Last updated: July 30, 2026

1. Purpose and Applicability

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Xponzy Tech LLC ("Xponzy" or the "Processor") and the client ("Client" or the "Controller") and applies whenever Xponzy processes personal data on behalf of the Client in the course of providing web hosting, business email, email migration, DNS management, email security, web development, technical support, or managed IT services (the "Services"). It reflects the requirements of Article 28 of the General Data Protection Regulation (GDPR) and of similar data protection laws where they apply to the parties' relationship.

This DPA does not apply to personal data that Xponzy processes for its own purposes as an independent controller, such as the Client's account, billing, and support records, which are governed by our Privacy Policy.

2. Definitions

"Personal data," "processing," "controller," "processor," "data subject," "personal data breach," and "supervisory authority" have the meanings given in the GDPR or, where the GDPR does not apply, the equivalent meanings under the applicable data protection law. "Client Personal Data" means personal data contained in content that the Client stores or transmits through the Services, including website files, databases, and mailboxes. "Subprocessor" means a third party engaged by Xponzy to process Client Personal Data.

3. Roles of the Parties

For Client Personal Data, the Client acts as controller (or as a processor acting on behalf of another controller, in which case the Client warrants that it has the necessary authority to bind that controller to this DPA), and Xponzy acts as processor. The Client is responsible for the lawfulness of the personal data it places on the Services, for having a valid legal basis, for providing any required notices to data subjects, and for issuing lawful instructions to Xponzy.

4. Details of the Processing

4.1 Subject matter and duration

The subject matter is the provision of the Services described in the Terms of Service and the applicable order pages. The duration is the term of the Services, plus the deletion period described in Section 12.

4.2 Nature and purpose

Hosting, storage, transmission, backup, migration, technical support, and related operations necessary to provide the Services, performed on infrastructure managed by Xponzy and its Subprocessors.

4.3 Types of personal data

Determined by the Client. Typically: names, contact details, account identifiers, communications content and metadata, transaction records, and any other personal data the Client or its users include in hosted content or mailboxes. The Client agrees not to place special categories of data on the Services unless the parties have agreed on measures appropriate to that data.

4.4 Categories of data subjects

Determined by the Client. Typically: the Client's customers, prospects, employees, contractors, suppliers, and website visitors and correspondents.

5. Instructions

Xponzy will process Client Personal Data only on the Client's documented instructions, including with regard to international transfers, unless processing is required by law to which Xponzy is subject; in that case Xponzy will inform the Client of the legal requirement before processing, unless the law prohibits it. The Terms of Service, this DPA, and the Client's use of the configuration options of the Services constitute the Client's complete documented instructions. Additional instructions require agreement of both parties. Xponzy will inform the Client if, in its opinion, an instruction infringes applicable data protection law.

6. Confidentiality

Xponzy ensures that all persons authorized to process Client Personal Data, including employees and contractors, are bound by contractual or statutory obligations of confidentiality and receive appropriate instruction on data protection. Access to Client Personal Data is limited to personnel who need it to perform the Services, in line with the least-privilege rules described in our Security Policy.

7. Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, Xponzy implements appropriate technical and organizational measures to protect Client Personal Data, including:

  • Encryption of data in transit using TLS;
  • Role-based access controls, unique accounts, and the principle of least privilege;
  • Daily backups with restoration procedures;
  • Logging and monitoring of systems for anomalies and security events;
  • Timely application of security patches to managed systems;
  • Segregation between client environments on shared platforms;
  • A documented incident response process.

These measures are described further in our Security Policy and may be updated over time, provided that updates do not materially reduce the overall level of protection.

8. Subprocessors

The Client grants Xponzy general authorization to engage Subprocessors for the provision of the Services, such as data center and infrastructure providers and backup storage providers. Xponzy will:

  • Maintain a current list of Subprocessors involved in processing Client Personal Data, available upon request through our contact form at https://xponzy.com/contact.php;
  • Impose on each Subprocessor, by written contract, data protection obligations materially equivalent to those of this DPA;
  • Give the Client advance notice of the addition or replacement of a Subprocessor, through the client portal or other reasonable means, allowing the Client to object on reasonable data protection grounds;
  • Remain fully liable to the Client for the performance of each Subprocessor's obligations.

If the Client objects and no reasonable alternative is available, either party may terminate the affected Service, with a pro-rata refund of prepaid fees for the unused period.

9. Assistance to the Controller

Taking into account the nature of the processing, Xponzy will assist the Client with appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Client's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection). If a data subject contacts Xponzy directly about Client Personal Data, Xponzy will redirect the request to the Client without responding on the merits, unless required by law. Xponzy will also assist the Client, to a reasonable extent, with data protection impact assessments and prior consultations with supervisory authorities, where required, and with the Client's own security and breach notification obligations, based on the information available to Xponzy. Assistance that goes beyond what is included in the Services may be charged at reasonable rates agreed in advance.

10. Personal Data Breach Notification

Xponzy will notify the Client without undue delay after becoming aware of a personal data breach affecting Client Personal Data. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a point of contact for further information. Xponzy will provide updates as the investigation progresses and will reasonably cooperate with the Client's own notification obligations. Notification of a breach is not an acknowledgment of fault or liability.

11. International Transfers

Xponzy is established in the United States, and Client Personal Data is processed in the United States and in the countries where Subprocessors operate. Where the transfer of Client Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a third country requires appropriate safeguards, the parties rely on the European Commission's Standard Contractual Clauses (controller-to-processor module, or processor-to-processor module where applicable), which are deemed incorporated into this DPA and completed with the details set out in Section 4, together with the UK Addendum or Swiss adaptations where relevant, and supplementary measures where needed. If a required transfer mechanism is invalidated, the parties will cooperate in good faith to implement a lawful alternative.

12. Return and Deletion

Upon termination or expiration of a Service, Xponzy will, at the Client's choice expressed before or at termination, return Client Personal Data in a commonly used format by making it available for download, or delete it, unless applicable law requires further storage. Absent an instruction, Client Personal Data is deleted from production systems after the grace period described in the Terms of Service, and from backups in the course of routine backup rotation. The Client is responsible for exporting its data before the end of the grace period.

13. Audits

Xponzy will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA, starting with our published Security Policy and responses to reasonable written security questionnaires. Where the Client is legally required to conduct an audit, the Client or an independent auditor mandated by it (not a competitor of Xponzy) may audit the processing under this DPA, subject to: reasonable advance written notice; a maximum frequency of once per twelve months, except after a personal data breach or where required by a supervisory authority; confidentiality undertakings; no access to data of other clients; and execution during business hours with minimal disruption. Each party bears its own audit costs, and Xponzy may charge reasonable fees for assistance that exceeds what is legally required.

14. Liability and Precedence

The liability of each party under this DPA is subject to the exclusions and limitations of liability set out in the Terms of Service, except where applicable data protection law does not permit such limitation. In case of conflict between this DPA and the Terms of Service regarding the processing of Client Personal Data, this DPA prevails. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.

15. Term

This DPA takes effect when the Client accepts the Terms of Service or uses the Services, and remains in force as long as Xponzy processes Client Personal Data.

16. Contact

Questions about this DPA, requests for the current Subprocessor list, and data protection inquiries can be sent through our contact form at https://xponzy.com/contact.php. Clients may also open a ticket at https://xponzy.com/submitticket.php.