Skip to content
← Legal centre

Data Processing Agreement

Our GDPR Article 28 Data Processing Agreement, incorporated into every Alta Ignite subscription, covering security, subprocessing, breach notice, transfers and audit rights.

Version in force · Last updated 6 February 2026

1. Purpose, scope and precedence

  • 1.1 This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms and Conditions between Alta Ignite B.V. ("Processor", "Alta Ignite", "we") and the customer that has entered into a subscription agreement with us ("Controller", "Customer", "you") for the design, development, hosting, domain and email Services (the "Principal Agreement").
  • 1.2 This DPA reflects the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR") and, where applicable, equivalent provisions of the UK GDPR and the Dutch GDPR Implementation Act (Uitvoeringswet AVG), and applies whenever Alta Ignite processes Personal Data on behalf of the Customer in the course of providing the Services.
  • 1.3 In the event of a conflict between this DPA and the Principal Agreement in respect of the processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses incorporated under clause 12, the Standard Contractual Clauses prevail in respect of the transfers they govern.
  • 1.4 Capitalised terms not defined in this DPA ("Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Personal Data Breach", "Supervisory Authority") have the meanings given in Article 4 GDPR.

2. Roles of the parties

  • 2.1 As between the parties, the Customer is the Controller and Alta Ignite is the Processor in respect of Personal Data contained in Client Materials, end-user data collected through websites we build or host for the Customer, mailbox content in business email accounts we provision, and domain registrant data submitted by the Customer for domains registered on the Customer's behalf.
  • 2.2 Where Alta Ignite determines the purposes and means of processing independently of the Customer's instructions, for example billing data processed to manage the Customer's own subscription account, or ICANN-mandated WHOIS/RDDS publication of registrant data required by the ICANN Registrar Accreditation Agreement, Alta Ignite acts as an independent Controller for that specific processing, and this DPA does not apply to that processing, which is instead governed by our Privacy Policy.
  • 2.3 Where the Customer processes Personal Data of its own end users through a website, form or mailbox we host, the Customer is the Controller (or, where applicable, joint controller with its own upstream customers) for that data and remains solely responsible for establishing a lawful basis for its own collection and use of that data.

3. Subject matter, duration, nature and purpose of processing

  • 3.1 Subject matter: the provision of website design, development, hosting, domain registration and management, and business email hosting Services as described in the Principal Agreement, and any associated technical support.
  • 3.2 Duration: processing continues for the term of the Principal Agreement and, in respect of specific data, for the shorter period required to comply with clause 10 (deletion and return) following termination, or such longer period as is required by applicable law.
  • 3.3 Nature of processing: hosting, storage, transmission, backup, retrieval, technical support access, security monitoring, and, where instructed, deletion or export of Personal Data contained in websites, mailboxes and associated databases operated for the Customer.
  • 3.4 Purpose of processing: to deliver, host, secure, support and maintain the Customer's website(s), domain(s) and business email account(s) in accordance with the Principal Agreement and the Customer's documented instructions.

4. Categories of data subjects and personal data

  • 4.1 Categories of Data Subjects may include the Customer's employees and contractors, the Customer's end customers, website visitors and form submitters, email correspondents, and, where relevant, the Customer's own registrants or beneficiaries identified in Client Materials.
  • 4.2 Categories of Personal Data may include names, email addresses, postal addresses, phone numbers, IP addresses, account credentials, transaction and order data submitted through website forms, email message content and metadata, and any other Personal Data the Customer chooses to include in Client Materials, website content, databases or mailboxes.
  • 4.3 The Customer warrants that it will not, without first notifying Alta Ignite in writing and agreeing appropriate additional safeguards, submit special categories of Personal Data within the meaning of Article 9 GDPR (such as health, biometric, or data concerning sex life or sexual orientation) or Personal Data relating to criminal convictions under Article 10 GDPR, for processing through the Services, except where reasonably incidental to standard website contact-form or email use and adequately protected by the security measures in clause 6.

5. Controller instructions

  • 5.1 Alta Ignite will process Personal Data only on the documented instructions of the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by European Union or Member State law to which Alta Ignite is subject, in which case Alta Ignite will inform the Customer of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.
  • 5.2 The Principal Agreement, the order confirmation, the documented service specifications, and support requests submitted by the Customer's authorised users through the client dashboard, together constitute the Customer's documented instructions for the purposes of this clause.
  • 5.3 Alta Ignite will promptly notify the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend performance of that instruction pending resolution.

6. Confidentiality of personnel

  • 6.1 Alta Ignite ensures that persons authorised to process Personal Data have committed themselves to confidentiality, whether by way of employment contract, contractor agreement, or a specific confidentiality undertaking, and that access is limited to personnel who need such access to perform the Services.
  • 6.2 Alta Ignite provides personnel with data protection training appropriate to their role prior to granting access to production systems containing Customer Personal Data.

7. Security measures (Article 32 GDPR)

  • 7.1 Alta Ignite implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, including the risks presented by accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • 7.2 Encryption: Personal Data in transit between the Customer, the Services and end users is encrypted using TLS 1.2 or higher; database volumes and backups are encrypted at rest using industry-standard AES-256 encryption.
  • 7.3 Access control: role-based access controls, unique credentials, multi-factor authentication for administrative and infrastructure access, and the principle of least privilege govern internal access to production systems; access logs are retained and reviewed periodically.
  • 7.4 Network security: firewalling, DDoS mitigation and web application firewall protection (via our CDN subprocessor) are applied to hosted websites; production infrastructure is segmented from development and staging environments.
  • 7.5 Resilience: automated daily backups of hosted websites, databases and mailboxes are retained on a rolling basis, replicated across at least two physically separate facilities, and periodically tested for restorability.
  • 7.6 Vulnerability and patch management: operating systems, container images and application dependencies used to deliver the Services are monitored for known vulnerabilities and patched on a risk-prioritised schedule; we run periodic penetration testing and remediate identified critical and high findings promptly.
  • 7.7 Monitoring and logging: security event logging, intrusion detection alerting and error monitoring (via our monitoring subprocessor) are used to detect anomalous activity affecting Customer Personal Data.
  • 7.8 Physical security: Personal Data is hosted in data centres operated by our hosting and cloud subprocessors, which maintain physical access controls, environmental controls and continuous monitoring consistent with recognised standards such as ISO/IEC 27001.
  • 7.9 Organisational measures: documented information security policies, an internal incident response plan, background-appropriate hiring checks for personnel with elevated access, and periodic internal review of this security programme.
  • 7.10 The Customer acknowledges that it is responsible for the security of its own credentials, its own content management practices, and any third-party integrations it configures independently of Alta Ignite.

8. Subprocessing

  • 8.1 The Customer provides Alta Ignite with a general written authorisation to engage subprocessors to assist in providing the Services, subject to the conditions in this clause.
  • 8.2 The current list of subprocessors, including their identity, processing purpose, location and applicable transfer safeguard, is published and kept up to date at our Subprocessors page, incorporated into this DPA by reference.
  • 8.3 Alta Ignite will give the Customer at least 14 days' prior notice, via the Subprocessors page and, on request, by email to a Customer contact who has subscribed to update notices, before engaging a new subprocessor or replacing an existing one, other than in an emergency requiring immediate substitution to preserve security or continuity of the Services, in which case notice will be given as soon as reasonably practicable.
  • 8.4 The Customer may object to a new subprocessor on reasonable data-protection grounds within 14 days of notice by emailing privacy@altaignite.com. If the parties cannot resolve the objection, the Customer may terminate the affected Services by written notice, without penalty, as its sole and exclusive remedy.
  • 8.5 Alta Ignite imposes data protection obligations on each subprocessor that are substantially no less protective than those set out in this DPA, by way of a written agreement, and remains fully liable to the Customer for the acts and omissions of its subprocessors in relation to the processing of Personal Data.

9. Assistance with data subject rights

  • 9.1 Taking into account the nature of the processing, Alta Ignite will assist the Customer, insofar as reasonably possible and using appropriate technical and organisational measures, in fulfilling its obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection).
  • 9.2 Where Alta Ignite receives a Data Subject request directly relating to processing carried out on the Customer's behalf, it will, without undue delay and in any event within 5 business days, forward the request to the Customer and will not itself respond to the Data Subject except to acknowledge receipt and redirect them to the Customer, unless otherwise required by law.
  • 9.3 Alta Ignite will provide reasonable technical support, such as data export or deletion tooling within the client dashboard, to enable the Customer to fulfil such requests within statutory deadlines.

10. Deletion and return of data on termination

  • 10.1 On termination or expiry of the Principal Agreement, and at the Customer's election communicated in writing before or within 30 days after termination, Alta Ignite will either (a) make available for export the Customer's website files, database contents and mailbox data in a commonly used, machine-readable format, or (b) delete all Personal Data processed on the Customer's behalf.
  • 10.2 Where the Customer does not make an election within 30 days of termination, Alta Ignite will delete the Personal Data, save for encrypted backup copies which will be purged in the ordinary rolling backup cycle described in clause 7.5, and save to the extent retention is required by applicable law, in which case Alta Ignite will isolate and protect that data from further active processing.
  • 10.3 Deletion under this clause is carried out using secure deletion methods appropriate to the storage medium and is confirmed to the Customer in writing on request.

11. Personal data breach notification

  • 11.1 Alta Ignite will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any Personal Data Breach affecting Personal Data processed on the Customer's behalf.
  • 11.2 The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its possible adverse effects; where full information is not available within 48 hours, Alta Ignite will provide it in phases without undue further delay.
  • 11.3 Alta Ignite will cooperate with the Customer and provide reasonable assistance necessary for the Customer to comply with its own obligations under Articles 33 and 34 GDPR, including notification to the competent Supervisory Authority within 72 hours and, where required, communication to affected Data Subjects.
  • 11.4 Notification of a breach is not, and will not be construed as, an acknowledgement by Alta Ignite of any fault or liability with respect to the breach.

12. International transfers

  • 12.1 Alta Ignite primarily hosts Customer Personal Data within the European Union and the European Economic Area, principally in Germany and other EU regions used by its infrastructure subprocessors.
  • 12.2 Where the provision of the Services requires a transfer of Personal Data to a country outside the EEA that has not been recognised by the European Commission as providing an adequate level of protection under Article 45 GDPR, Alta Ignite ensures that such transfer is subject to appropriate safeguards under Article 46 GDPR.
  • 12.3 For that purpose, the parties incorporate by reference the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("SCCs"), with the Customer as "data exporter" and Alta Ignite as "data importer", using Module Two (Controller to Processor) for transfers from the Customer to Alta Ignite, and Module Three (Processor to Processor) where Alta Ignite onward-transfers Personal Data to a subprocessor located outside the EEA, in each case completed with the details set out in Annexes I, II and III available on request from legal@altaignite.com.
  • 12.4 Where the Customer or a Data Subject is located in the United Kingdom, the UK International Data Transfer Addendum to the SCCs, issued by the UK Information Commissioner's Office, applies in place of or in addition to the SCCs as required to ensure a lawful transfer mechanism under the UK GDPR.
  • 12.5 Where a subprocessor located outside the EEA has self-certified under the EU-U.S. Data Privacy Framework (or the equivalent UK or Swiss extension), Alta Ignite may rely on that certification as an alternative or additional safeguard, in accordance with the relevant European Commission or ICO adequacy decision, in place of Standard Contractual Clauses for that specific transfer.

13. Data protection impact assessments

  • 13.1 Alta Ignite will provide the Customer with reasonable assistance, taking into account the nature of processing and information available to Alta Ignite, in relation to the Customer's obligations under Articles 35 and 36 GDPR to carry out data protection impact assessments and, where required, to consult with a Supervisory Authority.
  • 13.2 Such assistance may include providing a description of the technical and organisational security measures in clause 7 and confirming the categories and locations of processing set out in this DPA and the Subprocessors page.

14. Audits and demonstration of compliance

  • 14.1 Alta Ignite will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and this DPA, including summaries of security certifications held by its infrastructure subprocessors and, on reasonable written request no more than once per 12-month period, a copy of its current data protection and information security policies.
  • 14.2 Where the Customer reasonably requires an on-site or remote audit beyond the documentary review in clause 14.1, for example following a Personal Data Breach or at the request of a Supervisory Authority, the parties will agree in advance a reasonable scope, timing and confidentiality framework for that audit, which will be conducted during normal business hours, with at least 30 days' notice, no more than once in any 12-month period absent a specific compliance trigger, and at the Customer's cost, using independent auditors bound by confidentiality.
  • 14.3 Audits must not unreasonably interfere with Alta Ignite's business operations or the confidentiality and security of other customers' data.

15. Liability and indemnity

  • 15.1 Each party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, is subject to the limitations and exclusions of liability set out in the Principal Agreement, save that nothing in this DPA or the Principal Agreement limits either party's liability for infringements of data subjects' rights that cannot lawfully be limited under applicable data protection law, or for a party's liability towards Data Subjects or Supervisory Authorities under Article 82 GDPR.
  • 15.2 As between the parties, each party will bear the share of any fine, penalty, compensation or damages award attributable to its own or its personnel's or (in Alta Ignite's case) its subprocessors' breach of applicable data protection law or this DPA.

16. Order of precedence and term

  • 16.1 This DPA takes effect on the date the Customer accepts the Principal Agreement and remains in force for as long as Alta Ignite processes Personal Data on the Customer's behalf under the Principal Agreement, notwithstanding the earlier expiry or termination of the Principal Agreement itself in respect of any surviving processing obligations under clause 10.
  • 16.2 If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the parties will substitute a valid provision that most closely reflects the commercial and data-protection intent of the invalid provision.

17. Governing law and jurisdiction

  • 17.1 This DPA is governed by the laws of the Netherlands, without regard to conflict of laws principles, save that the SCCs incorporated under clause 12 are governed by the law of the EU Member State specified in those clauses.
  • 17.2 The courts of Amsterdam, the Netherlands, have exclusive jurisdiction over any dispute arising out of or in connection with this DPA, without prejudice to any mandatory right a Data Subject may have to bring proceedings in another competent jurisdiction under applicable data protection law.

18. Contact

  • 18.1 Questions about this DPA, requests for the SCC annexes referenced in clause 12.3, or notice of a Personal Data Breach discovered by the Customer, should be sent to privacy@altaignite.com, with a copy to legal@altaignite.com.
  • 18.2 Postal correspondence should be addressed to Alta Ignite B.V., Keizersgracht 391, 1016 EJ Amsterdam, the Netherlands, KvK 76392014, VAT NL860627193B01.

Requests for a countersigned DPA or SCC annexes: privacy@altaignite.com — Alta Ignite B.V., Keizersgracht 391, 1016 EJ Amsterdam, the Netherlands.