Last updated 29 June 2026

Data Processing Agreement.

How I handle personal data on your behalf when I host your website, email, domains and backups.

This Data Processing Agreement (“DPA”) forms part of the agreement between Michael Overton, Freelance Designer (“we”, “us”, “our”) and the client named in the main agreement (“you”, “your”). It sets out how we handle personal data on your behalf, as required by Article 28 of the UK GDPR.

Who is who

When we host or manage services for you, the personal data involved is yours, not ours. You decide what happens to it. We only act on your instructions.

In data protection terms:

  • You are the controller. The personal data in your website, your mailboxes and your systems belongs to you and your customers. You decide why it is held and what is done with it.
  • We are the processor. We hold and handle that data solely to provide the services you have asked us to provide.

Separately, we are a controller of the limited data we hold about you as our client, such as your contact details and billing records. That is covered by our privacy policy and not by this DPA.

What we process, and why

The services

This DPA applies to any of the following we provide to you: email hosting, website hosting, domain and DNS management, and backups.

Subject matter and duration

We process your data for as long as we provide those services to you, and for the short retention periods set out below.

Nature and purpose

Storing, hosting, transmitting, backing up and, where you ask us to, migrating or deleting your data. We do not use it for anything else.

Types of personal data

Depending on the service, this may include:

  • Email content, attachments, contacts and calendar data in mailboxes we host for you
  • Names, email addresses, phone numbers and messages submitted through your website forms
  • Any personal data held in your website’s database, its users or its content
  • IP addresses and server or access logs generated when your site and mailboxes are used

Categories of people

Your staff, your clients and customers, your suppliers, and visitors to your website.

Special category data

We do not expect to process special category data (such as health, ethnicity or political views) on your behalf. If your site or mailboxes will hold such data, tell us in advance so we can agree what extra protections are needed.

Our obligations to you

We will:

  • Only process your data on your documented instructions, including for any transfer outside the UK, unless we are required to do otherwise by law. If that happens, we will tell you first unless the law forbids it.
  • Take appropriate technical and organisational measures to keep your data secure.
  • Make sure anyone with access to your data is bound by a duty of confidentiality.
  • Help you, so far as we reasonably can, to respond to requests from individuals exercising their rights, such as access, correction or deletion.
  • Help you, so far as we reasonably can, with your obligations around security, breach notification and data protection impact assessments.
  • Tell you promptly if, in our opinion, an instruction you give us would breach data protection law.
  • Make available to you the information you reasonably need to show we are meeting these obligations, and allow for and contribute to audits or inspections on reasonable notice.

Sub-processors

To provide these services we use the sub-processors listed below. By agreeing to our terms, of which this DPA forms part, you authorise us to use them.

Hetzner Online GmbH

Germany (EU)

Server infrastructure

Your website, its database and its live environment are hosted here.

FlyWP Inc

United States

Server and site management platform

FlyWP is a control layer, not a storage location. It does not host your data. It holds encrypted server credentials and can access the servers to carry out tasks we ask of it, such as backups, deployments and monitoring. FlyWP Inc is based in the United States, but your data remains on Hetzner in Germany.

Bunny.net (BunnyWay d.o.o.)

Slovenia (EU), backups in Frankfurt

Content delivery network, DNS and backup storage

Backups of your website and database are held in Frankfurt, Germany. Bunny.net is an EU company based in Slovenia, with content delivered and DNS resolved from edge locations worldwide.

MXroute

United States

Email hosting and delivery

Your mailboxes and their contents are held here.

We remain fully responsible to you for the acts and omissions of our sub-processors, as if they were our own.

If we intend to add or replace a sub-processor, we will give you reasonable notice in advance so you have a chance to object. If you object on reasonable data protection grounds, and we cannot find a workable alternative, you may terminate the affected service.

International transfers

Your website data stays in the EU

Your website and its database are hosted on Hetzner in Germany, and its backups are held in Bunny.net storage in Frankfurt, Germany. Personal data in your website therefore remains within the EU, and is covered by the UK’s adequacy arrangements with the EU.

Two points of nuance, stated for completeness:

  • FlyWP Inc, the platform we use to manage the servers, is based in the United States. It does not store your website data, which stays on Hetzner, but it can access those servers to carry out tasks we ask of it. FlyWP relies on Standard Contractual Clauses for any transfer of personal data outside the EEA.
  • Content delivery and DNS are served from edge locations worldwide, which is how a CDN works. This involves caching your public website content and processing visitor IP addresses at the nearest edge, rather than storing your database or your customers’ records outside the EU.

Email is hosted in the United States

MXroute is US-based, so where we host your email, the mailboxes and their contents are stored in the US. That transfer is made on the basis of the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism recognised under UK data protection law.

If you would prefer your email to be hosted only within the UK or EU, tell us and we will discuss the options with you.

Security

We take appropriate measures to protect your data, which include:

  • Encryption in transit. Websites are served over HTTPS and mail is sent and received over encrypted connections.
  • Access control. Access to servers and hosting accounts is limited to those who need it, protected by strong credentials and multi-factor authentication where available.
  • Server hardening and prompt application of security updates.
  • Regular backups, held separately from the live environment.
  • Logging and monitoring of the hosting environment.

No system is ever completely secure, but we will keep these measures under review and adjust them as the risks change.

Personal data breaches

If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it.

We will give you the information you need to meet your own obligations, including what happened, the categories and rough numbers of people and records affected, the likely consequences, and what we are doing about it.

It is your responsibility as controller to decide whether to report the breach to the Information Commissioner’s Office or to affected individuals. We will support you in doing so.

What happens at the end

This is the part that matters most, so it is set out plainly.

Your data is yours.

When our services to you end, for any reason, we will, at your choice, either return your data to you or delete it. We will not decide that for you.

We will ask before deleting anything.

We will not delete your website, your mailboxes or their contents without first asking you what you want done with them.

Retrieval window.

After the services end, we will retain your data for a period of 30 days to give you a reasonable opportunity to retrieve it or ask us to migrate it. During that period we will not delete it, and we will provide it to you in a commonly used, machine-readable format on request. If you need longer, ask us and we will agree it in writing.

Migration.

Transferring your domain to another registrar does not, of itself, delete your data or require us to remove any service. Where you are moving to another provider, we will keep your mailboxes and website intact so their contents can be migrated across, and we will cooperate reasonably with your new provider.

After the window.

Once the retrieval period has passed and you have either taken your data or asked us to delete it, we will delete it from our live systems. Copies held in routine backups will be deleted in the normal course of the backup cycle, and remain protected by this DPA until they are.

Legal exception.

We may keep data for longer where the law requires it, and if we do we will tell you why.

How this fits with our other terms

This DPA sits alongside our main terms and does not replace them. If anything in this DPA conflicts with the main terms, this DPA takes precedence in respect of the processing of personal data.

Words such as controller, processor, personal data, processing and personal data breach have the meanings given to them in the UK GDPR.

Contact us

If you have any questions about this Data Processing Agreement, or about how we handle personal data on your behalf, please get in touch.

Michael OvertonBased in Woking

Woking, Surrey

Independent studio
Working with clients worldwide

Mon–Fri, 9am to 5pm UK time
Calls in person or on video

Let’s talk about your project.

A new website, a complete rebrand, or just exploring what’s possible. Tell me a little and I’ll take it from there.

What are you interested in?
What’s your timeline?

I’ll get back to you within 24 hours.