Data Processing Agreement (DPA)
Last updated: August 2026
Data Processor (Data Importer):
“Alexhost” Limited Liability Company, having its place of business at str. C. Brâncuși 3, mun. Chișinău, Republic of Moldova, represented by the General Director Alexandru Scutaru, hereinafter referred to as (“ALEXHOST” or “Processor“), and
Data Controller (Data Exporter):
[CLIENT COMPANY NAME], having its registered address at [CLIENT REGISTERED ADDRESS], represented by [REPRESENTATIVE POSITION AND NAME], hereinafter referred to as (“Client” or “Controller“)
Each individually referred to as a “Party” and collectively as the “Parties”.
RECITALS
WHEREAS, the Client has entered into a Hosting Services Agreement (the “Agreement“) with ALEXHOST under which ALEXHOST provides web hosting, server infrastructure, domain management, and related services (the “Services“);
WHEREAS, in the course of providing the Services, ALEXHOST may process personal data on behalf of the Client in its capacity as a data processor;
WHEREAS, the Parties wish to set out their respective obligations with respect to such processing, in accordance with Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”) and applicable data protection law;
NOW THEREFORE, the Parties agree as follows:
1. DEFINITIONS
All capitalised terms not defined herein have the meaning given to them in the Agreement. The terms of this DPA take precedence over any conflicting terms in the Agreement.
“Data Protection Law” means the General Data Protection Regulation (EU) 2016/679 (“GDPR”), any applicable national implementing legislation, and, where applicable, the data protection law of the Republic of Moldova (Law no. 195/2024) and any other applicable data protection regulation.
“Controller” has the meaning given to it under Data Protection Law, and refers to the Client in the context of this DPA.
“Processor” has the meaning given to it under Data Protection Law, and refers to ALEXHOST in the context of this DPA.
“Personal Data” means any information relating to an identified or identifiable natural person that the Client provides to ALEXHOST or that ALEXHOST processes in the course of providing the Services.
“Processing” (and “Process”) has the meaning given to it under Data Protection Law.
“Personal Data Breach” has the meaning given to it under Data Protection Law.
“Data Subject” means any identified or identifiable natural person whose Personal Data is processed under this DPA.
“Sub-processor” means any processor engaged by ALEXHOST to carry out specific processing activities on behalf of the Client in connection with the Services. The current list of Sub-processors is set out in Annex 3 to this DPA, published at alexhost.com/dpa/.
“Services” means the web hosting, server infrastructure, domain management, email hosting, and related services provided by ALEXHOST to the Client under the Agreement.
2. PROCESSING OF PERSONAL DATA
2.1 Roles. For all processing of Client’s Personal Data carried out by ALEXHOST in connection with the Services, the Client is the Controller and ALEXHOST is the Processor. ALEXHOST shall not act as a controller with respect to Client Personal Data.
2.2 Instructions. ALEXHOST shall process Personal Data only on the documented instructions of the Client. The Agreement and this DPA constitute the Client’s complete documented instructions. Any further instructions shall be agreed in writing. If ALEXHOST believes that an instruction infringes Data Protection Law, it shall notify the Client immediately.
2.3 Scope. A description of the processing activities covered by this DPA is set out in Annex 1.
3. OBLIGATIONS OF ALEXHOST AS PROCESSOR
ALEXHOST shall, in its capacity as Processor:
3.1 Process Personal Data only in accordance with the Client’s documented instructions, except where required to do so by Union or Member State law or the law of the Republic of Moldova; in such case, ALEXHOST shall inform the Client of that requirement before processing, unless prohibited from doing so on grounds of public interest;
3.2 Ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations (whether contractual or statutory);
3.3 Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as specified in Annex 2 and Section 8 of this DPA;
3.4 Respect the conditions for engaging Sub-processors as set out in Section 7;
3.5 Take all measures required pursuant to Article 32 of the GDPR regarding security of processing;
3.6 Assist the Client, by appropriate technical and organisational measures and to the extent reasonably possible, in fulfilling the Client’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR;
3.7 Assist the Client in ensuring compliance with the Client’s obligations under Articles 32–36 of the GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and the information available to ALEXHOST;
3.8 At the Client’s choice, delete or return all Personal Data to the Client after the end of the provision of Services, and delete existing copies, unless applicable law requires otherwise (see Section 10);
3.9 Make available to the Client all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits in accordance with Section 9.
4. INTERNATIONAL TRANSFERS OF PERSONAL DATA
4.1 Where the Services involve the processing of Personal Data on servers located in the United States of America or other countries for which no EU adequacy decision is in force, such transfer shall be governed by the Standard Contractual Clauses.
4.2 Server locations. If your servers are located in Romania, Bulgaria, Sweden, France, or the Netherlands (within the EEA), no additional transfer mechanism is required. Transfers to Switzerland are covered by an EU adequacy decision.
If personal data is transferred outside the EEA, an appropriate transfer mechanism under the GDPR must be in place. For example, transfers to the UK are covered by an EU adequacy decision, while transfers to the USA may require the Standard Contractual Clauses (SCCs).
4.3 The Client may select server locations that avoid non-adequate third countries. ALEXHOST will endeavour to accommodate such requests within the scope of available service options.
5. RIGHTS OF DATA SUBJECTS
5.1 ALEXHOST shall, to the extent reasonably identifiable as relating to Services provided to the Client, promptly notify the Client if ALEXHOST receives a request from a Data Subject to exercise their rights under Chapter III of the GDPR (including rights of access, rectification, erasure, restriction, portability, or objection).
5.2 ALEXHOST shall not respond to such requests on the Client’s behalf unless expressly authorised in writing by the Client.
5.3 ALEXHOST shall provide the Client with reasonable assistance, by appropriate technical and organisational means and insofar as possible, to fulfil the Client’s obligation to respond to Data Subject requests.
6. PERSONNEL
6.1 ALEXHOST shall ensure that all personnel engaged in the processing of Personal Data under this DPA are subject to appropriate contractual confidentiality obligations and receive adequate data protection training.
6.2 ALEXHOST shall restrict access to Personal Data to those personnel who require such access to perform the Services.
7. SUB-PROCESSORS
7.1 General authorisation. The Client grants ALEXHOST general written authorisation to engage Sub-processors for carrying out specific processing activities in connection with the Services. The current list of authorised Sub-processors is set out in Annex 3 to this DPA, published at alexhost.com/dpa/.
7.2 Change notification. ALEXHOST shall notify the Client of any intended addition or replacement of Sub-processors at least 14 days in advance by email or by publication of an updated Annex 3 at alexhost.com/dpa/. The Client may object to a new Sub-processor by written notice to ALEXHOST within 14 days of notification, specifying the data protection grounds for the objection. ALEXHOST shall work in good faith to address legitimate objections. If the objection cannot be resolved and the Client suffers material harm as a result, the Client may terminate the relevant Services on written notice.
7.3 Flow-down obligations. ALEXHOST shall impose data protection obligations on each Sub-processor that are equivalent in substance to those imposed on ALEXHOST under this DPA, in particular regarding security of processing, confidentiality, and restrictions on onward transfer.
7.4 Liability. ALEXHOST remains fully liable to the Client for the performance of each Sub-processor’s obligations.
8. SECURITY
8.1 ALEXHOST shall implement and maintain the technical and organisational security measures specified in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of Data Subjects.
8.2 Breach notification. ALEXHOST shall notify the Client without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting Personal Data processed under this DPA. Such notification shall include:
(a) a description of the nature of the breach, including the categories and approximate number of Data Subjects and Personal Data records concerned;
(b) the name and contact details of the Data Protection Officer or other point of contact from whom further information may be obtained;
(c) a description of the likely consequences of the breach;
(d) a description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.
Where all information is not available at the same time, ALEXHOST may provide it in phases without undue delay.
8.3 ALEXHOST shall document all Personal Data Breaches and make such documentation available to the Client on request.
9. AUDITS AND CERTIFICATIONS
9.1 ALEXHOST shall allow for, and contribute to, audits conducted by the Client or an auditor mandated by the Client, subject to the following conditions:
(a) the Client shall give ALEXHOST at least 30 days prior written notice of the intended audit, unless an emergency security incident requires shorter notice;
(b) audits shall be conducted during business hours and in a manner that minimises disruption to ALEXHOST’s operations;
(c) any third-party auditor nominated by the Client shall (i) not be a direct competitor of ALEXHOST; (ii) be subject to appropriate professional confidentiality obligations; and (iii) sign a non-disclosure agreement in terms reasonably required by ALEXHOST;
(d) the Client shall bear all costs of the audit, including ALEXHOST’s reasonable costs of supporting the audit.
9.2 As an alternative to or supplement to a direct audit, ALEXHOST may provide the Client with relevant certifications, third-party audit reports, or security assessments that demonstrate compliance with this DPA.
10. RETURN AND DELETION OF DATA
10.1 Upon termination or expiry of the Agreement, or upon the Client’s written request, ALEXHOST shall, at the Client’s election:
(a) return all Personal Data to the Client in a structured, commonly used and machine-readable format; or
(b) securely delete or destroy all Personal Data and all copies thereof.
10.2 ALEXHOST shall complete the return or deletion within 30 days of the termination date or the Client’s request.
10.3 ALEXHOST shall provide the Client with written confirmation of deletion upon completion.
10.4 Notwithstanding the above, ALEXHOST may retain Personal Data where required by applicable law, for as long as required by that law, provided that ALEXHOST continues to ensure the confidentiality and security of such data and processes it only to the extent required by law.
11. CLIENT’S OBLIGATIONS
11.1 The Client warrants that it has a lawful basis under Data Protection Law for the processing of Personal Data and that it complies with all applicable data protection requirements in relation to the Personal Data provided to ALEXHOST under this DPA.
11.2 The Client shall ensure that Personal Data provided to ALEXHOST has been collected fairly, transparently, and in accordance with applicable law, including providing appropriate privacy notices to Data Subjects.
11.3 The Client shall notify ALEXHOST if it provides special categories of Personal Data (Article 9 GDPR) for processing as part of the Services and shall ensure that a valid condition under Article 9(2) GDPR applies to such processing.
11.4 The Client shall promptly inform ALEXHOST of any changes to its processing instructions that may affect ALEXHOST’s obligations under this DPA.
12. LIABILITY
12.1 Each Party’s liability arising out of or related to this DPA is subject to the limitations of liability set out in the Agreement.
12.2 Nothing in this DPA limits either Party’s liability to Data Subjects or to supervisory authorities under Data Protection Law.
13. GOVERNING LAW AND DISPUTES
13.1 This DPA shall be governed by the laws of the Republic of Moldova, without prejudice to the mandatory provisions of Data Protection Law applicable in the Client’s jurisdiction.
13.2 Any dispute arising out of or in connection with this DPA shall be submitted to the exclusive jurisdiction of the courts of the Republic of Moldova, without prejudice to the Client’s right to bring proceedings before the courts of its domicile.
SIGNATURES
Controller (Client)
[CLIENT COMPANY NAME] [AUTHORISED REPRESENTATIVE NAME AND POSITION]
Signature: _________________
Processor (ALEXHOST SRL)
Alexandru Scutaru, Director General
Signature: _________________
ANNEX 1 — DESCRIPTION OF PROCESSING ACTIVITIES
Pursuant to Article 28(3) GDPR
A. Subject Matter and Nature of Processing
ALEXHOST SRL provides web hosting, server infrastructure, virtual private servers (VPS), dedicated servers, domain management, email hosting, SSL certificate management, database hosting, and related technical services. In the course of providing these Services, ALEXHOST stores, transmits, backs up, and provides access to Client data (including personal data of Client’s end-users) on its server infrastructure.
Processing operations carried out by ALEXHOST as Processor:
- Storage of Client data on physical and virtual server infrastructure
- Transmission of data over network connections
- Backup and restoration of Client data (where included in the Service)
- Infrastructure security monitoring (at network/infrastructure level — not content inspection)
- Technical support access to Client servers (on explicit Client instruction via authenticated support ticket, logged)
- Deletion of Client data on contract termination
B. Purpose of the Processing
The processing is carried out solely for the purpose of providing the Services as specified in the Agreement. ALEXHOST does not process Client Personal Data for any independent purpose.
C. Duration of Processing
ALEXHOST will retain and process the Personal Data for the duration of the Agreement. Upon termination, Personal Data will be deleted or returned in accordance with Section 10 of the DPA.
D. Categories of Data Subjects
The Personal Data transferred may concern the following categories of Data Subjects, as determined by the Client:
- End-users of the Client’s website(s), application(s), or platform(s) hosted on ALEXHOST infrastructure
- The Client’s own customers or registered users
- Email recipients, where email hosting is included in the Services
- Any other natural persons whose data the Client stores on ALEXHOST infrastructure
ALEXHOST does not determine the categories of data subjects. The Client, as Controller, is responsible for identifying all relevant data subjects.
E. Categories of Personal Data
The categories of Personal Data processed may include the following, as determined by the Client:
1. Identification data — names, usernames, user IDs 2. Contact data — email addresses, phone numbers, postal addresses 3. Authentication data — hashed passwords, session tokens, login records 4. Transaction data — orders, payments, purchase history 5. Technical data — IP addresses, device identifiers, browser data, access logs 6. User-generated content — messages, files, uploads stored on Client servers 7. Any other category — as determined by Client’s application/service
F. Special Category Data (Article 9 GDPR)
The Client shall notify ALEXHOST in writing if any special category data (Article 9(1) GDPR) is to be stored on ALEXHOST infrastructure. Where special category data is involved, the Client shall:
(a) confirm the applicable Article 9(2) condition;
(b) specify any additional security requirements to be applied to such data.
ALEXHOST does not independently collect or access special category data and is not aware of its presence unless disclosed by the Client.
G. Frequency of Processing
Processing occurs continuously for the duration of the Services (24/7 infrastructure availability).
H. Recipients / Onward Transfers
Personal Data processed by ALEXHOST may be accessed by or transferred to Sub-processors as listed in Annex 3. All Sub-processors are bound by equivalent data protection obligations.
ANNEX 2 — TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
Pursuant to Article 32 GDPR
These measures represent ALEXHOST’s minimum security commitments. ALEXHOST may implement additional measures at its discretion.
A. Access Control
1. Role-based access control (RBAC) for all infrastructure systems — access granted on a least-privilege basis 2. Multi-factor authentication (MFA) required for all administrative access to hosting control panels and infrastructure management systems 3. Access to Client server content only permitted on explicit Client instruction via authenticated support ticket; all access logged 4. Removal of access for terminated staff within 1 business day 5. Unique named user accounts for all system administrators — shared/default credentials prohibited 6. Regular access rights review (minimum: quarterly)
B. Encryption
7. TLS 1.2 or higher enforced on all client-facing connections and control panel interfaces 8. Encryption at rest for Client data stored on USA-based servers (AES-256 minimum); client-managed key option available where technically feasible 9. Encrypted transmission for all salary and financial data transfers to third parties (SFTP or equivalent) 10. Backups stored in encrypted form
C. Network and Perimeter Security
11. Firewall protection on all servers with default-deny policy for non-essential ports 12. Intrusion Detection and Prevention System (IDS/IPS) on all infrastructure 13. DDoS mitigation measures in place for hosted services 14. Web Application Firewall (WAF) available as an optional service layer 15. Remote access to infrastructure management systems restricted to VPN connections with MFA 16. Network segmentation between client environments
D. Availability and Business Continuity
17. Daily automated backup of infrastructure and (where included in Service) Client data, with tested restoration capability 18. Recovery Time Objective (RTO): < 4 hours for critical systems 19. Recovery Point Objective (RPO): < 24 hours 20. Backup restore tests conducted on a minimum quarterly basis 21. UPS (Uninterruptible Power Supply) protection for server infrastructure 22. Redundant network connectivity
E. Patch Management and Vulnerability
23. Security patches applied to operating systems and critical software on a minimum monthly cycle; critical patches applied within 72 hours of release 24. Periodic vulnerability scanning of infrastructure (minimum: quarterly) 25. Annual external penetration testing; results reviewed and remediation planned within 30 days 26. Antivirus/anti-malware protection on applicable systems
F. Physical Security
27. Data centres with restricted physical access — authorised personnel only; access logged 28. 24/7 CCTV surveillance of data centre facilities 29. Visitor pre-authorisation and accompaniment required in all data centre areas 30. Physical and environmental protections: fire suppression, temperature controls, flood protection
G. Personnel and Organisational Measures
31. All personnel with access to Client data subject to binding confidentiality agreements 32. Annual data protection training for all technical and administrative staff 33. Pre-hire background checks consistent with applicable local law 34. Incident response plan documented and tested; 72-hour breach notification to Client (in accordance with Section 8.2) 35. Information security policies published internally and communicated to all relevant staff and Sub-processors 36. Designated point of contact for data protection matters: gdpr@alexhost.com
H. Logging and Monitoring
37. Access logs maintained for all administrative access to infrastructure: retained minimum 12 months 38. All staff access to Client servers via support ticket logged in ticketing system and available for Client inspection on request 39. Security event monitoring and alerting in place for anomalous access patterns
I. Sub-processor Security
40. All Sub-processors assessed for security compliance before engagement 41. Sub-processors bound by data protection obligations equivalent to this Annex 42. Sub-processor agreements include right of ALEXHOST to audit Sub-processor security measures
ANNEX 3 — LIST OF SUB-PROCESSORS
This Annex is published and kept current at alexhost.com/dpa/.
| Sub-processor | Country | Services provided | Transfer mechanism |
|---|---|---|---|
| Digital Realty | Sweden | Physical co-location, power, network | EU/EEA — no restriction |
| Digital Realty | Netherlands | Physical co-location, power, network | EU/EEA — no restriction |
| Voxility | Romania | Physical co-location, power, network | EU/EEA — no restriction |
| S3C | Bulgaria | Physical co-location, power, network | EU/EEA — no restriction |
| DC2Scale | France | Physical co-location, power, network | EU/EEA — no restriction |
| NTT | Switzerland | Physical co-location, power, network | EU adequacy decision (Switzerland) |
| Fiberhub | United States (Las Vegas) | Physical co-location, power, network (USA servers) | SCC Module 2 + TIA |
| CMI (China Mobile International) | United Kingdom | Physical co-location (UK servers) | UK adequacy + IDTA |
| MAIB; Paynet | Moldova | Card payment processing for ALEXHOST’s own invoicing — does not process Client Personal Data | N/A |
| PayPal Pte. Ltd. | Singapore | Payment processing for ALEXHOST’s own invoicing — does not process Client Personal Data | N/A |
| CoinGate | Lithuania | Cryptocurrency payment processing for ALEXHOST’s own invoicing — does not process Client Personal Data | N/A |
| Cryptomus (Xeltox Enterprises Ltd) | Canada | Cryptocurrency payment processing for ALEXHOST’s own invoicing — does not process Client Personal Data | N/A |
| Openprovider | Netherlands | Domain registration and WHOIS management | EU/EEA — no restriction |
| Yelles AB (Sweden); Inter.link GmbH (Germany); FBW Networks SAS (France); Belcloud LTD (Bulgaria); INTERKVM HOST SRL (Romania) | EU/EEA | Transit connectivity | EU/EEA — no restriction |
| RETN Limited | United Kingdom | Transit connectivity | EU adequacy decision (UK) |
| iFog GmbH | Switzerland | Transit connectivity | EU adequacy decision (Switzerland) |
| Cogent Communications, LLC; Hurricane Electric LLC; VegasNAP, LLC (Fiberhub) | United States | Transit connectivity | SCC Module 2 + TIA |
| Moldtelecom SA | Moldova | Transit connectivity | SCC Module 2 + TIA |
| China Mobile International Limited | Hong Kong | Transit connectivity | SCC Module 2 + TIA |
ALEXHOST will notify the Client at least 14 days in advance of any changes to this list.
Note: Sub-processors handle ALEXHOST’s infrastructure. They do not independently access or process Client application data.