This Data Processing Agreement ("DPA") forms part of the agreement between SRV-CORE LLC ("Processor," "we," "us") and the customer entity that purchases services from us ("Controller," "you") when we process personal data on your behalf in connection with those services.
This DPA is designed for small-business hosting and related services. It is not a HIPAA Business Associate Agreement and does not certify ISO, SOC 2, or similar frameworks.
1. Roles
| Role | Party |
|---|---|
| Controller | You (the customer), for personal data you collect or place in systems we host or administer for you |
| Processor | SRV-CORE LLC, when we process that personal data to provide the contracted services |
For data about your account with us (billing identity, invoices, tickets about your account), SRV-CORE typically acts as an independent controller. This DPA focuses on customer content and end-user data you entrust to our hosting or managed services.
2. Subject matter and duration
We process personal data only to provide the services described in your order, our Terms of Service, and applicable SLAs, for the duration of the service term and a reasonable wind-down period after termination (see Terms §11 and our Privacy Policy).
3. Nature and purpose of processing
Depending on the services you buy, processing may include hosting, backup, email delivery for your domains, support troubleshooting, security monitoring, and remote administration within the agreed scope.
4. Types of personal data and data subjects
You determine the categories. Typical examples on hosting plans include website visitor data, account credentials you store, email mailbox contents, and form submissions on your sites. Data subjects may include your customers, employees, or website visitors. You must not use our standard hosting plans to store regulated health records requiring HIPAA without a separate written agreement (which we do not currently offer as a standard product).
5. Processor obligations
We will:
- Process personal data only on documented instructions from you (including configuration you set in Plesk/WHMCS and tickets you authorize), unless required by law.
- Ensure persons authorized to process personal data are under confidentiality obligations.
- Implement appropriate technical and organizational security measures for a small hosting provider (access controls, TLS in transit, network controls, monitoring).
- Engage subprocessors listed in our Privacy Policy (and similar infrastructure providers). We remain responsible for their performance as relates to this DPA. We will post material subprocessor changes in the Privacy Policy.
- Taking into account the nature of processing, assist you with reasonable requests related to data-subject rights, security incidents affecting your hosted data, and information needed for your own DPIAs — within support scope and business hours.
- Delete or return customer content after termination as described in the Terms, unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this DPA (for example, policy links and high-level security descriptions). Formal audits or on-site inspections are available only by separate written agreement and may be chargeable.
6. Controller obligations
You warrant that you have a lawful basis to collect and process personal data you place on our systems, that your privacy notices are accurate, and that your instructions will not cause us to violate applicable law. You are responsible for application-level security (CMS/plugins/passwords) unless a managed service explicitly covers that scope.
7. International transfers
Primary processing occurs in the United States. If you are in the EEA/UK, you instruct us to process and transfer personal data to the U.S. as necessary to provide the services. Where required, transfer mechanisms may include standard contractual clauses offered by our infrastructure/providers or other lawful bases. Contact [email protected] if you need additional transfer documentation for a specific enterprise engagement.
8. Security incidents
If we become aware of a personal-data breach affecting your hosted environment in a way that requires notice under applicable law, we will notify you without undue delay at your account email and cooperate reasonably on next steps.
9. Liability
Liability under this DPA is subject to the limitations in our Terms of Service, except where prohibited by law.
10. Order of precedence
If this DPA conflicts with the Terms for data-processing topics, this DPA controls for those topics. Commercial terms (fees, SLAs, refunds) remain governed by the Terms, Refund Policy, and order confirmation.
11. Contact
Email: [email protected]
Postal: SRV-CORE LLC, 117 South Lexington Street, Suite 100, Harrisonville, MO 64701, United States