. Controller's Obligations
You warrant and represent that:
- You have a valid lawful basis under Article 6 UK GDPR (and, where applicable, Article 9) for the personal data you process via our services;
- You have provided all required notices to data subjects;
- Your instructions to us in relation to the processing of personal data comply with applicable data protection law;
- You will not transfer to us, or process via our services, personal data that is unlawful for you to transfer or process.
5. Processor's Obligations
We will:
- Process on documented instructions. Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by UK or EU law (in which case we will inform you of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest);
- Confidentiality. Ensure that personnel authorised to process personal data are subject to a duty of confidentiality;
- Security. Implement appropriate technical and organisational measures as required by Article 32 UK GDPR, including TLS encryption in transit, access controls, segregation of customer data, and prompt patching of infrastructure;
- Subprocessors. Engage subprocessors only under the conditions set out in clause 6 below;
- Data subject rights. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligations to respond to requests from data subjects exercising their rights under Chapter III UK GDPR;
- Breach notification. Notify you without undue delay after becoming aware of a personal data breach affecting your data, providing sufficient information to enable you to meet your obligations under Articles 33 and 34 UK GDPR;
- Assistance with DPIAs. Provide reasonable assistance with data protection impact assessments and prior consultations with the ICO under Articles 35 and 36 UK GDPR, taking into account the nature of processing and the information available to us;
- Return or deletion. At your choice, delete or return all personal data to you on termination of our services, and delete existing copies, unless UK or EU law requires retention of the personal data;
- Demonstrate compliance. Make available to you all information necessary to demonstrate compliance with the obligations in Article 28 UK GDPR.
6. Subprocessors
You provide a general written authorisation for us to engage subprocessors to provide our services. The current list of authorised subprocessors is published at novagridhosting.com/subprocessors.html.
We will inform you of any intended changes to subprocessors by updating the subprocessors page. If you object to a new subprocessor on reasonable data-protection grounds, you must notify us within 30 days of the change being published. We will work with you in good faith to address your objection; if we cannot, you may terminate the affected services as your sole remedy, with a pro-rata refund for prepaid amounts.
We remain liable to you for any failure of a subprocessor to fulfil its data-protection obligations under our subprocessor contract.
7. International Transfers
Our infrastructure is located in New York, NY, United States. By using our services, you instruct us to transfer your personal data to the United States and to any country in which an authorised subprocessor is established.
Transfers of UK personal data. Where the transfer mechanism for a particular subprocessor relies on the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU SCCs, the applicable mechanism is identified on our subprocessors page.
Transfers of EEA personal data. Where the EU GDPR applies to personal data you process via our services, the EU SCCs (Module Two: Controller to Processor) are incorporated into this DPA by reference, completed with the processing details set out in clause 3, with you as data exporter and Nova Grid as data importer. For each subprocessor, the equivalent EU mechanism (the EU-US Data Privacy Framework or the EU SCCs, as implemented in that subprocessor's data processing terms) applies to onward transfers.
You are entitled to a copy of the executed safeguard documentation on request to privacy@novagridhosting.com.
8. Audit Rights
We will, on reasonable written request and no more than once in any 12-month period (except where required by a supervisory authority or where there has been a documented material change to processing), make available to you the results of our most recent third-party security assessments, where available, and information about our technical and organisational measures.
Where the above is insufficient to demonstrate compliance, you may request an audit conducted by a mutually agreed independent auditor on terms set out in writing in advance, including reasonable confidentiality undertakings, scope, duration, and the obligation to bear your own audit costs except where the audit reveals a material breach of this DPA.
9. Liability
The liability of each party under this DPA is subject to the limitations of liability in our Terms of Service, except that nothing in this DPA limits liability that cannot lawfully be limited under applicable data protection law.
10. Term and Termination
This DPA continues for as long as we process personal data on your behalf. On termination of the underlying services, the deletion or return obligations in clause 5 apply.
11. Governing Law
This DPA is governed by the law set out in the Governing Law clause of our Terms of Service, without prejudice to any non-waivable rights of UK data subjects under UK data protection law.
12. Order of Precedence
If you require a separately negotiated and signed DPA (for example, if your own customers' compliance programmes require it) please contact legal@novagridhosting.com. Absent a separately signed agreement, this published DPA applies.
Contact
For questions about this DPA or to exercise rights under it, contact privacy@novagridhosting.com.
Trademark Notice
“Nova Grid Hosting” is a trademark of Nova Grid Hosting LLC. The “Nova Grid Hosting” word mark is the subject of a pending federal trademark application with the United States Patent and Trademark Office (Serial No. 99793639, filed April 29, 2026). All other product names, logos, brands, and marks identified on this site are the property of their respective owners.