Data Processing
Agreement
This Data Processing Agreement (“DPA”) is part of the agreement between X ZONE IT SRL, trading as X-ZoneServers (“we”), and you, the customer. It applies whenever personal data is stored or processed on the services we provide to you, and sets out the terms required by Article 28 of the GDPR (Regulation (EU) 2016/679).
1. Scope and roles
You decide what you store on the servers you rent from us. For the personal data in that content (“Customer Content”) you are the controller and X ZONE IT SRL is your processor.
For the personal data we collect to run your account — your name, contact and billing details, support tickets — we are the controller. That processing is covered by our Privacy Policy, not by this DPA.
This DPA takes effect when you accept our Terms at sign-up or when you place an order, and it lasts for as long as we provide services to you and until Customer Content is deleted under section 10.
2. Details of the processing
- Subject matter: the hosting and network services you order — VPS, dedicated servers, game servers and related services.
- Nature and purpose: storing Customer Content on the server you ordered, carrying it over our network, and the technical operations needed to run, protect and support that service. We do not otherwise look at, copy or use Customer Content.
- Types of personal data: whatever you choose to store or transmit — for example names, contact details, IP addresses, account records, logs and in-game identifiers.
- Data subjects: decided by you — for example your customers, end users, players, website visitors and staff.
- Special categories of data: only if you choose to store them. You are responsible for any additional safeguards that data requires, such as encryption inside your server.
- Location: the data-centre location you select when ordering (section 7).
- Duration: the term of your services plus the deletion period in section 10.
3. Processing on your instructions
We process Customer Content only on your documented instructions. Our Terms, this DPA and the actions you take in the control panel or API — creating, reinstalling, capturing an image of or deleting a server — are your complete instructions.
We may also process Customer Content where EU or Member State law requires it. In that case we tell you first, unless that law forbids it.
If we believe an instruction infringes the GDPR or other data protection law, we tell you promptly.
We access a customer server only when you ask us to in a support ticket, to stop an ongoing security incident or abuse that threatens our network or third parties, or when the law requires it.
4. Confidentiality
Everyone we authorise to process Customer Content is bound by a written duty of confidentiality or a statutory one, and accesses it only as far as their task requires.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. They include:
- Isolation: every VPS is a KVM virtual machine with its own virtual disks; dedicated servers are single-tenant hardware.
- Physical security: servers run in professionally operated data centres.
- Administrative access: access to our hypervisors and network equipment is limited to authorised X ZONE IT SRL staff, and brute-force protection runs on our nodes.
- Control panel: served over HTTPS only; account passwords are stored hashed; account and administrative actions are recorded in an activity log.
- Deletion: when a server is terminated, its virtual disks are destroyed.
- Backups of our own systems: our account and billing databases are continuously archived to separate servers in Germany and Finland.
Security inside your server — operating system updates, firewall rules, passwords, encryption and backups — is your responsibility, because only you control it.
6. Sub-processors
You give us general authorisation to engage sub-processors. The current list is at x-zoneservers.com/subprocessors.
We announce any new or replaced sub-processor at least 30 days before it starts processing Customer Content, by updating that page and emailing the address on your account.
You may object within that period on reasonable data-protection grounds by writing to [email protected]. If we cannot resolve the objection, you may terminate the affected services before the change takes effect, without penalty, and we refund any prepaid fees for the remaining period.
Every sub-processor is bound by a written contract with data protection obligations equivalent to this DPA. We remain fully liable to you for their performance.
7. Where Customer Content is processed
Customer Content stays in the data-centre location you select. We do not move it to another country without your instruction — for example when you migrate a server or order in another location.
In our EU/EEA locations, Customer Content is stored in the country you chose and our servers are administered only by our staff in the EU. No one outside the EEA has administrative access to them.
If you choose a location outside the EEA, such as Ashburn (United States), Customer Content is stored there on your instruction.
Traffic to our control panel and browser console passes through the network of one sub-processor based outside the EEA; that transfer is covered by the safeguard shown on the sub-processor list.
8. Helping you meet your obligations
You have full control of your server, so you can answer most data subject requests yourself. If a data subject contacts us about Customer Content, we pass the request to you without undue delay and do not answer it ourselves unless you instruct us to. We give you reasonable help where you need it.
We also give you the information reasonably needed for your security obligations, data protection impact assessments and prior consultations (Articles 32 to 36 GDPR), taking into account the nature of the processing and the information available to us.
9. Personal data breaches
We notify you without undue delay — and, where feasible, within 48 hours — after becoming aware of a personal data breach affecting Customer Content. The notice goes to the email address on your account and includes the information required by Article 33(3) GDPR as far as we have it; we add the rest as it becomes available.
We take reasonable steps to contain the breach and limit its effects. A notification is not an admission of fault.
10. Return and deletion
Until your services end you can copy your data off your servers at any time.
When a service is terminated, its storage is destroyed as set out in section 11 (Termination) of our Terms. Deletion is permanent, and we keep no copy unless EU or Member State law requires us to.
11. Information and audits
On request, we provide the information you need to show that this DPA is complied with.
If that is not sufficient, or a supervisory authority requires it, you or an independent auditor bound by confidentiality may audit our compliance. Audits need at least 30 days’ notice, take place during business hours, are limited to once in any 12 months (unless they follow a personal data breach or a supervisory authority’s request), are at your cost, and may not give access to other customers’ data or weaken our security.
12. Liability, precedence and law
Liability under this DPA is subject to the limitations in our Terms, except where Article 82 GDPR or other mandatory law does not allow them.
If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.
This DPA is governed by Romanian law, and disputes go to the courts named in the Terms. We may update it to reflect changes in law or in our services; we give 30 days’ notice of material changes and never reduce the protection it gives you without your agreement.
13. Form and contact
Accepting the Terms concludes this DPA in electronic form, which satisfies Article 28(9) GDPR. It is not signed separately: the text published on this page is the agreement.
Processor: X ZONE IT SRL · VAT RO48893724 · Reg. Com. J52/908/2023 · Bdul. 1 Mai 57, Sat Mihai Vodă, jud. Giurgiu, 087016, Romania · [email protected]