Data Processing Agreement (DPA) - RaiaWeb
Version 1.2 - Last updated: 18 July 2026
Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.
This Data Processing Agreement ("DPA") is entered into under Article 28 GDPR, Regulation (EU) 2016/679 ("GDPR"), between:
- Processor: Alex Nabais Gomes, a sole trader operating under the trade name "RaiaWeb", NIF 268386625, Rua da Fonte Mestre, N.º 22, 6320-637 Soito, Portugal ("RaiaWeb"); and
- Controller: the Customer, as identified in the account and in the General Terms and Conditions of Service ("Terms").
1. Scope and Automatic Application
1.1. This DPA forms an integral part of the Terms (clause 20.2) and applies automatically, without the need for a separate signature, whenever the provision of the Services involves the processing of personal data by RaiaWeb on behalf of the Customer - namely the hosting of websites, applications, databases, email or other content that includes personal data of third parties, as well as the Maintenance Services and the SEO Services (Annex C to the Terms), to the extent that they involve access to personal data processed on behalf of the Customer.
1.2. The processing of the Customer's own personal data carried out by RaiaWeb as controller (account, billing, support), which is governed by the Privacy Policy, is not covered by this DPA.
1.3. If the Customer itself acts as processor for a third-party controller, the Customer warrants that the instructions it transmits to RaiaWeb reflect the instructions of that controller, with RaiaWeb acting as sub-processor. For the purposes of this DPA, references to the "Customer" include that capacity.
1.4. On data protection matters in the controller-processor relationship, this DPA prevails over the Terms.
1.5. Exclusion - self-hosted software (TapNTable): this DPA does not apply to the licensing of the TapNTable software installed on the Customer's own systems: the data processed through that software remains on the Customer's systems, and the Customer is solely responsible for such processing, with RaiaWeb having no access whatsoever. The data processed by RaiaWeb in connection with licence verification and updates is processed by RaiaWeb as controller, under the Privacy Policy. Where, in the context of technical support, RaiaWeb accesses the Customer's systems on an occasional basis and at the Customer's request, such access is carried out on behalf of the Customer, and the confidentiality and security obligations of this DPA apply, with the necessary adaptations, during the support session. If the Customer chooses to host TapNTable on a RaiaWeb hosting service, the processing of the hosted data is governed by this DPA under the general terms applicable to hosting (clause 1.1) - it is the hosting service, not the software licensing, that determines the application of the DPA.
2. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning assigned to them in Article 4 GDPR. The remaining capitalised terms have the meaning defined in the Terms.
3. Subject Matter, Nature and Duration of the Processing
3.1. The subject matter, nature, purpose and duration of the processing, as well as the categories of data subjects and personal data, are set out in Annex I.
3.2. The Customer, as controller, determines the purposes and means of the processing and warrants that it has a lawful basis for the data it hosts, and is responsible for compliance with the information duties and for the exercise of data subjects' rights.
3.3. Special categories of data: the shared hosting Services are not intended for the large-scale processing of special categories of data (Article 9 GDPR) or of data relating to criminal convictions. The Customer must not host such data without RaiaWeb's prior written agreement as to the appropriate measures.
4. Customer Instructions
4.1. RaiaWeb processes personal data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by law - in which case it informs the Customer before processing, unless the law prohibits this on important grounds of public interest.
4.2. Documented instructions comprise: the Terms, this DPA, the configurations and actions carried out by the Customer within the Services (control panel, Customer Area, APIs) and any additional written instructions that are reasonable and compatible with the nature of the Services.
4.3. RaiaWeb immediately informs the Customer if, in its view, an instruction infringes the GDPR or another data protection provision, and may suspend performance of that instruction pending clarification.
5. Confidentiality
RaiaWeb ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they only access the data to the extent necessary for the provision of the Services.
6. Security of Processing
6.1. RaiaWeb implements the appropriate technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to data subjects (Article 32 GDPR).
6.2. Annex II may be updated by RaiaWeb provided that this does not materially reduce the overall level of security.
6.3. In services where the Customer administers the environment (namely VPS), the security of the configuration, the operating system and the installed applications is the Customer's responsibility, under the AUP - except where the Customer has contracted Maintenance Services, in which case the security of the components covered by the plan is ensured by RaiaWeb, to the exact extent set out in Annex C.1 to the Terms.
7. Sub-processors
7.1. The Customer grants RaiaWeb general authorisation to engage the sub-processors identified in Annex III.
7.2. RaiaWeb informs the Customer of any addition or replacement of sub-processors at least 30 days in advance (by email), and the Customer may raise reasoned objections within that period. Where no reasonable solution is possible, the Customer may terminate the affected service, with a pro-rata refund of the unused pre-paid period.
7.3. RaiaWeb imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this DPA and remains liable to the Customer for the fulfilment of those obligations.
8. Assistance to the Customer
8.1. Data subject rights: taking into account the nature of the processing, RaiaWeb provides the Customer with reasonable assistance, by means of appropriate technical and organisational measures, to enable it to comply with requests to exercise data subject rights. If a data subject contacts RaiaWeb directly in relation to data hosted by the Customer, RaiaWeb does not respond on the merits and forwards the request to the Customer, where possible.
8.2. Data protection impact assessments and prior consultations: RaiaWeb provides the Customer with reasonable assistance in complying with Articles 32 to 36 GDPR, to the extent of the information available to it.
8.3. Reasonable assistance is included in the Services; requests that are manifestly disproportionate or that require specific work may be quoted as an additional service.
9. Personal Data Breaches
9.1. RaiaWeb notifies the Customer without undue delay - and, in any event, within a maximum of 72 hours - after becoming aware of a personal data breach affecting the data processed on behalf of the Customer.
9.2. The notification includes, to the extent of the information available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed, and such information may be provided in phases.
9.3. It is for the Customer, as controller, to assess and carry out the notifications to the supervisory authority and to data subjects (Articles 33 and 34 GDPR). RaiaWeb provides reasonable cooperation to that end.
10. Deletion and Return of Data
10.1. During the term of the contract, the Customer may export its data at any time using the available tools (control panel, FTP, backups). Export and assistance with switching providers are governed by Annex B to the Terms and are provided free of charge.
10.2. Upon termination of the contract, the 30-day recovery period provided for in clause 23.3 of the Terms and in Annex B (Article 25 of Regulation (EU) 2023/2854) applies, during which the Customer may export the data. Upon expiry of that period, RaiaWeb permanently deletes the personal data, save where retention is required by law.
10.3. Backup copies expire under the normal retention cycle (7 days), meaning that deletion from all systems, including backups, is completed within a maximum of 45 days after termination. At the Customer's request, RaiaWeb confirms the deletion in writing.
11. Demonstrating Compliance and Audits
11.1. RaiaWeb makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, in particular through this DPA, its Annexes and responses to reasonable security questionnaires.
11.2. The Customer may carry out audits, including inspections, either directly or through a mandated auditor (who must not be a competitor of RaiaWeb), subject to the following conditions: a minimum of 30 days' prior notice; a maximum of one per calendar year, except following a relevant data breach or at the request of a supervisory authority; during business hours and without disrupting operations; with no access to other customers' data or third parties' confidential information; with the Customer bearing the associated costs.
11.3. Wherever possible, audits are addressed, in the first instance, through the documentation and information referred to in clause 11.1.
12. International Transfers
12.1. Processing relating to shared hosting and email is carried out in datacentres located in Portugal (Annex III). RaiaWeb does not transfer that data outside the European Economic Area.
12.2. For virtual private servers (VPS), the datacentre region is chosen by the Customer during the order process, from the available regions, which include regions within the European Union and regions in third countries. The list of regions and their respective jurisdictions is set out on the Switching Providers and Transparency page published on the Website and forms an integral part of this DPA.
12.3. The Customer's choice of a region located outside the European Union constitutes a documented instruction for the purposes of clause 4.1, and it is the Customer's responsibility, as controller, to assess the lawfulness of that transfer under Chapter V GDPR. RaiaWeb does not change the chosen region without the Customer's instruction.
12.4. Transfers to countries for which no European Commission adequacy decision exists are carried out under Standard Contractual Clauses entered into with the infrastructure provider. On request, RaiaWeb provides information or a copy of the applicable safeguards.
12.5. A Customer wishing processing to take place exclusively within the European Union must select an EU region at the time of ordering.
13. Liability and Term
13.1. The liability of the parties is governed by Article 82 GDPR and by clause 22 of the Terms.
13.2. This DPA remains in force for as long as RaiaWeb processes personal data on behalf of the Customer and ends upon completion of the deletion obligations set out in clause 10.
Annex I - Description of the Processing
| Element | Description |
|---|---|
| Subject matter | Provision of web hosting services, virtual servers, email, website and application maintenance services, SEO services and associated services |
| Nature of the processing | Storage, retention, transmission, backup, restoration and deletion; technical operation of the applications installed by the Customer; administrative access for maintenance and updates, retention of access credentials in a RaiaWeb management panel, automated availability monitoring, and the making and retention of backups on RaiaWeb infrastructure, including of websites and applications hosted with third-party providers (Maintenance Services); management access to the Customer's accounts and properties on third-party platforms (SEO Services) |
| Purpose | Provision of the contracted services (hosting, website and application maintenance, SEO); RaiaWeb does not use the data for its own purposes |
| Duration | Term of the service provision contract, plus the periods set out in clause 10 |
| Categories of data subjects | Determined by the Customer - typically: visitors, users and customers of the hosted websites/applications; subscribers; the Customer's staff |
| Categories of data | Determined by the Customer - typically: identification and contact details, account data, submitted content, technical logs. Special categories of data on a large scale are excluded (clause 3.3) |
Annex II - Technical and Organisational Measures
- Encryption in transit (TLS) for exposed services; SSL certificates available for all hosted domains;
- Isolation between hosting accounts at platform level;
- Daily backups with 7-day retention;
- Access control based on the principle of least privilege; two-factor authentication available in the Customer Area;
- Regular updates and security patches to the hosting platform, managed jointly with infrastructure providers;
- Logging of relevant access and security events;
- Internal management and monitoring panels accessible only through mutual certificate authentication (mTLS), issued by an internal certificate authority and limited to authorised devices, with no password-based access;
- Isolation of internal panels at operating system level: dedicated system user, execution environment, database and directory, with restricted filesystem access;
- Credentials for access to Customer systems kept solely in the aforementioned management panel, never in documents, email messages or support records;
- Backups made under the Maintenance Services encrypted at rest, kept on infrastructure in the European Union, with a retention period of 7 days;
- Datacentres with physical access control managed by the infrastructure providers (Annex III), located in Portugal for shared hosting and email and, for VPS, in the region chosen by the Customer under clause 12;
- Internal incident response and notification procedure (clause 9).
Annex III - Authorised Sub-processors
| Entity | Country | Service |
|---|---|---|
| Innov4web | Portugal | Shared hosting infrastructure (cPanel) and datacentre |
| OVH SAS and companies within the same group | Region chosen by the Customer (cl. 12): France, Germany, Poland or Italy (EU); Canada, United Kingdom, Singapore, Australia or India (third countries) | Virtual server infrastructure (VPS) |
Changes to this list are communicated in accordance with clause 7.2.