1. When this page applies
This page concerns personal data a customer places in an ordered hosting service, not ordinary website visits or sales conversations.
This page explains our framework for Customer Content that includes personal data. Our Privacy Policy applies separately when HYPERHOSTGATE LLC determines how to use website, account, billing, support, security, or business-contact information.
A public service description is not enough to approve a regulated workload. Before processing begins, the customer must disclose material data categories and requirements, and the accepted Order and any data processing addendum (“DPA”) must confirm the relevant scope.
2. Customer and HYPERHOSTGATE roles
The customer decides why its hosted personal data is used. We process it to provide the ordered service and follow documented instructions.
For Customer Content, the customer generally acts as controller or business and HYPERHOSTGATE acts as processor, service provider, or contractor, as applicable. The customer is responsible for its legal basis, notices, instructions, data accuracy, end-user requests, and choosing a service suitable for the workload.
We process Customer Content only to provide, secure, support, and maintain the ordered service; follow documented instructions; comply with applicable law; and enforce the agreement. If we are legally required to process contrary to an instruction, we will provide any notice the law permits and requires.
3. Data processing addendum
A DPA is an order-specific contract, not a badge or generic website claim.
Where applicable law requires processor terms, the parties should sign or incorporate a DPA before covered processing. Depending on the service and law, it should address:
- subject matter, duration, nature, purpose, data categories, and data subjects;
- documented instructions and each party’s privacy responsibilities;
- confidentiality and risk-appropriate security obligations;
- subprocessor authorization and change-notice procedures;
- assistance with rights requests, incidents, assessments, and regulator inquiries;
- return or deletion after service ends, subject to lawful retention;
- information and audit rights appropriate to the service and risk; and
- any required international-transfer mechanism.
Our Trust & Security page describes public security commitments; the signed or incorporated terms define the controls required for a particular service.
4. Subprocessors and service providers
The relevant provider list depends on the service and region. We will not invent a public list from the marketing-site code.
We may use infrastructure, network, support, communications, billing, security, and professional-service providers to deliver an ordered service. A provider is a subprocessor only when it processes covered personal data on our behalf for that service.
Before a covered Order is accepted, ask for the current subprocessor information relevant to the proposed configuration. The DPA or Order should identify the agreed list or a location where it is maintained, the notice process for material additions or replacements, and any objection right required by the agreement or law.
For our own website and business communications, Cloudflare D1 stores accepted quote applications and related pseudonymous security and delivery records, Resend attempts delivery to the configured business mailbox, and the configured mail provider may retain or forward the message under its account settings. Termly processes browser-level consent choices and blocks optional resources as configured. These business-purpose providers are not automatically subprocessors for a customer's hosted data, and they are not a complete subprocessor list for hosting services or deployment infrastructure. The current site has no deliberate analytics, advertising, chat, or payment integration.
5. Service locations and international transfers
A map or location preference is not a residency promise. Confirm the actual processing and support locations in writing.
The customer must identify any residency or transfer restriction before ordering. We will confirm available service locations, operational-access locations, relevant subprocessors, and contractual transfer safeguards for the proposed configuration.
Where a restricted international transfer occurs, the parties will use a lawful mechanism appropriate to the transfer, such as an adequacy basis or approved contractual clauses where available and applicable. This page does not represent that one mechanism fits every customer or destination.
6. Data-subject requests, assessments, and incidents
The customer remains the decision-maker for its users. We assist within the agreed scope.
A person whose information appears in Customer Content should generally contact the relevant customer first. If we receive the request, we may refer it to that customer unless law prohibits doing so. We will provide reasonable assistance required by the DPA for access, correction, deletion, portability, restriction, objection, impact assessments, regulator consultation, and incident response.
Assistance that requires unusual engineering or is outside the purchased service may be subject to reasonable fees stated in the agreement, unless applicable law requires otherwise.
7. Return, export, retention, and deletion
The Order should say what can be exported, when access ends, and how deletion works. Customers should keep independent backups.
Before termination, customers should use available export functions and maintain independent backups. The Order or DPA should state any post-termination retrieval period and the deletion process for active systems and backups. We may retain limited information where law requires it, but will isolate it from ordinary use and delete it when the lawful retention need ends.
No indefinite storage, instant deletion from every backup, or particular export format is promised unless the accepted agreement expressly provides it.
8. Request a DPA or subprocessor information
Describe the proposed workload and legal requirements before asking us to confirm suitability.