Purpose
This draft DPA is intended for customers who process personal data on self-managed VPS services provided by Senra Cloud. It must be reviewed and completed before production use.
This draft DPA is intended for customers who process personal data on self-managed VPS services provided by Senra Cloud. It must be reviewed and completed before production use.
The customer is generally the controller for data processed inside the VPS. Senra may act as processor for infrastructure-related processing where it can technically access or process customer data for service delivery.
Processing relates to hosting, provisioning, maintenance, support, backups if booked, monitoring if booked and abuse/security handling. Duration follows the customer contract and legal retention obligations.
Possible data includes customer account data, server identifiers, technical logs, support content and any data the customer stores on the VPS. The final categories must be completed for the production DPA.
Measures may include access control, account separation, secure credential handling, encrypted transport, logging, provider-side security controls and abuse response processes. Exact measures must be documented.
Potential sub-processors include Cloudflare, WHMCS hosting/provider stack, upstream cloud infrastructure providers, payment providers, monitoring providers and accounting tools. The final list must be published and maintained.
After contract end, customer data is deleted or returned according to the final terms, technical feasibility and legal retention duties.