View Categories

HOSTING SUBPROCESSOR AND DATA LOCATION REGISTER

11 min read

Effective Date: 01 February 2026

Applicable To: All clients, partners, licensees, resellers and authorised shared-service operators using Fludnox services where The Xdemór Group Limited processes personal data on their behalf.

This Subprocessor and Data Location Register (“Register”) identifies the third parties authorised to process personal data on behalf of The Xdemór Group Limited in connection with Fludnox hosting and infrastructure services.

This Register forms part of the Shared Services Data Processing Agreement and the Fludnox Hosting Data Processing Schedule.

1. Scope of the Register #

1.1 Direct Subprocessors #

A Direct Subprocessor is a third party engaged directly by The Xdemór Group Limited to process Client Personal Data for the provision of Fludnox services.

1.2 Onward Subprocessors #

An Onward Subprocessor is a third party engaged by a Direct Subprocessor to perform part of the processing required for the Fludnox services.

The inclusion of an Onward Subprocessor provides transparency concerning the processing chain but does not create a direct agreement between that provider and the Client.

1.3 Independent Controllers #

This Register does not include third parties acting solely as independent Controllers, including Registries, Registrars, payment providers, financial institutions, competent authorities and Client-selected integrations where those parties determine their own purposes and means of processing.

Where a third party performs both processor and independent-controller functions, this Register applies only to its processor activities. A provider selected, contracted and controlled directly by the Client is not a Fludnox Subprocessor solely because Fludnox assists with its technical configuration. The Client remains responsible for the provider’s appointment, contractual terms, data-protection assessment and international-transfer arrangements.

Cloudflare Registrar may act as an independent Controller for domain-registration data processed under its ICANN, Registry, verification, security and registration-administration obligations. Its Registrar activities are therefore not included in this Register as Subprocessor processing. Cloudflare’s separate role as a Subprocessor for CDN, DNS proxy, security and edge services remains listed in Section 3.

2. General Authorisation #

By entering into the Shared Services Data Processing Agreement or continuing to use an affected Fludnox Service after the applicable notice period, the Client grants general written authorisation for the appointment of the approved subprocessors identified in this Register.

Each approved subprocessor must be subject to written data-protection obligations offering an equivalent level of protection to the relevant obligations imposed on The Xdemór Group Limited.

The Xdemór Group Limited remains responsible to the Client for the performance of the applicable data-protection obligations of its subprocessors.

3. Approved Direct Subprocessors #

Subprocessor Contracting Location Processing Purpose Categories of Data Processing Locations Transfer Position
SpeedyPage Ltd United Kingdom Hosting infrastructure, virtual servers, storage, backups, content delivery, email, domain-related technical services and support Hosted Client content, account identifiers, technical metadata, logs, email data, support communications and backups United Kingdom and the hosting region selected for the applicable Service. Backup data is stored within the same region as the live service by default. No restricted transfer arises solely from engagement of the United Kingdom entity. Processing outside the United Kingdom is subject to an applicable adequacy regulation, UK IDTA, UK Addendum or other valid safeguard.
Google Ireland Limited and Google LLC Ireland and United States Shared Services operational email, support communications, document handling and authorised collaboration Client contact details, support-ticket content, attachments, service information and operational communications submitted through Google Workspace European Union, United States and other locations used for Google Workspace service delivery UK adequacy regulations may apply to Google LLC where its active UK Extension certification covers the transfer. Otherwise the UK Addendum to the 2021 EU SCCs or another valid safeguard applies.
Cloudflare, Inc. and applicable Cloudflare Group affiliates United States and applicable affiliate locations Authoritative DNS, reverse proxy, content delivery, edge caching, SSL/TLS termination, Web Application Firewall, DDoS mitigation, bot management, traffic routing, security monitoring and related support IP addresses, request and response metadata, URLs, HTTP headers, cookies, cached content, DNS data, security events, administrator data, account identifiers and support communications Global edge network. Regional processing restrictions apply only where the relevant Data Localization Service has been expressly purchased and configured. Cloudflare Customer DPA, including the UK Addendum to the 2021 EU Standard Contractual Clauses; the UK Extension to the EU–US Data Privacy Framework where applicable; and any required data protection test.

3.1 Service-Dependent Processing #

An approved provider processes Client Personal Data only where the relevant provider is used for the Client’s Service.

Listing a provider does not mean that every Client’s data is transferred to every provider or location shown in this Register.

3.2 Google Workspace Limitation #

Google Workspace is used for operational communications and document handling. It is not the default storage location for Client-hosted production databases or website content.

Clients should not send unnecessary special-category, criminal-offence or other high-risk personal data through ordinary support email.

4. Approved Onward Subprocessors Used Through SpeedyPage Ltd #

Onward Subprocessor Location Processing Purpose Processing Locations Transfer Position
Vultr Holdings, LLC United States Cloud infrastructure, hosting, virtual servers, compute and related storage The region selected for the applicable hosting Service; available regions are global UK IDTA, UK Addendum to the 2021 EU SCCs, adequacy regulations where applicable, and any required data protection test
BunnyWay d.o.o. (Bunny.net) Slovenia Content delivery, edge caching and edge storage European Union and global edge network No restricted transfer for processing confined to an adequate location; UK IDTA or UK Addendum and any required data protection test for other locations
Google Ireland Limited and Google LLC Ireland and United States Support email and document processing used by SpeedyPage European Union and United States UK adequacy regulations where applicable to an active UK Extension certification; otherwise UK Addendum to the 2021 EU SCCs or another valid safeguard

SpeedyPage states that it provides at least 30 days’ notice before adding or replacing a subprocessor and identifies applicable onward-transfer mechanisms in its published DPA.

5. Pending Approval Providers #

Provider Proposed Purpose Proposed Locations Current Status
InterServer, Inc. Cloud VPS, dedicated and bare-metal servers, web hosting, storage, backups, network infrastructure and technical support United States; service-specific region including the New York City/New Jersey area, Dallas or Los Angeles Pending approval for hosted Client Personal Data. Before production use, Fludnox must document the applicable Article 28 terms, current onward subprocessors, UK IDTA or UK Addendum transfer mechanism, data protection test, selected data-centre location, backup location and deletion arrangements.
Spaceship, Inc. and applicable Affiliates Hosting, domain, email, storage and related infrastructure services where selected United States and service-specific infrastructure locations Pending approval for hosted Client Personal Data. Use must not begin or continue for UK-regulated Client Personal Data until a current list of onward subprocessors, a valid UK transfer mechanism and the required data protection test have been documented.

5.1 Reason for Pending Status #

Spaceship’s public DPA states that processing may occur in the United States and permits the use of subprocessors, but it does not identify a current public list of those subprocessors.

The public DPA also refers to legacy UK contractual clauses based on European Commission Decision 2010/87/EU rather than clearly incorporating the current UK IDTA or UK Addendum to the 2021 EU Standard Contractual Clauses.

5.2 Permitted Use Before Approval #

Before approval is completed, Spaceship may be used only where:

the relevant processing does not involve Client Personal Data; the provider acts as an independent Registrar or Registry-related Controller under a separate legal framework; or a specific written assessment confirms that the intended processing and transfer are lawful.

Spaceship must not be represented to Clients as an approved Fludnox hosting subprocessor until the pending requirements have been resolved.

5.3 InterServer Approval Requirements #

InterServer must not be represented as an approved Fludnox Subprocessor for production Client Personal Data until Fludnox has documented:

  1. the legal entity contracting with The Xdemór Group Limited;
  2. binding Article 28 processor terms;
  3. the selected primary and backup processing locations;
  4. any onward subprocessors with access to Client Personal Data;
  5. a valid UK international-transfer mechanism;
  6. the applicable data protection test and any supplementary safeguards; and
  7. the applicable return, deletion and backup-expiry arrangements.

Once those requirements are satisfied, InterServer may be moved to Section 3 as an Approved Direct Subprocessor.

6. Data Locations by Service Function #

6.1 Live Hosting Data #

The primary location of live hosting data is the region identified in the applicable Order Form, Service Description or account configuration.

Where a specific location commitment is contractually agreed, Fludnox will not materially change that location except in accordance with the Hosting Data Processing Schedule, the DPA and the applicable change-notice procedure.

6.2 Backup Data #

Where SpeedyPage infrastructure is used, backups are stored offsite within the same region as the live service by default.

A different backup location may apply where stated in the applicable Order Form or where a separate backup service is selected.

6.3 Content-Delivery, DNS and Edge Processing #

Where Cloudflare is enabled and managed by Fludnox, website traffic, IP addresses, request metadata, DNS information, security events and cached Content may be processed through Cloudflare’s global edge network.

Cloudflare edge processing does not determine the primary location of the Client’s origin hosting environment. However, individual requests may be received, inspected, routed, cached or protected through infrastructure located outside the origin-hosting region.

Regional Services, Customer Metadata Boundary, regional log storage or other data-localisation controls apply only where they are expressly included in the applicable Service and properly configured. Fludnox must not represent that ordinary Cloudflare processing is confined to the United Kingdom or European Economic Area unless the relevant contractual and technical controls are active.

Cloudflare itself states that it operates a global network and that regional inspection or metadata restrictions require specific Data Localization functionality.

6.4 Support and Operational Data #

Support communications and attachments may be processed in the United Kingdom, European Union and United States through authorised operational providers.

Clients must minimise personal data included in support requests and must use the authenticated support channel where sensitive information is required.

6.5 Domain Registration Data #

Domain-registration information may be processed by the applicable Registrar and Registry in locations determined under their own legal, regulatory and contractual frameworks.

Registrars and Registries commonly act as independent Controllers for registration, verification, dispute, security and regulatory processing. Those independent-controller activities are governed by the Fludnox Domain Registration Agreement and the relevant Registrar or Registry privacy terms.

6.6 Security Logs #

Security, access and infrastructure logs may be processed in the hosting region and in authorised operational systems used for monitoring, incident response and investigation.

Log location and retention depend on the applicable Service, incident and legal requirements.

7. International-Transfer Safeguards #

Where a restricted transfer occurs, The Xdemór Group Limited will rely on an applicable mechanism under Chapter V UK GDPR.

The available mechanisms may include an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the 2021 EU Standard Contractual Clauses or another legally recognised safeguard.

Where appropriate safeguards are used, The Xdemór Group Limited will complete the data protection test required under current UK law and implement supplementary contractual, organisational or technical measures where necessary.

Current official information is available at:

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/appropriate-safeguards/what-are-standard-data-protection-clauses-the-uk-idta-and-the-addendum/

8. Changes to the Register #

8.1 Notice #

Fludnox will provide prior written notice of an intended new or replacement subprocessor in accordance with the notice period stated in the Shared Services DPA.

Notice may be provided by email, through the Client portal or through another recorded notification method identified in the DPA.

8.2 Emergency Changes #

A shorter notice period may apply where an immediate replacement is reasonably required because of a security incident, provider failure, legal prohibition, service discontinuation or other event that cannot reasonably be addressed within the ordinary notice period.

Fludnox will provide available information as soon as reasonably practicable and will not reduce the level of protection required by the DPA.

8.3 Objections #

The Client may object within the applicable notice period on reasonable and documented data-protection grounds relating specifically to the proposed subprocessor.

Commercial preference, general opposition to subcontracting or an objection unrelated to personal-data protection is not sufficient.

Where a valid objection cannot be resolved, Fludnox may offer an alternative service configuration or permit termination of the affected Service in accordance with the DPA and applicable contractual terms.

9. Contact and Notifications #

Questions concerning this Register, subprocessors or data locations may be submitted to privacy@xdemor.com.

Formal objections to a proposed subprocessor and matters requiring the attention of the Data Protection Officer must be sent to dpo@xdemor.com.

Formal legal notices must be sent to legal@xdemor.com.

Operational hosting-location requests must be submitted through the authenticated Fludnox support channel or to support-fludnox@shared-services.co.

This Register operates together with the Shared Services Data Processing Agreement, Shared Services Privacy Policy, Fludnox Hosting Data Processing Schedule, Fludnox Hosting and Infrastructure Policy and the applicable Order Form or Individual Agreement.

The Shared Services Data Processing Agreement prevails where there is any inconsistency concerning the appointment, authorisation or liability of subprocessors.