الانتقال إلى المحتوى
2-Host

Legal

Data Processing Agreement

The GDPR terms that apply when we host personal data for you. Part of every web hosting and VPS contract, with no signature needed.

Last updated 5 October 2026

When you store personal data in your web hosting or VPS, for example your customers’ orders, your visitors’ form submissions or your team’s email, you are the controller of that data and 2-Host is your processor. Article 28 of the GDPR requires a written agreement between us. This page is that agreement. In short:

  • The data you host (sites, databases, email and backups) is stored and processed in a Tier-3 datacenter in the EU. Backups stay in the EU too.
  • No sub-processor outside the EU/EEA handles the data you host.
  • It applies automatically to every web hosting and VPS service as part of our Terms of Service. If you need a signed copy for your records, email privacy@2-host.com.
  • We tell you without undue delay if a personal-data breach affects your data.
  • When your service ends, your data is deleted from our live systems and ages out of backups within the retention period of your plan.

1. Parties and scope

This agreement is between you, the customer (the "controller"), and 2-Host Web Hosting & Cloud Services, a sole trader (enskild firma), organisationsnummer 990729-6975, Enköping, Sweden (the "processor", "we"). It covers personal data that you store or process using our web hosting and VPS services (the "Services"). It runs for as long as you use the Services, and afterwards until the data has been deleted as described in section 10.

Personal data that we handle for our own purposes, such as your account, billing and support data, is not covered here. For that data we are the controller, as described in our Privacy Policy.

2. What we process, and why

  • Subject matter and purpose: providing the Services, which means storing, hosting, serving, backing up and transmitting your data, and giving technical support when you ask for it.
  • Types of personal data: whatever you choose to store, for example names, contact details, account data of your own users, order details, messages and email content. You decide what your services contain.
  • Data subjects: the people whose data you store, for example your website visitors, customers, members, employees and email correspondents.
  • Special categories of data (such as health data) are processed only if you choose to store them. You are responsible for deciding whether our Services are suitable for that data.

3. Processing only on your instructions

We process your data only on your documented instructions. Those instructions are this agreement, our Terms of Service, the way you configure your services, and the requests you send us through the client area or by email. We will tell you if we believe an instruction breaks the GDPR. If EU or Swedish law requires us to process your data in another way, we will tell you before we do, unless the law forbids it.

4. Confidentiality

Only people who need access to run and support the Services can reach your data, and they are bound by confidentiality. We do not look at the contents of your services unless you ask us to, or unless it is necessary to keep the Services secure or to comply with the law.

5. Security measures

We protect your data with technical and organisational measures suited to the risk, including:

  • Physical security, power and network redundancy of a Tier-3 datacenter in the EU.
  • DDoS filtering in the datacenter network before traffic reaches our servers.
  • Hardware-isolated VPS instances and isolated shared-hosting accounts.
  • Firewalled servers, key-only SSH for administrative access, automatic security updates and protection against login attacks.
  • Daily backups kept in a separate location in the EU, with 7 to 60 days of retention depending on the plan.
  • Encryption in transit: free SSL certificates for every site, and encrypted connections to the client area and control panels.
  • Monitoring of our infrastructure and a working incident-response process.

You are responsible for the security of what runs inside your services, for example keeping your applications updated and your passwords strong. On a VPS you have full root access, so you also manage the operating system’s own security.

6. Where the data is stored

The data you host, including backups, is stored and processed within the EU. We do not transfer it outside the EU/EEA. If that ever became necessary, we would tell you in advance and only proceed with a valid safeguard under the GDPR, such as an adequacy decision or the European Commission’s Standard Contractual Clauses.

7. Sub-processors

You give us general permission to use sub-processors for the data you host. Each one is bound by a contract with data-protection obligations at least as strict as these. The sub-processors that handle data you host are:

  • EU-based datacenter and backup-storage infrastructure providers, which provide the physical servers, power, network and DDoS filtering, and the storage for backups. Location: the EU.

Other providers we use, such as payment processing, domain registries, email delivery for our own messages, spam protection, statistics and live chat in the client area, handle our customer account data rather than the data you host. They are listed in our Privacy Policy.

We will email you at least 30 days before adding or replacing a sub-processor for the data you host. If you object on reasonable data-protection grounds and we cannot resolve it, you may end the affected service and receive a pro-rata refund for the unused period.

8. Helping you meet your obligations

Most requests from your data subjects, such as access, correction or deletion, you can handle yourself in cPanel or on your server. Where you need us, we will help as far as is reasonably possible. We will also give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority. If a data subject contacts us directly about data you host, we will pass the request on to you and not answer it ourselves.

9. Personal-data breaches

If we become aware of a personal-data breach affecting the data you host, we will notify you without undue delay. We will tell you what we know about the nature of the breach, the categories and approximate amount of data affected, the likely consequences, and what we have done or propose to do. We will keep you updated as we learn more, so that you can meet your own reporting duties to the supervisory authority and to the people affected.

10. Deletion and return at the end of the service

Before your service ends, you can download your data at any time, for example with a full cPanel backup or by copying it from your VPS. When the service ends, we delete your data from our live systems. Copies in backups are overwritten as they age out of the retention period of your plan, which is at most 60 days. We keep data longer only where EU or Swedish law requires it.

11. Information and audits

We will make available the information you need to show that this agreement is being followed, including this document and answers to reasonable security questionnaires. If you need an audit beyond that, we will agree on its scope, timing and confidentiality in advance. Audits take place at your cost, with reasonable notice and no more than once a year, unless a breach or a supervisory authority requires it.

12. Liability and precedence

This agreement is part of our Terms of Service, and the liability terms there apply. If this agreement and the Terms of Service conflict on the processing of personal data, this agreement applies. Swedish law governs it.

13. Contact

For questions about this agreement, a signed copy, or to report a concern, contact privacy@2-host.com.