Data processing agreement
Last updated 10 October 2026.
Need a signed copy? This agreement applies to every customer without signing. If your records need a copy with your company's details, signed by us, make one under Data processing in your account's settings.
This data processing agreement ("DPA") forms part of the WordPlus Cloud terms of service (the "Terms") between the customer and WordPlus. It applies whenever WordPlus processes personal data on the customer's behalf through WordPlus Cloud, and takes effect when the customer accepts the Terms, with no signature needed.
Parties
- The customer (controller): the person or organisation that accepted the Terms, as its WordPlus Cloud account names it.
- WordPlus (processor): Tkachenko Andrii Ivanovych (ФОП Ткаченко Андрій Іванович), an individual entrepreneur (FOP) registered in Ukraine, taxpayer number 3421406339, with the registered address stated in a signed copy. Notices: support@wordplus.cloud.
1. Definitions
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings the GDPR (Regulation (EU) 2016/679) gives them. "Data protection law" means the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and any other data protection law that applies to the processing. "Customer personal data" means the personal data WordPlus processes on the customer's behalf under this DPA.
2. Scope and roles
The customer is the controller of customer personal data, or a processor acting for its own client, in which case WordPlus is its sub-processor. WordPlus processes customer personal data only to provide the services the customer uses under the Terms, as Annex 1 describes. This DPA does not cover the data WordPlus processes as a controller, such as the customer's account, purchases and support requests, which the privacy policy describes. Nor does it cover a Self-Hosted server, which WordPlus does not operate, except while the customer gives WordPlus access to it for installation or support.
3. Instructions
The Terms, this DPA and the customer's settings and use of the services are the customer's documented instructions. WordPlus processes customer personal data only on them, including for transfers to third countries, unless the law requires otherwise, in which case WordPlus tells the customer first unless the law forbids it. WordPlus tells the customer if, in its opinion, an instruction breaks data protection law.
4. Confidentiality
WordPlus makes sure that everyone it authorises to process customer personal data is bound by confidentiality.
5. Security
WordPlus applies the technical and organisational measures in Annex 2, which are appropriate to the risk. It may improve them, but never lowers the overall level of protection.
6. Sub-processors
- The customer gives WordPlus general written authorisation to engage sub-processors. The current ones are listed in Annex 3.
- WordPlus tells the customer at least 30 days before it adds or replaces a sub-processor, by email to the account's address and by updating Annex 3. The customer may object on reasonable data protection grounds within that time. If the parties cannot resolve the objection, the customer may end the affected services, and WordPlus refunds the unused part of the period paid for.
- WordPlus binds each sub-processor by contract to data protection obligations that are no less protective than this DPA, and remains liable to the customer for its sub-processors' performance.
7. Data subjects' requests
Taking into account the nature of the processing, WordPlus helps the customer answer requests from data subjects to exercise their rights. WordPlus passes on any request it receives that concerns customer personal data, and does not answer it itself unless the customer asks it to.
8. Assistance
WordPlus helps the customer meet its obligations on security, personal data breaches, data protection impact assessments and prior consultation (Articles 32 to 36 of the GDPR), taking into account the nature of the processing and the information available to it.
9. Personal data breaches
WordPlus notifies the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting customer personal data. The notice describes the breach, the data and data subjects concerned, its likely consequences and the measures taken or proposed, as far as that information is available, and WordPlus adds to it as it learns more.
10. Deletion and return
Customer personal data is kept only as long as Annex 1 says. When the services end, WordPlus deletes customer personal data from its servers, or returns it first if the customer asks within 30 days, and deletes existing copies unless the law requires it to keep them. Copies in backups are deleted as the backups expire. Most customer personal data already lives in the customer's own WordPress database, which the services never delete.
11. Information and audits
WordPlus makes available the information needed to demonstrate compliance with Article 28 of the GDPR, and allows for and contributes to audits, including inspections, by the customer or an auditor it mandates. An audit is asked for in writing at least 30 days ahead, at most once a year unless a supervisory authority requires it or a breach has happened, at the customer's cost, and under confidentiality that protects other customers and WordPlus's security.
12. International transfers
- WordPlus's main servers, which hold customer personal data, are in the European Union (Frankfurt, Germany, with backups in Strasbourg, France). Group calls and live streams run on media servers nearer their participants, in the OVHcloud locations Annex 3 lists, which relay audio and video in transit and hold no data. A location outside the European Economic Area is covered as point 4 describes.
- WordPlus is established in Ukraine, which has no adequacy decision, and runs the services from there. To the extent the customer transfers personal data from the European Economic Area to WordPlus, the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 (the "SCCs") apply and are incorporated in this DPA by reference: Module Two (controller to processor), or Module Three (processor to processor) where the customer is a processor. The customer is the data exporter and WordPlus the data importer. Clause 7 applies. In Clause 9, Option 2 applies, with the notice period of section 6. The option in Clause 11 does not apply. In Clause 13, the supervisory authority is that of the Member State where the data exporter is established, or otherwise where its representative is. In Clause 17, Option 2 applies, and where that law does not allow for third-party beneficiary rights, the law of Ireland. In Clause 18, the courts are those of the same Member State. Annexes 1, 2 and 3 of this DPA complete the SCCs' Annexes I.B, II and III, and the parties above complete Annex I.A.
- For transfers from the United Kingdom, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies, with the SCCs as completed above, and either party may end it as its Section 19 allows. For transfers from Switzerland, the SCCs apply with the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, Swiss law as an alternative place of jurisdiction for data subjects there, and references to the GDPR read as references to the Swiss Act.
- Sub-processors outside the European Economic Area receive customer personal data under the SCCs, or under the EU-U.S. Data Privacy Framework where they are certified under it.
13. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where data protection law does not allow them. Where this DPA and the Terms differ on the processing of personal data, this DPA prevails. Where the SCCs and this DPA differ, the SCCs prevail.
14. Duration
This DPA applies for as long as WordPlus processes customer personal data, and section 10 survives it.
Annex 1: Details of the processing
| Data subjects | The users of the customer's sites and apps, registered members and guests, and the participants of their calls and live streams. |
|---|---|
| Nature and purpose | Hosting, routing and transmitting data to provide the services the customer uses: realtime delivery, push notifications, voice and video calls, live streaming, Cloud AI and the Pusher-compatible and developer APIs. |
| Frequency | Continuous, while the customer's sites use the services. |
| Special categories | Not intended. Content the customer's users write is not stored by the services, but may pass through them in transit or reach Cloud AI, where it may contain special categories if users write them. |
Personal data, by service, and how long it is kept
- Realtime delivery: users are known only by the numeric IDs the customer's site gives them. Their names, avatars and other profile details reach WordPlus's servers already encrypted by the site, which holds the key, so the servers cannot read them, and are cached for up to 24 hours. By those IDs the servers keep conversation and message identifiers, delivery and read state, unread counts, and who is online and typing. Message content and attachments stay in the customer's WordPress database and are not stored on WordPlus's servers. A connection's IP address is used only to carry it, and appears only in the servers' rotating logs. Delivery records are kept while the site uses the services.
- Push notifications: device tokens and push subscriptions, by user ID, kept until they stop working. The site writes each notification, and its title and text pass through WordPlus's servers to the push services in Annex 3 without being stored.
- Calls and live streams: participants' identifiers and names, call signalling and connection details, and the audio and video, which are relayed in transit and never recorded. A call's record, who called whom, when and how it connected, is kept for 7 days.
- Cloud AI (when the customer switches it on): the text of messages to translate or moderate, and voice recordings to transcribe, with the result. Kept for up to 30 minutes, until delivered back to the site.
- Pusher-compatible and developer APIs: channel names, the events the customer's code publishes and their data, and presence information, relayed in transit and not stored.
A site's data on WordPlus's servers is deleted once the site has had no activity for a year and no active licence, or sooner when the customer asks. Backups of it expire within 8 days.
Annex 2: Technical and organisational measures
- Encryption in transit: every connection, from browsers, apps and sites alike, uses TLS. Call media is encrypted with DTLS-SRTP.
- Minimisation: message content and attachments stay in the customer's WordPress database, and the services keep only what they need to deliver.
- Encryption at rest: cached display data and call signalling logs are encrypted.
- Backups: every hour, to object storage in another EU region (Strasbourg, France), written by a key that can only upload. They expire within 8 days.
- Separation: each site's data is kept under its own keys, and every request from a site or its users is signed with that site's own secrets.
- Access control: servers are reached only by SSH keys, over a private network, behind firewalls that open only the ports the services use. Only WordPlus's operator has administrative access.
- Availability: several servers that take over from each other, with monitoring and alerts.
- Data centres: run by OVHcloud, certified under ISO/IEC 27001.
- Deletion: idle sites' data is deleted automatically, as Annex 1 says.
Annex 3: Sub-processors
| Sub-processor | What it does | Where |
|---|---|---|
| OVHcloud (OVH SAS and its affiliates) | Hosts WordPlus's servers |
Main servers, which hold the data: the European Union, today Germany (Frankfurt), with backups in France (Strasbourg). Media servers for group calls and live streams, which relay audio and video and hold no data: any OVHcloud region or Local Zone, in Austria, Belgium, Bulgaria, the Czech Republic, Denmark, Finland, France, Germany, Ireland, Italy, Luxembourg, the Netherlands, Norway, Poland, Portugal, Romania, Spain, Sweden, Switzerland, the United Kingdom, Canada, the United States, Singapore, India, Australia and New Zealand, and any region OVHcloud adds later. |
| Google LLC | Firebase Cloud Messaging, which delivers pushes to the customer's Android apps | United States |
| Apple Inc. | Apple Push Notification service, which delivers pushes to the customer's iOS apps | United States |