Data Processing Addendum

Terms under which Megahost LLC processes personal data on behalf of customers (GDPR Article 28 and similar laws).

Last updated October 3, 2026 · Megahost LLC

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Megahost LLC ("Processor") and the Customer ("Controller") and applies where we process personal data on the Customer’s behalf in providing the Service.

2. Details of processing

  • Subject matter and duration: provision of the Service for the term of the subscription and the post-termination period described in the Terms.
  • Nature and purpose: storage, analysis, enrichment, email delivery, engagement tracking and reporting, as instructed by the Customer through the Service.
  • Data subjects: the Customer’s business prospects and contacts, and the Customer’s users.
  • Categories of data: names, job roles, business email addresses and phone numbers, company details, public website content, email engagement events, and notes entered by the Customer. The Service is not intended for special categories of data.

3. Processor obligations

  • Process personal data only on the Customer’s documented instructions, including those given through the Service.
  • Ensure that personnel with access are bound by confidentiality.
  • Implement appropriate technical and organisational measures, including encryption in transit, encryption of stored credentials, logical isolation of each customer’s data, access control, backups and monitoring.
  • Assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification and impact-assessment obligations.
  • Notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal-data breach affecting Customer data.
  • At the end of the service, delete or return Customer personal data as described in the Terms, unless the law requires storage.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

The Customer authorises the sub-processors listed in our Privacy Policy (hosting, DNS, payments, AI processing and email delivery). We will give notice of new sub-processors, and the Customer may object on reasonable grounds. We remain responsible for our sub-processors’ performance.

5. International transfers

Where personal data is transferred outside the European Economic Area, the UK or Switzerland to a country without an adequacy decision, the parties rely on the European Commission’s Standard Contractual Clauses (Module 2 or 3, as applicable), which are incorporated by reference.

6. Controller obligations

The Customer is responsible for the lawfulness of the processing it instructs, including having a valid legal basis for contacting its prospects and providing any required information to data subjects.

7. Contact

Questions about this DPA: privacy@webmodernize.com.

Megahost LLC

36 South 18th Avenue, Suite D, Brighton, CO 80601, United States

legal@webmodernize.com