Alex Gomes Individual - RaiaWeb Alex Gomes Individual - RaiaWeb
  • View Cart 0
  • English English
    english English
    portuguese Português
Alex Gomes Individual - RaiaWeb
  • Domains
  • Hosting
    • Web HostingServers with WordPress, JetBuilder, JetBackup and much more, included in every plan.
    • VPS HostingVPS servers with dedicated resources, full control panel and total scalability, included in every plan.
  • Services
    • Web DevelopmentBuild your professional website with us!
    • SEOSpeed, structure and Google-ready code.
    • GDPR ComplianceYour site compliant, without the headache.
    • Maintenance & UpdatesWe look after the site while you work.
  • Security & Tools
    • SSL CertificatesProtect your website and your customers' data with trusted SSL certificates, compatible with all browsers and devices.
    • -----
  • Company
    • About UsLearn about our story and what drives us.
    • Contact UsGet in touch with our team through the contact form for any questions or assistance.
  • Login
Legal

Data Processing Agreement

Data Processing Agreement (DPA) - RaiaWeb

Version 1.0 -  Last updated: 11 June 2026

Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.

This Data Processing Agreement ("DPA") is entered into under Article 28 of Regulation (EU) 2016/679 ("GDPR") between:

  • Processor: Alex Nabais Gomes, sole trader, operating under the commercial name "RaiaWeb", NIF 268386625, Rua da Fonte Mestre, N.º 22, 6320-637 Soito, Portugal ("RaiaWeb"); and
  • Controller: the Client, as identified in the account and in the Terms and Conditions of Service ("Terms").

1. Scope and Automatic Application

1.1. This DPA forms an integral part of the Terms (clause 20.2) and applies automatically, without the need for separate signature, whenever the provision of the Services involves the processing of personal data by RaiaWeb on behalf of the Client - in particular the hosting of websites, applications, databases, email or other content including third parties' personal data.

1.2. This DPA does not cover the processing of the Client's own personal data carried out by RaiaWeb as controller (account, billing, support), which is governed by the Privacy Policy.

1.3. If the Client itself acts as processor for a third-party controller, the Client warrants that the instructions it gives RaiaWeb reflect that controller's instructions, RaiaWeb acting as sub-processor. For the purposes of this DPA, references to the "Client" include that capacity.

1.4. In matters of data protection within the controller–processor relationship, this DPA prevails over the Terms.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them by Article 4 GDPR. Other capitalised terms have the meaning defined in the Terms.

3. Subject Matter, Nature and Duration of the Processing

3.1. The subject matter, nature, purpose and duration of the processing, as well as the categories of data subjects and of personal data, are set out in Annex I.

3.2. The Client, as controller, determines the purposes and means of the processing and warrants that it has a lawful basis for the data it hosts, being responsible for compliance with information duties and for handling data subjects' rights.

3.3. Special categories of data: shared hosting Services are not intended for large-scale processing of special categories of data (Article 9 GDPR) or of data relating to criminal convictions. The Client must not host such data without RaiaWeb's prior written agreement on appropriate measures.

4. Client Instructions

4.1. RaiaWeb processes personal data only on documented instructions from the Client, including with regard to international transfers, unless required to do so by law - in which case it informs the Client before processing, unless the law prohibits this on important grounds of public interest.

4.2. Documented instructions comprise: the Terms, this DPA, the configurations and actions performed by the Client in the Services (panel, Client Area, APIs) and reasonable additional written instructions compatible with the nature of the Services.

4.3. RaiaWeb shall immediately inform the Client if, in its opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend its execution pending clarification.

5. Confidentiality

RaiaWeb ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access the data only to the extent necessary for the provision of the Services.

6. Security of Processing

6.1. RaiaWeb implements the appropriate technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks for data subjects (Article 32 GDPR).

6.2. Annex II may be updated by RaiaWeb provided that this does not materially reduce the overall level of security.

6.3. For services where the Client administers the environment (in particular VPS), the security of the configuration, the operating system and the installed applications is the Client's responsibility, under the AUP.

7. Sub-Processors

7.1. The Client grants RaiaWeb general authorisation to engage the sub-processors identified in Annex III.

7.2. RaiaWeb shall inform the Client of any addition or replacement of sub-processors at least 30 days in advance (by email), and the Client may raise reasoned objections within that period. If no reasonable solution is possible, the Client may terminate the affected service, with a proportional refund of the prepaid period not enjoyed.

7.3. RaiaWeb imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA and remains liable to the Client for the performance of those obligations.

8. Assistance to the Client

8.1. Data subject rights: taking into account the nature of the processing, RaiaWeb provides the Client with reasonable assistance, through appropriate technical and organisational measures, to enable the Client to respond to requests for the exercise of rights. If a data subject contacts RaiaWeb directly regarding data hosted by the Client, RaiaWeb does not respond on the merits and forwards the request to the Client, where possible.

8.2. Impact assessments and prior consultations: RaiaWeb provides reasonable assistance to the Client in complying with Articles 32 to 36 GDPR, to the extent of the information available to it.

8.3. Reasonable assistance is included in the Services; manifestly disproportionate requests or requests requiring specific work may be quoted as an additional service.

9. Personal Data Breaches

9.1. RaiaWeb notifies the Client without undue delay - and in any case within a maximum of 72 hours - after becoming aware of a personal data breach affecting data processed on behalf of the Client.

9.2. The notification includes, to the extent of the information available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed; the information may be provided in phases.

9.3. It is for the Client, as controller, to assess and make the notifications to the supervisory authority and to data subjects (Articles 33 and 34 GDPR). RaiaWeb provides reasonable cooperation for that purpose.

10. Deletion and Return of Data

10.1. During the term of the contract, the Client may export its data at any time using the available tools (panel, FTP, backups).

10.2. Upon termination of the contract, the courtesy period of 15 days provided for in clause 23.3 of the Terms applies, during which the Client may export the data. After that period, RaiaWeb permanently deletes the personal data, except where retention is required by law.

10.3. Backups expire through the normal retention cycle (7 days), so deletion from all systems, including backups, is completed within a maximum of 30 days after termination. At the Client's request, RaiaWeb confirms the deletion in writing.

11. Demonstration of Compliance and Audits

11.1. RaiaWeb makes available to the Client the information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, in particular through this DPA, its Annexes and responses to reasonable security questionnaires.

11.2. The Client may carry out audits, including inspections, directly or through a mandated auditor (who must not be a competitor of RaiaWeb), under the following conditions: minimum 30 days' prior notice; a maximum of one per calendar year, except following a relevant data breach or at the requirement of a supervisory authority; during business hours and without disrupting operations; without access to other clients' data or third parties' confidential information; with the Client bearing the respective costs.

11.3. Wherever possible, audits are satisfied, in the first instance, by the documentation and information referred to in 11.1.

12. International Transfers

Processing under this DPA is carried out in datacenters located in the European Union (Portugal and France - Annex III). RaiaWeb does not transfer the data outside the European Economic Area; should this become necessary, it will do so only with adequate safeguards (adequacy decision or Standard Contractual Clauses) and upon prior information to the Client under clause 7.2.

13. Liability and Term

13.1. The parties' liability is governed by Article 82 GDPR and by clause 22 of the Terms.

13.2. This DPA remains in force for as long as RaiaWeb processes personal data on behalf of the Client and ends upon completion of the deletion obligations provided for in clause 10.


Annex I - Description of the Processing

Element Description
Subject matter Provision of web hosting, virtual private server, email and related services
Nature of the processing Storage, retention, transmission, backup, restore and deletion; technical execution of the applications installed by the Client
Purpose Provision of the hosting infrastructure; RaiaWeb does not use the data for its own purposes
Duration Term of the service contract, plus the periods in clause 10
Categories of data subjects Determined by the Client - typically: visitors, users and customers of the hosted sites/applications; subscribers; the Client's staff
Categories of data Determined by the Client - typically: identification and contact details, account data, submitted content, technical logs. Large-scale special categories are excluded (clause 3.3)

Annex II - Technical and Organisational Measures

  • Encryption in transit (TLS) on exposed services; SSL certificates available for all hosted domains;
  • Isolation between hosting accounts at platform level;
  • Daily backups with 7-day retention;
  • Access control under the least-privilege principle; two-factor authentication available in the Client Area;
  • Regular security updates and patches to the hosting platform, managed jointly with the infrastructure providers;
  • Logging of relevant access and security events;
  • Datacenters located in the European Union, with physical access control managed by the infrastructure providers (Annex III);
  • Internal incident response and notification procedure (clause 9).

Annex III - Authorised Sub-Processors

Entity Country Service
Innov4web Portugal Shared hosting infrastructure (cPanel) and datacenter
OVH SAS France (EU) Virtual private server (VPS) infrastructure

Changes to this list are communicated under clause 7.2.

  • Terms of Services
  • Privacy Policy

Data Processing Agreement (DPA) - RaiaWeb

Version 1.2 - Last updated: 18 July 2026

Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy, the Portuguese version prevails.

This Data Processing Agreement ("DPA") is entered into under Article 28 GDPR, Regulation (EU) 2016/679 ("GDPR"), between:

  • Processor: Alex Nabais Gomes, a sole trader operating under the trade name "RaiaWeb", NIF 268386625, Rua da Fonte Mestre, N.º 22, 6320-637 Soito, Portugal ("RaiaWeb"); and
  • Controller: the Customer, as identified in the account and in the General Terms and Conditions of Service ("Terms").

1. Scope and Automatic Application

1.1. This DPA forms an integral part of the Terms (clause 20.2) and applies automatically, without the need for a separate signature, whenever the provision of the Services involves the processing of personal data by RaiaWeb on behalf of the Customer - namely the hosting of websites, applications, databases, email or other content that includes personal data of third parties, as well as the Maintenance Services and the SEO Services (Annex C to the Terms), to the extent that they involve access to personal data processed on behalf of the Customer.

1.2. The processing of the Customer's own personal data carried out by RaiaWeb as controller (account, billing, support), which is governed by the Privacy Policy, is not covered by this DPA.

1.3. If the Customer itself acts as processor for a third-party controller, the Customer warrants that the instructions it transmits to RaiaWeb reflect the instructions of that controller, with RaiaWeb acting as sub-processor. For the purposes of this DPA, references to the "Customer" include that capacity.

1.4. On data protection matters in the controller-processor relationship, this DPA prevails over the Terms.

1.5. Exclusion - self-hosted software (TapNTable): this DPA does not apply to the licensing of the TapNTable software installed on the Customer's own systems: the data processed through that software remains on the Customer's systems, and the Customer is solely responsible for such processing, with RaiaWeb having no access whatsoever. The data processed by RaiaWeb in connection with licence verification and updates is processed by RaiaWeb as controller, under the Privacy Policy. Where, in the context of technical support, RaiaWeb accesses the Customer's systems on an occasional basis and at the Customer's request, such access is carried out on behalf of the Customer, and the confidentiality and security obligations of this DPA apply, with the necessary adaptations, during the support session. If the Customer chooses to host TapNTable on a RaiaWeb hosting service, the processing of the hosted data is governed by this DPA under the general terms applicable to hosting (clause 1.1) - it is the hosting service, not the software licensing, that determines the application of the DPA.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning assigned to them in Article 4 GDPR. The remaining capitalised terms have the meaning defined in the Terms.

3. Subject Matter, Nature and Duration of the Processing

3.1. The subject matter, nature, purpose and duration of the processing, as well as the categories of data subjects and personal data, are set out in Annex I.

3.2. The Customer, as controller, determines the purposes and means of the processing and warrants that it has a lawful basis for the data it hosts, and is responsible for compliance with the information duties and for the exercise of data subjects' rights.

3.3. Special categories of data: the shared hosting Services are not intended for the large-scale processing of special categories of data (Article 9 GDPR) or of data relating to criminal convictions. The Customer must not host such data without RaiaWeb's prior written agreement as to the appropriate measures.

4. Customer Instructions

4.1. RaiaWeb processes personal data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by law - in which case it informs the Customer before processing, unless the law prohibits this on important grounds of public interest.

4.2. Documented instructions comprise: the Terms, this DPA, the configurations and actions carried out by the Customer within the Services (control panel, Customer Area, APIs) and any additional written instructions that are reasonable and compatible with the nature of the Services.

4.3. RaiaWeb immediately informs the Customer if, in its view, an instruction infringes the GDPR or another data protection provision, and may suspend performance of that instruction pending clarification.

5. Confidentiality

RaiaWeb ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they only access the data to the extent necessary for the provision of the Services.

6. Security of Processing

6.1. RaiaWeb implements the appropriate technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to data subjects (Article 32 GDPR).

6.2. Annex II may be updated by RaiaWeb provided that this does not materially reduce the overall level of security.

6.3. In services where the Customer administers the environment (namely VPS), the security of the configuration, the operating system and the installed applications is the Customer's responsibility, under the AUP - except where the Customer has contracted Maintenance Services, in which case the security of the components covered by the plan is ensured by RaiaWeb, to the exact extent set out in Annex C.1 to the Terms.

7. Sub-processors

7.1. The Customer grants RaiaWeb general authorisation to engage the sub-processors identified in Annex III.

7.2. RaiaWeb informs the Customer of any addition or replacement of sub-processors at least 30 days in advance (by email), and the Customer may raise reasoned objections within that period. Where no reasonable solution is possible, the Customer may terminate the affected service, with a pro-rata refund of the unused pre-paid period.

7.3. RaiaWeb imposes on each sub-processor, by contract, data protection obligations equivalent to those set out in this DPA and remains liable to the Customer for the fulfilment of those obligations.

8. Assistance to the Customer

8.1. Data subject rights: taking into account the nature of the processing, RaiaWeb provides the Customer with reasonable assistance, by means of appropriate technical and organisational measures, to enable it to comply with requests to exercise data subject rights. If a data subject contacts RaiaWeb directly in relation to data hosted by the Customer, RaiaWeb does not respond on the merits and forwards the request to the Customer, where possible.

8.2. Data protection impact assessments and prior consultations: RaiaWeb provides the Customer with reasonable assistance in complying with Articles 32 to 36 GDPR, to the extent of the information available to it.

8.3. Reasonable assistance is included in the Services; requests that are manifestly disproportionate or that require specific work may be quoted as an additional service.

9. Personal Data Breaches

9.1. RaiaWeb notifies the Customer without undue delay - and, in any event, within a maximum of 72 hours - after becoming aware of a personal data breach affecting the data processed on behalf of the Customer.

9.2. The notification includes, to the extent of the information available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed, and such information may be provided in phases.

9.3. It is for the Customer, as controller, to assess and carry out the notifications to the supervisory authority and to data subjects (Articles 33 and 34 GDPR). RaiaWeb provides reasonable cooperation to that end.

10. Deletion and Return of Data

10.1. During the term of the contract, the Customer may export its data at any time using the available tools (control panel, FTP, backups). Export and assistance with switching providers are governed by Annex B to the Terms and are provided free of charge.

10.2. Upon termination of the contract, the 30-day recovery period provided for in clause 23.3 of the Terms and in Annex B (Article 25 of Regulation (EU) 2023/2854) applies, during which the Customer may export the data. Upon expiry of that period, RaiaWeb permanently deletes the personal data, save where retention is required by law.

10.3. Backup copies expire under the normal retention cycle (7 days), meaning that deletion from all systems, including backups, is completed within a maximum of 45 days after termination. At the Customer's request, RaiaWeb confirms the deletion in writing.

11. Demonstrating Compliance and Audits

11.1. RaiaWeb makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, in particular through this DPA, its Annexes and responses to reasonable security questionnaires.

11.2. The Customer may carry out audits, including inspections, either directly or through a mandated auditor (who must not be a competitor of RaiaWeb), subject to the following conditions: a minimum of 30 days' prior notice; a maximum of one per calendar year, except following a relevant data breach or at the request of a supervisory authority; during business hours and without disrupting operations; with no access to other customers' data or third parties' confidential information; with the Customer bearing the associated costs.

11.3. Wherever possible, audits are addressed, in the first instance, through the documentation and information referred to in clause 11.1.

12. International Transfers

12.1. Processing relating to shared hosting and email is carried out in datacentres located in Portugal (Annex III). RaiaWeb does not transfer that data outside the European Economic Area.

12.2. For virtual private servers (VPS), the datacentre region is chosen by the Customer during the order process, from the available regions, which include regions within the European Union and regions in third countries. The list of regions and their respective jurisdictions is set out on the Switching Providers and Transparency page published on the Website and forms an integral part of this DPA.

12.3. The Customer's choice of a region located outside the European Union constitutes a documented instruction for the purposes of clause 4.1, and it is the Customer's responsibility, as controller, to assess the lawfulness of that transfer under Chapter V GDPR. RaiaWeb does not change the chosen region without the Customer's instruction.

12.4. Transfers to countries for which no European Commission adequacy decision exists are carried out under Standard Contractual Clauses entered into with the infrastructure provider. On request, RaiaWeb provides information or a copy of the applicable safeguards.

12.5. A Customer wishing processing to take place exclusively within the European Union must select an EU region at the time of ordering.

13. Liability and Term

13.1. The liability of the parties is governed by Article 82 GDPR and by clause 22 of the Terms.

13.2. This DPA remains in force for as long as RaiaWeb processes personal data on behalf of the Customer and ends upon completion of the deletion obligations set out in clause 10.


Annex I - Description of the Processing

Element Description
Subject matter Provision of web hosting services, virtual servers, email, website and application maintenance services, SEO services and associated services
Nature of the processing Storage, retention, transmission, backup, restoration and deletion; technical operation of the applications installed by the Customer; administrative access for maintenance and updates, retention of access credentials in a RaiaWeb management panel, automated availability monitoring, and the making and retention of backups on RaiaWeb infrastructure, including of websites and applications hosted with third-party providers (Maintenance Services); management access to the Customer's accounts and properties on third-party platforms (SEO Services)
Purpose Provision of the contracted services (hosting, website and application maintenance, SEO); RaiaWeb does not use the data for its own purposes
Duration Term of the service provision contract, plus the periods set out in clause 10
Categories of data subjects Determined by the Customer - typically: visitors, users and customers of the hosted websites/applications; subscribers; the Customer's staff
Categories of data Determined by the Customer - typically: identification and contact details, account data, submitted content, technical logs. Special categories of data on a large scale are excluded (clause 3.3)

Annex II - Technical and Organisational Measures

  • Encryption in transit (TLS) for exposed services; SSL certificates available for all hosted domains;
  • Isolation between hosting accounts at platform level;
  • Daily backups with 7-day retention;
  • Access control based on the principle of least privilege; two-factor authentication available in the Customer Area;
  • Regular updates and security patches to the hosting platform, managed jointly with infrastructure providers;
  • Logging of relevant access and security events;
  • Internal management and monitoring panels accessible only through mutual certificate authentication (mTLS), issued by an internal certificate authority and limited to authorised devices, with no password-based access;
  • Isolation of internal panels at operating system level: dedicated system user, execution environment, database and directory, with restricted filesystem access;
  • Credentials for access to Customer systems kept solely in the aforementioned management panel, never in documents, email messages or support records;
  • Backups made under the Maintenance Services encrypted at rest, kept on infrastructure in the European Union, with a retention period of 7 days;
  • Datacentres with physical access control managed by the infrastructure providers (Annex III), located in Portugal for shared hosting and email and, for VPS, in the region chosen by the Customer under clause 12;
  • Internal incident response and notification procedure (clause 9).

Annex III - Authorised Sub-processors

Entity Country Service
Innov4web Portugal Shared hosting infrastructure (cPanel) and datacentre
OVH SAS and companies within the same group Region chosen by the Customer (cl. 12): France, Germany, Poland or Italy (EU); Canada, United Kingdom, Singapore, Australia or India (third countries) Virtual server infrastructure (VPS)

Changes to this list are communicated in accordance with clause 7.2.

Alex Gomes Individual - RaiaWeb

RaiaWeb - Alex Nabais Gomes, Sole Trader · Tax ID (NIF): 268386625 · Address: Rua da Fonte Mestre n.º 22, 6320-637 Soito, Portugal · Contact: (+351) 271 607 066 · support@raiaweb.pt · VAT exempt under Article 53 of the Portuguese VAT Code (CIVA) · In the event of a dispute, consumers may refer the matter to the Centro de Arbitragem de Conflitos de Consumo. Find out more at consumidor.gov.pt.

Payments

Products

  • Web Hosting
  • VPS Hosting
  • Web Development
  • SEO
  • GDPR Compliance
  • Maintenance & Updates
  • Domain Registration
  • Domain Transfer
  • SSL Certificates

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Domain and SSL Certificate Terms
  • Service Level Agreement
  • Report Illegal Content
  • Vulnerability Disclosure
  • Provider Switching and Transparency
  • Complaints Book

Company

  • About Us
  • Contact Us
Copyright © 2026 Alex Gomes Individual - RaiaWeb. All Rights Reserved.
  • EnglishEnglish
    english English
    portuguese Português
    No Records Found
This site uses only essential cookies required for its operation. We do not use any tracking, advertising, or third-party analytics cookies. The only data stored are your language and visual theme preferences, to provide a more comfortable browsing experience.

Generate Password
Please enter a number between 8 and 64 for the password length

Remove Sensitive Data

Are you sure you want to permanently delete this sensitive data? This action cannot be undone, and the information will no longer be accessible.