Home › Data Processing Agreement

Data Processing Agreement

When we host your site we process your visitors' personal data on your behalf. GDPR article 28 requires that to be set out in writing. Here it is.

Version: 2026-08-08

Version in force This agreement applies automatically to every active service contract — you do not need to request it separately. We give 30 days notice by email before any material change.

1. Parties and subject matter

This agreement is between the Customer (the "Controller") and Hostika EOOD, registered office ul. Louis Ayer 13, 1404 Sofia, Bulgaria (the "Processor"). It governs the personal data the Processor handles on the Controller's behalf when providing website hosting, development and support. It applies automatically to every active service contract and forms part of the Terms of Service.

2. Nature, purpose and duration

Subject matter: storage and technical operation of the Controller's website and its associated databases, e-mail and backups. Purpose: performance of the service contract. Duration: for the term of the contract and until the retention periods in §8 expire. The Processor does not use the data for its own purposes and does not sell it.

3. Categories of data and data subjects

The Processor has no control over what the Controller stores on their site. Typically: names, e-mail addresses, telephone numbers, delivery addresses, the content of form submissions, and IP addresses in server logs. Data subjects: the Controller's visitors and customers. The Controller undertakes NOT to store special categories of data under GDPR art. 9 (health, biometric, political opinions and the like) without prior written agreement, as the infrastructure is not certified for them.

4. Controller instructions

The Processor processes personal data only on the Controller's documented instructions, including as regards international transfers, unless required to do otherwise by EU or Bulgarian law — in which case it informs the Controller before processing, unless the law prohibits that. The Processor notifies the Controller immediately if it considers an instruction to infringe the GDPR.

5. Confidentiality

Access to the data is limited to the Processor's managing director, who is bound by a statutory duty of confidentiality. The Processor has no employees with access to the production environment. Any future extension of access requires a written confidentiality undertaking before it is granted.

6. Security measures (art. 32)

TLS 1.2+ on all traffic with automatic certificate renewal. Administrative server access by cryptographic key only — password authentication is disabled. Hashed passwords (bcrypt). CSRF protection on every form. Parameterised SQL. Login rate limiting with automatic IP blocking on abuse. Automatic security updates. Daily encrypted backups on a separate server, encrypted at source. External availability monitoring. Privilege separation: the interpreter cannot write to its own source code.

7. Subprocessors

The Controller gives general authorisation for the use of subprocessors. As at the date of this edition these are: AlexHost SRL (servers — production in Sofia, backups in Zürich, Switzerland), Brevo (e-mail delivery), Stripe and Revolut Business (payments), and Google Ireland Ltd. (advertising measurement, only with the visitor's consent). The Processor gives at least 30 days written notice before adding or changing a subprocessor; the Controller may object and, failing agreement, terminate without penalty.

8. Retention, return and deletion

On termination the Processor provides the Controller with a complete copy of the data in a machine-readable format within 30 days, then deletes it from live systems. Encrypted backups are never edited in place — the corresponding records disappear as their rotation expires, within 12 months. Accounting documents are kept for 10 years under art. 12 of the Bulgarian Accountancy Act; that is a statutory obligation and is not subject to a deletion request.

9. Personal data breaches

The Processor notifies the Controller without undue delay and no later than 48 hours after becoming aware of a personal data breach, providing the information available on its nature, the categories and approximate number of data subjects affected, the likely consequences and the measures taken. This allows the Controller to meet its own 72-hour deadline under GDPR art. 33.

10. Assistance to the Controller

The Processor assists the Controller in responding to data subject requests (access, rectification, erasure, portability, objection) and with impact assessments and prior consultations with the supervisory authority, insofar as possible given the nature of the processing and the information available. Assistance with ordinary requests is free of charge.

11. International transfers

The production server is in Sofia, inside the EU. Daily encrypted backups are held in Zürich, Switzerland, which is covered by a European Commission adequacy decision under GDPR art. 45; backups are encrypted at source before leaving the server. Any other transfer outside the EU takes place only under EU Standard Contractual Clauses or an adequacy decision.

12. Audit

The Processor makes available to the Controller all information necessary to demonstrate compliance with GDPR art. 28, and allows for and contributes to audits, including inspections conducted by the Controller or an auditor it mandates. Audits are scheduled on 14 days notice, no more than once a year except following an incident, and are conducted so as not to compromise the security of other customers' data.

13. Governing law and contact

Bulgarian law and the GDPR (Regulation 2016/679) apply. Disputes are resolved in Sofia. Questions and requests under this agreement: privacy@hostika-bg.com. Supervisory authority: the Bulgarian Commission for Personal Data Protection (KZLD), kzld.bg.

A question about data processing, or an audit request?

privacy@hostika-bg.com