Bring your server over

Migrate your existing server to InstantNode in minutes.

Try the Server Importer
Legal

Data Processing Agreement

Last updated: August 23, 2026 (v1.0)

English version · Deutsche Fassung

This Data Processing Agreement (DPA) applies between the customer as controller and InstantNode as processor within the meaning of Article 28 GDPR, wherever the customer stores or processes personal data of their own users on infrastructure booked from InstantNode. It supplements our Terms of Service. Where the customer accepts it electronically in the panel or in text form, the requirement of Article 28(9) GDPR is met.

For the personal data of the customer themselves, in particular account, billing and support data, InstantNode is the controller. That processing is governed by our Privacy Policy and not by this DPA.

1. Subject matter, nature and purpose

InstantNode processes personal data on behalf of the customer exclusively to provide the booked hosting, server, infrastructure and management services, including operation, storage, backup, monitoring, abuse defence and support. The processing consists of storing, hosting, transmitting, backing up and, where technically necessary for the provision of the service, otherwise handling the data.

The duration of the processing corresponds to the term of the underlying service. The types of personal data and the categories of data subjects are determined by the customer, since InstantNode has no influence on which content the customer stores. Typically they include contact and account data, usage and connection data, communication content and any other data the customer chooses to store, relating to the customer's own customers, employees, users or communication partners.

2. Instructions

InstantNode processes the data only on documented instructions from the customer. The booking of a service and the settings made in the panel constitute such an instruction. Verbal instructions must be confirmed in text form. InstantNode informs the customer without undue delay if, in its opinion, an instruction infringes data protection law, and may suspend the execution of that instruction until it is confirmed or changed. Where InstantNode is required by Union or Member State law to process the data otherwise, it informs the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3. Confidentiality

InstantNode ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they are instructed in the applicable data protection requirements.

4. Security of processing

InstantNode implements the technical and organisational measures set out in Annex 2 in accordance with Article 32 GDPR. The measures are subject to technical progress; InstantNode may replace them with equivalent or better measures. A reduction of the level of protection is not permitted.

5. Sub-processors

The customer grants general written authorisation for the engagement of sub-processors. The sub-processors engaged at the time this DPA is concluded are listed in Annex 3. InstantNode imposes on every sub-processor data protection obligations equivalent to those in this DPA and remains fully liable to the customer for their performance.

InstantNode informs the customer of any intended addition or replacement of a sub-processor at least 14 days in advance in text form or in the panel. The customer may object to the change on reasoned data protection grounds within that period. If the objection is justified and no reasonable alternative exists, the customer may terminate the affected service with effect from the end of the paid period; further claims are excluded.

6. Assistance

Taking into account the nature of the processing, InstantNode assists the customer by appropriate technical and organisational measures in fulfilling the customer's obligation to respond to requests for exercising data subject rights under Chapter III GDPR. Requests addressed directly to InstantNode are forwarded to the customer without undue delay and are not answered by InstantNode itself.

InstantNode assists the customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it. Assistance going beyond the effort typical for the service may be invoiced at the rates then in force, unless the need for assistance is attributable to InstantNode.

7. Personal data breaches

InstantNode notifies the customer without undue delay after becoming aware of a personal data breach affecting data processed on behalf of the customer, and provides the information available to it that the customer needs for its own notification under Articles 33 and 34 GDPR.

8. Deletion and return

After the end of the service, InstantNode deletes the data processed on behalf of the customer, including existing backups, unless Union or Member State law requires further storage. Backups are deleted when the service ends; log data is deleted after the retention periods stated in the Privacy Policy. Before the service ends, the customer is responsible for exporting their data through the functions available in the panel.

9. Evidence and audits

InstantNode makes available to the customer the information necessary to demonstrate compliance with the obligations under Article 28 GDPR, as a rule in the form of this DPA, Annex 2 and written information. Where this is not sufficient, the customer may carry out an inspection or have one carried out by an auditor bound to confidentiality and not competing with InstantNode, during business hours, after at least four weeks' notice in text form, at most once per calendar year and without disrupting operations. An inspection may not extend to data or systems of other customers. The customer bears the cost of the inspection unless it reveals a material breach attributable to InstantNode.

10. International transfers

The data processed on behalf of the customer is stored in the European Union. Where a sub-processor listed in Annex 3 processes data outside the EU or the EEA, this takes place only on the basis of an adequacy decision, the EU Standard Contractual Clauses or another safeguard permitted under Chapter V GDPR.

11. Liability and precedence

Liability is governed by Article 82 GDPR and, as between the parties, by the liability provisions of the Terms of Service. In the event of contradictions, this DPA takes precedence over the Terms of Service in matters of processing on behalf of the customer.

Annex 1: Details of the processing

  • Subject matter: provision of the hosting, server and infrastructure services booked by the customer.
  • Duration: the term of the respective service.
  • Nature and purpose: storage, hosting, transmission, backup, monitoring, abuse defence, support.
  • Types of personal data: determined by the customer; typically master and contact data, access and usage data, connection and log data, communication content, payment-related data and any further content stored by the customer.
  • Categories of data subjects: determined by the customer; typically the customer's own customers, users, members, employees and communication partners.

Annex 2: Technical and organisational measures (Art. 32 GDPR)

  • Physical access control: the servers are operated in a data centre of Skylink Data Centers B.V. in the Netherlands with the access controls, power and fire protection measures customary there. InstantNode has no data centre of its own.
  • System access control: individual accounts, passwords stored only as cryptographic hashes, two-factor authentication and passkeys (WebAuthn) available and recommended for all accounts, session management with expiry, administrative access restricted to the owner and to persons expressly authorised by him and bound to confidentiality.
  • Data access control: role-based permissions in the panel, separation of customer, reseller and administrator roles, logging of administrative actions.
  • Separation control: tenant separation through virtualisation (KVM and LXC under Proxmox), container isolation for bot hosting, separate credentials and networks per instance.
  • Transmission control: TLS encryption for the website, the panel and the API; encrypted administrative access.
  • Network security: packet filtering at host level, per-instance egress filtering, DDoS protection at the data centre and through the upstream CDN and proxy.
  • Availability control: monitoring and a public status page, optional customer-configured backups with at most five rolling copies, target availability of 99.9 % as an annual average.
  • Input control: access logs retained for 14 days, error logs for 30 days, security and audit logs for 90 days, each with automatic deletion afterwards.
  • Deletion control: deletion of customer data and backups when the service ends; scheduled deletion of log data.
  • Organisational measures: written confidentiality commitments, documented incident response and notification process, review of the measures when systems change.

Annex 3: Sub-processors

  • Skylink Data Centers B.V., Netherlands: data centre and physical server infrastructure. Processing location: EU.
  • Cloudflare: content delivery network, reverse proxy and DDoS protection. Processing location: EU and USA, on the basis of the EU Standard Contractual Clauses and the EU-US Data Privacy Framework.
  • Feather: game server management interface, where the customer books a game server. The current registered office and processing location are provided on request.
  • Porkbun LLC, USA: domain registration and WHOIS data, where the customer registers or transfers a domain. Processing location: USA, on the basis of the EU Standard Contractual Clauses.

Payment service providers (Stripe, PayPal, OxaPay) act as independent controllers for the payment transaction and are therefore not sub-processors within the meaning of this DPA.

This list is current as at the date shown at the top of this page. Changes are announced in accordance with Section 5.