Please note
This English translation is provided for your convenience only. In the event of any discrepancy, the German version is legally binding.
This agreement specifies the data protection obligations of the contracting parties arising from the contract concluded between them for hosting, domain, email and related services (hereinafter the “Main Agreement”). It applies to all activities in which employees of the Contractor or sub-processors engaged by the Contractor process personal data that the Client provides in the course of using the services or that arise on the systems provided by the Contractor.
The legal basis is Art. 28(3) GDPR in conjunction with Section 14 of our Terms and Conditions. The agreement becomes part of the contractual relationship upon conclusion of the Main Agreement. We will provide a separately signed copy upon request at support@servflix.com.
Version date: September 23, 2026
Scope: all hosting, managed WordPress, WooCommerce, domain and email services provided by servflix.com
Client (Controller)
The Client within the meaning of this agreement is the customer named in the Main Agreement, with the master data stored in their customer account – company name, address, authorized representative and contact details.
The Client is the controller within the meaning of Art. 4(7) GDPR for the personal data it processes via the Contractor's services. The Client alone decides on the purposes and means of this processing and assesses its lawfulness. The Client remains responsible for safeguarding the rights of data subjects.
Contractor (Processor)
servflix.com
a business unit of Wpress Group LTD
Piccadilly Business Centre
Aldow Enterprise Park
Manchester, M12 6AE
United Kingdom
Registered in England and Wales
Company number: 16682136
Email: support@servflix.com
Data Protection Officer
Jasmine Calvez
WPress Group LTD, 20 Wenlock Road
London, England, N1 7GU
Section 1 Subject Matter, Term and Termination
(1) The subject matter of the processing is the provision of the services agreed in the Main Agreement, in particular the provision and operation of server capacity, storage, databases, email mailboxes and domains, as well as the associated maintenance, backup and support services. In doing so, the Contractor processes personal data exclusively on behalf of and in accordance with the instructions of the Client.
(2) The term of this agreement corresponds to the term of the Main Agreement. It ends automatically upon termination of the Main Agreement without the need for separate cancellation.
(3) The Client may terminate this agreement at any time without notice if there is a serious breach by the Contractor of data protection regulations or of obligations under this agreement, if an instruction cannot be carried out, or if the Contractor refuses the Client's inspection rights in breach of contract.
(4) Obligations which by their nature extend beyond the end of the contract – in particular confidentiality, deletion and return – remain unaffected by termination.
Section 2 Nature, Scope and Purpose of the Processing
(1) The Contractor processes personal data exclusively for the purpose of providing the contractually owed services. No processing for the Contractor's own purposes takes place.
(2) The processing includes in particular the storage, retention, backup, transfer within the systems used, restoration and deletion of data, as well as read access in the course of support, maintenance and security measures.
(3) The processing takes place in member states of the European Union, in the European Economic Area or in third countries in accordance with Section 11 of this agreement.
Section 3 Data Categories and Data Subjects
(1) Categories of personal data (depending on the Client's specific use):
(2) Categories of data subjects:
(3) The Client decides on its own responsibility whether to process special categories of personal data pursuant to Art. 9 GDPR on the Contractor's systems and takes the necessary additional protective measures for this.
Section 4 Client's Right to Issue Instructions
(1) The Contractor processes personal data exclusively on documented instructions from the Client, unless it is required to do so by Union or Member State law. In such a case, the Contractor informs the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
(2) Instructions must generally be given in text form, primarily via the customer account or by email to support@servflix.com. The Client confirms verbal instructions in text form without undue delay.
(3) The processing specified in the Main Agreement, in the service description and in this agreement constitutes the Client's initial instruction. The Client's own configuration of the services via the customer account also constitutes an instruction.
(4) If the Contractor believes that an instruction violates data protection regulations, it informs the Client without undue delay. The Contractor is entitled to suspend execution of the instruction in question until it is confirmed or amended.
Section 5 Obligations of the Contractor
The Contractor undertakes in particular:
Section 6 Sub-processors
(1) The Client grants the Contractor general authorization to engage further processors (sub-processors). The sub-processors engaged at the time the contract is concluded are listed in Annex 2 and are deemed approved.
(2) The Contractor informs the Client in text form of any intended change concerning the addition or replacement of sub-processors, generally with four weeks' advance notice. The Client may object to the change within two weeks of receiving the information for an important reason based on data protection law.
(3) If the Client objects and the affected service cannot be provided without the sub-processor, or only with disproportionate effort, both parties have a special right of termination with regard to the affected service.
(4) The Contractor selects sub-processors carefully, taking particular account of the suitability of the technical and organizational measures they have taken. It contractually imposes on them the same data protection obligations as set out in this agreement (Art. 28(4) GDPR) and is liable for their conduct as for its own.
(5) Ancillary services that the Contractor uses from third parties – such as telecommunications services, postal services, maintenance and user service, cleaning staff, auditors or the disposal of data carriers – do not constitute sub-processing. The Contractor also takes appropriate precautions to protect the data in this respect.
Section 7 Rights of Data Subjects
(1) The Contractor assists the Client with appropriate technical and organizational measures in fulfilling its obligation to respond to requests from data subjects under Chapter III of the GDPR (Art. 28(3)(e) GDPR).
(2) If a data subject contacts the Contractor directly, the Contractor forwards the request to the Client without undue delay and does not respond to it itself.
(3) The Contractor carries out rectification, erasure and restriction of processing only on documented instructions from the Client, insofar as the Client cannot do this itself via the administrative functions provided.
Section 8 Notification of Personal Data Breaches
(1) The Contractor informs the Client without undue delay after becoming aware of a personal data breach (Art. 33(2) GDPR). The notification is sent to the contact address stored in the customer account.
(2) The notification contains, where available: a description of the nature of the breach, the categories and approximate number of data subjects and data records concerned, the likely consequences, and the measures taken or proposed to address it.
(3) The Contractor assists the Client with its notification and communication obligations under Art. 33 and 34 GDPR and takes the necessary measures without undue delay to secure the data and mitigate possible adverse consequences.
Section 9 Verification and Inspection Rights
(1) The Contractor demonstrates compliance with the obligations under this agreement to the Client by appropriate means, in particular through self-disclosure, documentation of the technical and organizational measures, or by presenting current certificates, attestations or reports from independent bodies.
(2) If this evidence is insufficient in an individual case, the Contractor allows the Client, or an auditor commissioned by the Client and bound to confidentiality, to conduct audits including inspections (Art. 28(3)(h) GDPR).
(3) Inspections take place after timely notice – generally two weeks – during normal business hours and without avoidable disruption to operations. The auditor may not be a competitor of the Contractor. The Contractor's trade and business secrets and the data of other customers must be protected.
(4) For inspections that go beyond the cooperation required by law or are caused by the Client's fault, the Contractor may demand reasonable remuneration.
Section 10 Deletion and Return of Data
(1) After the end of the provision of processing services, the Contractor deletes all personal data or, at the Client's choice, returns it and deletes existing copies, unless Union or Member State law requires storage of the data (Art. 28(3)(g) GDPR).
(2) The Client must request the return or deletion of the data in text form no later than the date on which termination of the contract takes effect. If the Client makes no choice, the data will be permanently deleted after a reasonable grace period.
(3) Backup copies are automatically overwritten and deleted in accordance with the agreed retention cycles. Until final deletion, they remain protected in the same way as production data.
(4) The Contractor may retain documentation that serves as evidence of proper data processing beyond the end of the contract in accordance with the statutory retention periods.
Section 11 Processing in Third Countries
(1) Personal data is generally processed in the European Union or the European Economic Area.
(2) The Contractor has its registered office in the United Kingdom. The transfer of personal data to the United Kingdom is based on the adequacy decision of the European Commission pursuant to Art. 45 GDPR.
(3) If an adequacy decision does not exist or no longer exists for a recipient country, a transfer will only take place on the basis of appropriate safeguards pursuant to Art. 46 GDPR – in particular the European Commission's Standard Contractual Clauses – supplemented by the additional measures required following a transfer impact assessment.
(4) The Contractor informs the Client of any intended relocation of processing to a third country in accordance with the procedure set out in Section 6 of this agreement.
Section 12 Liability and Final Provisions
(1) The liability of the parties is governed by Art. 82 GDPR. Otherwise, the liability provisions of the Main Agreement apply, insofar as they are compatible with mandatory data protection law.
(2) Amendments and additions to this agreement must be made in text form. This also applies to any amendment of this form requirement.
(3) In the event of conflicts between this agreement and the Main Agreement, the provisions of this agreement take precedence insofar as they concern the processing of personal data on behalf of the Client.
(4) Should any provision of this agreement be or become invalid, the validity of the remaining provisions remains unaffected. The parties will replace the invalid provision with a valid provision that comes closest economically to the intended purpose.
(5) Annexes 1 and 2 form part of this agreement.
Annex 1 – Technical and Organizational Measures (Art. 32 GDPR)
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, the Contractor takes the following measures to ensure a level of security appropriate to the risk.
1. Confidentiality
Physical access control – The server systems are operated in data centers with secured buildings, access control systems with logging, video surveillance of security-relevant areas and a visitor policy requiring escort. Only authorized persons are granted access.
System access control – Administrative access takes place via personal, non-shared user accounts. Measures include password policies with minimum complexity, two-factor authentication for administrative access, SSH access via key pairs, automatic lockout after failed attempts and a web application firewall with brute-force protection.
Data access control – Permissions are granted according to the principle of least privilege and based on roles, and are reviewed regularly. Administrative access to customer data only takes place when required in the course of support, maintenance and security measures, and is logged.
Separation control – The data of different customers is processed separately. Each customer is managed in their own isolated system environment with separate file system areas, databases and access credentials. Production, test and development environments are separated.
Pseudonymization – Where the purpose of processing allows, data is pseudonymized or anonymized, for example by truncating IP addresses in log data.
2. Integrity
Transfer control – Data is transmitted exclusively in encrypted form: TLS for website, panel and email access, SFTP or SSH for file transfers, and encrypted connections for administrative access. Data carriers are securely erased or destroyed before decommissioning.
Input control – System access, administrative activities and security-relevant events are logged. The logs are protected against subsequent alteration and retained for a defined period, so that it remains traceable who entered, changed or removed which data and when.
3. Availability and Resilience
Availability control – Redundant power supply with uninterruptible power supply and backup generators, redundant network connectivity, air conditioning, and early fire detection and extinguishing systems in the data centers. The storage systems are designed with redundancy.
Data backup – Regular, automated backup of customer data according to the cycles agreed in the Main Agreement. Backups are stored separately from the production system; recoverability is tested regularly.
Resilience – Continuous monitoring of system status, load and availability, protective measures against overload and DDoS attacks, and a defined process for security updates to the operating system, server services and applications.
4. Procedures for Regular Testing and Evaluation
Data protection management – Appointed Data Protection Officer, commitment of all employees to confidentiality, regular awareness training and a record of processing activities pursuant to Art. 30(2) GDPR.
Incident response management – Defined process for the detection, assessment, containment and reporting of security incidents, including the notification obligations under Section 8 of this agreement.
Data protection by design and by default – Data-minimizing configuration of systems, secure default settings and review of data protection-relevant changes before going live (Art. 25 GDPR).
Order control – Careful selection of sub-processors, written agreements pursuant to Art. 28 GDPR, ongoing monitoring of the agreed protective measures and regular review of the effectiveness of our own measures.
Annex 2 – Approved Sub-processors
The Contractor uses the following sub-processors as of this version. They are deemed approved pursuant to Section 6(1) of this agreement.
Data center and server infrastructure
Servflix · Server system srv72.servflix.com
Provision and operation of the physical server, network and storage infrastructure, including data backup
Payment processing
Stripe Payments Europe, Ltd. · 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
Processing of card and SEPA direct debit payments for paid services
We will provide the complete and current list of sub-processors used, including company name, registered office, place of processing and purpose of processing, upon request at support@servflix.com. We will inform you of changes in accordance with the procedure set out in Section 6(2).
Request a signed copy
If you need this Data Processing Agreement as a signed copy for your data protection documentation, send us a short message with your customer number and full company details to support@servflix.com. You will usually receive the signed copy within two business days.
Please direct any data protection questions to our Data Protection Officer Jasmine Calvez, WPress Group LTD, 20 Wenlock Road, London, England, N1 7GU.