Data Processing Agreement

Last updated: 14 September 2026

This Data Processing Agreement applies where Global Soft Technologies processes personal data on your behalf as a processor — for example, where you host a website with us and that site collects personal data from your own customers.

It forms part of our Terms of Service and takes effect automatically when you buy a service that involves us processing personal data for you. You do not need to sign anything separately, though we will sign a copy on request.

Roles

You are the controller. You decide what personal data is collected through your site and why. We are the processor. We act on your instructions.

For our own billing and account records we act as a controller, and our Privacy Policy governs that.

Subject matter and duration

ItemDetail
Subject matterProvision of hosting, maintenance and related services
DurationFor as long as we provide the service, plus the deletion window below
Nature and purposeStorage, backup, transmission and technical support of your site and its data
Types of personal dataDetermined by you. Typically names, email addresses, IP addresses, order and enquiry details submitted to your site
Categories of data subjectDetermined by you. Typically your customers, enquirers and site users

Our obligations

  • We process personal data only on your documented instructions, unless required otherwise by law, in which case we tell you first unless the law forbids it.
  • Everyone we let near your data is bound by confidentiality.
  • We apply appropriate technical and organisational security measures, described in our Privacy Policy.
  • We assist you, so far as is reasonable, with data subject requests, impact assessments and regulator consultations.
  • We notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with the detail you need to meet your own 72-hour obligation.
  • On termination we delete or return your personal data within 30 days, except where law requires us to keep it.
  • We make available the information you need to demonstrate compliance and allow audits, on reasonable notice and no more than once a year unless a regulator requires otherwise.

Sub-processors

You give general authorisation for us to engage the sub-processors listed on our Sub-processors page. We impose the same data protection obligations on each of them, and we remain fully liable to you for their performance.

We give 30 days’ notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will work to find an alternative. If we cannot, you may terminate the affected service without penalty.

International transfers

Where we transfer personal data outside the UK or EEA, we do so under an adequacy decision where one applies, and otherwise under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with a transfer risk assessment.

Requesting a signed copy

Email privacy@10mb.com with your company details and we will return a countersigned copy.