Panellicense
Legal

Data processing addendum.

Required under Article 28 of the UK and EU GDPR whenever we process personal data on your behalf. Forms part of the service agreement by reference.

Last updated
16 May 2026
Effective
1 June 2026

This addendum (“DPA”) is entered into between you (the “Controller”) and Panellicense Ltd (the “Processor”) and applies whenever the Processor processes personal data on the Controller's behalf in connection with the service agreement. In a conflict between this DPA and the service agreement on data protection matters, this DPA prevails.

1. Scope and roles

For most data we handle (your account, billing, support requests), we act as an independent controller — that is governed by our privacy policy. This DPA applies only to the narrow set of personal data we process strictly on your instructions, for example diagnostic data and end-user identifiers you transmit to us when requesting migration assistance.

2. Subject matter, duration, nature

The subject matter is the processing necessary to provide the service agreement. The duration is the term of the service agreement plus the retention period in section 11. The nature, purpose, categories of data, and categories of data subject are set out in Annex A.

3. Processing instructions

The Processor will process personal data only on the documented instructions of the Controller, including with regard to international transfers, except where required to do so by law — in which case the Processor will inform the Controller before processing, unless the law prohibits this on important grounds of public interest. The service agreement, the order, and this DPA together form the documented instructions.

4. Confidentiality of personnel

The Processor ensures that persons authorised to process personal data are bound by written confidentiality obligations and trained on data protection.

5. Security measures

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex B. The Controller has reviewed these measures and considers them appropriate for the personal data being processed.

6. Sub-processors

The Controller gives general authorisation for the engagement of sub-processors. The current list is in Annex C. The Processor will notify the Controller by email at least 30 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the service agreement without penalty. The Processor remains liable for the acts and omissions of its sub-processors as if they were its own.

7. Data subject rights

Where a data subject contacts the Processor directly to exercise rights, the Processor will (unless legally required to respond) refer them to the Controller and notify the Controller without undue delay. The Processor will assist the Controller, by appropriate technical and organisational measures, to respond to requests within the statutory time limits.

8. Assistance with DPIAs and breach

The Processor will provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and the information available to the Processor. On becoming aware of a personal data breach, the Processor will notify the Controller without undue delay and in any event within 48 hours, providing the information the Controller needs to comply with its own Article 33 notification obligations.

9. International transfers

Where the Processor or a sub-processor processes personal data outside the UK or EEA, the transfer is protected by the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses (Module 2 or Module 3 as applicable), each of which is incorporated by reference. Where SCCs apply, the Controller is the “data exporter” and the Processor (or sub-processor) is the “data importer”.

10. Audit and information rights

The Processor will make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR, including the latest third-party audit reports (e.g. ISO 27001 or SOC 2, where available) on request. The Controller may, no more than once per twelve-month period and on 30 days' written notice, audit the Processor's compliance, subject to reasonable confidentiality undertakings. A supervisory authority may exercise this right at any time as required by law.

11. Deletion and return

On termination of the service agreement, the Processor will, at the Controller's choice, return or delete all personal data processed on behalf of the Controller within 90 days, unless retention is required by applicable law. The Processor will certify deletion on request.

Annex A — Processing details

  • Categories of data subject:the Controller's end users and the Controller's personnel.
  • Categories of personal data: account identifiers (cPanel usernames, Plesk login names), server IPs, hostnames, email addresses contained in server configurations or migration payloads.
  • Special categories: none expected; the Controller agrees not to transmit special-category data.
  • Frequency: on Controller initiation (typically during migration assistance or troubleshooting).
  • Nature and purpose: storage, analysis, and transmission necessary to provide first-line support and license provisioning.
  • Retention: as set out in section 11 and in the privacy policy.

Annex B — Security measures

  • TLS 1.2+ for all data in transit; HSTS enforced on production hosts.
  • AES-256 at rest for the billing database and ticket attachments.
  • Hardware MFA required for all production and admin access.
  • Principle-of-least-privilege role-based access, reviewed quarterly; access revoked within 24 hours of role change.
  • Centralised, tamper-evident logging of administrative actions; 12-month retention.
  • Quarterly third-party penetration tests of the billing portal.
  • Documented incident-response runbook with a 48-hour controller notification SLA.
  • Daily encrypted backups with point-in-time recovery; restore drills every six months.
  • Annual security awareness training for all personnel.

Annex C — Sub-processors

Current list as of 16 May 2026. Live list available at privacy@panellicense.com on request.

  • Stripe Payments Europe Ltd(Ireland) — card processing and invoicing.
  • Amazon Web Services EMEA SARL(Ireland, Germany) — hosting of the billing portal and license-issuance API.
  • Postmark / ActiveCampaign(USA, with SCCs) — transactional email delivery.
  • HelpScout(USA, with SCCs) — support ticketing.
  • BetterStack(Czech Republic) — uptime monitoring and log aggregation.
  • Upstream license vendors— cPanel L.L.C., WebPros International, LiteSpeed Technologies, CloudLinux Inc., Softaculous Ltd. receive the minimum data needed to issue license keys; each is also an independent controller for the use of that data under its own terms.