Version 1.0 — effective from 1 January 2026 — published at
https://www.monsterasp.net/pages/dpa
between
MonsterASP.NET s.r.o.
Jicinska 226/17, 130 00 Prague, Czech Republic
Company ID: 21693421
E-mail: support [at] monsterasp [dot] net
(the “Processor” or “MonsterASP”)
and
the Customer
the natural or legal person who has registered a customer account with MonsterASP and uses
the Services (as identified in the customer account)
(the “Controller” or “Customer”)
(each a “Party”, together the “Parties”)
1. Scope and acceptance of this Agreement
1.1This Data Processing Agreement (“DPA”) forms part of the Terms of Service of MonsterASP (the “Terms”) and governs the processing of Personal Data by MonsterASP on behalf of the Customer in connection with the provision of web hosting, database hosting, e-mail hosting and related services ordered by the Customer (the “Services”).
1.2This DPA is accepted automatically by the Customer upon (a) ordering or renewing a paid (Premium) Service, or (b) continuing to use a paid Service after the effective date stated above. No signature is required. A Customer who requires a countersigned copy for its records may request one at support [at] monsterasp [dot] net; MonsterASP will return a signed copy of this DPA in PDF form.
1.3This DPA applies to paid (Premium) hosting plans. Free hosting plans are provided for development, testing and evaluation purposes only and are not intended for the production processing of Personal Data. Use of a free hosting plan for commercial purposes or for the production processing of Personal Data constitutes a breach of the Terms, and MonsterASP accepts no processor obligations under this DPA in respect of such use.
1.4In the event of conflict between this DPA and the Terms or any other agreement between the Parties, this DPA prevails with respect to the processing of Personal Data. In the event of conflict between the body of this DPA and its Annexes, the body of this DPA prevails.
1.5The version of this DPA applicable to the Customer is the version published at the address stated above at the time of the relevant processing. MonsterASP may update this DPA to reflect changes in law, in the Services or in the list of Sub-processors. Material changes will be announced to the Customer by e-mail or through the control panel at least 30 days before they take effect, except where a shorter period is required by law. The Customer may object to a material change by terminating the affected Services before the change takes effect.
2. Definitions
Terms used in this DPA have the meaning given to them in the GDPR. In addition:
- “GDPR”
- means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- “Data Protection Law”
- means the GDPR, the Czech Act No. 110/2019 Coll. on personal data processing, and any other data protection law applicable to a Party.
- “Personal Data”
- means any personal data within the meaning of Article 4(1) GDPR that the Customer, or users of the Customer’s applications, store, transmit or otherwise process through the Services and that MonsterASP processes on behalf of the Customer. Personal Data does not include the Customer’s own account, contact and billing data, which MonsterASP processes as an independent controller in accordance with its Privacy Policy.
- “Customer Data”
- means all data, including Personal Data, uploaded to, stored in or generated by the Customer’s use of the Services, including website files, databases, e-mail mailboxes and application logs.
- “Sub-processor”
- means any third party engaged by MonsterASP to process Personal Data on behalf of the Customer, as listed in Annex III.
- “Personal Data Breach”
- means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by MonsterASP or a Sub-processor.
- “Services”
- has the meaning given in clause 1.1.
3. Roles of the Parties and description of processing
3.1With respect to Personal Data, the Customer is the controller and MonsterASP is the processor. Where the Customer itself acts as a processor for a third-party controller, MonsterASP acts as a sub-processor and the Customer warrants that its instructions and this DPA are consistent with the terms agreed with that controller.
3.2The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of data subjects are described in Annex I.
3.3MonsterASP provides infrastructure and platform services. MonsterASP has no knowledge of, and does not control, the content of Customer Data or the categories of Personal Data and data subjects that the Customer chooses to process through the Services. The Customer alone determines the purposes and means of that processing.
4. Obligations of MonsterASP as processor
4.1 Instructions
4.1.1MonsterASP shall process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law to which MonsterASP is subject. In such a case MonsterASP shall inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
4.1.2This DPA, the Terms, the Customer’s configuration of the Services through the control panel and the Customer’s use of the Services (including uploading, storing, modifying and deleting Customer Data, and requesting backups and restores) constitute the Customer’s complete instructions. Additional instructions require the written agreement of both Parties and may be subject to additional fees.
4.1.3MonsterASP shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other Data Protection Law. MonsterASP is entitled to suspend the execution of such instruction until the Customer confirms or amends it.
4.2 Purpose limitation and confidentiality
4.2.1MonsterASP shall process Personal Data solely for the purpose of providing, maintaining, securing and supporting the Services. MonsterASP shall not access Customer Data except (a) as necessary to provide the Services, (b) to resolve a technical or security issue, (c) at the request of the Customer for support purposes, or (d) as required by law.
4.2.2MonsterASP shall not sell, share, disclose or grant access to Customer Data to any third party for marketing, advertising, profiling or any other commercial purpose.
4.2.3MonsterASP shall ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those persons who need it to perform their duties.
4.3 Security of processing
4.3.1MonsterASP shall implement and maintain the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks for the rights and freedoms of natural persons, so as to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR.
4.3.2MonsterASP may update the measures in Annex II from time to time, provided that the updates do not materially reduce the overall level of security of the Services.
4.3.3The Customer acknowledges that the Services are a shared, self-managed hosting platform and that the security of the Customer’s own applications, application code, application-level access control, encryption of data at the application level and the secrecy of the Customer’s credentials are the responsibility of the Customer.
4.4 Sub-processors
4.4.1The Customer grants MonsterASP general written authorisation to engage the Sub-processors listed in Annex III for the purposes described therein.
4.4.2MonsterASP shall inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days before the new Sub-processor starts processing Personal Data, by updating Annex III at the address stated above and by notifying the Customer by e-mail or through the control panel. The Customer may object on reasonable, documented data protection grounds within that period. If the Parties cannot resolve the objection in good faith, the Customer may terminate the affected Services with effect from the date the new Sub-processor is engaged, without penalty, and MonsterASP shall refund any prepaid fees for the remaining unused period.
4.4.3MonsterASP shall impose on each Sub-processor, by way of a written contract, data protection obligations that are substantially equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a Sub-processor fails to fulfil its data protection obligations, MonsterASP remains fully liable to the Customer for the performance of that Sub-processor’s obligations.
4.5 Assistance with data subject rights
4.5.1Taking into account the nature of the processing, MonsterASP shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III GDPR. As the Customer has direct access to all Customer Data through the Services (control panel, FTP, database tools), the Customer shall in the first instance fulfil such requests itself.
4.5.2If MonsterASP receives a request from a data subject relating to Personal Data processed on behalf of the Customer, MonsterASP shall not respond to the request itself (other than to refer the data subject to the Customer) and shall forward the request to the Customer without undue delay.
4.6 Personal Data Breach notification
4.6.1MonsterASP shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer. The notification shall be sent to the e-mail address registered in the customer account and shall, to the extent known at that time, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach and a contact point for further information. Information may be provided in phases as it becomes available.
4.6.2MonsterASP shall reasonably cooperate with the Customer and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation and remediation of a Personal Data Breach. The Customer is responsible for notifying the competent supervisory authority and data subjects where required by Articles 33 and 34 GDPR.
4.7 Data protection impact assessments and prior consultation
4.7.1Taking into account the nature of the processing and the information available to MonsterASP, MonsterASP shall provide reasonable assistance to the Customer in ensuring compliance with the Customer’s obligations under Articles 35 and 36 GDPR. Such assistance consists primarily of making available the information contained in this DPA and its Annexes and answering reasonable written questions about the Services.
4.8 Return and deletion of Personal Data
4.8.1During the term of the Services the Customer may at any time retrieve, export and delete Customer Data through the Services (control panel, FTP, database backup and export tools, e-mail clients). The Customer is responsible for exporting any Customer Data it wishes to retain before the Services end.
4.8.2Upon termination or expiry of the Services, MonsterASP shall delete all Customer Data from the production systems within the period defined in the Terms and Annex IV, unless Union or Member State law requires storage of the Personal Data. Copies of Customer Data contained in backups are deleted automatically upon expiry of the retention periods described in Annex IV and are not used for any purpose other than restoration and disaster recovery until then.
4.8.3Where the Customer deletes Customer Data itself during the term of the Services, the deleted data remains in backups until it expires under the retention periods described in Annex IV (21 days for customer-restorable backups, 31 days for disaster-recovery backups). MonsterASP does not restore backups except at the Customer’s request or for disaster recovery purposes.
4.9 Audits and demonstration of compliance
4.9.1MonsterASP shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA. MonsterASP shall satisfy this obligation primarily by providing this DPA and its Annexes, the documentation of its Sub-processors (including the ISO/IEC 27001 certification of its infrastructure provider) and written answers to reasonable questions from the Customer.
4.9.2Where the information provided under clause 4.9.1 is insufficient to demonstrate compliance, the Customer or an independent auditor mandated by the Customer and bound by confidentiality may conduct an audit, subject to the following conditions: (a) the Customer gives at least 30 days’ written notice; (b) audits take place during normal business hours, no more than once per calendar year unless required by a supervisory authority or following a Personal Data Breach; (c) the audit does not compromise the security or confidentiality of other customers’ data, which excludes physical access to the datacenters of Sub-processors and to shared systems; (d) the Customer bears its own costs and reimburses MonsterASP for reasonable time spent beyond one working day per audit.
4.9.3MonsterASP shall contribute to audits and inspections conducted by a competent supervisory authority in accordance with Data Protection Law.
4.10 Records
4.10.1MonsterASP maintains a record of the categories of processing activities carried out on behalf of its customers in accordance with Article 30(2) GDPR.
5. Obligations of the Customer as controller
5.1The Customer is responsible for the lawfulness of the processing of Personal Data through the Services, including for having a valid legal basis, providing information to data subjects, maintaining its own records of processing and responding to data subject requests.
5.2The Customer shall not use the Services to process special categories of Personal Data (Article 9 GDPR), Personal Data relating to criminal convictions and offences (Article 10 GDPR) or Personal Data subject to sector-specific security requirements (such as payment card data under PCI DSS) unless the Customer has implemented appropriate additional safeguards at the application level and has satisfied itself that the Services are suitable for such processing.
5.3The Customer shall keep its account credentials, FTP credentials, database credentials and API keys confidential, use strong passwords, and enable two-factor authentication where available. The Customer is responsible for all processing carried out through its account.
5.4The Customer shall promptly notify MonsterASP if it becomes aware of a Personal Data Breach affecting Customer Data that originates in the Customer’s application or credentials, so that MonsterASP can take protective measures for the platform.
5.5The Customer shall choose the datacenter location for its Services in accordance with its own obligations regarding international transfers (see clause 6).
6. Location of processing and international transfers
6.1By default, MonsterASP processes and stores Customer Data, including backups, exclusively in datacenters located within the European Union operated by its infrastructure Sub-processor Hetzner Online GmbH (Annex III). No Customer Data is transferred to, or accessed from, a country outside the European Economic Area unless the Customer explicitly requests it by selecting the USA datacenter location.
6.2Where the Customer chooses to operate its Services in a datacenter located in the United States of America, this choice constitutes a documented instruction from the Customer to process the relevant Customer Data in that location. The transfer is carried out by MonsterASP’s infrastructure Sub-processors for the USA location (Annex III) under the transfer safeguards described therein. The Customer is responsible for ensuring that it has a valid legal basis under Chapter V GDPR for the transfer of Personal Data to the chosen location, and for informing data subjects accordingly.
6.3MonsterASP shall not otherwise transfer Personal Data outside the European Economic Area without the Customer’s prior documented instruction and without an appropriate transfer mechanism under Chapter V GDPR being in place.
7. Liability
7.1Each Party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms, except to the extent that such limitations are not permitted by Data Protection Law. Nothing in this DPA limits either Party’s liability towards data subjects under Article 82 GDPR.
7.2The Customer shall indemnify MonsterASP against claims, fines and costs arising from the Customer’s processing of Personal Data in breach of Data Protection Law, this DPA or the Terms, including the use of a free hosting plan for the production processing of Personal Data.
8. Term, termination and final provisions
8.1This DPA takes effect on the date the Customer accepts it in accordance with clause 1.2 and remains in force for as long as MonsterASP processes Personal Data on behalf of the Customer. The obligations under clauses 4.2 (confidentiality) and 4.8 (deletion) survive termination until all Personal Data has been deleted.
8.2This DPA is governed by the laws of the Czech Republic, without prejudice to mandatory provisions of Data Protection Law. The courts of the Czech Republic have jurisdiction over disputes arising from this DPA, subject to the dispute resolution provisions of the Terms.
8.3If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and the invalid provision shall be replaced by a valid provision that comes closest to its economic purpose.
8.4This DPA is drawn up in English. Any translation is provided for convenience only; the English version prevails.
8.5Questions regarding this DPA and requests for a countersigned copy may be addressed to support [at] monsterasp [dot] net with the subject “Data Processing Agreement”.
Annex I – Description of the processing
| Item | Description |
| Subject matter | Provision of shared web hosting, database hosting (MS SQL Server, MySQL/MariaDB, PostgreSQL), other hosted data services that MonsterASP may offer from time to time (such as Redis or other key-value and caching services), e-mail hosting, file storage (FTP/SFTP), Git deployment and related management tools (control panel, web-based database and file managers) to the Customer. |
| Duration | For the duration of the Customer’s use of the Services, plus the retention periods for backups and deleted data set out in Annex IV. |
| Nature of processing | Storage, hosting, transmission, backup, restore and deletion of Customer Data on MonsterASP’s infrastructure. Technical support and troubleshooting at the Customer’s request. MonsterASP does not analyse, evaluate or otherwise use the content of Customer Data for its own purposes. |
| Purpose of processing | Providing, operating, securing, maintaining and supporting the Services ordered by the Customer, in accordance with the Customer’s configuration and instructions. |
| Categories of data subjects | Determined by the Customer. Typically: the Customer’s own employees and contractors; users, visitors and registered members of the Customer’s websites and applications; the Customer’s customers, suppliers and business contacts; senders and recipients of e-mail messages in hosted mailboxes. |
| Types of Personal Data | Determined by the Customer. Typically: identification and contact data (names, addresses, e-mail addresses, telephone numbers), account and login data, customer records, order, booking and appointment data, correspondence and e-mail content, IP addresses and technical data in application logs, and any other data the Customer chooses to process through its applications and databases. |
| Special categories of data | Not intended. The Customer shall not process special categories of Personal Data through the Services except in accordance with clause 5.2. |
| Frequency of processing | Continuous, for as long as the Services are active. |
Annex II – Technical and organisational measures
MonsterASP implements the following technical and organisational measures pursuant to Article 32 GDPR. MonsterASP does not currently hold its own ISO/IEC 27001 or SOC 2 certification. Its infrastructure Sub-processor (Hetzner Online GmbH) is ISO/IEC 27001 certified for its datacenter operations; MonsterASP’s internal practices are designed in line with commonly accepted best practices used in ISO-aligned environments.
1. Physical security (datacenter level, provided by the infrastructure Sub-processor)
- Servers serving the European Union are located exclusively in ISO/IEC 27001 certified datacenters operated by Hetzner Online GmbH in Germany and Finland. Only where the Customer explicitly selects the USA location, servers are located in datacenters operated by Hetzner and by FiberState in the United States.
- Physical access control, video surveillance, redundant power supply, climate control and fire protection are provided and certified at datacenter level.
2. Access control (logical)
- Logical access to servers and management systems is strictly restricted to authorised MonsterASP administrators and is protected by individual credentials, strong passwords and, where supported, multi-factor authentication.
- Role-based access control is applied internally; access rights are granted on a need-to-know basis and reviewed when personnel roles change.
- Administrative access to servers is restricted at network level to designated management IP addresses and encrypted management protocols.
- Customer access to the control panel is protected by individual credentials with optional two-factor authentication; customer sessions are tracked and can be revoked.
3. Isolation of customers
- Each customer website runs in its own isolated application pool under a dedicated identity with file system permissions limited to the customer’s own directory.
- Databases and other hosted data services (such as Redis) are isolated per customer; each customer receives dedicated logins with rights limited to its own databases and instances.
- E-mail domains and mailboxes are separated per customer.
4. Network security
- Firewalls and network segmentation are in place between public services, management interfaces and internal service endpoints.
- Internal service-to-service interfaces are restricted to whitelisted IP addresses and protected by API keys.
- Intrusion detection and automated blocking of malicious IP addresses (rate limiting, brute-force protection) are applied to public services.
5. Encryption
- Encryption in transit (TLS) is supported for all hosted services: HTTPS (with free certificates issued by Let’s Encrypt) for websites, TLS for database connections, FTPS/SFTP for file transfer and TLS for e-mail (IMAP, POP3, SMTP, webmail).
- Customer passwords for the control panel are stored using salted cryptographic hashing.
6. Malware protection and system hardening
- Servers are protected by an automated antivirus system with real-time scanning and an Endpoint Detection and Response (EDR) solution.
- Operating systems and platform components are patched regularly; security updates are applied on a prioritised basis.
7. Monitoring and logging
- Server availability, resource usage and service health are monitored continuously, with alerting to administrators.
- Administrative actions in the control panel and on the platform are logged.
8. Availability and backup
- Daily automated backups of website files, databases and e-mail are performed for paid hosting plans as described in Annex IV; customer-restorable backups are retained for 21 days and disaster-recovery backups for 31 days.
- Backups are stored on separate backup servers with access restricted to authorised administrators, and are replicated to a separate Hetzner datacenter in Finland as part of the disaster recovery strategy.
- Customers can restore database backups themselves through the control panel.
9. Incident management
- MonsterASP maintains internal monitoring and incident-handling procedures. Confirmed security incidents are analysed, contained and remediated, and affected customers are notified without undue delay in accordance with clause 4.6.
10. Organisational measures
- All personnel with access to Customer Data are bound by confidentiality obligations.
- Customer Data is accessed by MonsterASP personnel only for the purposes set out in clause 4.2.1.
- Sub-processors are selected on the basis of their security guarantees and are bound by written data processing agreements.
11. Deletion
- Customer Data is deleted from production systems after termination of the Services as described in Annex IV; backup copies expire through the backup retention cycle.
Annex III – Authorised Sub-processors
The Customer authorises MonsterASP to engage the following Sub-processors. The current list is maintained at the address stated above.
| Sub-processor | Purpose | Location of processing | Transfer safeguard |
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany |
Infrastructure provider: datacenter, dedicated servers, cloud servers, network and storage for production systems and backups |
Germany and Finland (European Union). United States only where the Customer explicitly selects the USA location. |
Within EU: not applicable. USA: EU Standard Contractual Clauses concluded between MonsterASP and Hetzner Online GmbH. |
| FIBERSTATE, LLC, 106 East 13200 South, Draper, UT 84020, United States |
Infrastructure provider for the USA location: datacenter, dedicated servers, network and storage for production systems and backups |
United States only, and only where the Customer explicitly selects the USA location. |
EU Standard Contractual Clauses (Module 3, processor to processor) concluded between MonsterASP and FiberState. |
Note: MonsterASP uses further service providers (for example payment processing and e-mail delivery) to process the Customer’s own account, contact and billing data. These providers process data for which MonsterASP is an independent controller and are described in the MonsterASP Privacy Policy; they do not process Customer Data hosted through the Services and are therefore not Sub-processors under this DPA.
Annex IV – Backups, retention and deletion
1. Backups (paid hosting plans)
| Item | Description |
| What is backed up | Website files (including uploaded content), databases (MS SQL Server, MySQL/MariaDB, PostgreSQL), other hosted data services where backup is technically applicable (such as Redis) and hosted e-mail mailboxes. |
| Frequency | Automatically once per day. |
| Retention | Customer-restorable backups (available to the Customer through the control panel) are retained for 21 days. Disaster-recovery backups replicated to the secondary datacenter are retained for 31 days. Retention is enforced automatically by the backup system; expired backups are deleted without manual intervention. |
| Storage location | Dedicated backup servers in Hetzner datacenters in Germany, replicated to a separate Hetzner datacenter in Finland. For Services operated in the USA location at the Customer’s choice, backups are stored in the Hetzner and FiberState datacenters in the United States. |
| Access | Restricted to authorised MonsterASP administrators; backup storage is not accessible from customer environments. Customers can download and restore their own database backups through the control panel. |
| Encryption | Backups are transferred to the backup servers over encrypted connections (HTTPS) and stored on access-controlled systems. |
| Purpose | Disaster recovery and restoration at the Customer’s request only. Backups are not used for any other purpose. |
2. Data deleted by the Customer during the Service
When the Customer deletes files, database records, mailboxes or messages, the data is removed from the production systems immediately. Copies remain in backups until they expire, i.e. for a maximum of 21 days in customer-restorable backups and 31 days in disaster-recovery backups. MonsterASP does not offer selective purging of individual records from backup archives, as backups are stored as consistent full snapshots; the data is deleted automatically upon expiry of the retention period.
3. Deletion after termination of the Services
Upon termination or expiry of a Service (including non-renewal), the website, databases and mailboxes are disabled and the Customer Data is deleted from the production systems within 90 days, unless the Customer renews the Service within that period or MonsterASP is required by law to retain specific data. Backup copies then expire within a further 31 days at most. Free hosting accounts are deleted in accordance with the Terms.
4. Server and platform logs kept by MonsterASP
MonsterASP keeps the following logs for the purposes of operating, securing and troubleshooting the Services:
- Web server (IIS) access logs: date and time, client IP address, requested URL, HTTP status, bytes transferred, user agent and referrer. Retained for 6 months and then deleted automatically. Logs for the Customer’s own websites are also made available to the Customer through the control panel.
- Mail server logs: date and time, sender and recipient addresses, client IP address and delivery status. Retained for 6 months.
- FTP/SFTP and database server logs: date and time, login name, client IP address and result of the connection. Retained for 6 months.
- Control panel and security logs: logins, administrative actions and intrusion-detection events, including IP addresses. Retained for 12 months for security and abuse-prevention purposes.
Log data is accessible only to authorised MonsterASP administrators and is not disclosed to third parties except where required by law.