Skip to main content

Data Processing Agreement (DPA)

Last updated: September 29, 2026

1. Parties and Purpose​

The infrastructure provider is AdaptGroup LLC, a company registered in Wyoming, USA, registration number 2026-002012463. Address: 30 N Gould St Ste R, Sheridan, WY 82801, USA.

This agreement governs processing of personal data that the customer places on AdaptGroup virtual machines and dedicated servers. It supplements the Infrastructure Terms and applies whether the service is ordered through Cloud Bots, Cloud API, or a partner.

The customer determines the purposes for which the hosted data is used, and AdaptGroup processes it on the customer's behalf when providing infrastructure. In GDPR terminology, these are the roles of controller and processor. If the customer itself processes data on another party's behalf, AdaptGroup acts as a subprocessor. The customer must have the necessary authority to engage AdaptGroup in that role.

Ordering through a partner does not, by itself, determine the parties' roles. These depend on who makes processing decisions and on whose behalf the service is provided. Notices and instructions follow the agreed contractual chain.

This agreement does not replace the privacy policy for account, payment, and support data that AdaptGroup uses for its own purposes. The purpose of technical logs is also considered when determining AdaptGroup's role; not all logs are automatically data processed on the customer's instructions.

2. Data and Operations Covered​

ParameterProcessing instructions
Subject matterPersonal data in the customer's systems and applications on rented resources
PurposeProviding computing, storage, and network communication resources for the customer's purposes
OperationsStorage, transmission, technical relocation, and deletion of data; access for agreed support
Data subjectsUsers, customers, employees, representatives, and other persons whose data the customer lawfully places in its systems
Possible data categoriesContact and account data, identifiers, IP addresses, user activity information, and the contents of files, databases, and correspondence, depending on the customer's application
DurationThe service period and subsequent conclusion of processing under Section 9

The actual data and data subjects depend on the customer's purposes. The customer provides the information needed to describe the processing and select protective measures without disclosing unnecessary contents of its systems. Where needed, the parties specify the details in the order or a separate annex.

Medical, biometric, and other sensitive personal data are not prohibited solely because of their category. The customer ensures lawful processing and appropriate system configuration; AdaptGroup fulfils its own infrastructure protection obligations. Ordinary VPS or dedicated server rental does not automatically meet every requirement applicable to medical, financial, or other regulated systems. Additional requirements must be agreed before such data is hosted.

3. Customer Instructions and Access​

AdaptGroup uses hosted data only to carry out documented customer instructions. These may include order terms, authorized commands in the service or API, and support requests from an authorized representative. AdaptGroup does not use the contents of customer systems for its own advertising or sale of data.

Staff do not routinely inspect the customer's operating system, files, or databases. Assistance inside the operating system requires explicit documented customer permission specifying the task. Access is limited to what is necessary and ends when the task is completed.

Working with the hypervisor, resource status, technical logs, and network metrics to operate and protect the infrastructure does not grant an unrestricted right to read customer files or correspondence. Threat investigations begin with the necessary technical information. Access to content requires a separate instruction or a specific lawful basis.

If AdaptGroup considers an instruction to violate applicable data protection rules, it informs the customer and suspends the disputed operation pending clarification. This does not automatically mean shutting down the entire resource.

Requests from public authorities are assessed for authority, binding effect, and permitted scope of disclosure. The customer is notified before disclosure unless prohibited by law. A foreign request alone does not replace the conditions for a lawful international data transfer.

4. Confidentiality and Security​

AdaptGroup ensures confidentiality obligations for persons authorized to process data and limits access according to their work responsibilities. Security measures are selected with regard to the nature of the data and risks to individuals.

AdaptGroup's responsibilities include protection of hardware and virtualization, control of administrative access, isolation of customer resources, infrastructure maintenance, and incident response. Specific technical and organizational measures must be described in an annex to the published agreement; a general statement about security is not a substitute.

The customer is responsible for accounts, applications, updates, and access rules within its operating system, lawful processing, and backups. This allocation does not relieve AdaptGroup of responsibility for its own processing and infrastructure.

Automatic backups of customer servers are not included in the standard service. The customer arranges backups and restoration checks. Technical copies made during maintenance do not constitute a backup service.

5. Other Processors​

Engaging another organization to process customer data requires the customer's prior written authorization, either specific or general. Under general authorization, AdaptGroup gives advance notice of the addition or replacement of a processor and an opportunity to raise a reasoned objection before that processor begins processing.

Appropriate data protection obligations are imposed on the engaged processor. AdaptGroup remains responsible to the customer for performance of the obligations entrusted to that processor.

The list must identify the legal entity, its function, and the countries of processing. Merely naming a data center or equipment supplier does not determine its role: the role depends on actual operations and access to data.

The list and change procedure have not yet been approved for this version; this version does not grant general authorization for unspecified contractors.

6. Processing Locations and International Transfers​

The server location is determined by the order. It does not mean that all administrative operations, support requests, and processing of service information occur exclusively in the same country. Storage locations and countries from which access may occur must be disclosed for the relevant service.

Transfers subject to restrictions under applicable law are made only where the necessary legal grounds and safeguards are in place. Where the GDPR applies, choosing a server in Europe does not, by itself, authorize subsequent access from third countries or transfer to another organization outside the EEA.

This DPA does not replace Standard Contractual Clauses (SCCs) for international transfers or any required transfer assessment. The mechanism, participants, and supplementary measures are determined separately before the relevant transfer. This agreement does not claim that AdaptGroup participates in any certification scheme.

7. Personal Data Breaches​

AdaptGroup notifies the customer or relevant partner without delay and no later than 24 hours after becoming aware of a personal data breach affecting data under this agreement. A breach includes not only disclosure but also unlawful destruction, loss, alteration, or access.

The initial notice contains the known circumstances, affected resources, likely consequences, measures taken, and a contact for further communication. Categories and approximate volumes of affected data and individuals are provided where known. Incomplete information is not a reason to wait for the investigation to finish: further information is provided as it becomes available.

AdaptGroup takes steps to contain the incident, preserves information needed for investigation, and helps the customer assess the consequences. The partner forwards the notice to the relevant customer without delay.

Notification of supervisory authorities and individuals is carried out by the party legally responsible for doing so. AdaptGroup supplies available information and assistance; the period specified here does not extend the customer's mandatory deadlines.

8. Requests, Assistance, and Audits​

Personal data enquiries are accepted at [email protected]. An additional support channel is @adapt_support. A request need only identify the service, the issue, and an authorized contact; passwords or customer database exports should not be sent unnecessarily.

If an individual contacts AdaptGroup directly about data in a customer's system, AdaptGroup forwards the request to the customer or relevant partner. Customer system contents are not disclosed to the requester without verification of authority and instructions, except where legally required.

Taking account of the nature of processing and available information, AdaptGroup assists with individual rights requests, data protection impact assessments, and necessary consultations with supervisory authorities.

AdaptGroup provides information needed to demonstrate compliance with this agreement and assists with audits, including inspections by the customer or its authorized auditor. Audit arrangements take account of service security and other customers' confidentiality; these restrictions must not deprive the customer of the ability to verify compliance.

9. Conclusion of Processing​

At the end of the service, the customer chooses either return of the data followed by deletion of remaining copies, or deletion. The customer may export data while it has access to the resource; any assistance from AdaptGroup must be requested before deletion is due under the terms. Return of data already deleted is not promised.

The agreed service deadlines remain applicable: an unpaid virtual machine is subject to deletion after 24 hours of non-payment. For a dedicated server, the rental ends after that period, after which an administrator resets and prepares it. This is not a promise to physically erase all media exactly 24 hours after expiry. This agreement provides no additional retention period.

AdaptGroup ensures deletion of data remaining with it and its engaged processors and does not reassign a resource with the previous customer's data accessible. Methods and deadlines for erasing media, technical copies, and logs are documented separately. Deleting a virtual machine record does not, by itself, confirm irreversible erasure of storage media.

If applicable law requires retention of particular data, retention is limited to the necessary data, purpose, and duration. Confidentiality and access restrictions remain in effect until deletion. Retaining billing records for lawful purposes of AdaptGroup does not authorize indefinite retention of the contents of the customer's server.

10. Relationship with Other Terms​

This agreement governs personal data processing on the customer's behalf; rental terms and resource management are governed by the Infrastructure Terms. Mandatory legal requirements and international transfer provisions binding on the parties take precedence. The AUP and termination rules do not cancel obligations to protect data and conclude processing.


All infrastructure documents

© 2026 AdaptGroup LLC. All rights reserved.
30 N Gould St Ste R, Sheridan, WY 82801, USA
Back to top