This Data Processing Agreement (“DPA”) is an addendum to the Terms & Conditions between UmbHost Limited (“UmbHost”) and you (“Customer”). This DPA is effective from 25th September 2026 and replaces any previously applicable data processing and security terms. It will continue for as long as UmbHost provides the Services as set out in the Terms & Conditions. The subject matter, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 3.
Definitions
“Customer Data” means data provided by or on behalf of Customer or Customer End Users via the Services under the account.
“Data Controller” means the entity that determines the purposes and means of the processing of Personal Data.
“Data Processor” means the entity that processes Personal Data on behalf of the Data Controller.
“Data Protection Laws” means all data protection and privacy laws and regulations applicable to the processing of Personal Data under the Agreement, including the GDPR.
“Data Subject” means the individual to whom the Personal Data relates.
“EEA” means the European Economic Area.
“GDPR” means the UK General Data Protection Regulation as defined in the Data Protection Act 2018 and, where applicable, EU General Data Protection Regulation 2016/679.
“Personal Data” means any Customer Data relating to an identified or identifiable natural person to the extent that such information is protected as personal data under GDPR.
“Processing” has the meaning given to it in the GDPR and “process”, “processes” and “processed” shall be interpreted accordingly.
“Sub-Processor” means any third party authorised under this DPA to have logical access to and process Customer Data to provide parts of the Services.
“Services” means any product or service provided to Customer and as described in the Terms & Conditions.
Data Processing
UmbHost Limited will only act and process Customer Data in accordance with the documented instruction from Customer (the “Instruction”), unless required by law to act without such Instruction. The Instruction at the time of entering into this DPA is that UmbHost Limited may only process Customer Data with the purpose of delivering Services as described in its Terms & Conditions and any product-specific agreements. Subject to the terms of this DPA and with agreement of the parties, Customer may issue additional written instructions consistent with the terms of this Agreement. Customer is responsible for ensuring that all individuals who provide instructions are authorised to do so.
UmbHost Limited will inform Customer of any instruction that it deems to be in violation of GDPR and will not execute the instructions until they have been confirmed or modified.
When Customer Data is processed by UmbHost Limited both parties acknowledge and agree that:
- UmbHost Limited is a Data Processor of Customer Data under the GDPR
- Customer is a Data Controller of Customer Data under GDPR.
Confidentiality
UmbHost Limited shall treat all Customer Data as strictly confidential information. Customer Data may not be copied, transferred or otherwise processed in conflict with the Instruction from Customer unless required by law.
UmbHost Limited employees, and any other persons authorised by UmbHost Limited to process Customer Data, shall be subject to an obligation of confidentiality that ensures that they shall treat all Customer Data under this DPA with strict confidentiality and only process Customer Data in accordance with the Instruction.
Sub-Processing
Customer authorises UmbHost Limited to engage third-parties to process Customer Data (“Sub-Processors”) without obtaining any further written, specific authorisation. UmbHost Limited will restrict Sub-Processor access to Customer Data to what is necessary to provide the Services.
UmbHost Limited shall complete a written agreement with any Sub-Processors. Such an agreement shall at minimum provide the same data protection obligations as the ones applicable under this DPA. It remains accountable for any Sub-Processor in the same way as for its own actions and omissions.
UmbHost Limited will inform Customer of any new Sub-Processor engagements at least 30 days before the new Sub-Processor processes any Customer Data. Notifications of such engagements will be delivered to the account email address and/or through the control panel interface. It is Customer’s sole responsibility to ensure account information is correct and kept up to date.
Customer has the right to object to a use of a Sub-Processor by terminating this Addendum and Services in accordance with UmbHost Limited Terms and Conditions. A list of current Sub-Processors can be found in Annex 1.
Security
UmbHost Limited will implement and maintain technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access as set out in Annex 2 of this Addendum and in accordance with GDPR, Article 32. The security measures are subject to technical progress and development and Customer acknowledges that UmbHost Limited may update or modify the security measures from time to time provided that such updates and modifications do not result in the degradation of the overall security. In addition, UmbHost Limited will make controls available to Customer to further secure Customer Data inside the control panel.
Data Breach Notifications
If UmbHost Limited becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data on systems managed by or otherwise controlled by UmbHost Limited, UmbHost Limited agrees to notify Customer without hesitation or delay. Notifications of such incidents will be sent to the account email address as set by Customer. It is Customer’s sole responsibility to ensure this information is correct and kept up to date inside the control panel.
UmbHost Limited will make reasonable efforts to identify the cause of any breach and take necessary steps to prevent such a breach from recurring.
Customer agrees that Data Breach Notifications will not include unsuccessful attempts or activities that do not compromise the security of Customer Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, and other network attacks on firewalls or networked systems.
Data Subject Rights
If UmbHost Limited directly receives a request from a Data Subject to exercise such rights in relation to Customer Data, it will forward the request to Customer. Customer must respond to any such request within the timeframes specified within GDPR.
UmbHost Limited will assist Customer in fulfilling any obligation to respond to requests by data subjects, which may include providing controls via the control panel to help comply with the commitments set out under GDPR.
Assistance
Taking into account the nature of the processing and the information available to it, UmbHost Limited will provide reasonable assistance to Customer in meeting its obligations under Articles 32 to 36 of the GDPR, including security of processing, notification of personal data breaches, data protection impact assessments and prior consultation with the Information Commissioner's Office or other relevant supervisory authority. Assistance beyond the standard Services may be charged at UmbHost Limited's standard hourly rate.
Data Transfers
UmbHost Limited stores and processes Customer Data in secure datacentres located in the United Kingdom, the European Economic Area ("EEA") and, where Customer has selected a US-hosted service, the United States. Data may also be transferred to and processed in other countries where Sub-Processors maintain their own data processing operations. Where Customer Data is transferred outside the UK or EEA to a country without an adequacy decision, UmbHost Limited will ensure an appropriate safeguard is in place, such as the Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or the relevant data privacy framework.
Compliance and Audit Rights
UmbHost Limited agrees to maintain records of its security standards and, upon written request by Customer, UmbHost Limited shall make available all relevant information necessary to demonstrate compliance with this DPA. Customer agrees any audit or inspection shall be carried out with reasonable prior written notice of no less than 30 days and shall not be conducted more than once in any 12-month period. If UmbHost Limited declines the request, Customer is entitled to terminate this addendum and Services.
Return or Deletion of Data
UmbHost Limited only retains Customer Data for as long as required to fulfil the purposes for which it was initially collected. Before termination of this Addendum or the Services, Customer may export its Customer Data using the tools available in the control panel or by request to UmbHost Limited. Following termination in line with UmbHost Limited Terms & Conditions, all Customer Data will be deleted, unless otherwise required by law. Customer Data archived on backup systems will be securely isolated and protected from any further processing, and deleted in line with the standard backup rotation, within 7 days, or at the end of any extended or immutable retention period purchased by Customer.
Limitation of Liability
The total liability of each party under this Addendum shall be subject to the limitation of liability as set out in UmbHost Limited Terms & Conditions. For the avoidance of doubt, in no instance will UmbHost Limited be liable for any losses or damages suffered by Customer where Customer is using Services in violation of its Terms & Conditions, regardless of whether it terminates or suspends an account due to such violation.
Annex 1 - Sub-Processors
Company | Location | Service |
Stripe Payments UK, Ltd | UK | Credit/Debit Card Payments |
GoCardless Ltd | UK | Direct Debit Payments |
Nominet UK | UK | Domain Names |
Tucows Domains Inc. | Canada | Domain Names |
PDR Ltd | India | Domain Names |
Google Ireland Limited | Ireland | Google Workspace |
Google Ireland Limited | Ireland | Control panel analytics. Reporting on anonymised data. |
FreeAgent Central Ltd | UK | Financial accounting |
OVH SAS | France | Physical, cloud and virtual servers, networking, object storage and backups |
Hetzner Online GmbH | Germany | Physical, cloud and virtual servers, networking, object storage and backups |
OVH US LLC | USA | Physical, cloud and virtual servers, networking, object storage and backups |
20i Limited | UK | Email, WordPress and Linux hosting, domain names and virtual servers |
Cloudflare, Inc | USA | Networking |
Microsoft Ireland Operations Limited | Ireland | Email, databases, cloud and virtual servers and networking |
Mailgun Technologies, Inc | USA | Email delivery |
Teamwork.com Ltd | Ireland | Support tickets and project management |
GitHub, Inc | USA | Source control |
Dext Software Limited | UK | Invoice management |
Growcreate Ltd (parent company) | UK | Technical and customer support cover |
Growcreate Netherlands B.V. | Netherlands | Technical and customer support cover |
Annex 2 - Security Measures
A summary of the technical and organisational measures UmbHost Limited maintains to protect Customer Data is set out below. Further detail is available to Customers on request.
Certifications
- All datacentre providers used by UmbHost Limited hold ISO 27001 certification.
- UmbHost Limited is working towards Cyber Essentials and ISO 27001 certification. Its parent company, Growcreate Ltd, holds both.
Physical security
- Customer Data is hosted in third-party datacentres operated by Hetzner, OVHcloud and Microsoft, which provide physical access control, surveillance, environmental controls and redundant power and connectivity.
Encryption
- Data in transit is encrypted using TLS.
- Backups are encrypted before leaving the source server.
Backups and resilience
- Customer Data is backed up regularly to storage in a separate location from the primary hosting.
- Extended backup retention and, for GreenStack hosting, immutable backups are available as add-ons.
Monitoring and incident response
- Infrastructure and service availability are monitored continuously, with automated alerting.
- A public service status page is maintained.
- Security incidents are investigated and Customers are notified in line with the Data Breach Notifications section of this Addendum.
Annex 3 - Details of Processing
Subject matter | Provision of the Services, including website hosting, email hosting, domain registration, infrastructure management and technical support |
Nature and purpose | Storage, hosting, transmission, backup and restoration of Customer Data, and access for support and maintenance, solely to deliver the Services |
Types of Personal Data | Any Personal Data Customer stores in or transmits through the Services, which may include names, contact details, account credentials, IP addresses and content submitted by Customer End Users, plus Customer account and billing contact details |
Special category data | Not required by the Services. Customer is responsible for determining whether any special category data it stores is appropriately protected |
Categories of Data Subjects | Customer's staff and contractors, Customer End Users, and visitors to Customer's websites and applications |
Duration | The term of the Services, plus the backup retention period set out under Return or Deletion of Data |