This Data Processing Addendum ("DPA") supplements the Terms of Service and applies to personal data we process on your behalf when you use our services. No separate signature is needed; it takes effect when you use the service.
Roles. For the visitor, customer and user data you host on your site, you are the controller and we are the processor. You decide what that data is, why it is collected and how long it is kept.
For data about your own account, invoices and support correspondence, we are the controller — see the Privacy Policy.
1. Subject matter and duration
Subject matter: the provision of hosting, email, database, backup and support services.
Duration: for the term of the service relationship and, after it ends, for the deletion periods set out below.
Nature of processing: storage, hosting, transmission, backup, restoration, deletion, and access in the course of support.
Categories of data: determined by you. Typically visitor and customer identity, contact, order and payment details, user accounts and site content.
Categories of data subject: determined by you — visitors, customers, members, employees.
2. Your instructions
We process personal data only on your documented instructions. Your use of the service and the directions you give in support requests constitute instructions for this purpose.
If we consider an instruction to infringe applicable data protection law, we will tell you before acting on it. Where a legally binding requirement compels us to act outside your instructions, we will inform you first unless the law prohibits that notice.
We do not use your data for our own purposes, do not sell it and do not profile it for advertising.
3. Confidentiality
Personnel with access to your data are bound by confidentiality obligations that survive the end of their engagement. Access is limited to those who genuinely need it and is logged.
4. Security measures
The technical and organisational measures we maintain under GDPR Art. 32 and KVKK Art. 12:
- Encryption in transit: all web and panel traffic is protected by TLS, with certificates renewed automatically.
- Isolation: each customer account runs under its own system user with resources separated at kernel level; one account cannot reach another's files.
- Access control: administrative access is key-based, two-factor authentication is mandatory, and password-based SSH is disabled.
- Network defence: host firewall with allowlist-based port management, ModSecurity web application firewall, malware scanning.
- Backups: regular backups held in restricted directories.
- Logging: access and security events are logged and retained in reviewable form.
- Physical security: our servers are housed in an ISO 27001 certified data centre.
5. Sub-processors
We use the following sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Hetzner Online GmbH | Server and data centre infrastructure | Germany (EU) |
| DomainNameAPI | Domain registration — only the contact data registration requires | Türkiye |
Each sub-processor is bound by contract to obligations at least equivalent to those in this DPA. We give at least 30 days' notice by email before adding or replacing a sub-processor. If you object on reasonable and substantiated grounds we will look for a solution with you; if none is found you may terminate without penalty and receive a refund of the unused portion of your term.
6. International transfers
Our servers are in Germany, so your data is processed within the EU as a rule. Where a transfer outside the EEA becomes necessary, it is made under the European Commission's Standard Contractual Clauses or an adequacy decision, and in accordance with the international transfer provisions of Turkish Law No. 6698.
7. Data subject requests
If a data subject contacts us directly we do not answer on your behalf; we forward the request to you without delay, because you are the controller for that data.
We provide the technical assistance you need to satisfy requests for access, rectification, erasure, restriction and portability. Where the panel already gives you access to the data, those tools are treated as sufficient assistance.
8. Personal data breach notification
If we become aware of a breach affecting data we process on your behalf we notify you without undue delay and in any event within 24 hours. Our notice includes, so far as known:
- the nature of the breach, the categories and approximate numbers of data subjects and records affected,
- the likely consequences,
- the measures taken and proposed,
- a contact point for further information.
Because the duty to notify the supervisory authority rests with you as controller, we provide the information and evidence you need to do so within your own deadline.
9. Audit
We make available the information needed to demonstrate compliance with this DPA. Once a year, on at least 30 days' written notice, during business hours and in a manner that does not expose other customers' data, you may conduct an audit or appoint an independent auditor. You bear the cost; if the audit reveals a material non-compliance, we bear it.
10. Deletion and return at the end of the service
When the service ends:
- you may access and export your data for 30 days;
- at the end of that period data is permanently deleted from live systems;
- copies held in backups are removed in the ordinary backup cycle, within 90 days at the latest;
- records we are legally required to keep (invoices, logs under Law No. 5651) are retained until the end of the applicable period and processed for that purpose only.
11. Conflict
Where this DPA and the Terms of Service conflict on a matter of personal data, this DPA prevails. Questions: destek@enahosting.com