Data Processing Agreement
The short version
- A Data Processing Agreement (DPA) is the contract that, under EU data-protection law, must be in place whenever one party handles personal data on another party’s behalf. When you host data with us, you decide what that data is and why; we simply process it to run the Services. That makes you the controller and us the processor.
- This DPA is in force by default for every paid account — you do not need to sign anything separately. It forms part of our Terms of Service.
- We process your data only on your instructions and apply the security measures set out in Annex 2.
- Your hosted data stays in Europe. Your websites, databases and our encrypted backups are held within the EU/EEA, with primary infrastructure in the Netherlands — but our helpdesk provider and the edge network that fronts our own websites are established outside the EEA, and our Subprocessors page names every recipient and the safeguard relied on.
- We give you at least 30 days’ notice before adding or replacing a subprocessor, so you can object.
- If there is ever a personal-data breach affecting your data, we notify you without undue delay so you can meet your own 72-hour duty.
- Resold Email (Microsoft 365 / Google Workspace) lives in your own tenant, not on our infrastructure, and is governed by Microsoft’s or Google’s own terms and DPAs — not this one.
This summary is for convenience only. The numbered clauses below are the binding agreement.
1. Background, scope & order of precedence
This DPA (Data Processing Agreement) records the terms on which Maxinodes (“we”, “us”, “our” — Maxinodes Ltd, a private company limited by shares registered in Ireland, registered office 1 Ballycoolin Road, Dublin 15, Ireland) processes personal data on behalf of the Customer (“you”, “your”) in connection with the Services.
It is concluded under and gives effect to Article 28 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Irish Data Protection Act 2018.
This DPA forms part of, and is incorporated into, our Terms of Service (the “Terms”). It is in force by default for every paid account from the moment you place an Order; no separate signature is required, although a signed counterpart is available on request to privacy@maxinodes.com.
This DPA applies only where, and to the extent that, we process personal data on your behalf as a processor in providing the Services. It does not apply to personal data for which we are the controller in our own right (for example, your account, billing and contact data, and our own operational logs); that processing is governed by our Privacy Policy.
Order of precedence. In the event of any conflict on data-protection matters, the documents prevail in this order: (a) this DPA; (b) the rest of the Terms; (c) any other Maxinodes policy. On all matters other than data protection, the Terms prevail over this DPA. Mandatory provisions of applicable data-protection law prevail over all of them.
Duration. This DPA takes effect when you first place an Order and continues for as long as we process personal data on your behalf. It terminates automatically with the main contract under the Terms, save that any provisions which by their nature should survive (including confidentiality and the return-or-deletion obligations in clause 11) survive termination.
2. Definitions & roles
Capitalised terms not defined here have the meaning given to them in the Terms. The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “special categories of personal data”, “personal data breach” and “supervisory authority” have the meanings given to them in the GDPR.
2.1 Roles of the parties
In respect of personal data contained in the Content / Customer Data that you store on, or transmit through, the Services:
- the Customer is the controller (or, where the Customer itself acts as a processor for a third party, the processor); and
- Maxinodes is the processor (or, where applicable, the sub-processor) acting on the Customer’s behalf.
You confirm that you are entitled to transfer the Customer Data to us so that we may lawfully process it in accordance with this DPA and your instructions, and that you have a lawful basis for that processing and have provided all required notices to data subjects.
2.2 Resold Email carve-out
Resold Email (Microsoft 365 or Google Workspace mailboxes resold by us) is hosted in the Customer’s own tenant with Microsoft or Google. The personal data in those mailboxes does not sit on Maxinodes infrastructure and is outside the scope of our processing under this DPA. For Resold Email, the relevant provider (Microsoft or Google) is your processor, under that provider’s own terms, DPA and security commitments. Our only role is to resell the licences; we do not access mailbox content as part of that role.
3. Details of the processing
The subject-matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1 (Details of the processing), which forms part of this DPA. Because the Services are general-purpose hosting, the precise personal data processed depends on what you choose to store and transmit; Annex 1 describes the typical, default position and the categories within which your actual use will fall.
4. Processing on documented instructions
We process personal data only on your documented instructions, including with regard to transfers, unless required to do otherwise by EU or Irish law to which we are subject; in that case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (GDPR Art. 28(3)(a)).
Your documented instructions are made up of: (a) this DPA and the Terms; (b) your configuration and use of the Services through the Client Area and the Services themselves; and (c) any further written instructions you give us — through the Client Area, or in writing to privacy@maxinodes.com — that are consistent with the Terms. Instructions that go beyond the standard functionality of the Services may be subject to a separate agreement, including on cost.
We will inform you without undue delay if, in our opinion, an instruction infringes the GDPR or other EU or Irish data-protection law. We may suspend performance of the affected instruction until you confirm, amend or withdraw it; we are not obliged to carry out an instruction we reasonably believe to be unlawful.
5. Confidentiality
We ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (GDPR Art. 28(3)(b)). That obligation survives the end of their engagement with us.
Access to personal data processed under this DPA is granted on a need-to-know basis only, under the principle of least privilege, and is limited to personnel and subprocessors who need it to provide, secure or support the Services.
6. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (GDPR Art. 28(3)(c) and Art. 32).
The measures we maintain are set out in Annex 2 (Technical & organisational measures), which forms part of this DPA. We may update these measures from time to time provided the level of protection is not materially reduced. You are responsible for assessing whether those measures meet your requirements and for the security of anything within your own control (including your application code, credentials, access management and the configuration choices you make in the Client Area and within your environment).
7. Subprocessors
You give us a general written authorisation to engage subprocessors to carry out specific processing activities on your behalf (GDPR Art. 28(2) and (4)). A current list of our subprocessors is maintained on the Subprocessors page.
7.1 Notice and right to object
We will give you at least 30 days’ prior notice of any intended addition or replacement of a subprocessor, by updating the Subprocessors page and, where you have subscribed to change notifications, by email.
Advance notice is not always possible. Where a provider fails or withdraws a service, where a security or continuity problem leaves us no reasonable alternative, or where the change has already had to be made, we will instead give notice as soon as reasonably practicable. In that case the notice period, and the objection right in the next paragraph, run from the date the notice is published rather than from the date of the change — so the right is not extinguished by the change happening first. The change history on the Subprocessors page records each change, the date it actually took effect, and which of these two routes applied. We would rather give you a late notice with the true dates than a re-dated page that implies nothing happened.
Within the notice period you may object on reasonable, data-protection-related grounds by writing to privacy@maxinodes.com. If we cannot accommodate a well-founded objection, you may terminate the affected Services on written notice as your sole remedy, in accordance with the Terms.
7.2 Flow-down of obligations
Where we engage a subprocessor, we do so under a written contract that imposes on it data-protection obligations equivalent in substance to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a subprocessor fails to fulfil its data-protection obligations, we remain fully liable to you for the performance of that subprocessor’s obligations.
8. Assisting with data-subject requests
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR — access, rectification, erasure, restriction, data portability, and objection (GDPR Art. 28(3)(e)).
If we receive a request directly from a data subject relating to personal data we process on your behalf, we will not respond directly (except to confirm that the request should be directed to you) and will, unless legally prohibited, forward the request to you without undue delay. The Client Area also gives you self-service tools to access, export and delete much of the Customer Data directly.
Requests sent to privacy@maxinodes.com are received through our helpdesk platform, operated by Zendesk, Inc. (United States), so a request forwarded to you under this clause — and anything attached to it, including identity evidence — will have been stored there. Where you or a data subject would rather that did not happen, write to us by post, or to billing@maxinodes.com, which reaches us directly, and we will handle the request outside the helpdesk.
9. Assisting with security, breaches & DPIAs
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with your obligations under GDPR Articles 32 to 36 (GDPR Art. 28(3)(f)), namely:
- Security of processing (Art. 32) — by maintaining the measures in Annex 2 and making available the information described in clause 12;
- Personal-data-breach notification (Arts. 33–34) — by notifying you and providing the information described in clause 10;
- Data-protection impact assessments and prior consultation (Arts. 35–36) — by providing, on reasonable request, the information about the Services within our possession that you reasonably need to carry out a DPIA or to consult the supervisory authority.
Where the assistance you request goes beyond the standard information and tooling we make available, we may charge our reasonable costs, notified to you in advance.
10. Personal-data-breach notification
We notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf (GDPR Art. 33(2)). Our notification will, to the extent then known and to help you meet your own 72-hour duty under Art. 33(1), describe:
- the nature of the breach, including, where possible, the categories and approximate number of data subjects and of personal-data records concerned;
- the likely consequences of the breach;
- the measures taken or proposed to address the breach and mitigate its possible adverse effects; and
- a contact point from whom you can obtain more information.
Where it is not possible to provide all of this information at once, we may provide it in phases without further undue delay. Notifications are routed through privacy@maxinodes.com, and, for abuse- or security-incident reports, abuse@maxinodes.com. It remains your responsibility as controller to assess the breach and to notify the supervisory authority and, where required, affected data subjects; we do not make those notifications on your behalf unless separately agreed in writing.
11. Return or deletion on termination
On termination of the Services to which the processing relates, we will, at your choice, either return the Customer Data to you or delete it, and delete existing copies, unless EU or Irish law requires storage of the personal data (GDPR Art. 28(3)(g)).
You may make your choice through the Client Area or by writing to privacy@maxinodes.com. In the absence of a documented instruction, and following a reasonable retrieval window after termination, we will delete the Customer Data.
Three practical limits apply, and we would rather set them out than let the obligation read as broader than we can perform:
- Legal retention. Where we are required by law to retain certain data (for example, records needed for tax or accounting purposes), we will retain only that data, only for as long as required, and continue to protect it under this DPA.
- Backup cycle. Encrypted backups, which are stored within the EU/EEA, are overwritten on their normal rotation cycle. Data persisting only in those backups is isolated from active processing and is deleted in the ordinary course as the backups expire.
- Support correspondence. Where you or your users have put Customer Data into a support ticket, a chat conversation or an email to us, a copy of it sits on the helpdesk platform described in clause 13 and Annex 3. On termination, or at any time on request, we will delete the tickets and end-user records relating to your account on that platform, and we will tell you what has been deleted. Two limits are worth knowing about before you rely on this: our current helpdesk plan provides deletion of tickets and end users, but not automated retention schedules or field-level redaction, and we cannot reach that provider’s own backups, from which deleted data ages out on the provider’s cycle. If Customer Data must not go to a third-country helpdesk at all, do not paste it into a ticket — tell us and we will agree a different route.
12. Audits & information
We make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you (GDPR Art. 28(3)(h)).
In the first instance, we satisfy this obligation by providing the documentation we maintain about the Services, including the measures in Annex 2 and answers to your reasonable written security questionnaires. Where that is not sufficient for your demonstrable compliance, you may carry out an audit on the following basis:
- on reasonable prior written notice (normally at least 30 days);
- at most once per calendar year, unless a more frequent audit is required by a competent supervisory authority or following a personal-data breach affecting your data;
- during European business hours, in a manner that does not unreasonably disrupt our operations or compromise the confidentiality or security of other customers’ data;
- under an obligation of confidentiality, with any third-party auditor not being a competitor of ours and bound to confidentiality; and
- with each party bearing its own costs, save that we may charge our reasonable costs for audit support that goes materially beyond providing existing documentation.
13. International transfers
Customer Data for the hosting Services is processed and stored in enterprise data centres in the Netherlands. Customer websites are served directly from those data centres and do not pass through a content-delivery or edge network. Our encrypted backups are stored within the EU/EEA, in Amsterdam; they are encrypted on our own infrastructure before upload and the encryption key is held only on our own hardware, so the storage provider holds Customer Data solely in a form it has no means to read.
Providing the Services nevertheless requires transfers of personal data to third countries. Those transfers, the importers, the processing each carries out and the Article 46 mechanism relied on for each are identified in Annex 3 and on the Subprocessors page. In summary, and as at the date of this DPA:
- Technical support — the processing purpose recorded in Annex 1 — is delivered through Zendesk, Inc., a Delaware corporation established in the United States. Support tickets, live chat, contact-form enquiries and inbound mail to our role addresses are held on its platform. That data currently sits in Zendesk’s Europe (Ireland) region, but we have not obtained a contractual commitment to that region and Zendesk reserves the right to move account data between its regions; personal data reaches the United States in any event, through Zendesk’s own operations and the United States sub-processors it names. We therefore treat this as a transfer to the United States and rely on the safeguards rather than on where the data happens to sit today: Zendesk’s published data processing agreement relies on Binding Corporate Rules approved by the Irish Data Protection Commission, and on the European Commission’s Standard Contractual Clauses; Zendesk, Inc. is additionally certified under the EU–US Data Privacy Framework.
- Edge delivery and request filtering for our own websites and the Client Area is provided by Microsoft over a global network, which processes request metadata — including the IP addresses of the individuals who visit those sites — at whichever point of presence is nearest, including points of presence outside the EEA. This does not apply to Customer websites, which are not behind that network. Microsoft Corporation, the group parent, is established in the United States. Microsoft’s Products and Services Data Protection Addendum applies the European Commission’s 2021 Standard Contractual Clauses to transfers of customer data out of the EEA within the Microsoft group; Microsoft Corporation is additionally certified under the EU–US Data Privacy Framework.
- Encrypted backup storage is provided by Backblaze, Inc., a United States company, from a facility in Amsterdam. Its data processing agreement for EEA residents incorporates the European Commission’s Standard Contractual Clauses.
Each of those mechanisms is published by the importer, and Annex 3 links to it. Before we add a new importer we will update the Subprocessors page in accordance with clause 7 and put the transfer mechanism in place. We will provide such further information about the safeguards applying to a transfer as we hold, on written request to privacy@maxinodes.com.
For the avoidance of doubt, the Resold Email path (clause 2.2) is separate: any transfer of mailbox data is carried out by Microsoft or Google under their own terms, DPAs and transfer mechanisms (including SCCs), not by us.
14. Liability
Each party’s liability arising out of or in connection with this DPA is subject to, and counts towards, the limitations and exclusions of liability set out in the Terms. Nothing in this DPA increases or extends those limits; this DPA does not create a separate liability cap.
Nothing in this DPA or the Terms limits any liability that cannot be limited or excluded under applicable law, including liability under Article 82 of the GDPR towards data subjects. As elsewhere in our documents, nothing in this DPA affects your mandatory statutory rights as a Consumer; where you are a Consumer, the consumer-protective provisions of the Terms (including any narrower liability framework that applies in your favour) prevail over any provision of this DPA that would otherwise be less favourable to you.
15. Annex 1 — Details of the processing
This Annex sets out the details of the processing as required by GDPR Art. 28(3). Because the Services are general-purpose hosting, your actual personal data depends on what you choose to store and transmit; the table below describes the default position and the categories within which your use will fall.
| Item | Details |
|---|---|
| Subject-matter | Provision of the Services — Self-Managed Services (Lite, Plus, Pro) and Managed Services (Starter, Growth, Business, Enterprise) — comprising the hosting, storage, processing, transmission and backup of the Customer Data that the Customer stores on, or transmits through, the Services. |
| Duration | For the term of the main contract under the Terms, and thereafter until the Customer Data is returned or deleted in accordance with clause 11 (subject to legal-retention and backup-cycle exceptions). |
| Nature & purpose | Hosting and operating the Customer’s websites, applications, databases and files; storing and transmitting the Customer Data; creating and storing encrypted backups within the EU/EEA; and maintaining the security, integrity and availability of the Services, including automated malware scanning on the shared hosting platform. For Managed Services we additionally operate the underlying environment on the Customer’s behalf; Self-Managed Services are self-managed by the Customer. Two operations are carried out through third parties and are called out separately because a reader is entitled to know that personal data leaves our own systems: (a) technical support — receiving, handling and retaining support tickets, chat conversations, contact-form enquiries and support email on a third-party helpdesk platform established outside the EEA, including any Customer Data the Customer or its users choose to put into that correspondence; and (b) edge delivery and request filtering for the Client Area and our own websites, where a third-party global network terminates the encrypted connection, screens the request and logs its metadata. Customer websites are not behind that edge network and are served directly from our data centres in the Netherlands. |
| Types of personal data | Any personal data the Customer includes in the Customer Data, the precise nature of which is determined and controlled by the Customer. Typically this may include identification and contact data, account and login data, transactional and order data, communications, technical identifiers (such as IP addresses and device data) and usage data of the Customer’s own users and contacts. The Customer must not store special categories of personal data or other high-risk data on the Services unless it has implemented the additional safeguards its own risk assessment requires and remains responsible for the lawfulness of doing so. Two further categories arise from the operations described above: whatever personal data the Customer or its users place in support correspondence with us — message content, attachments, pasted logs, database extracts, screenshots, and the contact details of the people named in them; and the request metadata generated when the Customer’s authorised users reach the Client Area — IP address, browser user-agent, the address requested and the technical details of the connection. Please do not paste credentials into support correspondence; we will never ask for your Client Area password. |
| Categories of data subjects | The data subjects whose personal data is contained in the Customer Data, as determined by the Customer. Typically this may include the Customer’s own customers, end users, website visitors, employees, contractors, suppliers and other contacts. It also includes the Customer’s own personnel and authorised users who contact our support channels or sign in to the Client Area, and any individual the Customer names in support correspondence. |
| Controller / processor | Customer = controller (or processor for a third party). Maxinodes = processor (or sub-processor). |
16. Annex 2 — Technical & organisational measures
This Annex describes the technical and organisational measures we maintain under Article 32 of the GDPR, organised by security goal. These are the ordinary, good-practice measures appropriate for our Services; we may update them provided the level of protection is not materially reduced. We make no certification claims of any kind.
16.1 Confidentiality
- Encryption in transit using current TLS. Customer websites are served directly from our servers in the Netherlands over TLS. Traffic to our own website and to the Client Area is encrypted from your browser to our content-delivery and security provider’s edge, where TLS is terminated and the request is screened, and separately re-encrypted from that edge to our servers. Only public marketing pages are cached at that edge; Client Area responses are never stored there, and customer websites do not traverse it at all.
- Encrypted backups. Off-site backups are encrypted on our own infrastructure before they leave it, with the encryption key held only on our own hardware and never given to the storage provider, and are stored within the EU/EEA. Live data at rest on our servers is not protected by full-disk encryption: it is protected by per-customer logical isolation, filesystem permissions, least-privilege access control and physical access control at the data centre. We state that plainly because a controller assessing its own Article 32 position needs to know it.
- Credentials are held in a form designed not to be reversible: Client Area account passwords are stored as salted one-way hashes and never in plain text, and administrative secrets are kept outside the web root with restricted file permissions.
- Access controls on a least-privilege, need-to-know basis. Administrative access to our servers is by SSH key only, with password authentication disabled for administrator logins. Two-factor authentication is enabled on the administrative interfaces of our virtualisation host and of the hosting platform, and is available to you on your own Client Area account. Customer SFTP and SSH accounts on the hosting platform may use either a password or a key, as you prefer.
- Physical security at enterprise data centres in the Netherlands, operated by our infrastructure provider under its own access-control regime. That provider has physical custody of the disks but no administrative access to the systems running on them.
- Personnel bound to confidentiality (clause 5) and granted access only as needed for their role.
16.2 Integrity
- Separation and logical isolation of customer environments on the hosting platform, and of the virtual machines that make up our estate.
- Network firewalling at more than one layer: a default-deny firewall on the virtualisation host, a separate firewall policy applied to each individual virtual machine, and firewalling on the hosting platform itself, together with brute-force protection that automatically blocks repeated failed logins on our virtualisation host and on the hosting platform.
- Request filtering. Requests to our website and the Client Area pass through a content-delivery and security edge that provides anycast DDoS absorption, an IP blocklist and per-IP rate limiting, and blocks matching requests automatically. It is not a managed rule set and we will not describe it as one: the substantive filtering — refusing access to configuration files, hidden files and known credential-scanning paths, and rate-limiting form submissions — is performed by our own servers behind it. Customer websites are not served through that edge at all.
- Automated malware scanning on our shared hosting platform, which inspects files as they are written and on a schedule, to detect malicious and compromised files. The scanning runs on our own servers: customer file content is not uploaded to the scanning vendor for analysis. The scanning software does send its own diagnostic and error telemetry to its vendor.
- Change management and the use of secure administrative channels for system access.
- Logging and monitoring of access to, and changes within, the infrastructure, to support accountability and to detect unauthorised processing. Request logs generated at the content-delivery edge — client IP address, user agent, requested URL and connection metadata — are collected at the serving edge location, which may be outside the EEA, and retained for 30 days in a log workspace in the EU.
16.3 Availability & resilience
- Operation in enterprise data centres with resilient power, cooling and network connectivity.
- Continuous monitoring of the platform, network and facilities; incidents are communicated via the SLA process and on the Status Page (status.maxinodes.com), with our monitoring systems as the authoritative measurement source.
- Regular encrypted backups, encrypted on our own infrastructure before they leave it and stored within the EU/EEA, with restores tested rather than assumed.
16.4 Restore
- The ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident, from the encrypted backups described above.
16.5 Regular testing & evaluation
- A process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures, including reviewing access rights, applying security updates, and verifying that backups can be restored.
17. Annex 3 — Subprocessors
We engage subprocessors as authorised under clause 7. The current list is maintained on the Subprocessors page, which forms part of this Annex. That page names each subprocessor individually and gives, for each, its legal entity, its country of establishment, what it does for us, where the processing actually takes place, which Services it applies to and, for recipients outside the EEA, the transfer mechanism relied on.
As at the date of this DPA, the subprocessors engaged in providing the Services include Worldstream (Netherlands — the dedicated server, network capacity and data-centre facility on which everything runs), Microsoft (edge delivery and request filtering for our own websites and the Client Area, DNS for our own corporate domains, and the mail platform through which our published addresses are received), BunnyWay d.o.o. (Slovenia — authoritative DNS for customer domains), Backblaze, Inc. (encrypted backup storage in Amsterdam), Zendesk, Inc. (United States — the helpdesk on which support correspondence is received and held), Key-Systems GmbH (Germany — domain registration, where you register a domain through us) and UptimeRobot s. r. o. (Slovakia — availability monitoring and the Status Page). The Subprocessors page also identifies two organisations that are not our processors, and explains why they are listed anyway.
Each of these providers publishes the data-protection terms and, where it is outside the EEA, the transfer mechanism referred to in clause 13:
- Worldstream — legal and privacy documents
- Microsoft (edge, DNS and our mail platform) — Products and Services Data Protection Addendum
- BunnyWay d.o.o. — sub-processor list
- Backblaze, Inc. — data processing agreement for EEA and EU residents
- Zendesk, Inc. — data processing agreement and sub-processor list
- Key-Systems GmbH — GDPR information
- UptimeRobot s. r. o. — data processing agreement
Where you purchase Resold Email, Microsoft or Google acts in respect of your own tenant under its own terms and DPA, as described in clause 2.2, rather than as our subprocessor under this DPA.
What changed in this version. This version was published on August 7, 2026 to record four infrastructure changes and the transfers that follow from them: authoritative DNS for customer domains moved to an EU provider on July 26, 2026; our own websites and the Client Area were placed behind Microsoft’s global edge network and our corporate DNS moved to Azure DNS on August 4, 2026; and support moved from our own self-hosted helpdesk to Zendesk, Inc. in the United States on August 6, 2026. Customer websites were not affected by any of them and are still served directly from our servers in the Netherlands. Clause 13, Annex 1, Annex 2 and Annex 3 were rewritten accordingly, and the notice mechanism in clause 7.1 was amended so that it can be performed. The full record is in the change history on our Subprocessors page.
Contact
Data-protection and DPA enquiries: privacy@maxinodes.com.
By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.
Mail sent to that address reaches our own Microsoft 365 tenant in the EU and is then forwarded into our helpdesk platform, operated by Zendesk, Inc., a Delaware corporation established in the United States. Your message, anything attached to it and our correspondence about it are stored there. Our account data is currently held in its Europe (Ireland) region, but we have no contractual commitment to that region, and the provider and its named United States sub-processors can reach that data from the United States — so it is processed outside the EEA. If you would rather your message did not pass through a third-party helpdesk — for example because it includes identity documents, or because it names someone else — write to us by post at the address above, or email billing@maxinodes.com, which reaches us directly.
If you have a concern about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the supervisory authority in Ireland:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence.