247 Live Chat
DATA PROTECTION

Data Processing Agreement

This DPA describes how myASP.NET processes and protects personal data on behalf of customers using our hosting services.

This Customer Data Processing Agreement (“DPA”) supplements our Terms of Service and applies where myASP.NET processes Personal Data on behalf of a customer in connection with the Services.

Definitions

Controller means the entity that determines the purposes and means of processing Personal Data. Customer Data means data processed by myASP.NET on behalf of the Customer. Processor means the entity processing Personal Data on behalf of the Controller. Security Incident means an unauthorized or unlawful breach affecting Personal Data. Subprocessor means another processor engaged to help provide the Services.

Scope and processing

The Customer is the Controller and myASP.NET acts as Processor for Customer Data. We process Customer Data to provide, secure, support and improve the Services, to follow the Customer's reasonable documented instructions, and to meet legal obligations.

The Customer is responsible for complying with applicable data protection laws, providing lawful instructions and obtaining the rights and consents necessary for processing.

Subprocessors

myASP.NET may engage Subprocessors to deliver the Services. We require Subprocessors to protect Personal Data under written data protection terms and remain responsible for our obligations under this DPA. Customers may request information about current Subprocessors.

Security and confidentiality

We maintain appropriate technical and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, disclosure or access. Personnel authorized to process Personal Data are subject to confidentiality obligations.

If a confirmed Security Incident affects Customer Data, we will notify the Customer without undue delay and provide available relevant information as the investigation progresses.

International transfers

Customer Data may be processed in the United States and other locations where myASP.NET or its Subprocessors operate. We use safeguards required by applicable data protection law for international transfers.

Data access, return and deletion

Customers can access and download their hosted files and databases while the Service is active. Following deactivation, Customer Data is deleted according to our retention practices, except where applicable law requires retention or data remains in securely isolated backup systems until normal expiration.

Cooperation

Where required by applicable law and where the Customer cannot complete a request using the Services, myASP.NET will provide reasonable assistance with data-subject requests, impact assessments and regulatory consultations. Additional work may be chargeable.

Miscellaneous

Except as modified by this DPA, the Terms of Service remain in effect. If this DPA conflicts with the Terms of Service regarding processing of Personal Data, this DPA controls to the extent of that conflict.