Legal
Data Processing Agreement
Last Updated: September 27, 2026
1. Parties and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service. The client is the controller of the personal data inside its own systems, such as websites, mailboxes, contact lists, marketing platforms and DNS zones. TK WebHosts Ltd, a company registered in England and Wales under company number 10252550, 20-22 Wenlock Road, London, N1 7GU, United Kingdom, is the processor for data inside the systems it hosts, manages or accesses for the client. For the client’s account and business information, TK WebHosts Ltd is the controller, as set out in the Privacy Policy.
2. Subject matter, nature and duration
TK WebHosts Ltd processes personal data only to deliver the services the client has ordered: hosting, domains and DNS, business email, websites and maintenance, email deliverability, SEO and automation. The personal data concerned is typically names, email addresses, message content and metadata, website content and contact records relating to the client’s staff, customers and contacts. Processing lasts for the service and ends when data is returned or deleted under section 8.
3. Processing on documented instructions
Personal data is processed only on the client’s documented instructions, which are the order, the written scope and any later instruction confirmed in writing, and for no other purpose. If an instruction appears to breach data protection law, the client is told before it is acted on.
4. Confidentiality of people
Everyone who works on the client’s services is bound by contractual confidentiality obligations.
5. Security measures
The controls on the Trust & Security page apply: temporary, least-privilege access wherever the platform allows it; multi-factor authentication required on every account granted; credentials held only in an encrypted password manager; and, on managed hosting and website maintenance plans, automated daily backups retained for 30 days on storage separate from the server that runs the site.
6. Sub-processors
TK WebHosts Ltd relies on providers in these categories: data-center and cloud infrastructure providers in the European Union and the United States; domain registries, registrars and DNS infrastructure; email infrastructure and deliverability tooling; payment processors and the client billing platform; and ticketing, scheduling, analytics and password-management tools. Each is bound by contractual confidentiality and security obligations and acts on TK WebHosts’ instructions, and TK WebHosts Ltd remains responsible for them. Specific providers are disclosed to clients on request. The client is told before a new sub-processor handles its personal data and may object on reasonable grounds.
7. Personal data breaches
If TK WebHosts causes or discovers a security incident affecting the client’s services or data, the client is notified within 24 hours of TK WebHosts becoming aware of it, told what is known and what has been done, and given cooperation in responding, including any notifications the client is required to make.
8. Deletion and return
Working data from an engagement, such as exports, screenshots, reports and diagnostic output, is retained for no more than 90 days after close and then deleted, unless the client asks in writing for it to be kept. For a hosting or email service, the client can ask before the end date for a reasonable opportunity to export its data; data within the terminated service is then deleted after the end date, as set out in section 15 of the Terms of Service.
9. Assistance, records and audits
TK WebHosts Ltd helps the client respond to requests from individuals exercising their data protection rights, and with security, breach and impact-assessment obligations, as far as the processing under this DPA is concerned, and answers reasonable audit questions in writing.
10. International transfers
Where personal data is processed outside the United Kingdom, including by the infrastructure providers in the European Union and the United States named by category above, the transfer relies on UK adequacy regulations or a recognized safeguard such as the UK International Data Transfer Agreement or Addendum.
11. Signed copies
Business clients that need this DPA in signed form can ask through the client billing area or the contact page.
See also: Trust & Security · Privacy Policy · Terms of Service