Data Processing Addendum
Effective: July 16, 2026
This Data Processing Addendum (DPA) forms part of the Host Little Terms of Service when a customer uses the service to process personal data that is subject to applicable data-protection law. In that case, the customer is the controller (or processor acting for its controller) and Host Little is the processor for that customer data.
Processing details
Subject matter and duration: hosting, deploying, supporting, securing, backing up, and deleting customer workloads for the term of the service and the limited post-termination retention period described in the Terms.
Nature and purpose: provision of the customer-selected hosting, email, DNS, backup, and support features; prevention and investigation of abuse and incidents; and compliance with applicable law.
Data subjects and data: any individuals whose information the customer chooses to place in the service. Categories may include identifiers, contact details, authentication data, communications, and application content. The customer determines the categories and does not need to provide them to Host Little to use this DPA.
Host Little commitments
- Process customer personal data only on the customer's documented instructions, including this DPA and use of the service, unless law requires otherwise.
- Require personnel authorized to process customer data to be bound by confidentiality obligations.
- Maintain reasonable technical and organizational measures appropriate to the service and risks involved; our current public security overview is available at /security.
- Reasonably assist the customer with data-subject requests, security obligations, and required assessments, taking account of the nature of processing and information available to us.
- Notify the customer without undue delay after confirming a personal-data breach affecting customer data, and provide available information needed for the customer's response.
- At the end of the service, delete or return customer data as described in the Terms, unless applicable law requires retention.
Subprocessors and transfers
The customer gives general written authorization for Host Little to use subprocessors needed to deliver the service, including payment, email, infrastructure, DNS/CDN/SSL, security, and support providers. We will remain responsible for their relevant processing obligations. Customers may request the current subprocessor list and may object on reasonable data-protection grounds by emailing us within 14 days of notice of a material new subprocessor; we will work in good faith on a reasonable solution, which may include ending the affected service if no solution is available.
Customer workloads are offered in US East, US West, or EU. A customer is responsible for determining whether a transfer mechanism, supplementary measure, or other safeguard is needed for its data. On request, Host Little will discuss an appropriate transfer addendum for the services actually purchased.
Customer responsibilities
The customer is responsible for lawful instructions, its notices and legal bases, responding to data-subject requests, and configuring its own applications, access controls, secrets, and content. The customer must not use the service for regulated data or high-risk processing unless Host Little has expressly agreed in writing to the applicable scope and safeguards.
Priority and contact
If this DPA conflicts with the Terms on processing customer personal data, this DPA controls to that extent. For a signed copy, current subprocessor list, or an enterprise transfer addendum, email [email protected] from your account email.