This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer", "Controller") and HostLuma ("Processor") wherever HostLuma processes personal data on your behalf as part of providing hosting services. It applies automatically — you don't need to countersign it separately for it to take effect, though we're happy to execute a signed copy on request for your own compliance records.
When you host a website, application, or database with HostLuma, you determine what personal data it holds and why (for example, your WordPress site's own visitor comments, customer records, or user accounts). You are the Controller of that data. HostLuma is the Processor.
This is distinct from data HostLuma collects about you as our customer (your Portal account, billing details), which is covered by our Privacy Policy instead, where HostLuma is the controller.
The categories of personal data and data subjects are determined entirely by Customer's own use of the service — HostLuma has no visibility into what a Customer chooses to store. Typically, this may include Customer's own end users, site visitors, or customers, and data such as names, email addresses, and any other information Customer's site or app is configured to collect.
HostLuma will:
Customer is responsible for:
HostLuma applies the following measures across its hosting infrastructure:
Customer provides general authorisation for HostLuma to engage the sub-processors listed in our Subprocessor List, which is kept current and forms part of this DPA by reference. HostLuma will give reasonable advance notice of any new sub-processor via that page (reflected in its "last updated" date) or by direct notice to active customers on request. If Customer reasonably objects to a new sub-processor on data-protection grounds, the parties will work in good faith to resolve the objection; if it can't be resolved, Customer may terminate the affected service.
HostLuma remains liable for the acts and omissions of its sub-processors to the same extent it would be liable if performing their services directly.
Where a sub-processor is located outside the UK, HostLuma relies on the UK's adequacy regulations, Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable to that transfer.
Consistent with our Terms of Service, suspending an account (for non-payment or a policy breach) does not trigger deletion of Customer's data. Data remains stored, inaccessible to the public but not destroyed, until the account is either restored or formally closed.
On termination of the service, or on Customer's written request, HostLuma will delete Customer's personal data from active systems within a reasonable period, and it will subsequently age out of the backup cycle in the ordinary course as older backups are rotated out. Customer may request an export of its data prior to closure. HostLuma may retain data beyond this where required by UK law (for example, billing records retained for tax purposes, which are HostLuma's own controller data under the Privacy Policy, not Customer's end-user data under this DPA).
HostLuma will provide Customer with information reasonably necessary to demonstrate compliance with this DPA on request. Given the shared-infrastructure nature of the service, on-site audits are not offered as standard; where a regulator or Customer's own compliance obligations genuinely require one, the parties will agree reasonable scope, notice, and cost allocation in good faith.
Liability under this DPA is subject to the limitations set out in Section 8 of the Terms of Service, except that nothing in this DPA limits either party's liability for a breach of UK GDPR that cannot lawfully be limited.

Real UK support with no outsourcing or ticket roulette. Get help with hosting, billing and WordPress support directly from the Host Luma team.
💬 Start WhatsApp Support → 💬 Open Live Chat ✉ support@hostluma.co.uk 💳 Customer Billing Portal© 2026 Host Luma. All rights reserved.