Hodi
Location Congo-Brazzaville
  • Pan-Africa Grow your business across the continent ›
  • Africa data centers
    Algeria Angola Benin Cameroon Chad Congo-Brazzaville Côte d’Ivoire DRC Egypt Ethiopia Gabon Ghana Kenya Madagascar Mauritius Mayotte Morocco Nigeria Réunion Rwanda Senegal South Africa Tanzania Togo Tunisia Uganda Zambia Zimbabwe
  • Overseas data centers
    Guadeloupe Martinique New Caledonia
Language English
  • English
  • Français
Currency XAF
  • AED · AED AOA · Kwanza CAD · CAD CDF · Congolese Franc DZD · Algerian Dinar EGP · Egyptian Pound ETB · Ethiopian Birr EUR · Euro GHS · Cedi GNF · Guinean Franc KES · Kenyan Shilling MAD · Dirham MGA · Ariary MUR · Rupee NGN · Naira RWF · Rwandan Franc TND · Tunisian Dinar TZS · Tanzanian Shilling UGX · Ugandan Shilling USD · US Dollar XAF · CFA Franc XOF · CFA Franc ZAR · Rand ZMW · Kwacha
Chat on Whatsapp
  • My profile
  • My account
Hodi
  • Hosting
    • My vCard FREE!
    • Domain name
    • Minisite
    • Site Pro
    • Site Pro Cyber+
    • Archipel (up to 50 sites)
    • Dedicated virtual servers
    • Odoo Servers
  • Cybersecurity
    • Included cyber services
    • MDR - Managed cybersecurity
    • Managed DRP
    • Attack Surface Monitoring
    • AI Smart Firewall
    • WordPress Serenity
    • SpamExperts
    • SSL Certificate
    • Cloudflare Managed Services
  • Host different
    • Servers & datacenters
    • Our NR commitments
    • Pulse Africa Magazine
    • Hodipulse
  • Support
    • FAQ
    • Open a request
    • My requests
    • My IP address
    • IP unblock
    • Network status
  • Contact us Login

Data Processing Agreement (DPA)

Version dated 15/07/2026

This English text is a translation provided for information purposes only. Only the French version of this Data Processing Agreement is legally binding between the Parties. In the event of any discrepancy, ambiguity or conflict of interpretation between this translation and the French version, the French version shall prevail. The French version is available at https://hodi.host/cg-fr/dpa/.

Why this DPA?

At Hodi, we process our customers' personal data solely to provide the services they entrust to us.

This Agreement sets out the commitments we make as a processor within the meaning of the GDPR and of local personal data protection laws, to ensure the confidentiality, integrity and availability of that data.

It forms an integral part of our General Terms of Service.

Recitals

This Data Processing Agreement (the "Agreement" or "DPA") forms an integral part of the Hodi General Terms of Service (the "GTS") and of the Contract concluded between HODI SAS, a simplified joint-stock company (société par actions simplifiée) with share capital of €20,000, registered with the Saint-Denis de La Réunion Trade and Companies Register under number 910 167 758, with registered office at 14 rue Pasteur, 97400 Saint-Denis, Réunion (hereinafter "Hodi" or the "Processor"), and the customer identified in the Hodi Order / Service Contract (hereinafter the "Customer" or the "Controller"), together the "Parties" and individually a "Party".

It sets out the conditions under which Hodi processes, on behalf of the Customer, the personal data contained in the content hosted through the Services, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR") and French Act No. 78-17 of 6 January 1978 as amended.

In the event of conflict between this Agreement and the GTS regarding the processing of personal data, this Agreement prevails.

ARTICLE 1. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in Article 4 GDPR. Capitalised terms not defined here have the meaning given in the GTS.

ARTICLE 2. Purpose and allocation of roles

2.1. In accordance with Article 20 of the GTS, each Party is the controller of the data it processes for its own purposes.

2.2. Hodi acts as controller for the processing necessary to perform the Contract, in particular Customer identification data and payment details. This processing is described in Hodi's Privacy Policy at https://hodi.host/confidentialite.

2.3. Hodi acts as processor on behalf of the Customer for the personal data contained in the content the Customer hosts, stores or processes through the Services. This Agreement governs solely that processing scope.

2.4. Unmanaged dedicated servers. For unmanaged (virtual) dedicated server offers, Hodi has no administrator access to the Customer's systems (Article 31 of the GTS) and provides infrastructure only. The Customer is solely responsible for administration, security and data processing. Hodi's processing scope is limited to providing and maintaining the underlying infrastructure.

ARTICLE 3. Description of the processing

The nature, purpose and duration of the processing, the types of data and the categories of data subjects are described in Annex 1.

ARTICLE 4. Obligations of the Processor

Hodi undertakes to:

4.1. Process on documented instructions. Hodi processes personal data solely to provide the Services and on the Customer's documented instructions, including regarding transfers, as set out in the Contract, the GTS, this Agreement and the Customer's use of the Services. Where required to process by Union or Member State law, Hodi informs the Customer beforehand unless legally prohibited.

4.2. Flag non-compliant instructions. Hodi immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.

4.3. Ensure confidentiality. Hodi ensures that persons authorised to process the data are bound by confidentiality and appropriately trained, and applies the principle of least privilege (Article 6.3 of the GTS).

4.4. Implement security measures. Hodi implements the appropriate technical and organisational measures under Article 32 GDPR, described in Annex 2 and Article 6 of the GTS.

4.5. Govern the use of sub-processors under the conditions of Article 5.

4.6. Assist with data subject rights. Taking into account the nature of the processing, Hodi assists the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection). Where a request is addressed directly to Hodi, Hodi forwards it to the Customer promptly without responding itself, unless otherwise instructed.

4.7. Assist with security and compliance. Hodi assists the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of the processing and the information available to it.

4.8. Notify data breaches. Hodi notifies the Customer of any personal data breach without undue delay and no later than 72 hours after detecting it (Article 6.6 of the GTS), providing the information needed for the Customer to notify the supervisory authority and data subjects where applicable.

4.9. Maintain records of the categories of processing carried out on behalf of the Customer, in accordance with Article 30(2) GDPR.

4.10. Make information available and allow audits necessary to demonstrate compliance with Article 28 GDPR, under the conditions of Article 7.

ARTICLE 5. Sub-processors

5.1. The Customer authorises Hodi to engage sub-processors to perform the Services (Article 24 of the GTS). The current list is set out in Annex 3.

5.2. Hodi imposes on each sub-processor, by contract, data protection obligations substantially equivalent to those in this Agreement, and remains fully liable to the Customer for the sub-processor's performance.

ARTICLE 6. Transfers outside the European Union

6.1. Data hosted by customers is stored on Hodi's infrastructure or that of selected hosting partners, and not on US public cloud platforms. It is located according to the offer and the Customer's choice (Réunion, mainland France, other covered territories). Certain backups are made to a data centre located in Germany (EU) for the "web hosting and emails", "web hosting PRA/PCA", "Nuaz" and "CYBER+" offers (Article 21 of the GTS). Hodi does not change, without the Customer's agreement, the location or geographical area chosen at the time of the Order.

6.2. Where processing involves a transfer to a third country without an adequacy decision, Hodi implements appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (Article 20 of the GTS) and, where necessary, supplementary measures.

6.3. The Customer grants Hodi a mandate to conclude, in its name and on its behalf as data exporter, the Standard Contractual Clauses required with the relevant data importers. The Customer warrants that it holds the authorisations necessary for this purpose.

ARTICLE 7. Audits

7.1. On request, Hodi makes available the information and documents demonstrating its compliance, including its Security Assurance Plan (Article 6.8 of the GTS) and, subject to a non-disclosure agreement, available audit reports.

7.2. The Customer may carry out an audit at its own expense, at most once per year, on reasonable notice, during business hours and without disrupting the Services or compromising other customers' security. Additional audits may be conducted following a proven breach or at a supervisory authority's request.

ARTICLE 8. Obligations of the Controller

The Customer warrants that it has a legal basis for the processing it carries out through the Services, provides lawful instructions, informs data subjects, does not host data for unlawful purposes, and complies with the GDPR (Articles 11 and 20 of the GTS). The Customer remains responsible for the lawfulness of the data it processes and the instructions it gives.

ARTICLE 9. Fate of data at the end of the contract

9.1. On termination of the Services, Hodi deletes or returns the personal data at the Customer's choice, under the reversibility conditions of Article 31 of the GTS, and destroys existing copies unless legally required to retain them.

9.2. As a security measure, Hodi retains backups after termination, automatically deleted 30 days after termination for the "web hosting and emails", "web hosting PRA/PCA" and "Nuaz" offers, and 7 days for other Services provided by Hodi (Article 25.3 of the GTS).

9.3. It is the Customer's responsibility to retrieve and export its personal data before the end of the Services, under the reversibility conditions set out in Article 31 of the GTS. The Customer is informed that termination or expiry of the Services results in deletion of the data, including backups, within the periods indicated above.

ARTICLE 10. Liability

Hodi is liable for damage caused by processing only where (i) it has not complied with the obligations of the GDPR specifically incumbent on processors, or (ii) it has acted outside or contrary to the Customer's lawful instructions. In all other cases, the Customer remains responsible for the processing it carries out through the Services.

The limitations and caps on liability set out in the GTS and the Contract apply to this Agreement.

ARTICLE 11. Term

This Agreement takes effect on acceptance of the Contract and remains in force for the duration of Hodi's processing of personal data on behalf of the Customer. Confidentiality obligations survive for twelve (12) months after termination (Article 19 of the GTS).

ARTICLE 12. Governing law and jurisdiction

This Agreement is governed by French law. Any dispute falls, after the prior mediation provided for in Article 34 of the GTS, within the jurisdiction of the Courts of Saint-Denis de La Réunion.

ARTICLE 13. Contact

For any question relating to this Agreement or to the processing of personal data, in particular to notify a security incident, the Customer may contact Hodi:

  • by email at securite@hodi.host;
  • by opening a request from its client area;
  • by post at: HODI SAS, 14 rue Pasteur, 97400 Saint-Denis, Réunion.

Annex 1: Description of the processing

  • Nature and purpose: hosting, storage, backup and provision of the Customer's content through the subscribed Services (web hosting and emails, PRA/PCA, CYBER+, Nuaz, VPS, managed or unmanaged virtual dedicated server, Odoo Cloud, and related services).
  • Duration: the term of the Contract plus backup retention periods (Article 9).
  • Categories of data subjects: determined by the Customer (e.g. its customers, prospects, employees, users of its sites and applications).
  • Categories of data: determined by the Customer, corresponding to the content it hosts. The Customer shall not host special categories of data (Article 20 of the GTS) without appropriate measures and specific instructions.
  • Processing operations: storage, hosting, backup, replication, restoration, and technical operations necessary to provide and secure the Services.

Annex 2: Technical and organisational security measures

Summary of the measures under Article 6 of the GTS:

  • Physical data centre security: fire compartments, backup power, early fire detection, oxygen-reduction suppression, redundant cooling, restricted and logged physical access.
  • High availability: redundant architecture, real-time replication across two data centres in the same territory for the relevant offers, per-component firewalling.
  • Network segmentation: separation of administration traffic from regular traffic; strong isolation between customers on shared hosting, with dedicated segmentation available as an option on dedicated servers.
  • Access security: logical access via a secured dedicated link and ZTNA, administration interfaces not exposed to the internet, multi-factor authentication for staff, least-privilege principle, password policy compliant with the ANSSI-PG-078 guide, logging of administrator access, regular reviews of rights and privileged accounts, encryption of workstations, media and devices.
  • Application protection: antivirus/antimalware, web application firewall (WAF), layer 3/4 DDoS protection.
  • Vulnerability management: regular application of security patches, with rebootless kernel updates for critical vulnerabilities.
  • Backups: automated and supervised daily procedure, encrypted backups that are technically inaccessible from the production infrastructure; retention and locations per offer (Article 21 of the GTS).
  • Business continuity and disaster recovery (PRA/PCA): continuity and recovery plan covering in particular cyclone risk and cryptolocker-type attacks (backups inaccessible to Hodi), tested at least once a year.
  • Monitoring: real-time monitoring 24/7, with redundant alerting.
  • Incident management: breach notification within a maximum of 72 hours.
  • Documentation: Security Assurance Plan provided on request.
  • Continuous improvement (ISO/IEC 27001): Hodi has initiated an ISO/IEC 27001 certification process to continuously strengthen its information security management system.

Annex 3: List of sub-processors

This lists the sub-processors that may process the personal data hosted by the Customer. The sub-processors actually engaged depend on the offer subscribed and the location chosen by the Customer. Transfers outside the EU/EEA are covered by appropriate safeguards (standard contractual clauses).

Sub-processorTypeCountryRegistration number
Acronis International GmbHBackup, security (EDR/SOC)SwitzerlandCHE-113.666.835
AlbideyNetHostingChadRCCM TC/NDJ/13B234
Aqua Ray SASHostingFranceSIREN 447 997 099
Assistance Maîtrise Conseil Informatique SASMonitoring and managed servicesFranceSIREN 400 201 828
Blue SASHostingFranceSIREN 483 400 628
Broadband Systems Corporation LtdHosting, domain nameRwandaTIN 101982714
Cloud & Racks SASHostingTogoRCCM TG-LOM 2020B 1153
DataKeepers (Pty) LtdHostingSouth AfricaCIPC 2016/532469/07
EGATE CLOUD SERVICE SAHosting, domain nameAngolaNIF 5417520438
EO Data Center SAHostingTunisiaRC Tunis B2418282009
Exodata EU SASHosting, backup, security (EDR/SOC), monitoring and managed servicesFranceSIREN 817 893 639
Hetzner Online GmbHHosting, backupGermanyHRB 6089 (Ansbach)
Home Made Softwares SARLDomain nameMadagascarRCS Antananarivo 2009 A 00841
Host Africa (Pty) LtdHostingSouth AfricaCIPC 2008/019975/07
Hosted LtdHostingMauritiusBRN C18158096
HOSTOWEB SARL AUHostingMoroccoRC Fès 65903
Hyperping SASMonitoringFranceSIREN 930 471 743
INFRATEL Corporation LimitedHostingZambiaTPIN 1018813907
IT Cloud & Services SRLHostingBelgiumBCE 0662.392.808
Link Datacenter for Data Exchange L.L.C.HostingEgyptRC 101146
Liquid Intelligent TechnologiesHostingZimbabweTIN 2000036892
N-able Technologies Ltd.Anti-spamUnited KingdomSC252676
Netim SASDomain nameFranceSIREN 451 394 720
NEWTELNET Cameroun SASDomain nameCameroon
Poornam Info Vision Pvt. LtdMonitoring and managed servicesIndiaCIN U72200KL1999PTC013407
RunCloud SASHostingFranceSIREN 813 751 229
SCPTHosting, domain nameDR CongoRCCM CD/KIN/RCCM/14-B-3432
Seacom Kenya LtdHostingKenyaPIN P051202980Z
Société Réunionnaise du Radiotéléphone (SRR) SCSHostingFranceSIREN 393 551 007
SONATEL SAHostingSenegalRCCM SN.DKR.74.B.61
ST Digital Africa LtdHostingMauritiusBRN C203886
Stellar-IX SAHostingMadagascarRCS Antananarivo 2021 B 00344
Zeop SASHostingFranceSIREN 531 379 295

Switzerland and the United Kingdom benefit from a European Commission adequacy decision. Transfers to any country outside the European Union without an adequacy decision (see the "Country" column above) are covered by standard contractual clauses. This list is kept up to date; it does not include sub-processors relating to the "marketplace" products defined in the GTS.

Note: payment and billing providers (Stripe, pawaPay, WHMCS) process identity and payment data for which Hodi acts as controller (Article 20 of the GTS); they fall under Hodi's Privacy Policy, not this DPA.

  • Legal notice
  • Terms of Service
  • DPA
  • Privacy policy
  • Rights and responsibilities of domain name holders
  • Information for domain holders

Professional Liability Insurance Hiscox No. RCP22112464176. Prices shown are exclusive of VAT. Applicable VAT will be calculated in your cart.


Generate Password
Please enter a number between 8 and 64 for the password length