Skip to main content

Averonix Host is rolling out new hosting plans and server locations. See what is available

Averonix HostAveronix Host

Data Processing Addendum

For business customers whose hosted data includes personal data.

Applies to: Business customers acting as a data controller.

Draft, pending professional review

This document is a working draft prepared for review by a qualified legal adviser. It is not legal advice, and it is not the final agreement. Highlighted passages mark positions that must be settled before publication.

1. Roles and scope

Where you host personal data with us, you are the controller and we are the processor for that data. For the data we hold to run your account and bill you, we are the controller, as described in the Privacy Policy.

This addendum forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this addendum prevails.

It is drafted to satisfy Article 28 of the GDPR and the equivalent UK GDPR provision, and to be serviceable under PIPEDA, Law 25, the Australian Privacy Principles, the Privacy Act 2020 and the PDPA.

2. Your instructions

We process personal data only on your documented instructions, which comprise this addendum, the Terms of Service, and the configuration choices you make in the client area — including the region you select.

If we believe an instruction breaches applicable data protection law, we will tell you and may pause that processing rather than carry it out. We will not process your hosted personal data for our own purposes.

3. Our obligations as processor

We will:

  • Apply appropriate technical and organisational security measures, as set out in section 5.
  • Impose confidentiality obligations on staff with access, which survive the end of their engagement.
  • Assist you with data subject requests, taking into account the nature of the processing.
  • Assist you with data protection impact assessments and prior consultation where you need it.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • Delete or return the data at the end of the service, subject to statutory retention.
  • Make available the information reasonably necessary to demonstrate compliance with this addendum.

4. Your obligations as controller

You are responsible for having a lawful basis for the personal data you put on our platform, for providing the privacy notices your own data subjects require, and for the accuracy of the data.

You must not place special category data, health data, payment card data or children's data on a standard hosting plan without agreeing that with us first, so that appropriate measures can be put in place.

5. Security measures

The measures below are our current baseline for Article 32 purposes. Where we change them, we do not reduce the overall level of protection.

  • Encryption in transit for all customer-facing services, and encryption at rest for sensitive stored data.
  • Per-account isolation on shared platforms, so one account cannot read another's data.
  • Role-based access control, least privilege, and multi-factor authentication on all administrative access.
  • Audit logging of administrative actions, retained and reviewable.
  • Backup and restoration procedures, tested rather than assumed.
  • Vulnerability management and patching on a defined cycle.

6. Where processing takes place

Processing takes place in the region you select for the service, plus our management systems for account and support data. Our current hosting locations are:

Where we operate servers
CountrySitesLaw governing data stored there
NepalKathmanduIndividual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020)
AustraliaSydneyPrivacy Act 1988 (Cth) and the Australian Privacy Principles
IndiaMumbaiDigital Personal Data Protection Act 2023
SingaporeSingaporePersonal Data Protection Act 2012
CanadaBeauharnois, Montréal, Cambridge, TorontoPIPEDA and, because these sites are in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25
United StatesHillsboro, Oregon, Vint Hill, VirginiaUnited States federal law and applicable state law, including the Oregon Consumer Privacy Act
FranceParis, Roubaix, Gravelines, StrasbourgEU GDPR and the French Loi Informatique et Libertés
GermanyLimburg, FrankfurtEU GDPR and the German Bundesdatenschutzgesetz
ItalyMilanEU GDPR and the Italian Codice in materia di protezione dei dati personali
PolandWarsaw, OżarówEU GDPR and the Polish Personal Data Protection Act
United KingdomLondon, ErithUK GDPR and the Data Protection Act 2018

7. International transfers

Where a transfer out of your own jurisdiction requires a legal mechanism, we apply one. The mechanisms are set out in the Privacy Policy and apply equally here.

For transfers of EU or EEA personal data, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this addendum, with Module Two applying where you are a controller and we are your processor, and Module Three where you are yourself a processor. For UK data the UK Addendum to those clauses applies.

Placeholder, pending verification: TRANSFER MECHANISMS AND STANDARD CLAUSES — TO BE CONFIRMED BY COUNSEL

8. Sub-processors

You give general authorisation for us to engage sub-processors for infrastructure, payments and communications. We impose data protection obligations on them no less protective than those in this addendum, and we remain liable to you for their performance.

We maintain a current list and will give you advance notice of any addition or replacement, so that you have a reasonable opportunity to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a pro-rata refund of the unused paid term.

Placeholder, pending verification: SUB-PROCESSOR LIST — TO BE PUBLISHED ONCE PROVIDERS ARE CONTRACTED

9. Data subject requests

If we receive a request from one of your data subjects, we will not respond to it substantively ourselves. We will redirect the requester to you and tell you promptly, unless the law requires otherwise.

Where you need our help to answer a request, the tools in the client area cover export and deletion for most cases, and we will assist directly where they do not.

10. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data you have entrusted to us, with the information you need to meet your own notification duties: what happened, which categories and approximate numbers of records are involved, the likely consequences, and what we are doing about it.

Where the full picture is not available at once, we will send what we have rather than delaying the first notification until everything is known.

Notifying you is not an admission of fault by either of us.

11. Deletion and return

At the end of the service you may export your data from the client area. After the retention window stated in the Privacy Policy, we delete it, including from backups on their normal rotation cycle.

Where we are legally required to retain a record — a financial record, for example — we retain only that record and only for as long as the law requires, and we tell you what has been kept.

12. Audit

We will provide the information reasonably necessary to demonstrate compliance with this addendum, and will accommodate audits on reasonable notice, during business hours, no more than once a year unless a regulator or a breach requires otherwise, and subject to confidentiality.

13. Annex: details of the processing

For the purposes of Article 28(3) and the Standard Contractual Clauses:

ItemDetail
Subject matterProvision of hosting, domain, email and related services
DurationThe term of the service, plus the retention window in the Privacy Policy
Nature and purposeStorage, hosting, transmission, backup and support of the controller's systems and content
Types of personal dataWhatever the controller places on the platform, which the controller determines. Typically website, application and email content, and the controller's own customer and user records.
Categories of data subjectsDetermined by the controller. Typically the controller's customers, users, employees and correspondents.
Frequency of transferContinuous, for the duration of the service
RetentionPlaceholder, pending verification: RETENTION PERIODS PER DATA CLASS — TO BE CONFIRMED AGAINST NEPALESE AND AUSTRALIAN REQUIREMENTS

Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.

Version and effective date are applied when the document is approved and published through the admin content module.