50% off your first month on monthly billing, for new customers, with code See the plans
HostCrafter
Get started

Data processing agreement

For customers who need it in writing: what we hold, who touches it, and where it sits. Short, because the honest version is short.

Last updated 29 August 2026

If you run a website for people in Europe or the UK, data-protection law asks you to have this in writing with anyone who stores that data for you. That is what this page is. It forms part of the terms of service and applies automatically — you do not need to sign anything or ask us for a copy.

The roles, in plain words: your visitors' and customers' data is yours. You decide what to collect and why — you are the controller. We store and serve it on your instructions and do nothing else with it — we are the processor. For your own account and billing details we are the controller, and the privacy policy covers those.

What we actually hold

Two things, and it is worth being concrete because the honest list is shorter than people expect:

  • Your websites. The files, the database, the media, the mailboxes and the backups — whatever your WordPress puts on disk. If your site collects orders, form submissions or customer accounts, those live in your database and we store the database. We do not read it, index it, analyse it or copy it anywhere else.
  • Your account with us. Your name, email, phone, billing address, invoices and support conversations — what any company needs to bill you and talk to you.

Plus the ordinary technical exhaust: server logs recording IP address, time and page for requests, which is how we investigate an outage or an attack and how we count your traffic.

We never see card numbers. Payments go straight to the payment provider and card details never reach our servers — we hold a reference that lets us match a payment to an invoice and send a refund back to the right place, and nothing more. That is not a policy we chose to be generous; it is how the payment is built, and it means a breach here cannot expose a card.

What we do with it

Only what is needed to run the hosting you bought: store it, serve it to your visitors, back it up, restore it when you ask, and investigate a problem when you report one or when the platform is under attack.

We do not sell it, share it for advertising, profile anyone, or use it to train anything. Our staff do not read customer data except when you ask us to look at something or when we are legally required to, and that access is logged.

If a law or a court requires us to disclose something, we ask for the legal basis, we check the request is genuine, we give the narrowest answer that satisfies it, and we tell you unless we are forbidden from doing so.

Who else is involved

These are our sub-processors — the companies that touch some part of this in order for the service to work. Each sees only what its job requires:

WhoWhat they handle
Our datacentre and node providerHouses the physical server your websites and backups sit on.
CloudflareSits in front of our own website, hostcrafter.com, making it fast and absorbing attacks. Every request to our website passes through it. Whether your own site uses a CDN is your choice.
Google AnalyticsTells us which pages of our marketing website people read. Nothing is placed on your websites.
Google Search ConsoleWhich searches bring people to our website. Reports on pages, not on people.
Our payment providersTake payments and send refunds. They hold the card details; we do not.
Our email providerDelivers invoices, alerts and replies to you.
Monitoring and server-management toolsWatch the servers and, where necessary, help us operate them. Narrowest access that does the job, for as long as the job takes, logged and then removed.

Read that list carefully and you will notice the pattern: Cloudflare, Google Analytics and Search Console are about our marketing website, not about your websites. The only sub-processors that touch your site's data are the datacentre that houses the disk and the tools we use to keep the machine alive.

We will tell you before adding a sub-processor that would handle your site's data, and you may cancel for a pro-rata refund if you object.

Where it lives

Your websites, their databases and their backups sit on our hosting node in Europe (France). For an EU customer that means the data does not leave the EU to be stored.

Your account and billing records sit on our control-plane server, and HostCrafter is operated from India — so account data is accessible from India, and some of the services above operate outside the EU as part of doing their job. If we add nodes in other regions your site stays in the region it was created in unless you ask us to move it.

How it is kept safe

  • Every account is a separate Linux user with its own PHP processes and its own database credentials, and CPU, memory and disk limits the kernel enforces.
  • Traffic to your site is encrypted — every site gets a certificate, renewed automatically.
  • Automatic daily backups, stored outside the account so a compromise or a deletion cannot take them with it.
  • Malware scanning that quarantines rather than deletes, and automatic blocking of addresses that hunt for files a visitor never asks for.
  • Administrative access to servers is key-based and logged.

If a breach affects your data we will tell you without undue delay, with what we know, what we have done, and what we advise you to do — in time for you to meet your own 72-hour obligation.

Your rights, and what happens at the end

You can export everything at any time: a full backup from the panel, files and database together, downloaded and yours.

If one of your own visitors or customers exercises a right — access, correction, deletion — that request is yours to answer, because it is your database. We will help you get at the data if you need us to.

When your account ends, your site files, databases and backups are deleted on the schedule in the terms. What we keep beyond that is set out in the privacy policy: billing records the law requires us to hold, and a small fraud-prevention record stored as one-way fingerprints.

Questions, or a written request: [email protected]. We acknowledge within 24 hours and answer within 30 days, and we do not charge for it.