View Categories

HOSTING DATA PROCESSING SCHEDULE

16 min read

Effective Date: 01 February 2026

Applicable To: All clients, partners, licensees, resellers and authorised shared-service operators using Fludnox hosting and infrastructure services where The Xdemór Group Limited processes personal data on their behalf.

This Hosting Data Processing Schedule (“Schedule”) forms part of the Shared Services Data Processing Agreement (“DPA”) and describes the processing of personal data carried out in connection with hosting and infrastructure services supplied by The Xdemór Group Limited under the Fludnox brand.

Capitalised terms not defined in this Schedule have the meanings given to them in the DPA. References to the “Client” mean the Controller or Processor purchasing or using the applicable Fludnox services. References to “Fludnox” mean The Xdemór Group Limited acting under the Fludnox brand.

1. Status and Application #

1.1 Incorporation into the DPA #

This Schedule supplements the DPA and applies whenever Fludnox processes personal data contained in websites, applications, databases, email accounts, files, backups, logs or other hosted environments on behalf of the Client.

This Schedule does not replace the DPA. Where there is any inconsistency concerning personal-data processing, the DPA prevails, followed by this Schedule, the applicable Order Form and the relevant service policies, except where an expressly negotiated written agreement provides a higher level of protection or mandatory law requires otherwise.

1.2 Controller-to-Processor Relationship #

Where the Client determines the purposes and means of processing personal data hosted through the Services, the Client acts as Controller and The Xdemór Group Limited acts as Processor.

Where the Client processes personal data on behalf of a downstream Controller, the Client acts as Processor and The Xdemór Group Limited acts as Sub-processor. In that case, the Client represents that the downstream Controller has authorised the appointment of The Xdemór Group Limited and the other subprocessors identified in the Fludnox Subprocessor and Data Location Register.

1.3 Independent Controller Processing #

This Schedule does not govern personal data processed by The Xdemór Group Limited as an independent Controller for account administration, billing, fraud prevention, legal compliance, security administration, service communications, contract management or dispute handling. That processing is governed by the Shared Services Privacy Policy.

A Registrar, Registry, payment provider, competent authority or other third party may also act as an independent Controller where it determines the purposes and means of processing under its own legal or regulatory obligations.

2. Documented Instructions #

2.1 Form of Instructions #

The Client instructs Fludnox to process personal data only as necessary to provide, secure, maintain and support the Services in accordance with the DPA, this Schedule, the applicable Order Form, the selected account configuration and further documented instructions issued by an authorised person.

Documented instructions may include an Individual Agreement, Order Form, authenticated support request, authorised email, control-panel configuration, migration instruction, restoration request or other recorded instruction accepted by Fludnox.

2.2 Limits of Instructions #

Fludnox will not process personal data for an independent purpose merely because the data is technically accessible within the Services.

Fludnox may refuse, suspend or seek clarification of an instruction that is unlawful, technically unsafe, outside the agreed Services, inconsistent with the DPA or issued by a person whose authority cannot reasonably be verified.

Where Fludnox considers that an instruction infringes applicable data-protection law, it will inform the Client without undue delay unless prohibited by law.

2.3 Processing Required by Law #

Fludnox may process personal data other than on the Client’s instructions where required by applicable law. Where legally permitted, Fludnox will inform the Client of the relevant legal requirement before processing.

3. Description of Processing #

3.1 Subject Matter #

The subject matter of the processing is the provision of Fludnox hosting and infrastructure services, including web hosting, managed website hosting, virtual or isolated server environments, databases, business email, DNS, content delivery, storage, backups, restoration, monitoring, migration, technical support and related infrastructure operations.

3.2 Nature of Processing #

Processing may include collection, receipt, recording, organisation, structuring, hosting, storage, replication, transmission, retrieval, consultation, encryption, decryption, caching, backup, restoration, migration, isolation, restriction, deletion and other technical operations required to provide the Services.

Human access to the substantive contents of personal data is not routine and is limited to circumstances permitted by the DPA, this Schedule and the Client’s documented instructions.

3.3 Purposes of Processing #

Fludnox processes personal data for the purposes of operating and delivering the Services, authenticating users, managing technical access, hosting and transmitting Client content, maintaining service availability, creating backups, restoring data, completing migrations, providing support, monitoring infrastructure, preventing abuse, responding to security incidents and complying with lawful instructions or legal obligations.

Fludnox will not use hosted personal data for unrelated advertising, data brokerage or general-purpose artificial-intelligence model training unless the Client has given separate express written instructions and all applicable legal requirements have been satisfied.

3.4 Frequency #

Processing may occur continuously for active hosting, storage, email, DNS, content-delivery, monitoring and security functions. Support, migration, restoration, investigation and manual-access processing occurs only when required by the Services, requested by the Client or otherwise permitted under the DPA.

3.5 Duration #

Processing continues for the duration of the applicable Service and any limited post-termination period required for return, export, deletion, backup expiry, security investigation, legal preservation or compliance with applicable law.

4. Categories of Data Subjects #

The personal data processed through the Services may relate to the Client’s website visitors, prospective customers, customers, subscribers, account holders, patients or service users where expressly approved, employees, workers, contractors, directors, representatives, suppliers, business contacts, users of online platforms, recipients and senders of communications, and any other individuals whose personal data the Client chooses to process through the Services.

The Client determines the actual categories of Data Subjects and must ensure that each category is covered by an appropriate lawful basis, transparency information and other applicable legal requirements.

5. Categories of Personal Data #

5.1 Hosted Content #

Hosted personal data may include names, postal addresses, email addresses, telephone numbers, usernames, account identifiers, customer references, business contact information, communications, form submissions, uploaded files, profile information, service records, transaction records, order information, invoice information and other content selected and controlled by the Client.

5.2 Technical and Usage Data #

Technical personal data may include IP addresses, device and browser information, timestamps, authentication events, cookies, session identifiers, access logs, server logs, request data, error data, security events, DNS records, email routing information and infrastructure metadata.

5.3 Authentication and Security Data #

The Services may process usernames, password hashes, access tokens, API keys, security settings, multi-factor authentication data, recovery information, access permissions and other credentials or security information controlled by the Client.

The Client must not transmit unencrypted passwords, private encryption keys or other highly sensitive credentials through an insecure channel.

5.4 Communications #

Where email or messaging services are used, personal data may include sender and recipient information, message content, attachments, delivery data, routing information, spam indicators and related metadata.

5.5 Payment Data #

Standard hosting Services are not intended to store full payment-card data. Payment-card information must be processed through an appropriately authorised payment provider unless an Individual Agreement expressly approves a compliant environment.

Fludnox may process limited transaction and invoice metadata where required for service integration or technical operation, but does not act as the Client’s payment processor merely by hosting a website.

6. Restricted and High-Risk Data #

6.1 Special-Category Data #

The Client must not process special-category personal data through standard or shared hosting unless Fludnox has approved the processing in writing.

Approval may require an identified condition under Article 9 UK GDPR, a Data Protection Impact Assessment, additional contractual terms, enhanced security controls, an appropriate hosting environment and an updated processing description.

6.2 Criminal-Offence Data #

Personal data relating to criminal convictions, offences or related security measures must not be processed through standard or shared hosting without prior written approval and confirmation that the requirements of Article 10 UK GDPR and the Data Protection Act 2018 have been addressed.

6.3 Other Regulated Data #

Medical records, biometric identifiers, government identifiers, full payment-card data, highly sensitive financial information, children’s high-risk data and information subject to sector-specific hosting requirements may be processed only where the applicable Order Form expressly permits the relevant workload.

6.4 Client Responsibility #

Approval of an infrastructure configuration does not constitute confirmation that the Client’s processing is lawful. The Client remains responsible for establishing lawful basis, additional processing conditions, transparency, necessity, proportionality and regulatory compliance.

7. Client Obligations #

7.1 Lawfulness and Authority #

The Client is responsible for the accuracy, quality and legality of the personal data and for the means by which it was obtained.

The Client must have all necessary lawful bases, permissions, contractual authority and notices required to instruct Fludnox and its authorised subprocessors to process the personal data.

7.2 Transparency #

The Client must provide the privacy information required under Articles 13 and 14 UK GDPR and must accurately explain the relevant hosting, backup, support, security, subprocessor and international-transfer arrangements where required.

7.3 Data Minimisation and Retention #

The Client must configure its applications, forms, databases, logs and retention settings so that it processes only personal data that is adequate, relevant and limited to what is necessary.

The availability of storage capacity does not authorise indefinite retention.

7.4 Security of Client-Managed Components #

The Client is responsible for the security of Client-managed applications, credentials, users, code, plugins, themes, databases, integrations, access permissions and encryption keys.

The Client must follow reasonable security and remediation instructions issued by Fludnox.

7.5 Data Subject Requests #

The Client remains responsible for receiving, assessing and responding to requests from Data Subjects. The Client must use available account and technical tools before requesting additional assistance from Fludnox.

8. Technical and Organisational Measures #

8.1 Risk-Based Security #

Fludnox will implement and maintain technical and organisational measures appropriate to the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of individuals.

The measures applicable to a particular Service depend on the selected service model, hosting environment and any additional controls identified in the Order Form.

The statutory security requirements are set out in Article 32 UK GDPR:

https://www.legislation.gov.uk/eur/2016/679/article/32

8.2 Governance and Confidentiality #

Personnel authorised to process Client personal data will be subject to appropriate confidentiality obligations and will receive access only where required for their role.

Fludnox will maintain appropriate policies and procedures concerning access, security incidents, supplier management, backup handling and secure deletion.

8.3 Identity and Access Management #

Administrative access will be restricted according to role and operational need. Fludnox will use appropriate authentication controls and will record or otherwise monitor security-sensitive administrative access where reasonably practicable.

Multi-factor authentication will be used for privileged systems where supported and appropriate to the risk.

8.4 Infrastructure and Network Security #

Measures may include firewalls, network segregation, logical isolation, secure configurations, access restrictions, intrusion or anomaly monitoring, malware controls and protection against unauthorised access.

The Client acknowledges that some network and infrastructure controls are provided by authorised subprocessors.

8.5 Transmission and Encryption #

Fludnox will use appropriate encryption or secure transmission protocols where supported and appropriate to the Service and risk.

Encryption at rest, customer-managed encryption keys and field-level encryption are included only where specified in the relevant Service or Order Form.

8.6 Vulnerability and Patch Management #

Fludnox will assess and address vulnerabilities affecting managed infrastructure in accordance with their severity, available remediation and operational risk.

The Client remains responsible for Client-managed code, applications, plugins, themes, libraries and other software unless management is expressly included in the Service.

8.7 Logging and Monitoring #

Fludnox may maintain logs and monitoring records relating to authentication, administrative access, resource use, availability, network activity, security alerts, system events and abuse indicators.

Log retention depends on the applicable Service, security purpose and legal requirements.

8.8 Resilience and Backups #

Where included in the selected Service, backups and recovery controls will be operated in accordance with the Fludnox Backup and Data Recovery Policy.

The Client remains responsible for maintaining independent copies of personal data required for its business continuity and legal obligations.

8.9 Deletion and Media Handling #

Personal data will be deleted or rendered inaccessible using measures appropriate to the relevant system, storage medium, backup cycle and risk.

Where individual deletion from a protected rotational backup is not technically practicable, the data will be placed beyond ordinary use and deleted through the applicable destruction cycle.

8.10 Supplier Management and Testing #

Fludnox will assess subprocessors before appointment and require written data-protection obligations offering an equivalent level of protection to the relevant obligations imposed on Fludnox.

Fludnox will periodically review the effectiveness and appropriateness of its controls and update them where reasonably required by changes in risk, law, technology or the Services.

9. Personal Data Breaches #

9.1 Notification #

Fludnox will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting personal data processed under this Schedule.

An initial notification may be provided before the investigation is complete and may be supplemented as additional information becomes available.

9.2 Information Provided #

To the extent known and available, the notification will describe the nature of the breach, the categories of personal data and Data Subjects affected, the likely consequences, the measures taken or proposed and a contact point for further information.

9.3 Client Decisions #

The Client remains responsible for deciding whether notification to the Information Commissioner’s Office, another supervisory authority, affected individuals or another recipient is required.

Fludnox will provide reasonable assistance in accordance with the DPA, taking into account the nature of the processing and the information available.

9.4 Security Events That Are Not Breaches #

Unsuccessful access attempts, scans, blocked attacks, spam, denial-of-service traffic or other events that do not result in accidental or unlawful destruction, loss, alteration, disclosure of or access to personal data do not constitute a Personal Data Breach solely because they triggered a security alert.

10. Assistance to the Client #

Fludnox will provide the assistance required under the DPA in relation to Data Subject requests, security obligations, breach assessment, Data Protection Impact Assessments and prior consultation with a supervisory authority.

Assistance will be proportionate to the nature of the processing and the information available to Fludnox.

Where a request requires custom development, extensive data extraction, forensic work, repeated manual searches or assistance beyond the standard Services, reasonable additional charges may apply to the extent permitted by the DPA and applicable law.

11. Subprocessors #

11.1 General Authorisation #

The Client grants general written authorisation for Fludnox to use the subprocessors identified in the Fludnox Subprocessor and Data Location Register.

The current Register is published at:

https://policies.shared-services.co/docs/fludnox/hosting-subprocessors-and-data-locations/

11.2 Appointment Requirements #

Fludnox will enter into written terms with each subprocessor that impose data-protection obligations offering an equivalent level of protection to the relevant obligations in the DPA.

Fludnox remains responsible to the Client for the performance of its subprocessors’ applicable data-protection obligations.

11.3 Changes and Objections #

Fludnox will notify the Client of intended additions or replacements in accordance with the notice procedure and objection period stated in the DPA.

An objection must be based on reasonable and documented data-protection grounds relating to the proposed subprocessor.

Where the parties cannot resolve a valid objection, Fludnox may offer an alternative configuration or permit termination of the affected Service in accordance with the DPA and applicable contractual terms.

12. International Transfers #

12.1 Transfer Requirements #

Where Fludnox initiates a restricted transfer of personal data outside the United Kingdom, it will use a mechanism permitted under Chapter V UK GDPR and complete any required data protection test.

The applicable statutory framework is available at:

https://www.legislation.gov.uk/eur/2016/679/chapter/V

Current ICO guidance is available at:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/

12.2 Permitted Mechanisms #

Applicable mechanisms may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the 2021 EU Standard Contractual Clauses, Binding Corporate Rules or another legally recognised safeguard.

An exception under Article 49 will not be used for systematic or routine transfers where an appropriate regular transfer mechanism should be implemented.

12.3 United States Transfers #

The UK Extension to the EU-US Data Privacy Framework may be relied upon only where the specific United States recipient is actively certified for the UK Extension and the transferred data falls within the scope of that certification.

Where those requirements are not met, another valid transfer mechanism must be used.

13. Return, Export and Deletion #

13.1 End of Processing #

At the end of the applicable Service, Fludnox will delete or return personal data processed on the Client’s behalf in accordance with the Client’s documented choice and the DPA, unless applicable law requires continued retention.

13.2 Client Export #

The Client is responsible for using available export mechanisms and retaining any copy it wishes to keep before the relevant Service or export period ends.

Custom export, format conversion, reconstruction or migration assistance may require separate payment where not included in the Service.

13.3 Backup Copies #

Personal data may remain in protected rotational backups until the relevant backup is overwritten or securely destroyed under the applicable retention cycle.

During that period, the data will not be restored to ordinary use except where required for legitimate recovery, legal compliance or an authorised investigation.

Where a complete backup is restored, relevant deletion, restriction and correction instructions will be reapplied where technically and legally required.

13.4 Required Retention #

Where law requires retention, Fludnox will isolate the retained data from ordinary processing and process it only for the legally required purpose and period.

13.5 No Commercial Override #

A payment dispute, suspension or commercial handover restriction does not override a mandatory obligation to return, delete, restrict, preserve or disclose personal data under the DPA or applicable law.

14. Records, Audits and Compliance Information #

Fludnox will make available the information reasonably necessary to demonstrate compliance with the obligations applicable under Article 28 UK GDPR.

Audits and inspections are subject to the procedure, notice, confidentiality, proportionality and cost provisions in the DPA.

Fludnox may satisfy a reasonable audit request by providing relevant policies, security information, certifications or independent audit materials where those materials provide sufficient assurance.

An audit does not entitle the Client to access another client’s data, source code, privileged legal material, credentials, internal threat intelligence, trade secrets or information whose disclosure would create a security risk.

15. Resellers and Downstream Controllers #

A Client acting for a downstream Controller must ensure that its own processing agreement authorises the use of Fludnox and the subprocessors identified in the Register.

The Client must accurately pass downstream instructions to Fludnox and must not issue an instruction exceeding its authority.

Fludnox may request direct confirmation from the downstream Controller where authority is disputed, unclear or materially affects data security, return, deletion or disclosure.

Nothing in this Schedule automatically creates a direct commercial agreement between Fludnox and a downstream Controller.

16. Contact #

Questions concerning this Schedule or processing under the DPA may be submitted to privacy@xdemor.com.

Matters requiring the attention of the Data Protection Officer may be submitted to dpo@xdemor.com.

Formal legal notices must be sent to legal@xdemor.com.

Operational hosting and data-export requests must be submitted through the authenticated Fludnox support channel or to support-fludnox@shared-services.co.

17. Governing Law #

This Schedule is governed by the governing-law and jurisdiction provisions of the Shared Services Data Processing Agreement.

Where an international-transfer instrument specifies mandatory governing-law, jurisdiction or supervisory-authority terms, those terms apply to the relevant transfer.