Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.
Version and effective date are applied when the document is approved and published through the admin content module.
Averonix Host is rolling out new hosting plans and server locations. See what is available
For business customers whose hosted data includes personal data.
Applies to: Business customers acting as a data controller.
Draft, pending professional review
This document is a working draft prepared for review by a qualified legal adviser. It is not legal advice, and it is not the final agreement. Highlighted passages mark positions that must be settled before publication.
Where you host personal data with us, you are the controller and we are the processor for that data. For the data we hold to run your account and bill you, we are the controller, as described in the Privacy Policy.
This addendum forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this addendum prevails.
It is drafted to satisfy Article 28 of the GDPR and the equivalent UK GDPR provision, and to be serviceable under PIPEDA, Law 25, the Australian Privacy Principles, the Privacy Act 2020 and the PDPA.
We process personal data only on your documented instructions, which comprise this addendum, the Terms of Service, and the configuration choices you make in the client area — including the region you select.
If we believe an instruction breaches applicable data protection law, we will tell you and may pause that processing rather than carry it out. We will not process your hosted personal data for our own purposes.
We will:
You are responsible for having a lawful basis for the personal data you put on our platform, for providing the privacy notices your own data subjects require, and for the accuracy of the data.
You must not place special category data, health data, payment card data or children's data on a standard hosting plan without agreeing that with us first, so that appropriate measures can be put in place.
The measures below are our current baseline for Article 32 purposes. Where we change them, we do not reduce the overall level of protection.
Processing takes place in the region you select for the service, plus our management systems for account and support data. Our current hosting locations are:
| Country | Sites | Law governing data stored there |
|---|---|---|
| Nepal | Kathmandu | Individual Privacy Act, 2075 (2018) and the Individual Privacy Regulation, 2077 (2020) |
| Australia | Sydney | Privacy Act 1988 (Cth) and the Australian Privacy Principles |
| India | Mumbai | Digital Personal Data Protection Act 2023 |
| Singapore | Singapore | Personal Data Protection Act 2012 |
| Canada | Beauharnois, Montréal, Cambridge, Toronto | PIPEDA and, because these sites are in Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25 |
| United States | Hillsboro, Oregon, Vint Hill, Virginia | United States federal law and applicable state law, including the Oregon Consumer Privacy Act |
| France | Paris, Roubaix, Gravelines, Strasbourg | EU GDPR and the French Loi Informatique et Libertés |
| Germany | Limburg, Frankfurt | EU GDPR and the German Bundesdatenschutzgesetz |
| Italy | Milan | EU GDPR and the Italian Codice in materia di protezione dei dati personali |
| Poland | Warsaw, Ożarów | EU GDPR and the Polish Personal Data Protection Act |
| United Kingdom | London, Erith | UK GDPR and the Data Protection Act 2018 |
Where a transfer out of your own jurisdiction requires a legal mechanism, we apply one. The mechanisms are set out in the Privacy Policy and apply equally here.
For transfers of EU or EEA personal data, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated into this addendum, with Module Two applying where you are a controller and we are your processor, and Module Three where you are yourself a processor. For UK data the UK Addendum to those clauses applies.
Placeholder, pending verification: TRANSFER MECHANISMS AND STANDARD CLAUSES — TO BE CONFIRMED BY COUNSEL
You give general authorisation for us to engage sub-processors for infrastructure, payments and communications. We impose data protection obligations on them no less protective than those in this addendum, and we remain liable to you for their performance.
We maintain a current list and will give you advance notice of any addition or replacement, so that you have a reasonable opportunity to object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate the affected service and receive a pro-rata refund of the unused paid term.
Placeholder, pending verification: SUB-PROCESSOR LIST — TO BE PUBLISHED ONCE PROVIDERS ARE CONTRACTED
If we receive a request from one of your data subjects, we will not respond to it substantively ourselves. We will redirect the requester to you and tell you promptly, unless the law requires otherwise.
Where you need our help to answer a request, the tools in the client area cover export and deletion for most cases, and we will assist directly where they do not.
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data you have entrusted to us, with the information you need to meet your own notification duties: what happened, which categories and approximate numbers of records are involved, the likely consequences, and what we are doing about it.
Where the full picture is not available at once, we will send what we have rather than delaying the first notification until everything is known.
Notifying you is not an admission of fault by either of us.
At the end of the service you may export your data from the client area. After the retention window stated in the Privacy Policy, we delete it, including from backups on their normal rotation cycle.
Where we are legally required to retain a record — a financial record, for example — we retain only that record and only for as long as the law requires, and we tell you what has been kept.
We will provide the information reasonably necessary to demonstrate compliance with this addendum, and will accommodate audits on reasonable notice, during business hours, no more than once a year unless a regulator or a breach requires otherwise, and subject to confidentiality.
For the purposes of Article 28(3) and the Standard Contractual Clauses:
| Item | Detail |
|---|---|
| Subject matter | Provision of hosting, domain, email and related services |
| Duration | The term of the service, plus the retention window in the Privacy Policy |
| Nature and purpose | Storage, hosting, transmission, backup and support of the controller's systems and content |
| Types of personal data | Whatever the controller places on the platform, which the controller determines. Typically website, application and email content, and the controller's own customer and user records. |
| Categories of data subjects | Determined by the controller. Typically the controller's customers, users, employees and correspondents. |
| Frequency of transfer | Continuous, for the duration of the service |
| Retention | Placeholder, pending verification: RETENTION PERIODS PER DATA CLASS — TO BE CONFIRMED AGAINST NEPALESE AND AUSTRALIAN REQUIREMENTS |
Averonix Host is operated by Averonix Group Pvt. Ltd., Nepal.
Version and effective date are applied when the document is approved and published through the admin content module.