WordPress tuned for LiteSpeed, with engineer support
Self-managed hosting with cPanel and LiteSpeed
Dedicated-vCPU nodes, fully managed by our engineers
Edge protection and account hardening
Maintenance, SEO, marketing and brand identity
ALTIUS HOST LLC | Last Updated: September 27, 2026
This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Service between ALTIUS HOST LLC (“Processor”, “we”, “us”) and the Client (“Controller”, “you”). It is automatically accepted upon acceptance of the Terms of Service and applies whenever the Client uses our hosting infrastructure to process personal data that is subject to a data protection law imposing obligations on controllers and processors — including, without limitation, personal data of individuals located in the European Economic Area (“EEA”), the United Kingdom, or Switzerland.
For the avoidance of doubt:
This DPA is entered into in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”) and, where applicable, the UK GDPR, the Swiss Federal Act on Data Protection, and any other data protection law requiring a written processing agreement. Where such a law imposes requirements beyond those set out here, those requirements apply to the extent of the difference.
Subject matter: The provision of managed web hosting, cloud infrastructure, and related technical services.
Duration: For the entire term of the Client’s active service subscription, plus any retention period set out in Section 10 below.
Nature and purpose of processing: Storage, hosting, transmission, backup, and technical maintenance of Client data as necessary to deliver the contracted services, including — for Clients who order Managed Edge Security — configuration and monitoring of the Client’s own Cloudflare account through member access granted by the Client. We do not access, analyse, or use Client content for any purpose other than service delivery, technical support requested by the Client, security incident response, and legal compliance.
Types of personal data: Determined entirely by the Client. This may include names, email addresses, postal addresses, telephone numbers, IP addresses, account credentials, transaction records, and any other data the Client chooses to store. For Managed Edge Security, this additionally includes the IP addresses, request metadata, and security-event records of visitors to the Client’s website, as displayed in the Client’s Cloudflare account.
Categories of data subjects: Determined entirely by the Client. This may include the Client’s own customers, website visitors, employees, suppliers, and other individuals.
We process personal data only on documented instructions from the Client, including with regard to transfers to third countries, unless required to do otherwise by applicable law. Where we are required by law to process data beyond the Client’s instructions, we will inform the Client of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest.
The Client’s instructions are constituted by: (a) the Terms of Service; (b) this DPA; (c) the Client’s configuration of and use of the services; and (d) any written instructions submitted through our support channels.
We will inform the Client if, in our opinion, an instruction infringes the GDPR or other applicable data protection law.
All personnel authorised to process personal data on our behalf are bound by written confidentiality obligations that survive the termination of their engagement. Access to Client data is granted strictly on a need-to-know basis and is limited to what is necessary for service delivery, technical support, and security operations.
We implement and maintain appropriate technical and organisational measures, including:
Clients whose own risk assessment requires encryption at rest should implement it within their own environment — for example, application-level or database-level encryption, or encrypting exports before storing them elsewhere. We are happy to advise on configuration.
The Client remains responsible for the security of its own application layer, including software updates, plugin management, credential hygiene, and independent backups of its own data.
The Client provides general written authorisation for us to engage sub-processors. We impose data protection obligations on each sub-processor that are no less protective than those set out in this DPA, and we remain fully liable to the Client for the performance of each sub-processor’s obligations.
The sub-processors we engage, together with those we have disclosed in advance of engaging, are listed below. This list is maintained on this page and is accurate as at the date shown at the top of this document:
| Sub-processor | Purpose | Location | Status |
|---|---|---|---|
| Hetzner Online GmbH | Physical server infrastructure and backup storage | Germany, Finland | Active |
| WHMCS Ltd | Client portal, billing, and support ticketing; processes personal data from hosted content only where the Client includes it in a support ticket | United States (Houston, Texas) | Active |
| OVH SAS | Physical server infrastructure | France, Netherlands | Planned — not yet in use |
| MailBaby (InterServer, Inc.) | Outbound mail relay for hosted accounts | United States | Planned — not yet in use |
| WebPros International GmbH and its group affiliates | Server monitoring and read-only administrative access to hosting accounts through the WebPros Dashboard and its MCP interface, used by our staff for administration and support | Switzerland, with group affiliates in other countries including the United States | Planned — not yet in use |
| Anthropic, PBC | AI assistant (Claude, under Anthropic’s commercial terms) used by our staff for server administration, log review, and configuration support; processes Client data only to the extent contained in the information reviewed | United States | Planned — not yet in use |
Other service providers. The following providers support our own website, account management, fraud prevention, and domain registration. They process account, billing, and website-visitor data for which we act as an independent Controller under our Privacy Policy, and they do not process the personal data contained in your hosted content:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | DNS and edge protection for our own website and corporate systems; not applied to hosted Client accounts by default (see Section 5) | Global |
| Namecheap, Inc. | Domain registration and management | United States |
| MaxMind, Inc. | Fraud risk scoring at registration and checkout | United States |
| Intuition Machines, Inc. (hCaptcha) | Bot protection on login and registration forms | United States |
Planned sub-processors. An entry marked planned is disclosed in advance so that you have notice of it before it is engaged, and so that you can raise any objection at the outset rather than mid-term. No Client data is processed by a planned sub-processor until it is brought into service, at which point this list is updated and its status changes to active. You may object to a planned sub-processor at any time under the paragraph below, on the same terms as an addition.
We will give the Client at least thirty (30) days’ prior notice of the addition or replacement of any sub-processor. The Client may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Client may terminate the affected services without penalty and receive a pro-rata refund of prepaid fees.
Note to the Client: Our client portal, billing, and support platform is hosted in the United States, and our payment processing, banking, fraud screening, and bot protection providers are likewise United States entities. These systems hold account, billing, and support data — in respect of which we act as an independent Controller under our Privacy Policy — and not the personal data contained within your hosted websites, databases, or applications, which remains at rest within the EEA as described in Section 7.
Where you submit personal data relating to your own data subjects through a support ticket, that data is transmitted to and stored on the United States platform. We ask Clients not to include end-user personal data in support tickets except where strictly necessary to resolve a technical issue.
Client-initiated integrations. Where the Client connects its account or website to third-party services of its own choosing — including AI assistants and agents, and the cPanel MCP connection activated through the Client’s own WebPros account — those services act on the Client’s instructions under their own terms. They are not sub-processors engaged by us, and this DPA does not apply to data the Client sends to them. Where we ourselves use such a provider to operate or support the services — for example for server monitoring or AI-assisted administration — that provider acts as our sub-processor and is listed in the table above.
Client’s own Cloudflare account. Where the Client orders Managed Edge Security, Cloudflare provides its services to the Client directly under the Client’s own agreement with Cloudflare, and is not our sub-processor for that service. We access the Client’s Cloudflare account as an invited member on the Client’s instructions, and any processing we carry out through that access — including review of security-event records — is covered by this DPA.
Client content data — the websites, databases, email, and applications you host with us — is stored at rest exclusively within the European Economic Area. Infrastructure is currently located in Germany and Finland, with planned expansion to France and the Netherlands as set out in the sub-processor list above. All locations, current and planned, are within the EEA. Hosted content is not transferred to or stored in the United States as part of normal service delivery.
Outbound mail relay. Where a hosted account sends email, the message is handed to an outbound mail relay for delivery. Once the planned relay described in the sub-processor list above is brought into service, messages sent from hosted accounts will pass through infrastructure located in the United States while in transit. Messages are relayed and delivered rather than stored: the relay holds a message only for as long as delivery requires, and mailboxes, archives, and incoming mail remain on our EEA infrastructure. Clients for whom transit outside the EEA is unacceptable should configure their own outbound mail provider, and we will assist with the configuration.
Account, billing, and support data is different. Our client portal, billing system, and support ticketing platform are hosted in the United States. Account details, invoices, and support correspondence are therefore stored and processed there. Where this involves a transfer of personal data from the EEA or the United Kingdom, it is carried out under the Standard Contractual Clauses referred to below.
Managed Edge Security. Hosted accounts are not served through any content delivery network operated by us or on our behalf. Where the Client orders Managed Edge Security, Cloudflare operates within the Client’s own Cloudflare account under the Client’s own agreement with Cloudflare, as described in Section 6. In that case, content the Client has made publicly available may be cached transiently at Cloudflare edge locations outside the EEA in order to serve visitors in those regions. Such caching is temporary and does not change where the Client’s hosted data is stored, which remains within the EEA.
Where administrative or support access from outside the EEA is necessary (for example, technical support performed by our personnel), such transfers are carried out under the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three (processor to processor) or Module Two (controller to processor) as applicable, which are incorporated into this DPA by reference. Where the UK Addendum, the Swiss adaptations, or an equivalent transfer instrument is required for a particular transfer, that instrument applies in addition and is likewise incorporated by reference. We have conducted a transfer impact assessment covering these access scenarios and maintain supplementary measures including encryption, access logging, and minimisation of administrative access.
Transfers to sub-processors located outside the EEA, including the outbound mail relay and the administration tools listed in Section 6, are carried out under Module Three of the Standard Contractual Clauses concluded with the sub-processor, or under the EU–U.S. Data Privacy Framework where the sub-processor is certified under it. The details required by the Standard Contractual Clauses are set out in the Annex to this DPA.
We will provide reasonable assistance to the Client in relation to:
We will notify the Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Client data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned insofar as known, the likely consequences, and the measures taken or proposed to address it.
Upon termination or expiry of the services, the Client may export its data through the client portal. Following termination, Client data is retained for a period of thirty (30) days to allow for recovery, after which it is permanently deleted from active systems. Backup archives operate on a rolling seven (7) day rotation and are overwritten within that window, so no backup copy of terminated data persists beyond it.
We will not retain Client content data beyond these periods unless required by applicable law. Billing and tax records are retained separately under our own legal obligations as described in the Privacy Policy. For Managed Edge Security, our member access to the Client’s Cloudflare account ends with the service, and we do not retain copies of security-event records beyond those included in reports delivered to the Client.
We will make available to the Client all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including relevant third-party certifications and audit reports held by us or our sub-processors.
Where the Client requires an audit beyond the provision of such documentation, the Client may request one no more than once per calendar year, subject to thirty (30) days’ written notice, execution of a confidentiality agreement, conduct during normal business hours, and no unreasonable disruption to our operations or to other clients. The Client bears the cost of any such audit. In the case of a supervisory authority exercising its powers, the foregoing limitations do not apply.
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except where such limitation is not permitted by applicable data protection law.
Data protection enquiries, data subject requests, and sub-processor objections should be directed to:
Data Protection Contact
ALTIUS HOST LLC
8206 Louisiana Blvd NE, Ste A #9372
Albuquerque, NM 87113, United States
Email: [email protected]
In the event of a conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails.
A. List of parties
Data exporter: the Client, as identified in its account with us. Role: controller (Module Two) or, where the Client itself processes the data on behalf of another controller, processor (Module Three). Contact details: those registered in the Client’s account. The Client’s acceptance of the Terms of Service constitutes its signature of the Standard Contractual Clauses.
Data importer: ALTIUS HOST LLC, 8206 Louisiana Blvd NE, Ste A #9372, Albuquerque, NM 87113, United States. Contact: [email protected]. Role: processor. Publication of this DPA as part of our Terms of Service constitutes our signature of the Standard Contractual Clauses.
B. Description of the transfer
C. Competent supervisory authority
Determined in accordance with Clause 13 of the Standard Contractual Clauses: the supervisory authority of the Member State in which the Client is established; where the Client is not established in the EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which its representative is established or, where no representative is required, of one of the Member States in which the data subjects concerned are located.
D. Technical and organisational measures
The measures described in Section 5 of this DPA.
E. Sub-processors
The sub-processors listed in Section 6 of this DPA.
F. Selected options
Clause 7 (docking clause) applies. Clause 9: Option 2 (general written authorisation), with the notice period set out in Section 6. Clause 11: the optional wording does not apply. Clause 13: as set out in Part C above. Clause 17: Option 1, the law of Ireland. Clause 18: the courts of Ireland.
For your administrative records, an official PDF copy of this Data Processing Agreement is available for download.
For your administrative records, you may download an official copy of the ALTIUS HOST LLC Data Processing Agreement (DPA).
Download PDF Document →