BorgohostSee pricing

Data Processing Agreement

This applies to personal data inside your website, where you are the controller and we process it for you. It is part of your contract and you do not need to sign anything separately.

Last reviewed 8 August 2026. Forms part of theTerms of Service.

1. The two roles, because people get this backwards

There are two different sets of personal data and we are a different thing for each.

  • Your account and billing data. Your name, email, billing address, VAT number, invoices. We are the controller. This agreement does not govern it; ourPrivacy Policy does.
  • Personal data inside your website. Your visitors, your form submissions, your customers, your WordPress users. You are the controller and we are your processor.That is what this document is for.

You decide what personal data goes into your site and why. We never do.

2. Parties

Processor: Sean Jeremiah Vella St John, trading as Borgohost, a Malta sole proprietorship. Registered address and VAT number on thelegal notice. Controller: you, the customer named on the subscription.

3. What we will and will not do with it

  • We process it only to provide the hosting service, and only on your instructions. Your instructions are this agreement, the Terms, and anything specific you ask us to do in writing.
  • We will never use it for our own purposes. Not analytics, not marketing, not profiling, not benchmarking, and not training any machine-learning model.
  • We will not sell it, rent it or share it, other than with the sub-processors in Annex III.
  • If we ever think an instruction of yours breaks data protection law, we will tell you and not just carry on.
  • If we are legally compelled to disclose it, we will tell you first unless the law forbids that.

We do read site content when you ask us to fix something, and when we are investigating abuse under the Acceptable Use Policy. That is support and safety, not a separate purpose, and it is done by one named person rather than a team with standing access.

4. Confidentiality

One person operates this service and that person is bound to confidentiality. If that ever changes, anyone with access will be under a written confidentiality obligation before they get it, and Annex II will be updated before rather than after.

5. Security

The measures are in Annex II, split into what is running today and what is committed before the first customer site exists. Where a common control is absent, Annex II says so instead of leaving you to assume it is there.

Report a suspected vulnerability to security@borgohost.com. See the security and vulnerability disclosure policy.

6. Personal data breaches

If we become aware of a breach affecting personal data in your site, we notify youwithout undue delay and in any case within 24 hours of becoming aware. You are the controller, so the 72-hour notification to your supervisory authority is your call to make, and a processor who takes three days to tell you has spent your deadline for you.

Our notice will contain what we know, what we do not yet know, what we are doing, and when you will hear from us next. We will not delay a notification to make it complete.

7. Assisting you

  • Data subject requests. If a visitor to your site contacts us directly we will not answer on your behalf; we will forward it to you promptly. Where you need our help to find, export, correct or delete something, we help at no charge.
  • Impact assessments and consultations. We give you the information we hold that you need for a DPIA or a prior consultation.
  • Audits. You may ask for the information needed to demonstrate our compliance, and we will answer in writing. For a one-person business, an on-site audit is neither proportionate nor useful, so what we offer instead is a written answer to any specific question, and we will not hide behind commercial confidentiality to avoid one.

8. Sub-processors

You authorise the sub-processors in Annex III. We impose data protection obligations on each of them equivalent to those in this agreement, and we remain liable to you for what they do.

Before adding or replacing one, we give you 30 days notice by email. If you object on reasonable data protection grounds within that period and we cannot resolve it, you may terminate the affected subscription and we refund the unused part of your term. We will not add a sub-processor silently and we will not treat an updated web page as notice.

9. International transfers

Some sub-processors in Annex III are outside the EEA. Where they are, we rely on an adequacy decision where one covers the recipient, and on the European Commission's standard contractual clauses otherwise, with a transfer risk assessment. Site data itself is stored in the EU: Germany for the live site, and see Annex III for backups.

10. Deletion and return

On termination we delete personal data from your site on the schedule in thebackup and data retention policy: the site leaves the node 45 days after a non-payment termination, and everything including backups is purged at 75 days. A voluntary cancellation is gentler: service to the end of your paid term, then purge 14 days later.

Before either purge you can export everything, and we will help. After the purge it is gone, which is the point of a deletion commitment: we cannot restore a site we have honestly destroyed. Off-site backups roll off within 14 days, so the purge reaches them too.

We keep no copy afterwards, with one exception we state rather than bury: invoices and tax records, which contain your account details and not your site's data, are kept for six years because Maltese VAT law requires it.

11. Liability and precedence

The liability limits in the Terms of Service apply. Where this agreement and the Terms conflict on the treatment of personal data, this agreement wins. Nothing here limits liability that cannot be limited by law.

Annex I. What is being processed

Subject matterManaged WordPress hosting for one website per subscription.
DurationThe life of your subscription, plus the retention periods in clause 10.
Nature and purposeStoring, serving, backing up and restoring your website, and supporting you when it breaks.
Type of personal dataWhatever you put in your site. Typically visitor IP addresses and server logs, contact-form submissions, WordPress user accounts, comments, and any customer records or order data your site holds.
Categories of data subjectYour website's visitors and users, and any person whose data you choose to store in it.
Special category dataNot expected, and the service is not designed for it. If your site will hold health, biometric, political, religious or similar data, tell us before you buy so we can say honestly whether we are the right host.

Annex II. Security measures, including the gaps

Running today, on the infrastructure that serves this website:

  • TLS on every public connection, with strict origin verification behind the edge, so the encrypted connection does not silently become plaintext between the edge and our server.
  • No credentials of any kind stored in the source repository. The one deployment credential lives only on the server, and an automated secret scan blocks the build on any credential reaching a commit.
  • An automated dependency audit on every change, blocking on a high or critical advisory.
  • Administrative and staging access behind a zero-trust proxy, with no login form exposed on the public internet and no shared accounts.
  • No third-party script, analytics, tracking pixel or cookie on the public site at all, which is verifiable from your own browser. See the Cookie Policy.

Committed before the first customer site is provisioned. These are not running today because there is nothing yet to run them against, and we would rather label them than let you read them as current:

  • Encryption at rest for off-site backups, applied on our own server with AES-256 before upload, so the storage provider holds ciphertext it cannot read.
  • Backups verified by checksum and by an actual test restore, not by the backup job reporting success.
  • Least-privilege database credentials, separated per service.
  • Logical separation between customer sites on shared infrastructure, and resource limits so one site cannot starve another.
  • A retention and deletion schedule enforced by scheduled jobs rather than by someone remembering, on the dates in the backup and data retention policy.

If you are evaluating us and any item in the second list matters to you, ask before you buy and we will tell you exactly where it stands rather than which list we would prefer it to be in.

What is not in place, stated because a security annex that lists only strengths is marketing:

  • No 24/7 staffed response. One person, 09:00 to 17:30 CET, Monday to Friday. Automated containment runs at any hour for the most serious abuse categories, but a human does not. If your risk model needs an overnight responder, we are not the right host and we would rather say so here than in an incident.
  • No SOC 2, ISO 27001 or PCI DSS certification. We hold none of them and we will not imply otherwise. Card data is handled entirely by our payment provider and never reaches our servers, so our PCI exposure is the minimum, but that is not the same as being certified.
  • No independent penetration test yet. When one has been done, this line will say so and give the date.
  • No bug bounty. Reports are welcome and taken seriously; there is no money behind them.

Annex III. Sub-processors

The full list, with what each one can see and where it is, is on thesub-processor page, which is the maintained version and forms part of this annex. As of 8 August 2026 it names 10 sub-processors. Changes are notified as in clause 8.

Questions about any of this: privacy@borgohost.com.