Data Processing Agreement
Last updated: 14 September 2026
This Data Processing Agreement applies where Global Soft Technologies processes personal data on your behalf as a processor — for example, where you host a website with us and that site collects personal data from your own customers.
It forms part of our Terms of Service and takes effect automatically when you buy a service that involves us processing personal data for you. You do not need to sign anything separately, though we will sign a copy on request.
Roles
You are the controller. You decide what personal data is collected through your site and why. We are the processor. We act on your instructions.
For our own billing and account records we act as a controller, and our Privacy Policy governs that.
Subject matter and duration
| Item | Detail |
|---|---|
| Subject matter | Provision of hosting, maintenance and related services |
| Duration | For as long as we provide the service, plus the deletion window below |
| Nature and purpose | Storage, backup, transmission and technical support of your site and its data |
| Types of personal data | Determined by you. Typically names, email addresses, IP addresses, order and enquiry details submitted to your site |
| Categories of data subject | Determined by you. Typically your customers, enquirers and site users |
Our obligations
- We process personal data only on your documented instructions, unless required otherwise by law, in which case we tell you first unless the law forbids it.
- Everyone we let near your data is bound by confidentiality.
- We apply appropriate technical and organisational security measures, described in our Privacy Policy.
- We assist you, so far as is reasonable, with data subject requests, impact assessments and regulator consultations.
- We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the detail you need to meet your own 72-hour obligation.
- On termination we delete or return your personal data within 30 days, except where law requires us to keep it.
- We make available the information you need to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless a regulator requires otherwise.
Sub-processors
You give general authorisation for us to engage the sub-processors listed on our Sub-processors page. We impose the same data protection obligations on each of them, and we remain fully liable to you for their performance.
We give 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will work to find an alternative. If we cannot, you may terminate the affected service without penalty.
International transfers
Where we transfer personal data outside the UK or EEA, we do so under an adequacy decision where one applies, and otherwise under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment.
Requesting a signed copy
Email privacy@10mb.com with your company details and we will return a countersigned copy.
