FDOSoftwareFDO Software

Data Processing Addendum

The terms under which we process personal data on your behalf, published rather than kept behind a sales call.

Version 1 · Effective from

Why this exists

When you host personal data on a server you rent from us, you are the controller and we are your processor. Article 28 GDPR requires that relationship to be governed by a contract with specific terms. This is that contract, and it applies automatically to every customer — you do not need to request it or negotiate it.

Subject matter and duration

We process personal data contained in your server for as long as you hold the subscription, and for the retention window described in the Terms of Service after it ends.

The nature and purpose of the processing is the provision of infrastructure. The types of personal data and categories of data subject are determined by you, since you decide what to place on the server.

Our obligations

  • We process personal data only on your documented instructions, which includes the instruction implicit in you using the service.
  • We ensure that personnel with access are bound by confidentiality.
  • We implement appropriate technical and organisational measures, including encryption at rest for credentials, access controls, and logging of administrative access.
  • We assist you, so far as we reasonably can, with data subject requests, security obligations, breach notification and impact assessments.
  • We notify you without undue delay on becoming aware of a personal data breach affecting your data.
  • On termination we delete your data at the end of the retention window, or return it earlier if you ask, unless we are required by law to keep it.
  • We make available the information needed to demonstrate compliance and allow audits, on reasonable notice and subject to confidentiality.

Sub-processors

You give general authorisation for us to engage sub-processors. Our current list is published on the Sub-processors page. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds — if we cannot resolve the objection, you may terminate the affected service without penalty.

International transfers

Where personal data is transferred outside the EEA or the UK, the parties adopt the European Commission's standard contractual clauses, and the UK Addendum where the UK GDPR applies. Those clauses take precedence over this document to the extent of any conflict.

Your obligations

You are responsible for having a lawful basis for the data you place on a server, for providing any notices your own data subjects require, and for configuring the server securely. Root access means the operating system and application layer are yours to secure.