Version dated 15/07/2026
This English text is a translation provided for information purposes only. Only the French version of this Data Processing Agreement is legally binding between the Parties. In the event of any discrepancy, ambiguity or conflict of interpretation between this translation and the French version, the French version shall prevail. The French version is available at https://hodi.host/mu-fr/dpa/.
Why this DPA?
At Hodi, we process our customers' personal data solely to provide the services they entrust to us.
This Agreement sets out the commitments we make as a processor within the meaning of the GDPR and of local personal data protection laws, to ensure the confidentiality, integrity and availability of that data.
It forms an integral part of our General Terms of Service.
Recitals
This Data Processing Agreement (the "Agreement" or "DPA") forms an integral part of the Hodi General Terms of Service (the "GTS") and of the Contract concluded between HODI SAS, a simplified joint-stock company (société par actions simplifiée) with share capital of €20,000, registered with the Saint-Denis de La Réunion Trade and Companies Register under number 910 167 758, with registered office at 14 rue Pasteur, 97400 Saint-Denis, Réunion (hereinafter "Hodi" or the "Processor"), and the customer identified in the Hodi Order / Service Contract (hereinafter the "Customer" or the "Controller"), together the "Parties" and individually a "Party".
It sets out the conditions under which Hodi processes, on behalf of the Customer, the personal data contained in the content hosted through the Services, in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR") and French Act No. 78-17 of 6 January 1978 as amended.
In the event of conflict between this Agreement and the GTS regarding the processing of personal data, this Agreement prevails.
ARTICLE 1. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in Article 4 GDPR. Capitalised terms not defined here have the meaning given in the GTS.
ARTICLE 2. Purpose and allocation of roles
2.1. In accordance with Article 20 of the GTS, each Party is the controller of the data it processes for its own purposes.
2.2. Hodi acts as controller for the processing necessary to perform the Contract, in particular Customer identification data and payment details. This processing is described in Hodi's Privacy Policy at https://hodi.host/confidentialite.
2.3. Hodi acts as processor on behalf of the Customer for the personal data contained in the content the Customer hosts, stores or processes through the Services. This Agreement governs solely that processing scope.
2.4. Unmanaged dedicated servers. For unmanaged (virtual) dedicated server offers, Hodi has no administrator access to the Customer's systems (Article 31 of the GTS) and provides infrastructure only. The Customer is solely responsible for administration, security and data processing. Hodi's processing scope is limited to providing and maintaining the underlying infrastructure.
ARTICLE 3. Description of the processing
The nature, purpose and duration of the processing, the types of data and the categories of data subjects are described in Annex 1.
ARTICLE 4. Obligations of the Processor
Hodi undertakes to:
4.1. Process on documented instructions. Hodi processes personal data solely to provide the Services and on the Customer's documented instructions, including regarding transfers, as set out in the Contract, the GTS, this Agreement and the Customer's use of the Services. Where required to process by Union or Member State law, Hodi informs the Customer beforehand unless legally prohibited.
4.2. Flag non-compliant instructions. Hodi immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
4.3. Ensure confidentiality. Hodi ensures that persons authorised to process the data are bound by confidentiality and appropriately trained, and applies the principle of least privilege (Article 6.3 of the GTS).
4.4. Implement security measures. Hodi implements the appropriate technical and organisational measures under Article 32 GDPR, described in Annex 2 and Article 6 of the GTS.
4.5. Govern the use of sub-processors under the conditions of Article 5.
4.6. Assist with data subject rights. Taking into account the nature of the processing, Hodi assists the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection). Where a request is addressed directly to Hodi, Hodi forwards it to the Customer promptly without responding itself, unless otherwise instructed.
4.7. Assist with security and compliance. Hodi assists the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of the processing and the information available to it.
4.8. Notify data breaches. Hodi notifies the Customer of any personal data breach without undue delay and no later than 72 hours after detecting it (Article 6.6 of the GTS), providing the information needed for the Customer to notify the supervisory authority and data subjects where applicable.
4.9. Maintain records of the categories of processing carried out on behalf of the Customer, in accordance with Article 30(2) GDPR.
4.10. Make information available and allow audits necessary to demonstrate compliance with Article 28 GDPR, under the conditions of Article 7.
ARTICLE 5. Sub-processors
5.1. The Customer authorises Hodi to engage sub-processors to perform the Services (Article 24 of the GTS). The current list is set out in Annex 3.
5.2. Hodi imposes on each sub-processor, by contract, data protection obligations substantially equivalent to those in this Agreement, and remains fully liable to the Customer for the sub-processor's performance.
ARTICLE 6. Transfers outside the European Union
6.1. Data hosted by customers is stored on Hodi's infrastructure or that of selected hosting partners, and not on US public cloud platforms. It is located according to the offer and the Customer's choice (Réunion, mainland France, other covered territories). Certain backups are made to a data centre located in Germany (EU) for the "web hosting and emails", "web hosting PRA/PCA", "Nuaz" and "CYBER+" offers (Article 21 of the GTS). Hodi does not change, without the Customer's agreement, the location or geographical area chosen at the time of the Order.
6.2. Where processing involves a transfer to a third country without an adequacy decision, Hodi implements appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (Article 20 of the GTS) and, where necessary, supplementary measures.
6.3. The Customer grants Hodi a mandate to conclude, in its name and on its behalf as data exporter, the Standard Contractual Clauses required with the relevant data importers. The Customer warrants that it holds the authorisations necessary for this purpose.
ARTICLE 7. Audits
7.1. On request, Hodi makes available the information and documents demonstrating its compliance, including its Security Assurance Plan (Article 6.8 of the GTS) and, subject to a non-disclosure agreement, available audit reports.
7.2. The Customer may carry out an audit at its own expense, at most once per year, on reasonable notice, during business hours and without disrupting the Services or compromising other customers' security. Additional audits may be conducted following a proven breach or at a supervisory authority's request.
ARTICLE 8. Obligations of the Controller
The Customer warrants that it has a legal basis for the processing it carries out through the Services, provides lawful instructions, informs data subjects, does not host data for unlawful purposes, and complies with the GDPR (Articles 11 and 20 of the GTS). The Customer remains responsible for the lawfulness of the data it processes and the instructions it gives.
ARTICLE 9. Fate of data at the end of the contract
9.1. On termination of the Services, Hodi deletes or returns the personal data at the Customer's choice, under the reversibility conditions of Article 31 of the GTS, and destroys existing copies unless legally required to retain them.
9.2. As a security measure, Hodi retains backups after termination, automatically deleted 30 days after termination for the "web hosting and emails", "web hosting PRA/PCA" and "Nuaz" offers, and 7 days for other Services provided by Hodi (Article 25.3 of the GTS).
9.3. It is the Customer's responsibility to retrieve and export its personal data before the end of the Services, under the reversibility conditions set out in Article 31 of the GTS. The Customer is informed that termination or expiry of the Services results in deletion of the data, including backups, within the periods indicated above.
ARTICLE 10. Liability
Hodi is liable for damage caused by processing only where (i) it has not complied with the obligations of the GDPR specifically incumbent on processors, or (ii) it has acted outside or contrary to the Customer's lawful instructions. In all other cases, the Customer remains responsible for the processing it carries out through the Services.
The limitations and caps on liability set out in the GTS and the Contract apply to this Agreement.
ARTICLE 11. Term
This Agreement takes effect on acceptance of the Contract and remains in force for the duration of Hodi's processing of personal data on behalf of the Customer. Confidentiality obligations survive for twelve (12) months after termination (Article 19 of the GTS).
ARTICLE 12. Governing law and jurisdiction
This Agreement is governed by French law. Any dispute falls, after the prior mediation provided for in Article 34 of the GTS, within the jurisdiction of the Courts of Saint-Denis de La Réunion.
ARTICLE 13. Contact
For any question relating to this Agreement or to the processing of personal data, in particular to notify a security incident, the Customer may contact Hodi:
- by email at securite@hodi.host;
- by opening a request from its client area;
- by post at: HODI SAS, 14 rue Pasteur, 97400 Saint-Denis, Réunion.
Annex 1: Description of the processing
- Nature and purpose: hosting, storage, backup and provision of the Customer's content through the subscribed Services (web hosting and emails, PRA/PCA, CYBER+, Nuaz, VPS, managed or unmanaged virtual dedicated server, Odoo Cloud, and related services).
- Duration: the term of the Contract plus backup retention periods (Article 9).
- Categories of data subjects: determined by the Customer (e.g. its customers, prospects, employees, users of its sites and applications).
- Categories of data: determined by the Customer, corresponding to the content it hosts. The Customer shall not host special categories of data (Article 20 of the GTS) without appropriate measures and specific instructions.
- Processing operations: storage, hosting, backup, replication, restoration, and technical operations necessary to provide and secure the Services.
Annex 2: Technical and organisational security measures
Summary of the measures under Article 6 of the GTS:
- Physical data centre security: fire compartments, backup power, early fire detection, oxygen-reduction suppression, redundant cooling, restricted and logged physical access.
- High availability: redundant architecture, real-time replication across two data centres in the same territory for the relevant offers, per-component firewalling.
- Network segmentation: separation of administration traffic from regular traffic; strong isolation between customers on shared hosting, with dedicated segmentation available as an option on dedicated servers.
- Access security: logical access via a secured dedicated link and ZTNA, administration interfaces not exposed to the internet, multi-factor authentication for staff, least-privilege principle, password policy compliant with the ANSSI-PG-078 guide, logging of administrator access, regular reviews of rights and privileged accounts, encryption of workstations, media and devices.
- Application protection: antivirus/antimalware, web application firewall (WAF), layer 3/4 DDoS protection.
- Vulnerability management: regular application of security patches, with rebootless kernel updates for critical vulnerabilities.
- Backups: automated and supervised daily procedure, encrypted backups that are technically inaccessible from the production infrastructure; retention and locations per offer (Article 21 of the GTS).
- Business continuity and disaster recovery (PRA/PCA): continuity and recovery plan covering in particular cyclone risk and cryptolocker-type attacks (backups inaccessible to Hodi), tested at least once a year.
- Monitoring: real-time monitoring 24/7, with redundant alerting.
- Incident management: breach notification within a maximum of 72 hours.
- Documentation: Security Assurance Plan provided on request.
- Continuous improvement (ISO/IEC 27001): Hodi has initiated an ISO/IEC 27001 certification process to continuously strengthen its information security management system.
Annex 3: List of sub-processors
This lists the sub-processors that may process the personal data hosted by the Customer. The sub-processors actually engaged depend on the offer subscribed and the location chosen by the Customer. Transfers outside the EU/EEA are covered by appropriate safeguards (standard contractual clauses).
| Sub-processor | Type | Country | Registration number |
|---|---|---|---|
| Acronis International GmbH | Backup, security (EDR/SOC) | Switzerland | CHE-113.666.835 |
| AlbideyNet | Hosting | Chad | RCCM TC/NDJ/13B234 |
| Aqua Ray SAS | Hosting | France | SIREN 447 997 099 |
| Assistance Maîtrise Conseil Informatique SAS | Monitoring and managed services | France | SIREN 400 201 828 |
| Blue SAS | Hosting | France | SIREN 483 400 628 |
| Broadband Systems Corporation Ltd | Hosting, domain name | Rwanda | TIN 101982714 |
| Cloud & Racks SAS | Hosting | Togo | RCCM TG-LOM 2020B 1153 |
| DataKeepers (Pty) Ltd | Hosting | South Africa | CIPC 2016/532469/07 |
| EGATE CLOUD SERVICE SA | Hosting, domain name | Angola | NIF 5417520438 |
| EO Data Center SA | Hosting | Tunisia | RC Tunis B2418282009 |
| Exodata EU SAS | Hosting, backup, security (EDR/SOC), monitoring and managed services | France | SIREN 817 893 639 |
| Hetzner Online GmbH | Hosting, backup | Germany | HRB 6089 (Ansbach) |
| Home Made Softwares SARL | Domain name | Madagascar | RCS Antananarivo 2009 A 00841 |
| Host Africa (Pty) Ltd | Hosting | South Africa | CIPC 2008/019975/07 |
| Hosted Ltd | Hosting | Mauritius | BRN C18158096 |
| HOSTOWEB SARL AU | Hosting | Morocco | RC Fès 65903 |
| Hyperping SAS | Monitoring | France | SIREN 930 471 743 |
| INFRATEL Corporation Limited | Hosting | Zambia | TPIN 1018813907 |
| IT Cloud & Services SRL | Hosting | Belgium | BCE 0662.392.808 |
| Link Datacenter for Data Exchange L.L.C. | Hosting | Egypt | RC 101146 |
| Liquid Intelligent Technologies | Hosting | Zimbabwe | TIN 2000036892 |
| N-able Technologies Ltd. | Anti-spam | United Kingdom | SC252676 |
| Netim SAS | Domain name | France | SIREN 451 394 720 |
| NEWTELNET Cameroun SAS | Domain name | Cameroon | |
| Poornam Info Vision Pvt. Ltd | Monitoring and managed services | India | CIN U72200KL1999PTC013407 |
| RunCloud SAS | Hosting | France | SIREN 813 751 229 |
| SCPT | Hosting, domain name | DR Congo | RCCM CD/KIN/RCCM/14-B-3432 |
| Seacom Kenya Ltd | Hosting | Kenya | PIN P051202980Z |
| Société Réunionnaise du Radiotéléphone (SRR) SCS | Hosting | France | SIREN 393 551 007 |
| SONATEL SA | Hosting | Senegal | RCCM SN.DKR.74.B.61 |
| ST Digital Africa Ltd | Hosting | Mauritius | BRN C203886 |
| Stellar-IX SA | Hosting | Madagascar | RCS Antananarivo 2021 B 00344 |
| Zeop SAS | Hosting | France | SIREN 531 379 295 |
Switzerland and the United Kingdom benefit from a European Commission adequacy decision. Transfers to any country outside the European Union without an adequacy decision (see the "Country" column above) are covered by standard contractual clauses. This list is kept up to date; it does not include sub-processors relating to the "marketplace" products defined in the GTS.
Note: payment and billing providers (Stripe, pawaPay, WHMCS) process identity and payment data for which Hodi acts as controller (Article 20 of the GTS); they fall under Hodi's Privacy Policy, not this DPA.