DATA PROCESSING AGREEMENT (DPA)
Your rights and our obligations regarding the processing of personal data.
This document is an English translation of the French original.
It is provided so that our English-speaking customers can read our terms in their own language.
Only the French version has legal value. If a sentence here differs from the French text, the French text applies. The French original is available at winheberg.com/autres/legal/dpa.
Data Processing Agreement (DPA)
Version 3.0 — In force from 20/07/2026
This Data Processing Agreement (hereinafter "the DPA") is concluded under Article 28 of Regulation (EU) 2016/679 (hereinafter "GDPR") and Article 5.5 of Winheberg's General Terms of Sale and Use (hereinafter "the GTSU"). It forms an integral part of the contract concluded between Winheberg and the Client and prevails, on the personal data protection matters it expressly addresses, over the GTSU.
This DPA governs exclusively the processing carried out by Winheberg on behalf of the Client, that is, the data the Client chooses to host or process through the Services. Processing carried out by Winheberg on its own behalf (client account management, billing, payments, identity verification, support, customer reviews, audience measurement) is performed in the capacity of data controller and is governed by Winheberg's Privacy Policy, available on winheberg.com.
Article 1 — Definitions
For the purposes of this DPA, the following terms have the meanings set out below, unless defined otherwise in the GTSU:
"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
"Personal data" has the meaning defined in Article 4(1) GDPR: any information relating to an identified or identifiable natural person.
"Processing" has the meaning defined in Article 4(2) GDPR.
"Client Data" means the Personal data that the Client hosts, stores, transmits or processes through the Services, and for which the Client determines the purposes and means of processing.
"Controller" means the Client, as regards Client Data.
"Processor" means Winheberg, which processes Client Data on behalf of the Client and in accordance with its documented instructions.
"Sub-processor" means any third-party provider engaged by Winheberg to perform all or part of the Services involving the processing of Client Data.
"Data breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal data.
Article 2 — Subject matter and duration
This DPA governs the processing of Client Data carried out by Winheberg, as Processor, on behalf of the Client, as Controller, in the context of providing the Services defined in the GTSU.
The DPA takes effect on the date the contract is concluded between the parties and applies throughout the contractual relationship involving the processing of Client Data. It ends on the expiry or termination of the contract, subject to the end-of-processing obligations set out in Article 9 and to applicable statutory retention obligations.
Article 3 — Description of the processing
3.1 Nature of the processing
Depending on the Services taken out, Winheberg may carry out the following processing operations on behalf of the Client: storage, hosting, transmission, backup, return and deletion of Client Data hosted on Winheberg's servers.
3.2 Purposes of the processing
The processing is carried out solely for the purpose of providing the contractual Services ordered by the Client. Winheberg does not process Client Data for its own purposes. Security operations (antivirus scanning, malicious file detection, network traffic analysis) carried out on the infrastructure hosting Client Data are performed for the sole purposes of the security and integrity of the Services, in accordance with the GTSU and the applicable Specific Terms.
3.3 Categories of data processed
Depending on the nature of the service taken out and the data the Client chooses to host, the following categories of data may be involved, without this list being exhaustive:
- identification and contact data (names, email addresses, telephone numbers);
- technical data (IP addresses, connection logs, application metadata);
- content data hosted by the Client (files, databases, application configurations);
- any other category of data the Client chooses to store or process through the Services, subject to Article 3.5.
3.4 Categories of data subjects
The persons affected by the processing may include, depending on the Services: the Client's end users, its customers, its staff, its prospects or any other person whose data is hosted through the Services.
3.5 Formal prohibition on hosting sensitive data
3.5.1 Prohibited categories of data
Winheberg is not HDS-certified (French certification for hosting health data) and does not permit the hosting of the following categories of personal data:
- Health data (Art. L. 1111-2 of the French Public Health Code): medical records, patient files, test results, treatment histories, prescriptions;
- Biometric data processed for the purpose of uniquely identifying a person (Art. 9(1) GDPR): facial recognition, fingerprints, iris recognition;
- Genetic data (Art. 4(13) GDPR): DNA profiles, genetic markers;
- Data relating to criminal convictions and offences (Art. 10 GDPR): criminal records, convictions, offences;
- Data revealing racial or ethnic origin (Art. 9(1) GDPR);
- Data revealing political opinions (Art. 9(1) GDPR);
- Data revealing religious or philosophical beliefs (Art. 9(1) GDPR);
- Data revealing trade union membership (Art. 9(1) GDPR);
- Data concerning sex life or sexual orientation (Art. 9(1) GDPR).
This prohibition targets processing whose object or purpose is the collection or exploitation of such data (structured files, databases, collection forms). It does not target incidental, unstructured mentions that may appear in content generated by the Client's end users (chat messages, forum content), for which the Client nonetheless remains solely responsible in its capacity as controller.
3.5.2 Client warranty
The Client expressly warrants to Winheberg that:
- the hosted data does not fall within the categories listed above;
- it has checked the nature of the hosted data before any transmission to Winheberg;
- it will inform Winheberg as promptly as possible, and no later than within 24 hours, should such data be detected subsequently;
- it assumes full responsibility for the compliance of the data with this prohibition.
3.5.3 Consequences of a breach — Winheberg's rights
Where this clause is proven to have been breached, Winheberg has the following rights, without prejudice to any other remedy:
Immediate suspension: Winheberg may immediately suspend or interrupt access to the services without prior notice where prohibited data is detected, the Client being informed as promptly as possible after the measure is taken;
Termination: the contract may be terminated as of right, without indemnity, 48 hours after written notification of the breach to the Client, unless full and demonstrated remediation occurs within that period;
Deletion of prohibited data: data falling within the prohibited categories is permanently deleted, including from backups, with no possibility of recovery;
Export window for other data: unless all hosted data is inseparable from the prohibited data, or unless a legal obligation or an order from an authority prevents it, the Client benefits from the return period provided for in Article 9 to export data not affected by the breach;
Disclosure to the authorities: Winheberg reserves the right to notify the competent authorities (CNIL, law enforcement) in the event of a serious breach threatening the security or the rights of others;
Billing for the services: the Client remains liable for payment of the services until the effective date of termination.
3.5.4 Liability
Winheberg cannot be held liable for damage resulting from the good-faith application of this clause, in particular the suspension of the services, the deletion of prohibited data, or administrative, civil or criminal penalties imposed on the Client for breaching this restriction. This exclusion applies without prejudice to mandatory statutory provisions, in particular those protecting consumers.
3.5.5 Referral to HDS-certified hosting providers
For health data or sensitive data hosting needs, Winheberg recommends that the Client turn to HDS-certified providers meeting the requirements of the French Public Health Code:
https://esante.gouv.fr/offres-services/hds/liste-des-hebergeurs-certifies
3.5.6 Universal applicability
This restriction applies irrespective of:
- whether or not a Data Processing Agreement has been concluded;
- the type or nature of the service taken out;
- the billing arrangements;
- any subsequent agreement between the parties, save for an express written waiver from Winheberg.
Article 4 — Winheberg's obligations as processor
In accordance with Article 28(3) GDPR, Winheberg undertakes to:
Act on documented instructions: process Client Data only on the Client's documented instructions, including with regard to transfers of data to third countries or international organisations, unless required to do so by Union or French law; in the latter case, Winheberg informs the Client of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Client's subscription to the Services and their configuration by the Client through the client area and the management panels constitute the Client's initial documented instructions. If Winheberg considers that an instruction infringes the GDPR or any other applicable data protection provision, it informs the Client as promptly as possible;
Ensure confidentiality: ensure that persons authorised to process Client Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
Implement security measures: apply the technical and organisational measures referred to in Article 8 of this DPA, in accordance with Article 32 GDPR;
Manage sub-processors: comply with the conditions referred to in Article 5 of this DPA for any engagement of a Sub-processor;
Assist the Client in handling rights requests: assist the Client, by appropriate technical and organisational measures and insofar as possible, in fulfilling its obligation to respond to requests from data subjects exercising their rights (Article 6 of this DPA);
Assist the Client with its compliance obligations: assist the Client in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, notification of breaches to the supervisory authority and to data subjects, impact assessments, prior consultations), taking into account the nature of the processing and the information available to Winheberg;
Notify breaches: inform the Client of any Data breach under the conditions of Article 7 of this DPA;
Return and delete data: implement the end-of-processing obligations set out in Article 9 of this DPA;
Demonstrate its compliance: make available to the Client all information necessary to demonstrate compliance with the obligations set out in this Article and allow for audits to be conducted, under the conditions of Article 10.
Article 5 — Sub-processors
5.1 General authorisation
The Client generally authorises Winheberg to engage the Sub-processors listed in Article 5.2 for the performance of the Services. Winheberg concludes with each Sub-processor a contract imposing data protection obligations at least equivalent to those of this DPA, in accordance with Article 28(4) GDPR. Winheberg remains fully liable to the Client for the performance by its Sub-processors of their obligations.
5.2 List of sub-processors
This list includes only providers liable to process Client Data or to access the infrastructure hosting it. Providers involved exclusively in processing for which Winheberg is the controller (payments, identity verification, support, customer reviews, audience measurement, domain name registration) are not Sub-processors within the meaning of this DPA; they are listed in Winheberg's Privacy Policy.
Winheberg is the exclusive owner of its servers and storage hardware.
5.2.1 Hardware infrastructure and physical hosting
The infrastructure providers below are involved only in physical hosting (colocation), power supply, cooling and network connectivity. They have no logical access to Winheberg's systems (operating systems, applications, databases, content and Client Data), except under a duly notified mandatory legal requirement.
| Provider | Role | Location | Security policy / Access |
|---|---|---|---|
| FEELB SARL | Provision of colocation hosting space, IP transit and DDoS protection (network mitigation operating on traffic flows, without access to stored content). Physically hosted within nLighten facilities (FEELB's sub-processor). | France (Lyon area) | Physical rack access managed by FEELB. No logical access to servers, systems, applications or content; hardware owned by Winheberg. |
5.2.2 Software services acting on Client Data
| Sub-processor | Role and scope | Location and transfer safeguards | Privacy policy |
|---|---|---|---|
| Cloudflare Inc. | Reverse proxy, network protection and CDN for access traffic to the management interfaces (game server management panel) and to the sites operated by Winheberg. Processing of traffic data in transit only; no storage of hosted content. | United States — certified under the EU-US Data Privacy Framework (DPF) | cloudflare.com/privacypolicy |
| CloudLinux Inc. (Imunify360) | Antivirus scanning and detection of malicious files among the files hosted through the web hosting services (Plesk). | United States — standard contractual clauses (Decision 2021/914) | imunify360.com/legal/privacy-policy |
5.3 Changes to the list
Winheberg informs the Client of any intended addition or replacement of a Sub-processor by updating the list above and notifying the Client through the client area or by email, with a minimum notice period of 30 days before it takes effect.
The Client may raise reasoned objections in writing within that period. In the absence of an objection within the 30-day period, the engagement of the new Sub-processor is deemed accepted. Where a reasoned and legitimate objection is raised for which Winheberg cannot provide a reasonable solution (retaining the current provider, an equivalent alternative measure), the Client may terminate the Service or Services concerned without penalty, with a pro rata temporis refund of the sums paid for the unused period.
Article 6 — Assistance with data subject rights requests
Where a data subject sends a request to exercise their rights (access, rectification, erasure, restriction, portability, objection) directly to Winheberg in relation to Client Data, Winheberg informs the Client as promptly as possible and forwards the request so that the Client can respond to it.
Winheberg does not respond directly to data subject requests concerning Client Data, unless instructed otherwise by the Client or required to do so by a mandatory legal obligation.
The data access, export, modification and deletion features made available to the Client through the Services (SSH/SFTP access, management panels, backup and restore tools) constitute the technical assistance measures enabling the Client to respond itself to data subject requests.
Article 7 — Notification of data breaches
Where a Data breach affecting Client Data is detected, Winheberg notifies the Client as promptly as possible after becoming aware of the incident, in accordance with Article 33(2) GDPR, and no later than within 72 hours.
The notification includes, to the extent the information is available at the time it is sent:
- the nature of the breach and, where possible, the categories and approximate number of data subjects concerned, together with the categories and approximate volume of data records concerned;
- the contact details of the point of contact from which further information can be obtained;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and, where appropriate, to mitigate its adverse effects.
If all the information is not available within that period, Winheberg sends an initial notification and communicates the additional information in successive stages, without undue delay.
It is for the Client, in its capacity as Controller, to assess whether the breach must be notified to the competent supervisory authority (CNIL) in accordance with Article 33(1) GDPR and/or to the data subjects in accordance with Article 34 GDPR. Winheberg provides the Client, on request, with the technical information in its possession necessary for those notifications.
Article 8 — Security measures
In accordance with Article 32 GDPR, Winheberg implements the following technical and organisational measures, proportionate to the risks presented by the processing:
Technical measures:
- control of logical access to processing systems (authentication, permission management);
- encryption of data in transit (TLS);
- logging and monitoring of access to the infrastructure;
- backups under the arrangements set out in the applicable Specific Terms;
- network protection systems (firewall, filtering, DDoS protection through the Infrastructure providers);
- network segmentation between client environments.
Organisational measures:
- confidentiality imposed on persons with access to the data;
- incident management and breach notification procedures;
- assessment of Sub-processors against their data protection obligations.
These measures may evolve to reflect the state of the art and the risks identified, without their overall level of protection being reduced. Winheberg does not guarantee absolute security; its liability is assessed under the conditions of Article 13 of this DPA and Article 12 of the GTSU.
Article 9 — Return and deletion of data at the end of processing
On the expiry or termination of the contract, Winheberg retains the hosted Client Data for a period of 7 calendar days following the effective date of termination, in order to allow its return or export at the Client's request.
During that period, the Client may request the return or transfer of its data through the client area, according to the portability arrangements set out in the applicable Specific Terms. On the expiry of that period, in the absence of instructions to the contrary from the Client, the data is permanently deleted, including from backups, through Winheberg's automated deprovisioning systems, save for any statutory retention obligation.
Billing data and Client account information, for which Winheberg is the controller, are retained in accordance with applicable legal obligations (in particular accounting and tax obligations), irrespective of the termination of the service contract.
Article 10 — Audits and evidence of compliance
10.1 Documentary evidence
On the Client's reasonable written request, Winheberg makes available to it all information necessary to demonstrate compliance with its obligations under this DPA and Article 28 GDPR, in particular in the form of certifications, descriptions of security measures, internal policies or responses to compliance questionnaires. This documentary route is the preferred means of demonstrating compliance.
10.2 Audits and inspections
The Client (or an independent third-party auditor mandated by it and not a competitor of Winheberg) may carry out an audit, including an on-site inspection, of Winheberg's compliance with its obligations under this DPA, under the following conditions:
- prior written notification with a minimum notice period of 30 working days, specifying the scope, duration and intended arrangements;
- prior signature of a confidentiality agreement by the Client and any mandated auditor;
- a limit of one audit per twelve-month period, except in the event of a proven Data breach affecting Client Data or a request from a supervisory authority, in which cases an additional audit may be conducted without waiting;
- carried out during working hours, without unreasonably disrupting Winheberg's operations or compromising the security or confidentiality of other clients' data;
- scope limited to the processing of Client Data, excluding other clients' data and information covered by trade secrecy that is not necessary for the audit.
The parties agree in good faith on the practical arrangements for the audit. The costs of the audit are borne by the Client, including Winheberg's reasonable assistance time, unless the audit reveals a proven failure by Winheberg to meet its obligations, in which case those costs are borne by Winheberg.
Article 11 — Client obligations as controller
The Client acknowledges and warrants that:
- it has a valid legal basis within the meaning of Article 6 GDPR (and, where applicable, Article 9) for each processing of Personal data carried out through the Services;
- it has informed the data subjects of Winheberg's existence as Processor, in accordance with Articles 13 and 14 GDPR;
- it does not host special categories of data within the meaning of Article 9 GDPR nor data falling under Article 10 GDPR, in accordance with Article 3.5 of this DPA, and informs Winheberg as promptly as possible should such data be detected;
- the instructions it gives to Winheberg comply with applicable data protection regulations;
- it maintains, where applicable, the record of processing activities provided for in Article 30(1) GDPR for the processing it operates through the Services.
Article 12 — Data transfers outside the European Union
Client Data is hosted in France (Lyon area), within the European Union. Winheberg does not transfer Client Data outside the European Union for storage purposes.
Where engaging a Sub-processor established outside the European Union is necessary (see Article 5.2), Winheberg ensures that appropriate safeguards within the meaning of Chapter V GDPR are in place: an adequacy decision (in particular the EU-US Data Privacy Framework for certified entities), standard contractual clauses (SCCs) adopted by the European Commission (Decision 2021/914) supplemented where necessary by additional measures, or any other valid transfer mechanism within the meaning of Article 46 GDPR.
Should a transfer not provided for in this DPA become necessary in the course of providing the Services, Winheberg informs the Client beforehand, in accordance with the procedure of Article 5.3, and puts appropriate safeguards in place before any transfer.
Article 13 — Liability
Each party is responsible for compliance with its own legal obligations under the GDPR, under the conditions of Article 82 GDPR. The limitations of liability set out in Article 12 of the GTSU apply to this DPA, save for any mandatory statutory provision to the contrary; they may not limit Winheberg's liability towards data subjects as it arises under Article 82 GDPR.
Winheberg cannot be held liable for non-compliant processing resulting from Client instructions contrary to the GDPR or to applicable regulations, provided it has informed the Client in accordance with Article 4.1 of this DPA.
Article 14 — General provisions
14.1 Order of precedence
In the event of a contradiction between this DPA and the GTSU on the personal data protection matters it expressly addresses, this DPA prevails.
14.2 Severability
If any clause of this DPA is declared void or unenforceable, the remaining clauses remain fully in force.
14.3 Governing law
This DPA is governed by French law. In the event of a dispute concerning its interpretation or performance, the provisions of Articles 23.3 and 23.4 of the GTSU apply.
14.4 Changes to the DPA
Winheberg may update this DPA to reflect regulatory or operational developments. Any substantial change is notified to Clients under the conditions of Article 27 of the GTSU. The version in force is the one published on the Winheberg website at the time of consultation.