Data Processing Agreement
Forest Website Hosting
This Data Processing Agreement sets out how Forest Website Hosting handles personal data in connection with the services we provide, in accordance with the UK GDPR and applicable Data Protection Legislation.
Forest Website Hosting (“Forest”, “we”, “our”, or “us”) is operated by A Latty, of Ashburnham, Battle, TN33 9NF.
Contents
Definitions
Data Protection Legislation means the UK GDPR, the Data Protection Act 2018, and all applicable laws and regulations relating to the processing of personal data and to privacy which apply in England and Wales, in each case as amended, updated, or replaced from time to time, together with any successor legislation.
In this Data Processing Agreement (the “Agreement”), the following terms shall have the meaning set out in the Data Protection Legislation: “data controller”, “data processor”, “data subject”, “personal data”, “processing/processes” (and cognate terms thereof) and “supervisory authority”.
- Customer
- the purchaser of the services from Forest Website Hosting, operated by A Latty, of Ashburnham, Battle, TN33 9NF (“Forest”).
- Company Supplied Software
- a piece of software supplied and installed by Forest such as (but not limited to) the operating system, web server and database server on a managed server.
- Logical Security
- the protection of the computer software (“Operating System”) of Forest’s platform, including user identification and password access, authentication, and access rights. These measures are to ensure that only authorised users are able to perform actions or access information on our platform.
- Parties
- Forest together with the Customer.
- Physical Security
- the protection of hardware, software, network and data from physical action and events that could cause serious loss or damage to the Forest platform. This includes protection from fire, flood, natural disasters, theft and vandalism.
- Customer Supplied Software
- any application that is developed, hosted or used by the Customer including WordPress, Magento and any other custom applications developed by, used by, or supplied to the Customer as part of their service.
- UK GDPR
- has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.
Data Protection Legislation
Both parties will comply with all applicable requirements of the Data Protection Legislation. This clause is in addition to, and does not relieve, remove or replace, a party’s obligations under the Data Protection Legislation.
Roles
The parties acknowledge that for the purposes of the Data Protection Legislation, Forest is the data processor and the Customer is the data controller.
This Agreement should be read in conjunction with Forest’s Acceptable Use Policy and Terms of Service. To the extent there is a conflict between this Agreement and the Acceptable Use Policy and Terms of Service, the terms of this Agreement shall take precedence.
The duration of the processing shall be from the date of the Customer’s acceptance of this Agreement, until the Agreement expires or terminates in accordance with the expiry or termination of the Customer’s services with Forest. The subject matter, nature and purpose of the processing shall be the provision of the Services by Forest to the Customer.
The categories of data subjects and types of personal data are those provided or made available to Forest by or on behalf of the Customer through the use or provision of the services purchased by the Customer (the “Services”) and shall exclude special categories of personal data or data relating to criminal convictions and offences.
Forest shall process the personal data for the Customer in accordance with article 4 no. 2 and article 28 of the UK GDPR.
Forest’s Responsibilities
Forest’s responsibilities with regard to the processing of personal data provided by the Customer in its use of the Services are limited to providing adequate security measures to store the data uploaded by the Customer onto the hosting platform. Forest is responsible, whether directly or through its suppliers, for the Physical Security of its platform, and the Logical Security of the Operating System and the Company Supplied Software which serves the Customer’s database. Forest is not responsible for the security of the data however populated within such databases and/or hosting space by the Customer, or Customer Supplied Software managed by the Customer and the access to the data that this has. This is the sole responsibility of the Customer.
Forest shall, in relation to any personal data processed in connection with the performance by Forest of its obligations under this Agreement:
- process that personal data only on the written instructions of the Customer, unless Forest is otherwise required to do so by the laws of the United Kingdom that apply to Forest (“Applicable Laws”). Where Forest is required by Applicable Laws to process personal data, Forest shall promptly notify the Customer of this before performing the processing required by the Applicable Laws, unless those Applicable Laws prevent Forest from notifying the Customer;
- pursuant to article 32 of the UK GDPR, ensure that it has appropriate technical and organisational measures in place in order to protect against any unauthorised or unlawful processing of personal data, accidental loss or destruction of personal data, and damage being caused to personal data;
- ensure that only personnel required for the purposes of carrying out this Agreement have access to the personal data, and that all personnel who have access to and/or process personal data are obliged to keep the personal data confidential;
- at the Customer’s cost, provide reasonable assistance to the Customer in responding to any request from a supervisory authority or a data subject (taking into account the nature of the processing) and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators (taking into account the nature of processing and the information available to Forest);
- notify the Customer without undue delay upon becoming aware of a personal data breach;
- in accordance with Forest’s standard policies, delete or return (at the Customer’s cost, in a format determined by Forest) personal data and copies thereof on termination of the Agreement, unless required by any Applicable Laws to continue to store the personal data; and
- maintain complete and accurate records and information to demonstrate its compliance with this clause, and allow for audits to be carried out by the Customer, only so far as is necessary in order to demonstrate compliance, provided that the Customer (a) provides Forest with no less than 30 days’ notice of such audit or inspection; (b) refunds Forest for all reasonable costs and expenses that it incurs as a result of any such audit or inspection; and (c) both parties agree the scope, duration and purpose of such audit or inspection. If the Customer becomes privy to any Confidential Information of Forest as a result of this clause, the Customer shall hold such Confidential Information in confidence and, unless required by law, not make the Confidential Information available to any third party, or use the Confidential Information for any other purpose. The Customer acknowledges that Forest shall only be required to use reasonable endeavours to assist the Customer in procuring access to any third party assets, records or information as part of any audit; and
- provide a list of sub-processors engaged to fulfil the Services by sending an email request to domains@theforest.uk.
The Customer’s Responsibilities
The Customer acknowledges that Forest has no knowledge of the type or content of any personal data received, stored, or transmitted to Forest’s platform through the Customer’s use of the Services.
If Forest believes or becomes aware that its processing of Customer personal data is likely to result in a high risk to the data protection rights and freedoms of data subjects, it shall inform the Customer and provide reasonable cooperation to the Customer (at the Customer’s expense) in connection with any data protection impact assessment that may be required under the Data Protection Legislation.
In respect of personal data which the Customer receives, stores, or transmits using the Services, the Customer:
- will ensure, and warrants that, it has all necessary and appropriate consents and notices in place to lawfully transfer the personal data to Forest for the duration and purposes of this Agreement;
- undertakes that its use of the Services for processing personal data will (i) comply with privacy laws or regulations applicable to its processing of Customer personal data, and (ii) not cause Forest to infringe the Data Protection Legislation. The Customer will ensure that it has all necessary consents, notices and other requirements in place to enable lawful processing of the Customer personal data by Forest for the duration and purposes of this Agreement;
- shall, unless otherwise provided for in this Agreement, be solely responsible for the legality, confidentiality, integrity, availability, accuracy and quality of all data it processes;
- shall be solely responsible for ensuring the safety and security of all the data it controls and processes. The Customer warrants that it has relevant and appropriate security measures in place to adequately protect the personal data it collects and processes. The Customer must verify the adequacy of Forest’s security measures as appropriate for the type of personal data the Customer collects, processes and stores on Forest’s platform. The Customer should refer to the Acceptable Use Policy to ensure it is not in breach of Forest’s terms and conditions;
- is solely responsible for responding to any request from a data subject and for ensuring its own compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments and consultations with supervisory authorities or regulators;
- shall indemnify Forest against any claims, actions, liabilities, proceedings, direct losses, damages, expenses, fines and costs (including without limitation court costs and reasonable legal fees) incurred by Forest as a direct result of any negligence, wilful misconduct, or breach of the Data Protection Legislation by the Customer.
Third Party Processing
Forest delivers its hosting services using a third-party underlying infrastructure provider, which acts as a sub-processor. Details of the sub-processors engaged by Forest are available to the Customer on request (see “Forest’s Responsibilities” above).
The Customer grants Forest the authorisation to appoint (and to permit each third party processor appointed in accordance with this section to appoint) third party sub-processors in accordance with this section.
Forest may appoint alternative third party processors to provide materially like-for-like services to the Customer as part of the Services, subject to: (a) Forest entering into a written agreement with such third party processor incorporating terms which are substantially similar to those set out in this Agreement; and (b) such third party processor being able to demonstrate at least as high a standard of service quality and compliance as the previously appointed third party processor.
The Customer agrees to Forest giving any such sub-processors access to the Customer’s details so that Forest can deliver the Services under the agreement. The Customer further agrees that those sub-processors may be based outside of the country in which the Customer has chosen to store Customer personal data, subject to Forest taking steps to ensure appropriate transfer protections are in place where such transfers are made. Forest requires that its sub-processors maintain security and data protection practices that are consistent with this Agreement.
Liability
Nothing in this Agreement excludes or limits either party’s liability where it would be unlawful to exclude or limit it, including liability for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
Subject to the paragraph above, Forest’s total aggregate liability to the Customer arising out of or in connection with this Agreement — whether in contract, tort (including negligence), breach of statutory duty (including under the Data Protection Legislation), or otherwise — shall be subject to, and shall in no event exceed, the limitations and exclusions of liability set out in clause 11 (Limitation of Liability) of the Forest Terms of Service, which shall apply equally to this Agreement.
Without limiting the paragraph above, Forest shall not be liable to the Customer for any indirect or consequential loss, or for any loss of profit, revenue, business, goodwill, anticipated savings, or data, arising out of or in connection with this Agreement.
This clause does not limit the Customer’s indemnity obligations set out under “The Customer’s Responsibilities” above, and does not affect any liability of either party to a data subject or a supervisory authority that cannot lawfully be excluded or limited.
Governing Law
This Agreement and any dispute or claim arising out of or in connection with it, or its subject matter or formation (including non-contractual disputes or claims), shall be governed by, and construed in accordance with, the laws of England and Wales.
Jurisdiction
Each party irrevocably agrees that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with this Agreement or its subject matter or formation.