All legal documents
For data protection officers, legal and procurement teams

Data Processing Agreement

The Article 28 terms that apply when G7Cloud processes personal data on your behalf. Covers instructions, security, sub-processors, breach notification, international transfers, audit rights and deletion, with the processing details, security measures and sub-processor register set out in the annexes.

Version 1.0Last updated 7 August 2026

1. Roles, scope and precedence

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between you (the "Customer") and G7CLOUD ENTERPRISE LTD, a company registered in England and Wales under number 16828080, whose registered office is at 71-75 Shelton Street, London, England, WC2H 9JQ, trading as G7Cloud (the "Processor"). It applies whenever we process personal data on your behalf in providing the services.

For the personal data contained in your sites, databases, mailboxes, files and backups, you are the controller and we are the processor. You decide what personal data you place on the platform and why. We process it only to provide the services you have asked for.

For a limited set of data we determine ourselves, we are a controller in our own right: your account and billing records, our support correspondence with you, and the security and operational logs we keep to run and protect the platform. That processing is described in the Privacy Policy rather than here.

In this DPA, "UK GDPR", "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" carry the meanings given in the UK GDPR and the Data Protection Act 2018.

Where this DPA conflicts with the Terms of Service, this DPA prevails on data protection matters. Where a signed enterprise agreement conflicts with this DPA, the signed agreement prevails.

2. Processing on documented instructions

We process personal data only on your documented instructions, including on international transfers, unless we are required to do otherwise by law. Where a legal requirement compels us to process beyond your instructions, we will tell you before processing unless that same law prohibits us from doing so.

Your instructions are: the Terms of Service, this DPA, the configuration choices you make in the dashboard and API, and any further written instruction you give us. Operating the platform in the ordinary way, including running your sites, sending your email, taking backups, restoring on request, filtering hostile traffic and providing support you ask for, is processing on your instructions.

We will tell you if, in our opinion, an instruction infringes UK data protection law. We do not process your data for our own purposes, we do not sell it, we do not share it with advertising networks, and we do not use it to build profiles of you or of your visitors.

We do not use customer content to train machine learning models, and we do not permit our sub-processors to do so either.

3. Confidentiality and personnel

Everyone we authorise to process personal data is bound by a duty of confidentiality that survives the end of their engagement, and is granted access only to what their role requires.

Administrative access to customer environments is limited to the people who operate the platform, is protected by key-based authentication, and is recorded in an audit log that captures the actor and the action.

4. Security of processing

We implement and maintain the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, together with the risk to data subjects. Those measures are described more fully in our Security Statement.

We may update the measures over time. We will not make a change that materially reduces the overall level of protection for personal data during the term.

5. Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex III. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

We will give you at least 30 days' notice before a new sub-processor begins processing your personal data. Notice is given by updating the sub-processor page and emailing the address on your account. You may subscribe to change notifications by writing to privacy@g7cloud.com.

If you reasonably object to a new sub-processor on data protection grounds within the notice period, tell us why and we will work with you to find a reasonable alternative. If we cannot, you may terminate the affected services without penalty and receive a pro rata refund of fees paid in advance for the unused period.

The AI features are the one sub-processing relationship you can decline while keeping the rest of the service. See clause 11.

6. Assisting with data subject rights

The platform gives you direct access to the personal data you hold on it, so in most cases you can answer an access, rectification, erasure or portability request yourself: databases can be exported, files downloaded, mailboxes accessed and site content edited without our involvement.

Where you cannot, we will provide reasonable assistance by appropriate technical and organisational measures, taking into account the nature of the processing.

If a data subject contacts us directly about personal data we process on your behalf, we will not respond to the substance of the request. We will tell them to contact you, and forward the request to you promptly where we can identify the account it relates to.

7. Assistance with your wider obligations

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 UK GDPR: security of processing, breach notification to the ICO and to data subjects, data protection impact assessments, and prior consultation.

This DPA, the Security Statement and the annexes are written to answer most impact assessment questions without needing to ask us. Where you need more, contact privacy@g7cloud.com.

8. Personal data breach notification

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process on your behalf.

Our notification will describe, so far as we know it at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for further information. Where we cannot provide everything at once, we will provide it in phases without further undue delay rather than waiting for a complete picture.

Notifying you is not an acknowledgement of fault. Notifying the ICO and affected data subjects, where required, remains your responsibility as controller, and we will support you in doing it.

9. International transfers

Your sites, databases, mailboxes and files are hosted on infrastructure we operate in the United Kingdom. Backup copies are held in the United Kingdom and the EEA.

Two sub-processors involve processing in the United States: Stripe, for card payments, and Anthropic, where a user in your account chooses to use an AI feature. Both are covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with the supplementary measures described in Annex II.

We will not transfer personal data we process on your behalf to a country outside the UK except as described in Annex III or on your instruction, and never without an appropriate transfer mechanism in place.

10. Return and deletion

You can export your data at any time during the term. Databases, files, mailboxes and builder-created code are all exportable without our involvement.

On termination, and at your choice, we will return or delete the personal data we process on your behalf. Unless you ask us to delete it sooner, live data is retained for 30 days after termination so that an account closed by mistake or in a dispute can be recovered, and is then deleted.

You can also request deletion of your account at any time during the term. An account marked for deletion is permanently removed, with related records deleted with it, after a 7 day cooling-off period that exists so an accidental or unauthorised deletion can be reversed.

Backups are deliberately append-only: over the network, a client can create and read backups but cannot delete them, which is what stops an attacker who has fully compromised a server from destroying its backup history. The consequence is that deletion cannot reach historical backup copies on demand. Those copies expire on the backup retention cycle set out in Annex I, remain encrypted throughout, and are used only to restore the account they belong to. We think a customer is better served by backups an attacker cannot erase than by a promise of instant deletion from them, and we would rather write that down than leave you to discover it.

We may retain personal data where UK law requires it, for example billing records kept for tax purposes. Anything retained on that basis stays protected by this DPA for as long as we hold it.

11. AI features and how to switch them off

The AI Website Builder and the dashboard assistant are powered by Anthropic. This clause exists because it is the first question most data protection teams ask, and it deserves a clear answer rather than a footnote.

Nothing is sent unless someone chooses to send it. Content reaches Anthropic only when a user in your account uses one of those two features, including where that user has scheduled an assistant task to run on their behalf. No part of the platform sends your site content, databases, files, email or visitor data to any AI provider in the background, for our own analysis, or for any purpose other than answering the request a user made.

What is sent is the prompt the user submits together with the context needed to answer it, for example the files in the workspace being edited. It is used to produce the response and for nothing else. It is not used to train models, ours or anyone else's.

You can switch AI features off entirely. On an Enterprise agreement we will disable them at account level, so no user in your organisation can invoke them and no content can leave for an AI provider by any route. Anthropic then processes nothing for you at all and drops out of your sub-processor list. Ask for this at privacy@g7cloud.com or during contracting.

12. Audit and information rights

We will make available the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.

In practice we ask that you first accept this DPA, the Security Statement and any documentation we can supply in answer to your questions, because that resolves most reviews without an on-site visit. Where it does not, an audit may be carried out on at least 30 days' written notice, no more than once in any 12 month period unless a personal data breach or a regulator requires otherwise, during business hours, without unreasonable disruption, and subject to confidentiality.

An audit may not extend to another customer's data, to systems where an inspection would compromise the security of the platform for others, or to commercially confidential information not relevant to the processing of your personal data.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service or, where one is in place, the signed enterprise agreement.

Nothing in this DPA limits a data subject's rights under the UK GDPR, or either party's liability where the law does not permit it to be limited.

14. Term, changes and governing law

This DPA takes effect when you begin using the services and continues for as long as we process personal data on your behalf.

We may update this DPA where a change in law, in the services, or in our sub-processors requires it. We will give reasonable notice of a change that materially affects your rights, and will not make a change that reduces the overall level of protection during your term.

This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

A countersigned copy for your records is available on request from legal@g7cloud.com. Enterprise customers can have this DPA executed as part of a signed agreement.

Annex I: Details of the processing

ItemDetail
Subject matterProvision of managed hosting, application hosting, managed databases, email hosting, DNS, the AI Website Builder, backups, and the security and caching layer in front of customer sites.
DurationThe term of the Terms of Service or signed agreement, plus the retention periods set out below.
Nature and purposeHosting, storing, transmitting, caching, backing up, restoring and securing customer data so that the customer can operate its websites, applications and email.
Categories of data subjectsDetermined by the customer. Typically: the customer's own customers and prospects, its employees and contractors, visitors to its websites, senders and recipients of its email, and users it grants access to its G7Cloud account.
Types of personal dataDetermined by the customer. Typically: names, email addresses, postal addresses, telephone numbers, account credentials, order and transaction records, email content and attachments, uploaded files and images, support correspondence, and technical data such as IP address, user agent and pages requested.
Special category dataNot expected and not required by the services. The platform is not designed or offered for the processing of special category or criminal offence data. Tell us before placing such data on the platform so we can agree whether additional measures are needed.
Frequency of processingContinuous for the duration of the services.

Retention periods. The following apply to data we hold as processor. Content you place on the platform is retained until you delete it or the account is closed.

DataRetention
Site files, databases, mailboxesUntil deleted by you, or 30 days after termination.
Backup copiesNightly copies on a UK append-only backup service, with a monthly offsite copy. Copies expire on the retention cycle and cannot be deleted early by design (see clause 10).
Request and security logs for your site14 days, then deleted. Used to answer "what hit my site" and to detect attacks.
Email send recordsMetadata for 90 days. Message bodies stripped after 30 days.
Account and billing recordsRetained while the account is open and for 6 years after the last transaction, as UK tax law requires.
Administrative audit logRetained for the life of the account as a security record of who did what.

Annex II: Technical and organisational measures

These are the Article 32 measures. The Security Statement describes them in more detail and in plainer language.

AreaMeasures
Encryption in transitTLS on every public connection, with certificates issued and renewed automatically for every site and mailbox. Administrative access is over SSH with key-based authentication and passwords disabled.
Encryption at restBackup snapshots are encrypted on the machine that creates them, before they leave it, so the storage service never holds a decryptable copy. Account passwords are stored as salted hashes and are not recoverable. Stored platform credentials are encrypted.
IsolationEvery site runs in its own dedicated container with its own database and its own credentials. Sites do not share an application runtime, a filesystem or a database user, so one customer cannot reach another's data through the platform.
Access controlRole-based access in the dashboard, optional two-factor authentication on every account, scoped API keys that grant only the permissions selected, and internal administrative access limited to the people who operate the platform.
AccountabilityAdministrative actions are recorded in an audit log capturing the actor, the action and the time. Lifecycle operations against production hosts are blocked at the tooling layer rather than by convention.
Integrity of backupsThe backup service is append-only over the network: a client can create and read snapshots but cannot delete them. A server that is fully compromised, including its credentials and its repository password, cannot destroy its own backup history. This has been verified by exercise, not only by configuration.
Restore testingBackups are restore-tested automatically every day by restoring into a disposable environment and comparing the result against the source. A backup that has never been restored is not evidence of anything.
AvailabilityNightly backups with a monthly offsite copy, per-minute uptime monitoring from outside our own network, and automatic failover of the security and caching layer in front of customer sites.
Network securityA managed web application firewall, bot filtering, rate limiting and per-country rules in front of every site, maintained by us across the platform. Hostile traffic is rejected before it reaches a customer container.
Vulnerability managementPlatform images and dependencies are updated on an ongoing basis, with automated integrity scanning of hosted WordPress installations against published checksums.
Resilience and testingContinuous automated health checking across the platform's subsystems, with alerting to the operations team.
PersonnelConfidentiality obligations that survive engagement, access granted on a need-to-know basis, and removal of access when a role ends.
Supplementary transfer measuresFor the two sub-processors that process outside the UK: data minimisation (only what the specific function needs is sent), encryption in transit throughout, and contractual commitments to challenge and notify us of government access requests where the law permits.

Annex III: Authorised sub-processors

The current register, with the purpose and the categories of data each one receives. The sub-processor page carries the same list and is the page we update when it changes.

Sub-processorPurposeDataLocation
Stripe · Stripe Payments Europe, Ltd. and Stripe, Inc.Card payment processing, subscriptions and invoicing.Name, email address, billing address and card details. Card numbers are captured by Stripe directly and never reach G7Cloud systems.Ireland and the United States
Cloudflare · Cloudflare, Inc.Offsite backup storage (Cloudflare R2), and the security and DNS layer in front of the G7Cloud dashboard and API.Backup archives of customer sites and databases, which may contain any personal data held in them. Request metadata such as IP address and user agent for the dashboard and API.United Kingdom and the EEA
Anthropic · Anthropic PBCPowers the AI Website Builder and the dashboard assistant. Used only when a user in your account chooses to use one of those features.The prompt the user submits and the site content or account context needed to answer it. Nothing is sent unless a user actively uses the feature.United States

MaxMind GeoLite2 databases are used to identify the country and network of a request. They are downloaded and queried entirely on our own servers, so no visitor data is sent to MaxMind and it is not a sub-processor. Certificate authorities receive domain names during certificate issuance, which is not customer personal data.