Data processing agreement
Upkyo’s commitments as a processor for the personal data you host on our services. It applies automatically to every customer.
Data Processing Agreement
This agreement is the contract required by Article 28 of the General Data Protection Regulation between the customer, as controller, and Upkyo, as processor. It forms an integral part of our Terms of Service.
Last updated: October 5, 2026
1. Purpose and acceptance
This Data Processing Agreement, the “DPA,” governs the processing of personal data that Upkyo carries out on behalf of its customers when they use its hosting, server, email, backup, maintenance, website creation and migration services.
It is entered into between the customer and Upkyo, the trade name of a Limited Liability Company organized under the laws of the State of New Mexico, USA, company number 6867626, located at 1178 Broadway, 3rd Floor #1249, New York, NY 10001, USA.
This DPA applies automatically, with no separate signature, to every customer who accepts our Terms of Service, as soon as Upkyo processes on the customer’s behalf personal data covered by the GDPR, equivalent UK or Swiss law, or U.S. data protection laws. It remains in effect for as long as Upkyo processes such data.
2. Definitions
The terms “personal data,” “processing,” “controller,” “processor,” “data subject,” “personal data breach” and “supervisory authority” have the meanings given in the GDPR.
“Customer Data” means personal data contained in the content that the customer or its users place on the services, including websites, databases, mailboxes and messages, files, application logs and backups. “Sub-processor” means any third party Upkyo engages to process Customer Data. “SCCs” means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision 2021/914. “Applicable Laws” means the GDPR and any other data protection law that applies to the processing concerned.
3. Roles of the parties
For Customer Data, the customer is the controller and Upkyo acts as a processor. Where the customer itself acts as a processor on behalf of a third party, for example an agency hosting its own clients’ websites, Upkyo acts as a sub-processor and the customer warrants that its instructions and this DPA have been authorized by that third party. Upkyo’s contractual relationship is with the customer only.
This DPA does not apply to data Upkyo processes as a controller to manage the business relationship, such as account, billing, payment, support, domain registration and internal security data. That processing is described in our Privacy Policy.
4. Subject matter, nature and purpose of processing
The subject matter of the processing is the provision of the services ordered by the customer. Its nature includes storage, hosting, backup and restoration, sending, receiving and routing email, making content available online, protection against attacks and malware, migration and, at the customer’s request, support and maintenance work.
The sole purpose of the processing is to provide, secure, maintain and support the services in accordance with the contract and the customer’s instructions. Upkyo does not process Customer Data for its own purposes, including advertising, profiling or model training.
Processing lasts for as long as the customer uses the services, and then until Customer Data is deleted under section 20.
5. Categories of personal data
The categories of data processed are determined solely by the customer, who chooses what content to host. They may include identification and contact data, login data and credentials, email content, order and transaction data from online stores, data entered in forms, IP addresses and visit logs, and any other data the customer publishes or stores.
Upkyo has no knowledge of and does not control this content. The customer must not process special categories of data under Article 9 of the GDPR, criminal conviction data, health data subject to sector-specific rules, or full payment card numbers without first confirming that the services and its own safeguards are suitable for that data. Unless agreed separately in writing, the services are not designed to meet sector-specific requirements such as HIPAA or the PCI DSS standard for storing card data.
6. Categories of data subjects
Data subjects are determined by the customer. They may include visitors to and users of the customer’s websites and apps, its customers and prospects, its employees and contractors, its suppliers and partners, and the senders and recipients of email exchanged through the services.
7. Customer obligations
The customer is solely responsible for the lawfulness of the processing of Customer Data. In particular, the customer warrants that it has a legal basis for each processing activity, has informed data subjects, has obtained any required consents, and complies with the laws that apply to its business, including rules on cookies, marketing and e-commerce.
The customer is responsible for the accuracy and quality of the data it hosts, for the security settings under its control, and for deciding whether the services are suitable for its processing. The customer handles data subject requests and, where required, notifies supervisory authorities and data subjects of breaches affecting it.
8. Documented instructions
Upkyo processes Customer Data only on the customer’s documented instructions, including with regard to transfers to a third country. The contract, this DPA, the customer’s configuration of the services through the client area or the tools provided, and written requests to support are the customer’s complete instructions. Any additional instruction must be consistent with the contract and, if it requires specific work, may be quoted separately.
If Upkyo is required by EU law, the law of a member state or other applicable law to process Customer Data, it will inform the customer before processing unless that law prohibits it on important grounds of public interest.
Upkyo will inform the customer if, in its opinion, an instruction infringes Applicable Laws. Upkyo is not required to perform a legal review of instructions and may suspend carrying out a clearly unlawful instruction until the customer confirms or changes it.
9. Personnel confidentiality
Upkyo ensures that the people authorized to process Customer Data are bound by an appropriate contractual or statutory duty of confidentiality, receive training suited to their role, and access Customer Data only as needed to provide the services, maintain security, handle support requested by the customer or comply with the law.
These confidentiality obligations continue after their role ends.
10. Technical and organizational security measures
In line with Article 32 of the GDPR, Upkyo implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.
These measures include: hosting in European Union data centers with physical access controls and redundant power and cooling; servers paired for high availability with a 99.99% availability target; automatic hourly backups for hosting; encrypted administrative connections and support for encrypted communications through SSL certificates; DDoS and malware protection; firewalls and connection filtering; isolation between customer accounts; least-privilege access management with strong authentication for administrative access; logging and monitoring of access and security events; patch management and security updates for the infrastructure; incident management and business continuity procedures; and secure wiping of end-of-life media by our infrastructure partners.
Upkyo may update these measures as long as it does not reduce the overall security of the services.
11. Shared security responsibility
Security of Customer Data is a shared responsibility. Upkyo is responsible for the security of the infrastructure it manages. The customer is responsible for the security of what it controls, including choosing strong passwords and keeping them confidential, enabling the security options offered, updating its websites, plugins and software, managing the access it grants, configuring its applications, encrypting data where it considers it necessary, and keeping its own backup copies.
On VPS, cloud and dedicated servers managed by the customer, security of the operating system, installed software and their configuration is the customer’s responsibility unless it has purchased a management service from Upkyo. Backups provided by Upkyo are a convenience service and do not replace the customer’s own backups.
12. Sub-processors
The customer grants Upkyo general authorization to engage sub-processors to provide the services. The categories of sub-processors are: hosting infrastructure partners located in the European Union; transactional email delivery services; and, depending on the services ordered, technical providers needed to operate them. The detailed list is available to the customer on written request to support@upkyo.com.
Upkyo imposes on each sub-processor, by contract, data protection obligations that provide at least the same level of protection as this DPA, including on security. Upkyo remains responsible to the customer for its sub-processors’ performance of their obligations, subject to section 21.
Stripe, PayPal and the domain registrar are not sub-processors under this DPA. They process payment or registration data as independent controllers.
13. Prior notice and right to object
Upkyo will notify the customer of any new or replacement sub-processor by email or in the client area before it processes Customer Data, so the customer can object. Where a change is urgently needed for security or service continuity, notice may be given as soon as possible after the change.
The customer may object in writing, within the reasonable period stated in the notice, on reasonable data protection grounds. The parties will then work in good faith to find a solution. If no solution is found within a reasonable time, the customer’s sole remedy is to terminate the affected service under the Terms of Service, without any termination fee. If the customer does not object within the stated period, the change is deemed accepted.
14. International transfers
Customer Data is hosted on servers located in data centers in the European Union. Because Upkyo is a company organized in the United States, access to that data by its staff or sub-processors from a third country, for example for support or administration, may constitute a transfer.
Any transfer of Customer Data to a country outside the European Economic Area without an adequacy decision is governed by the SCCs as set out in section 22, or by another mechanism recognized under Applicable Laws. Upkyo assesses the laws of destination countries and, where necessary, applies supplementary measures such as encryption in transit and limiting access to what is strictly necessary.
15. Government access requests
If Upkyo receives a legally binding request from a public authority for access to Customer Data, it will notify the customer promptly unless the law prohibits it. Upkyo reviews the legality of the request, challenges it where there are reasonable grounds to consider it unlawful, and discloses only the minimum data needed to respond.
Where possible, Upkyo will ask the authority to contact the customer directly.
16. Assistance with data subject requests
Taking into account the nature of the processing, Upkyo assists the customer through appropriate technical and organizational measures, insofar as possible, in meeting its obligation to respond to data subject requests. The services let the customer access, correct, export and delete Customer Data itself.
If Upkyo receives a request from a data subject relating to Customer Data, it will forward it to the customer where it can identify the customer, and will not respond to the request itself except to direct the person to the customer or where the customer authorizes it.
Assistance beyond the tools provided with the services may be charged at a reasonable cost, unless it results from Upkyo’s own breach.
17. Personal data breach notification
Upkyo will notify the customer of any personal data breach affecting Customer Data without undue delay after becoming aware of it, by email to the account address or in the client area.
The notice will describe, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and mitigate its effects, and a contact point. Where it is not possible to provide this information at the same time, it may be provided in phases.
Upkyo will promptly take reasonable steps to contain the breach and limit its consequences, and will cooperate with the customer so it can meet its obligations, including notifying the supervisory authority within 72 hours as required by Article 33 of the GDPR. Notifying a breach is not an admission of fault or liability by Upkyo. Unsuccessful attempts, such as port scans or blocked login attempts, are not a breach.
18. Data protection impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, Upkyo provides the customer with reasonable assistance with data protection impact assessments and, where required, prior consultation with the supervisory authority under Articles 35 and 36 of the GDPR.
This assistance primarily consists of providing documentation describing the services and security measures. Additional assistance may be charged at a reasonable cost.
19. Audits
Upkyo makes available to the customer the information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR. The customer exercises its audit rights primarily by reviewing that documentation, Upkyo’s written answers to a reasonable questionnaire and, where available, the reports and certifications of its infrastructure partners.
An on-site audit or an audit by an auditor is only available if that information is not sufficient to demonstrate compliance, if a supervisory authority requires it, or following a personal data breach affecting the customer. It will take place at a reasonable frequency, with reasonable prior written notice, during business hours, under an agreed scope and schedule, without disrupting the services or compromising the security or confidentiality of other customers’ data. It will be conducted by the customer or by an independent auditor that is not an Upkyo competitor and is bound by confidentiality.
The customer bears the cost of any audit, including Upkyo’s reasonable time, unless the audit reveals a material breach of this DPA by Upkyo. Audit rights over sub-processors are exercised through the reports and documents they provide.
20. Return and deletion of data
The customer may export Customer Data at any time during the service using the tools provided. It is the customer’s responsibility to do so before the service ends.
When the service ends, Upkyo deletes Customer Data as set out in the Terms of Service, unless EU law, the law of a member state or other applicable law requires it to be kept. Copies in backups are deleted as those backups rotate out in the normal course and remain protected by this DPA until then. A return of data beyond the export tools can be provided at the customer’s request at a reasonable cost.
On the customer’s written request, Upkyo will confirm the deletion of Customer Data in writing.
21. Liability
Each party’s liability under this DPA and the SCCs is subject to the limitations and exclusions of liability in the Terms of Service, to the fullest extent permitted by law. The liability cap set out there applies in the aggregate to all claims under the contract, this DPA and the SCCs.
This limitation does not restrict any rights that data subjects have directly under the SCCs or Applicable Laws. The customer will indemnify Upkyo against any claim, penalty or expense arising from unlawful processing for which the customer is responsible or from instructions that violate Applicable Laws.
22. Standard Contractual Clauses
Where a transfer of Customer Data falls under section 14, the SCCs are incorporated into this DPA by reference, with the customer as data exporter and Upkyo as data importer. Module Two applies where the customer is a controller, and Module Three applies where the customer is itself a processor.
For the purposes of the SCCs: optional Clause 7 applies; in Clause 9, Option 2 for general written authorization applies, as described in sections 12 and 13 of this DPA; optional Clause 11 does not apply; in Clause 13, the competent supervisory authority is determined as set out in that clause; in Clauses 17 and 18, the governing law and courts are those of the EU member state where the customer is established or, failing that, those of Ireland. Annexes I and II of the SCCs are completed by sections 3 to 6, 10 and 11 of this DPA, and the list of sub-processors is available on request.
For transfers from the United Kingdom, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies. For transfers from Switzerland, the SCCs apply with the adaptations required by Swiss law, and the competent authority is the Federal Data Protection and Information Commissioner.
23. U.S. state privacy laws
Where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or another U.S. state privacy law applies to Customer Data, Upkyo acts as a “service provider” or “processor” as defined by those laws.
Accordingly, Upkyo will not sell or share Customer Data; will not retain, use or disclose it for any purpose other than providing the services specified in the contract or as otherwise permitted by law; will not retain, use or disclose it outside the direct business relationship with the customer; will not combine it with personal information received from other sources except as permitted by law; will comply with those laws and provide the level of privacy protection they require; and will notify the customer if it can no longer meet its obligations.
The customer may take reasonable and appropriate steps to ensure that Upkyo uses Customer Data in a manner consistent with those laws and to stop and remediate any unauthorized use. Upkyo certifies that it understands and will comply with the restrictions in this section.
24. Term
This DPA takes effect when the customer accepts the Terms of Service and ends when Upkyo no longer processes any Customer Data.
Provisions that by their nature should survive termination, including those on confidentiality, data deletion and liability, will continue to apply.
25. Order of precedence
In the event of a conflict, the following order of precedence applies: the SCCs, where they apply; this DPA; the Terms of Service; and Upkyo’s other contractual documents. On any matter relating to the protection of Customer Data, this DPA prevails over the Terms of Service.
This DPA is published in several languages. If there is any inconsistency between versions, the English version controls, except for the SCCs, for which the official version chosen by the parties is authoritative.
26. Changes and contact
Upkyo may update this DPA to reflect changes in Applicable Laws, regulatory guidance or the services, provided the update does not reduce the level of protection of Customer Data. Material changes will be notified in advance by email or in the client area.
For any question about this DPA, to request the list of sub-processors, or to submit an audit request, email support@upkyo.com or open a ticket from the client area. Mail: Upkyo, 1178 Broadway, 3rd Floor #1249, New York, NY 10001, USA.
Last updated: October 2026.