Skip to content
Host Little logo markHost Little

Data Processing Addendum

Effective: August 21, 2026

This Data Processing Addendum (“DPA”) forms part of the Host Little Terms when a customer uses the service to process personal data subject to applicable data-protection law. It is effective without a separate signature for that processing.

The customer is the controller, or a processor acting for its controller. Host Little Inc. is the processor or subprocessor for customer personal data. Host Little is a controller for its own account, billing, security, and business records as described in the Privacy Notice.

Processing details

Subject and durationBuilding, hosting, delivering, securing, backing up, supporting, exporting, and deleting customer workloads for the service term and stated post-termination retention.
Nature and purposeAutomated compute, storage, networking, database, email, observability, support, abuse prevention, and incident-response operations selected or initiated by the customer.
Data subjectsThe customer's users, employees, contractors, customers, visitors, and other people whose data the customer submits.
Personal dataIdentifiers, contact details, authentication data, communications, logs, network identifiers, and application or database content chosen by the customer.
Customer rightsThe customer keeps the rights and obligations of a controller under applicable law and may issue lawful instructions through the service, support, or a signed order.

Documented instructions and confidentiality

Host Little processes customer personal data only on documented instructions, including the Terms, this DPA, the customer's configuration and use of the service, and written support requests. We will notify the customer if an instruction appears to violate applicable data-protection law, unless law prevents notice. If law requires processing beyond the customer's instructions, we will notify the customer before processing unless prohibited.

People authorized to process customer personal data are bound by confidentiality and receive access only as needed for their role. The customer is responsible for lawful instructions, notices, legal bases, permissions, and its own application access controls.

Security measures

Host Little maintains measures appropriate to the service and risk, including encrypted network transport; scoped access and secret handling; tenant separation for source, caches, releases, runtime data, and database credentials; logs and incident response; backups and restoration where the plan states them; and controlled deletion workflows. Current public details are on the security page.

These measures do not claim a certification or make the service suitable for every type of regulated or high-risk data. The customer must not submit protected health information, payment-card data, government identifiers, biometric data, or other regulated sensitive data unless Host Little has agreed in writing to the required safeguards and contract.

Requests, incidents, and audits

  • We will reasonably assist with data-subject requests, security obligations, regulator consultations, and required impact assessments, considering the nature of processing and information available to us.
  • We will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for the customer's response.
  • We will provide information reasonably necessary to demonstrate compliance with this DPA. Once per year, or after a confirmed breach, the customer may request a reasonable remote audit. On-site audits require advance agreement, confidentiality, and reimbursement of reasonable costs unless law requires otherwise.
  • We will refer a government demand for customer data to the customer when legally permitted and challenge requests we reasonably believe are unlawful or overbroad.

Subprocessors

The customer gives general written authorization for the providers needed to deliver the selected service. Each subprocessor must be bound to data-protection obligations that are no less protective for the relevant processing. Host Little remains responsible for its subprocessor obligations under this DPA.

The current core provider register is published below. Not every provider applies to every customer. We will give at least 14 days' notice by email or in the portal before a material new subprocessor begins processing customer personal data when practical. The customer may object during that period on reasonable data-protection grounds. We will work in good faith on an alternative; if none is reasonable, either party may end the affected service.

ProviderPurposeLocation note
Amazon Web ServicesApp builds, runtime, image registry, object storage, delivery, and logsUnited States; current v3 App Hosting is based in us-east-1
CloudflareDNS, TLS, edge delivery, abuse controls, and optional object storageGlobally distributed edge network
DigitalOceanPlatform control plane and database infrastructureUnited States; current database infrastructure is based in NYC3
HetznerLegacy application runtime while projects move to v3United States or European Union, depending on the project
OVHcloudLegacy isolated application builds while projects move to v3United States
GitHubAccount sign-in and optional repository or source integrationVendor-managed locations
StripeCheckout, payments, invoices, refunds, and billing recordsVendor-managed locations
ResendAccount sign-in links and Host Little service emailVendor-managed locations
Microsoft Azure Communication ServicesOptional customer transactional emailRegion configured for the enabled email service

Locations and international transfers

Account and control-plane data is primarily processed in the United States, while edge traffic may be processed globally. Workload placement is the region shown for the project; it is not an exclusive residency promise for support, logs, account data, edge delivery, or all subprocessors. Current v3 App Hosting is based in AWS us-east-1, and current database infrastructure is based in DigitalOcean NYC3. Legacy workloads may use United States or European Union infrastructure during migration.

If restricted data requires a transfer mechanism, the parties will use an applicable lawful safeguard. For EEA transfers not otherwise covered by an adequacy decision, Host Little will make the applicable EU Standard Contractual Clauses and reasonable supplementary information available on request. Customers needing strict residency or a signed transfer schedule must arrange it before uploading the affected data.

Return and deletion

During an active service, the customer may use the export methods the product provides. At termination, Host Little will delete or return customer personal data at the customer's choice where the service supports that choice, then delete remaining copies on the schedules in the Terms and Privacy Notice, unless law requires retention. Active project or database deletion may be immediate. Current database backups rotate after seven days, current restore copies expire after 72 hours, and other supported production data is normally removed within 30 days.

This DPA controls over conflicting Terms only for processing customer personal data. To request a signed copy, transfer schedule, or assistance, email [email protected] from an account-owner address.