Zypheral — Data Processing Agreement

Effective date: 10 September 2026 Version: 1.0


1. Parties and structure

1.1 This Data Processing Agreement ("DPA") is entered into between:

("Zypheral", the "Processor"); and

1.2 This DPA forms part of and is subject to the Terms of Service between the parties (the "Agreement"). In the event of conflict on the subject of personal data processing, this DPA prevails over the Terms of Service.

1.3 This DPA applies where, and to the extent that, Zypheral processes Customer Personal Data on behalf of the Customer in the course of providing the Services, and where Data Protection Law applies to that processing.

1.4 Scope boundary. Zypheral acts as Controller, not Processor, in relation to Account Data — the personal data of the Customer's own account administrators used to operate, bill and secure the account. That processing is governed by the Privacy Policy, not by this DPA.


2. Definitions

"Customer Personal Data" means personal data contained within Customer Content that Zypheral processes on the Customer's behalf, including personal data within hosted websites and databases, and within mailboxes, email messages and attachments.

"Data Protection Law" means the data protection and privacy legislation applicable to the processing, which may include Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and the law of [GOVERNING LAW JURISDICTION].

"Sub-processor" means a third party engaged by Zypheral to process Customer Personal Data.

"Personal Data Breach", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meanings given in the GDPR.


3. Roles and responsibilities

3.1 The Customer is the Controller and Zypheral is the Processor in respect of Customer Personal Data. Where the Customer is itself a processor acting for a third-party controller, the Customer warrants that it has authority to appoint Zypheral as a sub-processor on these terms.

3.2 Customer responsibilities. The Customer:

(a) is solely responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which it was obtained; (b) warrants that it has a valid legal basis for the processing it instructs, and has provided all required notices and obtained all required consents; (c) is responsible for responding to data subjects, subject to Zypheral's assistance under clause 8; (d) is responsible for configuring and using the Services in a manner appropriate to the sensitivity of the data it chooses to store, including its choice of passwords, its management of delegated access, and the security of the applications and code it deploys; (e) must not instruct processing that would cause Zypheral to breach Data Protection Law.

3.3 Zypheral responsibilities. Zypheral will process Customer Personal Data only as set out in this DPA and will comply with the obligations imposed on processors by Data Protection Law.


4. Processing instructions

4.1 Zypheral will process Customer Personal Data only on the Customer's documented instructions, which comprise:

(a) the Agreement, this DPA, and the technical configuration the Customer selects in the dashboard; (b) the Customer's use of the Services, which constitutes an instruction to process as necessary to deliver them; and (c) any further written instruction the parties agree.

4.2 Zypheral will not process Customer Personal Data for its own purposes, and specifically will not sell it, use it for advertising or profiling, or use it to train machine learning models.

4.3 Legally required processing. If Zypheral is required by law to process beyond the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.

4.4 Zypheral will inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Zypheral may suspend the affected processing until the instruction is amended or confirmed.


5. Subject matter and details of processing

(Annex I to this DPA.)

Subject matter. Provision of managed website hosting and email hosting services, and related support, as described in the Agreement.

Duration. For the term of the Agreement, plus the retention periods in clause 11.

Nature of processing. Hosting, storage, transmission, backup where provided, automated malware and spam filtering, provisioning, monitoring, technical support, and deletion.

Purpose. Providing, maintaining, securing and supporting the Services.

Categories of data subjects — determined by the Customer, and typically:

Categories of personal data — determined by the Customer, and typically:

Special category data. The Services are not designed or offered for the processing of special categories of personal data under Article 9 GDPR, nor for personal data relating to criminal convictions and offences, nor for data subject to sector-specific regimes such as payment card data under PCI DSS or protected health information. If the Customer chooses to process such data, it does so on its own assessment and remains solely responsible for determining that the Services are appropriate, and for any additional measures required.


6. Confidentiality

6.1 Zypheral will treat Customer Personal Data as confidential.

6.2 Zypheral will ensure that personnel authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, that survives the end of their engagement.

6.3 Zypheral will limit access to Customer Personal Data to personnel who require it to provide or support the Services.


7. Security measures

7.1 Taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to individuals, Zypheral implements appropriate technical and organisational measures, which currently include:

Technical measures

dashboard, API and supported mail connections;

hashes;

the account owner;

Organisational measures

7.2 Zypheral may update these measures provided that the level of protection is not materially reduced.

7.3 Customer's own responsibility. The Customer is responsible for the security measures applicable to the applications, plugins, themes and code it deploys, for the credentials it and its users hold, and for the delegated access it grants.


8. Assistance to the Customer

8.1 Data subject requests. Taking into account the nature of the processing, Zypheral will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights.

8.2 Where Zypheral receives a request directly from a data subject relating to Customer Personal Data, it will not respond substantively, and will without undue delay direct the request to the Customer, unless legally required to respond.

8.3 Other assistance. Zypheral will provide reasonable assistance to the Customer with data protection impact assessments, prior consultation with supervisory authorities, and the security obligations in Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Zypheral.

8.4 Zypheral may charge a reasonable fee for assistance that is materially beyond the scope of its ordinary support obligations, having first notified the Customer of the anticipated cost.


9. Sub-processors

9.1 The Customer provides general written authorisation for Zypheral to engage Sub-processors, subject to this clause.

9.2 Zypheral will:

(a) enter into a written contract with each Sub-processor imposing data protection obligations no less protective than those in this DPA; (b) remain fully liable to the Customer for the performance of each Sub-processor's obligations; (c) maintain a current list of Sub-processors, available at [SUBPROCESSOR LIST URL].

9.3 Changes. Zypheral will give the Customer at least [SUBPROCESSOR NOTICE PERIOD] notice before adding or replacing a Sub-processor, by [NOTIFICATION METHOD].

9.4 Objection. The Customer may object on reasonable data protection grounds within [OBJECTION WINDOW] of notice. The parties will discuss in good faith. If no resolution is reached, the Customer may terminate the affected Service on written notice and receive a pro rata refund of prepaid, unused fees.


10. Personal Data Breach

10.1 Zypheral will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 The notification will describe, to the extent known and as it becomes available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point for further information.

10.3 Zypheral will provide reasonable cooperation and assistance to enable the Customer to meet its own notification obligations to supervisory authorities and data subjects. Notifying authorities and data subjects is the Customer's responsibility as Controller.

10.4 Zypheral's notification is not, and will not be construed as, an acknowledgement of fault or liability.


11. Deletion and return of data

11.1 During the term. The Customer may retrieve and delete Customer Personal Data at any time using the Services.

11.2 On termination. On expiry or termination of the Agreement, Zypheral will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless storage is required by law.

11.3 Retrieval window. The Customer must exercise the choice in clause 11.2 within [POST-TERMINATION RETRIEVAL WINDOW] of termination. After that period, Zypheral may delete Customer Personal Data.

11.4 Suspension for non-payment. Where a Service is suspended for non-payment, Customer Personal Data is retained for the retention period stated in the Terms of Service and Refund Policy, during which the Service does not operate. For Email Hosting that period is currently 30 days from suspension, after which retained data may be permanently and irreversibly deleted. Payment within the retention period restores the Service and access to the data.

11.5 Residual copies. Isolated copies may persist briefly within routine system records until overwritten in the ordinary course. Such copies remain subject to the confidentiality and security obligations of this DPA and are not made available to any party.


12. Audits and information

12.1 Zypheral will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA.

12.2 Zypheral will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to the following:

(a) audits are limited to [AUDIT FREQUENCY — e.g. once in any twelve-month period], except following a Personal Data Breach affecting the Customer or where required by a supervisory authority; (b) the Customer gives at least [AUDIT NOTICE PERIOD] written notice; (c) audits take place during business hours, without unreasonable disruption, and under confidentiality; (d) the auditor must not be a competitor of Zypheral; (e) the scope excludes information relating to other customers, and any information whose disclosure would compromise the security of the platform; (f) the Customer bears its own costs and Zypheral's reasonable costs of supporting the audit.

12.3 Zypheral may satisfy an audit request by providing an independent third-party audit report or certification, where one is available and reasonably addresses the scope of the request.


13. International transfers

13.1 The infrastructure used to store Customer Personal Data for the Services is located in the European Union.

13.2 Where Zypheral transfers Customer Personal Data outside the European Economic Area or the United Kingdom, including through a Sub-processor, it will do so only where a lawful transfer mechanism applies, which may include an adequacy decision, the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum.

13.3 Where the Standard Contractual Clauses apply, they are incorporated into this DPA by reference and the parties are deemed to have executed the applicable modules, with:


14. Liability

14.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent that Data Protection Law prohibits limiting that liability.

14.2 Nothing in this DPA limits any liability that cannot lawfully be limited, including a data subject's rights to compensation under Data Protection Law.


15. General

15.1 Term. This DPA takes effect on the Effective Date and continues for as long as Zypheral processes Customer Personal Data.

15.2 Changes. Zypheral may amend this DPA where necessary to reflect a change in Data Protection Law, a supervisory authority's guidance, or a certification scheme, provided the change does not materially reduce the protection afforded to Customer Personal Data. Material changes will be notified in advance.

15.3 Order of precedence. In case of conflict: this DPA, then the Terms of Service, then any other document.

15.4 Governing law. This DPA is governed by the law stated in the Agreement, unless Data Protection Law requires otherwise.

15.5 Severability. If a provision is held invalid, the remainder continues in force.


16. Contact

Data protection enquiries and notices under this DPA:


Signature

Where a signed copy is required:

ZypheralCustomer
EntityZypheral[CUSTOMER ENTITY]
Name[NAME][NAME]
Title[TITLE][TITLE]
Date[DATE][DATE]

Alternatively, this DPA may be incorporated by reference into the Terms of Service and accepted at sign-up. Which route you take is a legal decision, and affects whether enterprise customers will accept it without negotiation.