Legal

Data Processing Agreement (DPA)

In one read

If you store personal data about other people on your servers (your customers, your users, your employees), data protection law (GDPR) treats you as the controller of that data, and us, who provide the infrastructure it lives on, as the processor. The law requires that relationship to be set out in writing. That is what this document is.

In short: the data is yours, you decide what to do with it and you protect it inside your server. We look after the infrastructure underneath and we do not look inside.

This agreement complements the GINERNET Terms and Conditions and the Privacy Policy. Words with a legal meaning ("controller", "processor", "processing", "data subject") have the meaning given in Regulation (EU) 2016/679 (GDPR).

1. Who is who

  • You (the Client) are the data controller for the personal data you host on your services. We call it "your data".
  • GINERNET S.L. (Tax ID B54660485, Pza. San Cristóbal 14, 03002 Alicante, Spain) is the data processor, solely because we provide the infrastructure where it is stored.

This agreement does not cover the data of your own account (name, invoices, tickets, verification). We are the controller for that data, and it is explained in the Privacy Policy.

2. Exactly what service we provide

When you create a server you choose between two types of service:

Unmanaged (the usual one). We provide infrastructure: virtual server, disk, network and, if you contract them, backups. You install and administer the operating system, the software and the applications. We do not see, review or administer what is inside.

Managed. In addition to the infrastructure, we take care of the server's base system: we install and set up the operating system, keep it updated, and install and maintain the server management software agreed with you (for example, cPanel, Imunify or JetBackup). To do this we need administrator access to the server. It does not include your websites, applications, databases, email, user accounts or the data you store in them: that remains yours and you administer it. Details in section 5.

To comply with what the law requires (art. 28.3 GDPR), this is what we do with your data:

  • What: host it on the contracted infrastructure and, on managed servers, maintain the base system it is hosted on.
  • How long: while you have active services and, for backups, up to 90 days after the server is deleted.
  • How: storage, network transmission and the normal technical operations of the platform (copies, migrations between nodes, suspension, deletion). On managed servers, also administrator access for the tasks in section 5.
  • What for: to provide the service you contracted. Nothing else.
  • What kind of data and whose: whatever you decide to host. We do not know it and we do not inventory it.

3. What is up to you

As controller, you are the one who decides and who is accountable for:

  • Having the right to process that data, informing the people affected and handling their requests (access, erasure, etc.).
  • Deciding what data you store and whether our service is suitable for it. It is not designed for especially sensitive data (health, biometrics, ideology, etc., art. 9 GDPR). If you host it, it is at your own discretion and responsibility.
  • Security inside your server: updates, passwords, SSH keys, firewall, encryption of your data, who gets in and who does not. On managed servers, we take care of the base-system part described in section 5; the rest remains yours.
  • Keeping your own backups outside the server.
  • The location you choose for each service. If you choose one outside the European Economic Area, you assess whether it is suitable and apply the safeguards the law requires (Chapter V GDPR).
  • Exporting your data before cancelling or deleting a service. After cancellation the server is gone; only backups may remain for a maximum of 90 days (section 4) and we do not guarantee that a usable copy exists.
  • Your own records, impact assessments and notifications to the data protection authority or to the people affected, if needed.

4. What is up to us

Within what corresponds to a provider of infrastructure (and, on managed servers, of the base system), we commit to:

  • Do only what you instruct. Your instructions are what you contract, configure and do in the Manager, the tickets we accept and this agreement. If a law obliges us to do otherwise, we will tell you unless the law itself forbids it.
  • Confidentiality. The people on our team with access to the infrastructure are bound by confidentiality.
  • Infrastructure security (art. 32 GDPR): access control, isolation between clients, encryption of management channels and security event logging. Details in Annex I.
  • Notify you of a breach in our infrastructure or, on managed servers, in the base system we maintain, that affects your data, without undue delay and with the information we have at that time.
  • Help you with your legal obligations (security, breaches, impact assessments, data subject rights) as far as they depend on the infrastructure or on the base system we maintain, and using the tools of the service itself. Any help beyond that is assessed case by case, if technically possible, and may carry a cost.
  • Delete the data of the service when you cancel it, in accordance with the Terms. Note that the backups associated with the server may be retained for up to 90 days after its deletion; after that period they are permanently deleted. During those 90 days they are not used for anything, unless you ask us for a restore (if the service allows it) or the law, an authority or a security or abuse incident obliges us to keep them. Other exceptions to deletion: what the law obliges us to keep and security or abuse evidence.
  • Give you information that is reasonable so you can demonstrate compliance. Audits are in writing (questionnaires or documentation), at most once a year unless requested by an authority. We do not carry out on-site audits nor allow technical testing against our infrastructure without written authorisation.

5. Managed servers

If you choose the "Managed" service type when creating the server, this is what we do and what we do not do:

We do:

  • Install and set up the operating system.
  • Maintain the operating system and apply its updates.
  • Install and maintain the server management software we agree with you. Normally this is administration software for the server itself: control panel (cPanel), security (Imunify), backups (JetBackup) or similar.

We do not:

  • Administer, maintain, update or fix your websites, applications, scripts, databases, email accounts or user accounts, nor their content.
  • Review, search, modify or delete your data, unless you expressly ask us to by ticket and it is technically possible; in that case we will assess whether it carries a cost.
  • Decide what data you store or how you process it.

How we access: for these tasks we use administrator access to the server. We use it only for what is described here or for what you ask us by ticket. That access is subject to the confidentiality and security measures in section 4.

What changes in liability: on a managed server we are accountable for the base system we maintain (operating system and agreed management software) under the terms of this agreement. Everything else (section 3) remains yours. If you or anyone with your credentials modifies the base system, installs software not agreed, or disables updates or security measures, whatever happens from then on is your responsibility.

The commercial details of the managed service (price, specific scope, response times) are those shown in the Manager when you contract it.

6. Our providers (sub-processors)

To provide infrastructure we need providers: data centres, connectivity, hardware. By accepting this agreement you authorise us to use them. We require obligations equivalent to those in this document from them and keep their list in Annex II. If they change, we will publish it in the Manager. If you object to one of them on justified data protection grounds, your option is to cancel the affected services.

7. Where your data is

Your servers are in Madrid (Spain) and their backups in Roubaix (France), both within the European Union. Provider details are in Annex II. If in the future we offer other locations and you choose one outside the European Economic Area, that choice is your decision and your instruction: you assume the assessment and the corresponding safeguards.

8. Liability

Each party is liable for what the law assigns to its role.

GINERNET is not liable for anything arising from your content, instructions, configurations, locations or uses; for incidents originating inside your server in the part you administer (on unmanaged servers, everything inside; on managed servers, everything except the base system in section 5), including applications, credentials and your users' access; nor for data loss due to not keeping your own backups.

If a claim, penalty or cost reaches us because of a breach of your obligations as controller, you bear it.

Our liability under this agreement is subject to the limits in the Terms and, in any case, will not exceed what you paid for the affected services in the twelve months preceding the event, to the extent the law allows it to be limited.

9. Term and acceptance

This agreement applies while you have services in which we act as processor and ends with them. Confidentiality and deletion continue to apply afterwards.

On matters of processing on behalf of the controller, this agreement prevails; in everything else, the Terms and Conditions (including governing law and courts).

You accept it by ticking the legal documents acceptance box in the Manager, together with the Terms and the Privacy Policy, or by signing a copy. We keep technical evidence of that acceptance (date, time, IP address, user, version and language).


Annex I — How we protect the infrastructure

  • Access to management systems limited to authorised staff, with strong authentication and least privilege.
  • Logical isolation between each client's virtual machines and networks.
  • TLS encryption on management channels; platform secrets encrypted at rest.
  • Infrastructure security event logging, with limited retention.
  • Operating and incident response procedures.
  • On managed servers: operating system kept updated and agreed management software maintained by us; administrator access limited to authorised staff and to the tasks in section 5.
  • Whatever is inside your server and is not part of the base system we maintain (applications, websites, data) is protected by you.

Annex II — Providers (sub-processors)

ProviderLocationPurpose
Interxion España, S.L.U. (Digital Realty), MAD1 data centreMadrid, Spain (28037)Physical hosting of the servers: space, power, cooling and connectivity. The servers and their disks belong to GINERNET; the provider does not access the data.
OVH Hispano, S.L. (OVHcloud group), Roubaix campusRoubaix, FranceStorage of backups.

Both locations are within the European Union. If in the future we offer other locations, they will appear in the Manager when contracting and here.