#Introduction
This Data Processing Addendum (“DPA”) forms part of the HostCore Terms of Service between HostCore Limited (“HostCore”, “Processor”) and the tenant (“Tenant”, “Controller”). It applies where and to the extent HostCoreprocesses End Customer Personal Data on the Tenant’s behalf and the GDPR, UK GDPR, or a similar data-protection law applies to that processing.
#Definitions
Terms defined in the Terms of Service have the same meaning here. “Personal Data”, “processing”, “controller”, “processor”, “data subject”, “supervisory authority”, and “personal data breach” have the meanings given in the GDPR. “End Customer Personal Data” means Personal Data relating to End Customers (and other individuals whose data the Tenant submits to the Services) processed by HostCore on the Tenant’s behalf, as described in Annex A. “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, and “UK Addendum” means the UK International Data Transfer Addendum to the SCCs issued under s.119A of the UK Data Protection Act 2018.
#Roles and scope
- The Tenant is the controller (or, where the Tenant acts for another controller, a processor authorized to appoint HostCore as subprocessor) of End Customer Personal Data. HostCoreis the Tenant’s processor.
- This DPA does not apply to Personal Data for which HostCoreis itself the controller (such as the Tenant’s own account data), which is covered by the HostCore Privacy Policy.
- Details of the processing — subject matter, duration, nature and purpose, categories of data and data subjects — are set out in Annex A.
#Tenant instructions and responsibilities
- HostCore will process End Customer Personal Data only on the Tenant’s documented instructions, including with regard to international transfers, unless required otherwise by law that applies to HostCore (in which case HostCore will inform the Tenant before processing, unless that law prohibits it). The Terms of Service, this DPA, and the Tenant’s configuration and use of the Services constitute the Tenant’s complete documented instructions.
- HostCore will inform the Tenant if, in its opinion, an instruction infringes applicable data-protection law. HostCore is not obliged to perform a legal review of Tenant instructions.
- The Tenant is responsible for: the lawfulness of the End Customer Personal Data it submits; providing all required notices to, and obtaining all required consents and lawful bases from, its End Customers; and its own compliance obligations as controller, including maintaining its own privacy policy as required by our Terms of Service.
#Confidentiality and personnel
HostCore will ensure that persons authorized to process End Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Services.
#Security
HostCore implements and maintains the technical and organizational measures described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. HostCore may update these measures from time to time provided the updates do not materially reduce the overall level of protection.
#Subprocessors
- The Tenant provides general authorization for HostCore to engage the subprocessors listed in Annex C.
- HostCore will give at least 14 days’ notice (by email or dashboard notice) before adding or replacing a subprocessor. If the Tenant reasonably objects on data-protection grounds and HostCore cannot offer a reasonable alternative, the Tenant may terminate the affected Services as its sole remedy; the export window in the Terms applies.
- HostCore will impose data-protection obligations on each subprocessor materially equivalent to those in this DPA, and remains liable to the Tenant for its subprocessors’ performance.
- Providers the Tenant configures itself — including the Tenant’s own payment providers, SMTP or email API providers, and CAPTCHA services for its Stores — act for the Tenant directly and are not HostCore subprocessors.
#International transfers
- End Customer Personal Data is processed on infrastructure in Australia, the United States, and the European Union, and may be accessed from New Zealand for administration and support. New Zealand benefits from a European Commission adequacy decision.
- To the extent a transfer of End Customer Personal Data subject to the GDPR is made to a country without an adequacy decision (including to subprocessors in the United States), the parties incorporate the SCCs by reference as follows: Module Two (controller to processor) where the Tenant is a controller, and Module Three (processor to processor) where the Tenant is itself a processor; Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 14 days); Clause 11 optional language not included; Clause 17 governed by the law of Ireland; Clause 18 courts of Ireland; Annexes I, II, and III to the SCCs are completed by Annexes A, B, and C of this DPA respectively.
- For transfers subject to the UK GDPR, the UK Addendum applies to the SCCs with the parties’ details completed as above.
- For personal information subject to the New Zealand Privacy Act 2020, HostCore discloses information outside New Zealand only where permitted by IPP 12, including on the basis of comparable safeguards under this DPA.
#Assistance
- Data subject requests.
Taking into account the nature of the processing, HostCore will assist the Tenant with appropriate technical and organizational measures to respond to data subject requests (access, rectification, erasure, portability, restriction, objection). If a data subject contacts HostCore directly about End Customer Personal Data, HostCore will refer them to the Tenant without responding substantively, except where legally required. - DPIAs and consultations.
HostCore will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent the required information is available to HostCore.
#Personal data breach
HostCore will notify the Tenant without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting End Customer Personal Data, and will provide information reasonably available to HostCore about the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. HostCore’s notification is not an admission of fault. The Tenant is responsible for its own notifications to supervisory authorities and data subjects.
#Deletion and return
On termination of the Services, HostCore will make End Customer Personal Data available for export for 30 days as described in the Terms, and will thereafter delete it, including deleting Gateway Credentials within 30 days of termination, or on the discontinuation date where HostCore discontinues the Services. Residual copies in backups are deleted automatically on HostCore’s backup cycle, under which no backup is retained for more than 30 days. HostCore may retain data where required by law, for as long as required.
#Audit and information
- HostCore will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and, where available, third-party audit reports or certifications.
- Where the information in 11.1 is insufficient to satisfy a genuine legal requirement, the Tenant may conduct (through an independent auditor bound by confidentiality) an audit of HostCore’s relevant processing, no more than once per 12 months, on at least 30 days’ notice, during business hours, at the Tenant’s cost, and in a manner that does not compromise the security or confidentiality of other tenants’ data.
#Liability, precedence, general
- Each party’s liability under this DPA is subject to the exclusions and limitations in the Terms of Service, except to the extent liability cannot lawfully be limited.
- If there is a conflict between this DPA and the Terms regarding the processing of End Customer Personal Data, this DPA prevails; where the SCCs apply and conflict with this DPA, the SCCs prevail.
- This DPA is governed by the same law as the Terms, except where the SCCs require otherwise.
#Annex A — Details of processing (SCC Annex I)
Data exporter: the Tenant (controller, or processor where §2.1 applies) — identity and contact details as per the Tenant’s HostCore account.
Data importer: HostCore Limited, New Zealand — contact: legal@hostcore.co.
Subject matter and nature of processing: hosting and operation of a multi-tenant billing, provisioning, and store-management platform: storage, retrieval, transmission, and display of Tenant Data; order, invoice, and subscription lifecycle management; provisioning of services the Tenant sells; delivery of notifications and webhooks; computation of store analytics (e.g. sales, orders, churn) presented to the Tenant; support ticketing; backups.
Purpose: provision of the Services to the Tenant under the Terms of Service.
Duration:the term of the Tenant’s use of the Services plus the deletion periods in Section 10.
Categories of data subjects:End Customers of the Tenant’s Stores; the Tenant’s own staff and users interacting with the Services.
Categories of Personal Data: identity and contact data (name, email address, billing address, phone); account data (usernames, hashed credentials, Discord identifiers where the individual opts in); transaction and order data (products purchased, invoices, amounts, currency, payment status, payment metadata and gateway references — not full card numbers, which are held by the Tenant’s payment provider); support communications; technical data (IP addresses, logs).
Special categories of data: none intended or required. Tenants must not submit special-category data through free-text fields.
Frequency: continuous, for the duration above.
Retention: per Section 11.
#Annex B — Technical and organizational measures (SCC Annex II)
- Encryption in transit (TLS) for all external connections.
- Envelope encryption (AES-256-GCM) at rest for Gateway Credentials and other high-sensitivity values.
- Logical tenant isolation within the platform; per-tenant webhook signing secrets.
- Access controls on production systems; access limited to authorized personnel on a need-to-use basis.
- Bot and abuse protection on authentication and sign-up flows (Cloudflare Turnstile).
- Error reports sanitized before transmission to the error-tracking subprocessor.
- Encrypted backups stored in a private object-storage bucket; daily full backups, continuous database backups, and daily server-level backups; no backup retained beyond 30 days.
- Infrastructure hosted on hardened Kubernetes (K3s) clusters across the regions in Section 7.1.
- Breach response per Section 9; credential rotation guidance per the Terms.
#Annex C — Subprocessors (SCC Annex III)
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| OVH | Infrastructure hosting | Australia, United States, European Union |
| Cloudflare, Inc. | Content delivery, security, bot protection (Turnstile), encrypted backup storage (R2) | Global network; United States |
| Email delivery for communications HostCore sends | United States / global | |
| Functional Software, Inc. (Sentry) | Error tracking (sanitized reports) | United States |
| Discord, Inc. | Support-ticket message sync | United States |