Version 1.0 · Last Updated: August 19, 2026
If you host a website, database, application or mailbox with us and there is personal data inside it, then in law you are the controller of that data and we are your processor. Article 28 of the UK GDPR says that arrangement has to be written down. This is that document.
You do not need to sign anything
These terms form part of your contract with us automatically, from the moment you start using our services. If your own compliance process needs a countersigned copy on your paper or ours, email compliance@webfort.co.uk and we will sort it out. We do not charge for this.
This agreement is between Webfort Ltd (company number 15981490, 128 City Road, London EC1V 2NX) and the customer named on the hosting account. It applies alongside our Terms of Service; where the two conflict on a data protection question, this document wins.
Roles split in two, and the split matters:
Of everything inside the service you rent from us — your website's contact form entries, your customer database, your files, your mailboxes. You decide what goes in there and why. We only see it because it sits on our disks.
Of the data we need to run Webfort as a business — your account details, your invoices, your support tickets, our server logs. That side is governed by our Privacy Policy, not this agreement.
In plain terms: this document covers the data you put on our servers. The Privacy Policy covers the data we hold about you as a customer.
Article 28(3) requires this to be set out specifically rather than in general terms, so:
| Subject matter | Provision of web hosting, application hosting, email, domain and related services. |
| Duration | For as long as your account is active, plus the deletion window in section 10. |
| Nature and purpose | Storing, hosting, transmitting, backing up and restoring the data you place on our infrastructure, so that your website, application or mailbox works. We do not read it, mine it, or use it for any purpose of our own. |
| Type of personal data | Whatever you choose to put there. Typically names, email addresses, postal addresses, phone numbers, order histories, account credentials, message content and IP addresses. You control this; we do not dictate it. |
| Categories of data subject | Your customers, your enquiries, your staff, your members, your website visitors — whoever your own data relates to. |
| Special category data | Our standard hosting is not designed for health, biometric, political, religious or criminal offence data. If you intend to process it, tell us first at compliance@webfort.co.uk so we can agree whether our measures are appropriate. |
We process your data only on your documented instructions, including on transfers out of the UK. Your instructions are: this agreement, our Terms of Service, and whatever you do through your control panel or a support request.
We will not process your data for our own purposes. We do not sell it, share it, use it to train anything, or mine it for analytics.
If the law forces us to process your data some other way — a court order, for instance — we will tell you before we do it, unless the law prohibits us from saying so. We will push back on requests that look overbroad or unlawful, and we will require production of proper legal process rather than an informal ask.
If we think an instruction from you would breach data protection law, we will tell you promptly. We are not obliged to give you legal advice, and telling you does not make us responsible for your compliance.
Everyone at Webfort who can reach your data is under a written duty of confidentiality that survives them leaving. Access is granted on a need-to-know basis, tied to a named individual rather than a shared login, and removed when the need ends or the person leaves.
Our staff do not open, browse or read the contents of customer sites, databases or mailboxes. The exceptions are narrow: when you ask us to as part of a support request, when we must to fix a fault you have reported, or when we are investigating abuse originating from an account. Administrative access is logged.
We implement and maintain appropriate technical and organisational measures under Article 32. As at the version date above, those are:
We may change these measures as technology moves, but we will not reduce the overall level of security below what is described here during your contract.
Your own responsibilities matter too: keeping your application and plugins updated, choosing strong credentials, and configuring the parts of the service you control. Section 12 covers this.
You give us general authorisation to engage sub-processors, subject to the conditions in this section.
Before any sub-processor touches your data we put a written contract in place imposing data protection obligations no less protective than these. If a sub-processor fails to meet its obligations, we remain fully liable to you for its performance — you do not have to chase them.
The sub-processors we use are listed in section 3.1 of our Privacy Policy. We do not publish the identity of our data centre operators for commercial reasons; account holders can obtain the full named list, including those operators, on request to compliance@webfort.co.uk.
Changes and your right to object
We will give you at least 30 days' notice before adding or replacing a sub-processor that handles your hosted data. If you object on reasonable data protection grounds within that period, we will work with you to find an alternative. If we cannot, you may terminate the affected service without penalty and receive a pro-rata refund of anything paid in advance.
Where you host determines where your data lives, and you choose it.
For the USA region and for any sub-processor outside the UK, we rely on the European Commission's Standard Contractual Clauses as amended by the ICO's International Data Transfer Addendum, which is a valid Article 46 safeguard for UK restricted transfers. We have carried out a transfer risk assessment for the US infrastructure and will provide a copy on request.
We will not move your hosted data to a different country without instruction from you, other than where a sub-processor's ordinary operation requires it and the safeguards above are in place.
If the safeguard we rely on is invalidated or withdrawn, we will tell you promptly and either put an alternative in place or give you the option to move region or terminate without penalty.
If one of your data subjects exercises a right — access, correction, erasure, restriction, portability or objection — that is your request to answer, not ours. Most of the time you will not need us at all, because you have direct access to your own data through your control panel, database and mailboxes.
Where you do need us, we will provide reasonable assistance with appropriate technical and organisational measures, taking account of the nature of the processing. That includes retrieving data you cannot reach yourself and helping you locate data across backups.
If a data subject contacts us directly about data we hold as your processor, we will not respond substantively. We will tell them to contact you, and let you know it happened.
Assistance of this kind is included at no charge, unless a request is so repetitive or extensive that it goes well beyond reasonable support, in which case we will agree costs with you in advance rather than surprising you with a bill.
If there is a personal data breach affecting data we process for you, we will notify you without undue delay and in any event within 24 hours of becoming aware of it. That deadline is deliberately tighter than our own, because your 72-hour clock as controller starts when we tell you, and you should not lose most of it waiting on us.
Our notification will describe, as far as we know it at the time:
We will not sit on a partial picture. You get the first notification when we know something is wrong, and updates as the investigation develops. We will not make any public statement identifying you as affected without consulting you first, unless the law requires it.
We will give you reasonable assistance with data protection impact assessments and any prior consultation with the ICO, to the extent it relates to our processing and you cannot reasonably obtain the information elsewhere. In practice that usually means answering a security questionnaire, and we would rather do that than have you guess.
When your service ends, you choose: we return your data, or we delete it. Tell us which.
The only data we keep beyond that is what the law requires us to keep — chiefly billing records for tax purposes — and that is our own controller data, not yours.
We will make available all information reasonably necessary to demonstrate that we are meeting our Article 28 obligations, and allow for and contribute to audits.
In practice, most questions are answered by our written security documentation and a completed questionnaire, and we will provide those within 30 days of a request. If that genuinely is not enough for your compliance obligations, you may audit us — on reasonable notice, no more than once a year unless there has been a breach or a regulator requires it, during business hours, without disrupting other customers, and subject to confidentiality.
Physical inspection of data centre floors is not something we can grant, because those buildings are not ours; we will pass on the operator's own certifications and audit reports instead.
As controller, you warrant that:
A large share of hosting incidents start with an out-of-date plugin or a reused password rather than anything at the infrastructure layer. We will do our part; this is yours.
Precedence. This agreement forms part of your contract with us. On data protection matters it takes precedence over our Terms of Service.
Changes. We may update this agreement to reflect changes in law, our infrastructure or our sub-processors. Material changes get at least 30 days' notice by email to the address on your account. If a change materially reduces your protection and you object, you may terminate the affected service without penalty.
Duration. These terms apply for as long as we process personal data on your behalf, and the obligations that by their nature should survive termination — confidentiality, deletion, breach notification for incidents relating to the period of processing — do survive it.
Law. This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction. "UK GDPR", "controller", "processor", "personal data", "processing", "personal data breach" and "data subject" carry the meanings given in the UK GDPR and the Data Protection Act 2018.
For anything about this agreement — a countersigned copy, the named sub-processor list, our transfer risk assessment, a security questionnaire, or a due diligence pack:
Webfort Ltd, Company No. 15981490
128 City Road, London EC1V 2NX, United Kingdom