Skip to content
HostON

Legal · Art. 28 GDPR

Data Processing Agreement (DPA)

When you store personal data of other people (customers, visitors, employees) on our servers, HostON processes that data on your behalf. The agreement below sets out the rules.

Updated: 08.10.2026HOSTON SRL, Mărășești

The Romanian version of this document is the legally binding one; this translation is provided for information.

In brief

  • Only on your instructionsWe process the data only to provide the service, never for our own purposes.
  • Servers in Vrancea, RomaniaThe content of the services is stored on our own infrastructure in Vrancea, Romania (EU).
  • Incident notificationWe notify you without undue delay and within 72 hours at the latest.
  • Signed versionOn request, we send you the signed agreement; write to info@hoston.ro.

01

About this agreement

This data processing agreement (the “Agreement”) supplements the service contract between HOSTON SRL, registered office at Str. I.L. Caragiale nr. 47, Mărășești, jud. Vrancea, 625200, România, Tax ID (CUI) RO38066444, Trade Register No. J2017000806390, share capital 500 lei, as processor, and the Customer, as controller, in accordance with Art. 28 of Regulation (EU) 2016/679 (GDPR).

The Agreement applies when the Customer stores or processes personal data of third parties on the HostON infrastructure (for example website visitors, customers of an online shop, members of a portal, email recipients).

The Agreement is part of the contract and is accepted together with the Terms and Conditions. Business customers who need a signed version can write to us at info@hoston.ro.

02

Definitions

Controller
The Customer, who determines the purposes and means of processing third-party data.
Processor
HOSTON SRL, which processes the data on behalf of the Customer.
Personal data
Any information relating to an identified or identifiable natural person, stored by the Customer on the HostON infrastructure.
Data subject
The person whose data the Customer stores (a visitor, customer or employee of the Customer).
Security incident
A breach of security leading to the destruction, loss, alteration, disclosure of, or unauthorised access to, personal data.

03

Subject matter of the processing

Nature
Storage, hosting, transmission and backups of data on the HostON infrastructure (web hosting, reseller, VPS, email).
Purpose
Exclusively the provision of the contracted services. HostON does not use the data for its own purposes.
Types of data
Any personal data the Customer stores (for example names, email addresses, postal addresses, orders, messages).
Data subjects
Visitors, customers, users or employees of the Customer.
Duration
For the term of the service contract and the retention period after termination, described below.

04

Obligations of the Customer (controller)

  • has a valid legal basis for processing the data stored at HostON (Art. 6 and, where applicable, Art. 9 GDPR);
  • has informed the data subjects about the processing, including the use of a hosting provider;
  • applies security measures at the level of its own applications (updates, strong passwords, two-factor authentication, encryption where appropriate);
  • informs us in writing of any special instructions that go beyond the standard hosting service;
  • is responsible for the lawfulness of the content and of the processing it carries out.

05

Obligations of HostON (processor)

  • processes the data only on the documented instructions of the Customer (the contract and the service configuration), unless the law requires otherwise, in which case we inform you where the law permits;
  • ensures confidentiality: staff with access to the data are bound by confidentiality obligations;
  • applies the security measures described below;
  • helps you, as far as technically possible, to respond to data subject requests (access, rectification, erasure, portability);
  • does not transfer the data to third parties or outside the EU without the Customer’s consent, except where provided by law;
  • notifies you of security incidents without undue delay;
  • deletes or returns the data when the contract ends, at the Customer’s choice;
  • makes available the information needed to demonstrate compliance with Art. 28 and allows reasonable audits.

06

Sub-processors

The Customer gives general authorisation for the use of sub-processors. They currently are:

  • Cloudflare, Inc.

    RoleDelivery and protection of websites (DNS, DDoS protection, CDN), when the Customer uses them through HostON

    CountryUSA, global network

  • Brevo (Sendinblue SAS)

    RoleSending HostON notification emails to the Customer

    CountryFrance (EU)

The content of the services (files, databases, mailboxes) is stored on HostON servers in Vrancea, Romania. We notify you by email at least 14 days before adding or replacing a sub-processor; you may object and, if we cannot find a solution, you may terminate the contract without penalties. We impose on sub-processors data protection obligations equivalent to those in this agreement.

07

Security measures

  • TLS encryption for connections to the control panel, to email and to websites;
  • isolation of hosting accounts from one another (CloudLinux CageFS);
  • firewall and malware scanning on the servers (Imunify360);
  • automatic daily backups (JetBackup) on hosting plans;
  • server monitoring and automatic alerts;
  • staff access only as far as necessary, with individual authentication;
  • protection against DDoS attacks through Cloudflare.

08

Incident notification

  1. 1NotificationWe notify you without undue delay and within 72 hours at the latest after discovering an incident that affects your data.
  2. 2InformationWe send you what we know: the nature of the incident, the categories and approximate number of data records and persons affected, the likely consequences, and the measures taken or proposed.
  3. 3CooperationWe help you manage the incident and, where necessary, notify ANSPDCP (the Romanian data protection authority) and the data subjects.

The notification is sent to the email address in your customer account.

09

International transfers

Data stored in HostON services remains in Romania (EU). Transfers made by sub-processors outside the EU (Cloudflare) take place on the basis of the EU–US adequacy decision (Data Privacy Framework) or of standard contractual clauses. Details in the Privacy Policy.

10

Audits

On request, we make available the documentation needed to demonstrate compliance with Art. 28 GDPR. An on-site audit is possible once a year, with at least 30 days’ notice, at the Customer’s expense, without affecting the services of other customers and respecting their confidentiality.

11

Data when the contract ends

  • after the service expires or is terminated, you have 14 calendar days during which the data is kept and you can recover it (from cPanel or by a request to support);
  • after this period, the data is permanently deleted from the servers;
  • backups containing it are deleted through the automatic backup rotation;
  • on request, we confirm the deletion in writing.

12

Term and amendment of the agreement

The Agreement is valid for the entire term of the service contract and ends together with it. We may amend it by an email notice sent at least 30 days in advance; if you do not agree, you may terminate the contract without penalties during this period.

Other legal documents

Frequently asked questions

Yes, if you store personal data of other people (customers, subscribers, employees) on your HostON hosting, VPS or email. The agreement applies automatically together with the terms and conditions.

Yes. Business customers can request the signed version at info@hoston.ro, with the subject “DPA / GDPR Agreement”.

On HostON servers in Vrancea, Romania. If you use Cloudflare protection through HostON, traffic to the website also passes through the Cloudflare network.

It is kept for 14 days, during which you can recover it, and is then permanently deleted; backups are deleted through the automatic rotation. On request, we confirm the deletion in writing.

Yes, without undue delay and within 72 hours at the latest after discovery, with all the information you need for any notification to ANSPDCP.

Have a question? Write to us.

Whether you are about to order or already have a site with us, the people who manage the servers will answer you.

HostON technical support team member wearing a headset and answering a customer