This document describes the operational rules that apply to this topic across HOSTPHOX services.
Roles and instructions
The customer is controller or processor as applicable; the relevant CAPTEC GROUP entity acts as processor/subprocessor when processing Customer Personal Data solely to provide services and documented support.
Confidentiality and security
Authorised personnel are subject to confidentiality. Technical and organisational measures include access control, authentication, logging, network protection, vulnerability management and incident response appropriate to the service.
Subprocessors
Subprocessors may be used for infrastructure, networks, security, communications and support, subject to appropriate data-protection obligations where required.
International transfers
Where restricted transfers occur, recognised safeguards such as adequacy decisions or standard contractual clauses are used where required.
Rights and incidents
We provide reasonable assistance with data-subject requests where the customer cannot reasonably fulfil them alone and notify the customer without undue delay of confirmed breaches where legally required.
Return, deletion and audit
At termination, data is returned or deleted according to service functionality, lifecycle and backup rotation subject to legal retention. Reasonable compliance information is made available subject to confidentiality and security controls.
Contact
For questions, contact help@hostphox.com.
