Alvonyx Data Processing Agreement
Last updated: 20 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between:
Alvonyx
ALVONYX LTD
Camden House, TN2 3DH
(“Alvonyx”, “Processor”, “we”, “us” or “our”)
and
the customer purchasing or using the relevant Alvonyx Service
(“Customer”, “Controller”, “you” or “your”).
This DPA applies where Alvonyx processes Personal Data on behalf of the Customer in connection with an Alvonyx hosting, server, cloud or related infrastructure service.
It should be read together with the Alvonyx Terms and Conditions, Privacy Policy, Acceptable Use Policy and the applicable order or service description (together, the “Service Agreement”).
If there is a conflict between this DPA and the Service Agreement in relation to the processing of Personal Data on behalf of the Customer, this DPA will prevail to the extent of that conflict.
1. Definitions
For the purposes of this DPA:
“Applicable Data Protection Law” means applicable privacy and data-protection legislation relating to the processing covered by this DPA, including where applicable:
- the UK GDPR;
- the Data Protection Act 2018;
- the Privacy and Electronic Communications Regulations 2003;
- legislation amending or replacing those laws; and
- any other applicable data-protection legislation.
“Controller” has the meaning given to that term under Applicable Data Protection Law and, for the purposes of Customer Data processed under this DPA, generally means the Customer.
“Customer Data” means Personal Data processed by Alvonyx on behalf of the Customer through the Services.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Personal Data” means any information relating to an identified or identifiable natural person and includes any equivalent definition under Applicable Data Protection Law.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
“Process”, “Processing” and “Processed” have the meanings given under Applicable Data Protection Law.
“Processor” means an organisation which processes Personal Data on behalf of a Controller and, for the purposes of this DPA, generally means Alvonyx.
“Restricted Transfer” means a transfer of Personal Data which requires a lawful international-transfer mechanism under Applicable Data Protection Law.
“Services” means the Alvonyx hosting, server, cloud, backup, migration, security or other infrastructure services purchased by the Customer.
“Subprocessor” means another processor appointed by Alvonyx to process Customer Data in connection with the provision of the Services.
“UK GDPR” means Regulation (EU) 2016/679 as incorporated into United Kingdom law and amended from time to time.
2. Roles of the Parties
For Customer Data processed through the Services:
- the Customer is generally the Controller; and
- Alvonyx is generally the Processor.
The Customer determines the purposes for which Customer Data is processed and is responsible for determining that such processing is lawful.
Alvonyx processes Customer Data only to provide, secure, maintain and support the Services and otherwise in accordance with the Customer’s documented instructions.
Alvonyx acting as a Controller
This DPA does not apply where Alvonyx independently determines why and how Personal Data is processed.
For example, Alvonyx may act as an independent Controller in relation to information used for:
- customer account administration;
- billing and invoicing;
- fraud prevention;
- regulatory compliance;
- tax and accounting;
- Alvonyx’s own security records;
- service communications; and
- Alvonyx marketing.
Such processing is instead governed by the Alvonyx Privacy Policy.
3. Customer Instructions
The Customer instructs Alvonyx to process Customer Data as reasonably necessary to:
- provide the Services;
- host and transmit Customer websites and applications;
- operate servers and virtual infrastructure;
- store files and databases;
- provide backup and disaster-recovery functionality;
- provide network and security functionality;
- undertake migrations requested by the Customer;
- provide technical support;
- investigate technical incidents;
- protect the Services against fraud, abuse and security threats;
- carry out Customer configuration requests; and
- otherwise perform the Service Agreement.
The Service Agreement, this DPA, Customer support requests, account settings, configuration choices and other written instructions may constitute documented instructions for these purposes.
Alvonyx will process Customer Data only on documented instructions from the Customer unless Alvonyx is required to process the data by applicable law.
Where legally permitted, Alvonyx will inform the Customer before processing Customer Data pursuant to such a legal requirement.
The ICO confirms that processors must act on documented instructions, including in relation to international transfers, unless required otherwise by UK law.
4. Customer Responsibilities
The Customer is responsible for ensuring that:
- it has a lawful basis for processing Customer Data;
- appropriate privacy information has been provided to Data Subjects;
- any required consents have been obtained;
- its instructions to Alvonyx comply with Applicable Data Protection Law;
- Customer Data is appropriate for the Services being used;
- it does not unlawfully upload or process Personal Data;
- account permissions are appropriately configured;
- access credentials are protected;
- users authorised to access the Services are appropriately managed;
- its applications, websites and software are appropriately secured where they fall under the Customer’s control; and
- it complies with Data Subject rights and other obligations applicable to it as Controller.
The Customer must not instruct Alvonyx to undertake Processing which the Customer knows would breach Applicable Data Protection Law.
If Alvonyx reasonably believes that a Customer instruction infringes Applicable Data Protection Law, Alvonyx may inform the Customer and suspend performance of the relevant instruction while the matter is clarified.
5. Details of the Processing
The subject matter, nature and purpose of the Processing are described in Schedule 1 of this DPA.
The exact Personal Data processed will depend on:
- the Service purchased;
- the Customer’s own website or application;
- the Customer’s configuration; and
- the information the Customer chooses to store or process.
The UK GDPR requires processor agreements to document the subject matter and duration, nature and purpose, Personal Data types, categories of Data Subject and the Controller’s rights and obligations.
6. Confidentiality
Alvonyx will ensure that persons authorised to process Customer Data:
- are subject to appropriate confidentiality obligations; and
- only access Customer Data where reasonably necessary for their duties.
Access to Customer Data will be limited to authorised personnel, contractors and Subprocessors who require access in order to provide, support or secure the Services.
Confidentiality obligations will continue after an individual’s access to Customer Data ends.
7. Security Measures
Taking into account:
- the state of the art;
- implementation costs;
- the nature, scope, context and purpose of Processing; and
- the risks to Data Subjects,
Alvonyx will implement appropriate technical and organisational measures designed to protect Customer Data.
These measures may include, as appropriate to the relevant Service:
- logical access controls;
- user authentication;
- multi-factor authentication where available;
- least-privilege access;
- role-based permissions;
- password-security requirements;
- encrypted communications;
- TLS/HTTPS;
- SSH/SFTP or other secure administration methods;
- network security;
- firewalls;
- DDoS protection;
- malware detection;
- vulnerability-management processes;
- security monitoring;
- system logging;
- backup and recovery processes;
- data-centre physical security;
- redundancy;
- infrastructure monitoring;
- patch and update processes;
- employee confidentiality controls;
- incident-response procedures;
- supplier security assessment; and
- business-continuity measures.
The specific measures applicable to each Service may differ according to the nature of that Service.
8. Shared Security Responsibilities
Hosting and server security is a shared responsibility.
Alvonyx is responsible for security measures applicable to infrastructure and systems which Alvonyx has expressly agreed to manage.
The Customer remains responsible for security matters within its control.
Depending on the Service, these may include:
- WordPress administrator accounts;
- application users;
- passwords;
- plugins;
- themes;
- custom code;
- application vulnerabilities;
- website permissions;
- database credentials;
- API credentials;
- SSH keys;
- VPS operating-system configuration;
- VPS firewall configuration;
- root or administrator access;
- installed server software;
- Customer-managed backups; and
- Customer-controlled third-party integrations.
For self-managed VPS or server products, the Customer has greater responsibility for operating-system and application security.
9. Subprocessors
The Customer grants Alvonyx general written authorisation to appoint Subprocessors where reasonably necessary to provide the Services.
Subprocessors may provide services including:
- hosting infrastructure;
- virtual servers;
- physical servers;
- cloud infrastructure;
- networking;
- data-centre facilities;
- storage;
- backup;
- cybersecurity;
- DDoS protection;
- monitoring;
- email;
- technical-support systems;
- software platforms; and
- other infrastructure required to deliver the Services.
Alvonyx will ensure that each Subprocessor which processes Customer Data is subject to written contractual obligations providing an equivalent level of protection in respect of the relevant Article 28 obligations.
Alvonyx remains responsible to the Customer for the Subprocessor’s performance of those applicable data-protection obligations to the extent required by law.
UK GDPR requires prior specific or general written authorisation before a processor appoints a Subprocessor, and equivalent Article 28 protections must be flowed down contractually.
10. Changes to Subprocessors
Where the Customer provides general authorisation under Section 9, Alvonyx will provide reasonable notice of a material new Subprocessor where that Subprocessor will process Customer Data.
A current Subprocessor list may be made available on request from:
The Customer may raise a reasonable written objection relating specifically to data-protection risk.
Any objection must:
- identify the Subprocessor concerned;
- explain the reasonable data-protection grounds for the objection; and
- be submitted within the period stated in the applicable notice.
The parties will attempt in good faith to find a reasonable solution.
Where no commercially reasonable alternative is available, Alvonyx may permit the Customer to terminate the specifically affected Service without an additional termination charge, subject to any fees properly accrued before termination.
11. Data Subject Requests
Taking into account the nature of the Processing, Alvonyx will provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising rights under Applicable Data Protection Law.
These may include requests relating to:
- access;
- rectification;
- erasure;
- restriction;
- portability;
- objection; and
- other applicable rights.
If Alvonyx receives a request directly from a Data Subject concerning Customer Data, Alvonyx will not normally respond substantively on the Customer’s behalf unless:
- instructed by the Customer;
- required by law; or
- Alvonyx independently acts as Controller in relation to that information.
Where reasonably possible, Alvonyx will direct the Data Subject to the relevant Customer.
12. Data Protection Assistance
Taking into account the nature of the Processing and information available to Alvonyx, Alvonyx will provide reasonable assistance to the Customer in meeting applicable obligations concerning:
- Processing security;
- Personal Data Breaches;
- Data Protection Impact Assessments;
- consultation with supervisory authorities where required; and
- other Controller obligations under Articles 32–36 of the UK GDPR where relevant to the Services.
The extent of assistance will depend on the nature of the Service and the information reasonably available to Alvonyx.
ICO guidance requires processor contracts to provide for this form of assistance.
13. Personal Data Breaches
Alvonyx will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
Where information is reasonably available, the notification may include:
- the nature of the incident;
- the categories of affected data;
- the categories or approximate number of affected Data Subjects;
- the likely consequences;
- measures taken or proposed to address the incident; and
- measures taken to mitigate potential adverse effects.
Information may be provided in phases where it is not possible to provide everything at the same time.
Alvonyx’s notification of an incident does not constitute an admission of fault or liability.
The Customer remains responsible for determining whether the incident must be reported to:
- the ICO;
- another supervisory authority;
- affected Data Subjects; or
- any other person,
unless applicable law places that obligation directly on Alvonyx.
14. Security Incident Cooperation
Following a Personal Data Breach affecting Customer Data, Alvonyx will take reasonable steps to:
- contain the incident;
- investigate its cause;
- mitigate further risk;
- restore affected systems where appropriate;
- preserve relevant evidence where reasonably necessary; and
- assist the Customer with information reasonably required for its compliance obligations.
The Customer must cooperate with Alvonyx where its systems, software, credentials or configuration contributed to or may be affected by the incident.
15. International Transfers
Alvonyx may use infrastructure and Subprocessors located in different jurisdictions.
Alvonyx will not make a Restricted Transfer of Customer Data unless:
- the Customer has instructed or authorised the transfer; and
- a lawful transfer mechanism applies.
Relevant mechanisms may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement (“IDTA”);
- the UK Addendum to the European Commission Standard Contractual Clauses;
- another approved safeguard; or
- an applicable exception permitted by law.
Where required, Alvonyx or the relevant party will also conduct any required transfer risk assessment or data protection test.
The ICO updated its international-transfer guidance in January 2026 and confirms that the IDTA and UK Addendum remain standard safeguards available under the UK GDPR.
16. Transfers Involving EEA Personal Data
Where the Processing is also subject to the EU GDPR and Personal Data is transferred to a country requiring additional safeguards, the parties will implement an appropriate mechanism as required by applicable EU data-protection law.
This may include the European Commission Standard Contractual Clauses where applicable.
If both UK and EU transfer requirements apply, the parties may use the relevant UK Addendum alongside appropriate EU Standard Contractual Clauses where suitable.
17. Location of Processing
The location from which Customer Data is processed may depend upon:
- the infrastructure selected;
- data-centre availability;
- the Service ordered;
- backup architecture;
- support requirements; and
- the locations of authorised Subprocessors.
Where Alvonyx expressly sells a Service on the basis that primary hosting is located within a specified territory, Alvonyx will use reasonable efforts to maintain the primary hosting location within that territory.
This does not necessarily mean that all support, security, backup or ancillary Processing takes place exclusively within that territory.
18. Return and Deletion of Customer Data
On termination or expiry of the relevant Service, Alvonyx will, at the Customer’s choice where reasonably practicable:
- return Customer Data; or
- delete Customer Data,
unless applicable law requires retention.
Customers are responsible for exporting any data they wish to retain before their Service ends.
Customer Data remaining in active systems may be deleted following service termination according to applicable operational deletion processes.
19. Backups Following Termination
The parties acknowledge that immediate deletion from backup or archival systems may not always be technically possible.
Where Customer Data remains temporarily in backup systems following termination:
- it will be put beyond ordinary operational use;
- it will remain subject to the protections of this DPA;
- it will not be restored except where reasonably necessary for legitimate disaster recovery or legal requirements; and
- it will be deleted or overwritten according to the applicable backup retention cycle.
The ICO recognises that immediate backup deletion may not always be technically feasible provided data is placed beyond use and subsequently removed through an appropriate deletion cycle.
20. Audits and Compliance Information
Alvonyx will make available information reasonably necessary to demonstrate compliance with its Article 28 obligations.
This may include, as appropriate:
- data-protection documentation;
- relevant security policies;
- responses to security questionnaires;
- applicable certifications;
- audit reports;
- Subprocessor information; and
- other reasonable compliance evidence.
Alvonyx will allow for and contribute to reasonable audits or inspections as required under Applicable Data Protection Law.
21. Audit Procedure
Except following a material Personal Data Breach, regulator request or credible evidence of serious non-compliance, Customer audits should:
- normally occur no more than once in any 12-month period;
- be requested with reasonable written notice;
- take place during normal business hours;
- avoid unnecessary interruption to Alvonyx or other customers;
- be limited to systems and information relevant to the Customer;
- respect confidentiality obligations; and
- comply with applicable infrastructure and data-centre security requirements.
Alvonyx may satisfy an audit request in the first instance through documentation, independent audit reports or other compliance information where this reasonably demonstrates compliance.
The Customer will bear its own audit costs.
Where an audit requires material additional work outside normal compliance assistance, Alvonyx may charge reasonable costs agreed in advance, unless the audit identifies a material breach of this DPA by Alvonyx.
The UK GDPR expressly requires processors to provide necessary compliance information and allow and contribute to audits and inspections.
22. Third-Party Data Centres
For security reasons, this DPA does not automatically grant the Customer physical access to third-party:
- data centres;
- server facilities;
- network operations centres; or
- other secured infrastructure.
Physical inspection rights may be satisfied through:
- supplier audit reports;
- certifications;
- independent assurance documentation;
- Alvonyx audit information; or
- other proportionate evidence.
This does not limit any audit right which Applicable Data Protection Law requires and which cannot be satisfied through alternative evidence.
23. Government and Legal Requests
If Alvonyx receives a legally binding request requiring disclosure of Customer Data, Alvonyx may disclose Customer Data to the extent legally required.
Where legally permitted, Alvonyx will notify the Customer before disclosure so that the Customer may seek appropriate legal protection.
Alvonyx will not voluntarily disclose Customer Data to public authorities except:
- on Customer instruction;
- where required by law;
- where necessary to protect life or safety;
- to defend legal rights; or
- in other circumstances permitted by Applicable Data Protection Law.
24. Special Category and High-Risk Data
Unless expressly agreed in writing, the Services are not specifically designed for Processing unusually sensitive or specially regulated categories of information.
The Customer must assess whether its use of the Services is appropriate where it intends to process:
- special category Personal Data;
- criminal-offence data;
- large-scale medical records;
- biometric information;
- financial credentials;
- children’s information;
- government-classified information; or
- other high-risk data.
The Customer remains responsible for determining whether additional legal, contractual or technical safeguards are required.
Alvonyx may require additional terms or security arrangements before agreeing to host certain high-risk Processing.
25. PCI and Payment Card Data
Unless expressly agreed, the Customer must not store complete payment-card details directly within Alvonyx infrastructure where those details should instead be handled by a compliant payment-service provider.
Customers operating e-commerce websites remain responsible for determining and meeting any applicable PCI DSS obligations.
Use of a third-party payment gateway does not automatically make all elements of a Customer’s website PCI compliant.
26. Data Protection Impact Assessments
Where the Customer reasonably determines that a Data Protection Impact Assessment (“DPIA”) is required in connection with its use of the Services, Alvonyx will provide reasonable assistance relating to Processing undertaken by Alvonyx.
The Customer remains responsible for:
- determining whether a DPIA is required;
- preparing the DPIA;
- assessing risks relating to its own Processing; and
- making any required consultation with a supervisory authority.
27. Records of Processing
Alvonyx will maintain records of Processing activities where required by Applicable Data Protection Law.
The Customer is responsible for maintaining its own applicable records as Controller.
28. Data Protection Contacts
The parties will each maintain appropriate contact details for data-protection matters.
Alvonyx data-protection enquiries may be sent to:
or another privacy address subsequently published by Alvonyx.
The Customer must maintain an appropriate account contact capable of receiving data-protection and security communications.
29. Liability
Liability arising under this DPA will be governed by the liability provisions contained in the Alvonyx Terms and Conditions, except where Applicable Data Protection Law requires otherwise.
Nothing in this DPA excludes or limits liability to the extent that such exclusion or limitation is prohibited by applicable law.
Nothing in this DPA affects a Data Subject’s rights against a Controller or Processor under Applicable Data Protection Law.
30. Term
This DPA becomes effective when:
- the Customer accepts the Service Agreement;
- Customer Data begins to be processed by Alvonyx; or
- the parties otherwise agree this DPA,
whichever occurs first.
It continues for as long as Alvonyx processes Customer Data on behalf of the Customer.
Relevant confidentiality, deletion, security, audit and legal-compliance provisions continue for as long as Alvonyx retains Customer Data.
31. Changes to This DPA
Alvonyx may update this DPA where reasonably necessary to reflect:
- changes in Applicable Data Protection Law;
- regulatory guidance;
- new infrastructure;
- new Subprocessors;
- technical developments;
- new Services; or
- changes required to maintain legal compliance.
Alvonyx will provide appropriate notice where a material change affects existing Customer Processing.
Changes will not materially reduce the level of data protection required by applicable law.
32. Governing Law
Unless mandatory Applicable Data Protection Law requires otherwise, this DPA is governed by the law applicable to the underlying Service Agreement.
Where the Alvonyx Terms and Conditions are governed by the laws of England and Wales, the same governing law applies to this DPA.
Schedule 1 — Details of Processing
1. Subject Matter
Processing of Personal Data necessary to provide hosting, server, cloud, migration, backup, security, support and associated infrastructure services to the Customer.
2. Duration
Processing continues for:
- the duration of the applicable Service;
- any reasonable migration or termination period;
- any applicable backup-retention period; and
- any additional period required by applicable law.
3. Nature of Processing
Processing may include:
- collection;
- storage;
- hosting;
- organisation;
- retrieval;
- transmission;
- encryption;
- backup;
- duplication;
- migration;
- security scanning;
- technical troubleshooting;
- restoration;
- access where required for support;
- deletion; and
- other technical Processing required to provide the Services.
4. Purpose of Processing
Processing is undertaken for purposes including:
- hosting Customer websites;
- hosting applications;
- hosting databases;
- providing virtual or physical server resources;
- email hosting where applicable;
- backups;
- disaster recovery;
- security;
- networking;
- technical support;
- migrations; and
- infrastructure operation.
5. Categories of Data Subjects
Depending on Customer use, Data Subjects may include:
- Customer employees;
- Customer contractors;
- Customer representatives;
- website visitors;
- customers and prospective customers of the Customer;
- users of Customer applications;
- subscribers;
- suppliers;
- business contacts; and
- other individuals whose Personal Data the Customer chooses to process.
6. Types of Personal Data
Depending on Customer use, Customer Data may include:
- names;
- email addresses;
- telephone numbers;
- postal addresses;
- IP addresses;
- account identifiers;
- usernames;
- website-account information;
- order records;
- customer enquiries;
- support communications;
- transaction metadata;
- website usage information;
- browser information;
- server logs;
- application logs;
- user-generated content;
- database entries;
- files uploaded to Customer websites; and
- other Personal Data uploaded or generated by Customer systems.
7. Special Category Data
Alvonyx does not require Customers to upload special category data as part of normal hosting provision.
Where the Customer chooses to process such data, the Customer is responsible for ensuring:
- a lawful basis and Article 9 condition apply;
- the Service is appropriate;
- required safeguards are in place; and
- any additional compliance requirements are met.
Schedule 2 — Technical and Organisational Measures
Alvonyx’s security measures may include the following where appropriate to the Service.
Access Management
- access limited to authorised personnel;
- least-privilege principles;
- account-authentication controls;
- secure administrator access;
- periodic access review where appropriate;
- removal or amendment of access when no longer required.
Authentication
- strong passwords;
- MFA where supported and appropriate;
- protected SSH or server credentials;
- secure account-recovery processes.
Network Security
- firewall controls;
- DDoS protection where included;
- network segregation where appropriate;
- monitoring for suspicious traffic;
- protected administrative interfaces.
Encryption and Secure Transmission
- HTTPS/TLS;
- SSH;
- SFTP;
- encrypted administrative access;
- encryption at rest where supported by the relevant platform or Service.
Vulnerability and Malware Management
- security patching of Alvonyx-managed systems;
- vulnerability-management processes;
- malware scanning where included in the Service;
- security monitoring;
- threat mitigation where appropriate.
Backup and Recovery
- scheduled backups where included;
- redundant infrastructure where applicable;
- recovery procedures;
- retention cycles appropriate to the Service;
- monitoring of backup systems where applicable.
Availability
- infrastructure monitoring;
- redundancy where applicable;
- capacity management;
- incident-response procedures;
- business-continuity processes.
Physical Security
Physical infrastructure may be operated by approved data-centre and infrastructure providers using measures such as:
- controlled facility access;
- surveillance;
- environmental controls;
- power redundancy;
- fire detection or suppression; and
- controlled server access.
Personnel
- confidentiality obligations;
- access restrictions;
- security awareness;
- appropriate operational procedures.
Incident Management
- security-event identification;
- investigation;
- containment;
- mitigation;
- recovery;
- Customer notification where required;
- post-incident review where appropriate.
Supplier Management
- appropriate Subprocessor agreements;
- supplier security consideration;
- data-protection requirements;
- monitoring or reassessment where reasonably appropriate.
Schedule 3 — Subprocessors
The Customer gives general authorisation for Alvonyx to use categories of Subprocessor required to provide the Services.
These may include:
| Subprocessor Category | Purpose | Data Potentially Processed |
|---|---|---|
| Hosting & server infrastructure | Hosting websites, VPS and servers | Customer-hosted data, logs and technical data |
| Data centres | Physical infrastructure | Customer data stored on relevant systems |
| Networking providers | Internet/network connectivity | IP addresses and traffic metadata |
| Backup providers | Backup and disaster recovery | Copies of Customer-hosted data |
| Security providers | DDoS, malware and threat protection | IPs, logs, files or security events |
| Monitoring providers | Infrastructure monitoring | Technical and performance data |
| Support platforms | Customer support | Contact details, tickets and technical information |
| Email infrastructure | Service notifications | Names, addresses and communication data |
| Cloud/storage providers | Infrastructure and storage | Customer Data stored through the Service |
Schedule 4 — International Transfers
Where a Restricted Transfer occurs, Alvonyx will ensure an applicable lawful mechanism is used.
Depending on the transfer, this may include:
UK transfers
- UK adequacy regulations;
- UK International Data Transfer Agreement;
- UK Addendum to EU Standard Contractual Clauses;
- another permitted appropriate safeguard; or
- a valid statutory exception.
EU GDPR transfers where applicable
- an adequacy decision;
- European Commission Standard Contractual Clauses;
- another lawful safeguard; or
- an applicable derogation.
Where the transfer mechanism requires a transfer risk assessment or data protection test, the appropriate party will undertake that assessment as required.