This Data Processing Agreement ("DPA") sets out the terms on which RackGenius processes personal data on behalf of its customers. It is written to meet Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR, and the processor and service provider requirements of US state privacy laws.

This DPA is incorporated by reference into our Terms of Service and is in effect at all times. It applies automatically, from the moment you begin using our services, to every customer who stores, transmits or processes personal data on our infrastructure. No signature is needed for it to bind us, but we will provide a countersigned copy on request. See How to execute this DPA.

Data importer: Snakecraft Hosting, LLC, doing business as RackGenius, 1887 Holton Rd Ste D PMB 171, Muskegon, MI 49445, United States.
In effect: immediately and continuously. Last updated: August 31, 2026.
Questions, audit requests and signed copies: open a ticket from the client area, or use our contact form if you are not yet a customer.

Contents

  1. Parties and definitions
  2. How this DPA fits with our other terms
  3. Roles of the parties
  4. Scope of the processing
  5. Our obligations as processor
  6. Your obligations as controller
  7. Confidentiality and government access
  8. Security of processing
  9. Sub-processors
  10. International data transfers
  11. Assistance with data subject requests
  12. Personal data breaches
  13. Impact assessments and prior consultation
  14. Retention, return and deletion
  15. Audit rights
  16. Liability and indemnity
  17. US state privacy laws
  18. Term, changes and governing law
  19. How to execute this DPA
  • Annex I – Details of processing
  • Annex II – Technical and organizational measures
  • Annex III – Authorized sub-processors
  • Annex IV – Transfer mechanism details

1. Parties and definitions

This DPA is between:

  • The Processor: Snakecraft Hosting, LLC, a Michigan limited liability company doing business as RackGenius, of 1887 Holton Rd Ste D PMB 171, Muskegon, MI 49445, United States ("RackGenius", "we", "us").
  • The Controller: the person or entity named on the RackGenius billing account under which the services are purchased ("Customer", "you"). Your registered account details identify you for the purposes of this DPA.

Where you are acting as a processor for your own clients, references to you as "controller" should be read as "processor", and we act as your sub-processor. See Section 3.4.

"Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "supervisory authority" and "personal data breach" have the meanings given in the GDPR. "Data Protection Laws" means all privacy and data protection laws applicable to the processing under this DPA, including the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable US state privacy laws. "Customer Data" means any data you or your users store on, transmit through, or process using our services. "Services" means the RackGenius products on your account, including virtual private servers, dedicated servers, colocation, web hosting, game hosting, IP transit and related support.

2. How this DPA fits with our other terms

This DPA forms part of your agreement with us. Where terms conflict, the order of precedence is:

  1. The Standard Contractual Clauses or the UK Addendum, where they apply (Section 10);
  2. This DPA;
  3. Any signed order form or master services agreement between us;
  4. Our Terms of Service and Privacy Policy.

Nothing here reduces the commitments in our Privacy Policy about the personal data we hold on you as our own customer.

3. Roles of the parties

Our role depends on the data, not on the product name. Four situations are distinct.

3.1 Account data – we are the controller

The information you give us to open and run an account (name, business name, billing address, contact details, payment identifiers, support tickets, authentication and access logs) is processed by us as a controller, for billing, fraud prevention, support and legal compliance. That processing is governed by our Privacy Policy rather than this DPA. Three points are worth stating here because customers ask:

  • We do not sell personal data. We do not sell, rent, share for cross-context behavioral advertising, or otherwise monetize any personal data, in any role, under any product.
  • We do not disclose it to third parties beyond the sub-processors listed in Annex III, except where compelled by law under Section 7. Payment data is handled by our payment processors, and nothing else leaves us.
  • Identity and eligibility verification records are collected only where we need to confirm who you are, through our identity verification provider. Review is restricted to company members, and the records are redacted immediately once review is complete. We do not retain copies of verification documents.

Scholarship and community programs we operate are separate controller activities with their own notices, and are not covered by this DPA.

3.2 Customer Data – we are the processor

Any personal data inside your servers, containers, hosting accounts, databases or backups is processed by us as a processor, strictly on your instructions. We do not decide why or how that data is processed, we do not use it for our own purposes, and we do not index, mine, profile or analyze its contents.

3.3 Unmanaged services – processing without routine access

For unmanaged VPS, dedicated servers and colocation, you hold root or physical control and we do not routinely access the operating system or its contents. Our processing there is limited to hosting, powering, storing and transmitting the data, plus any access you specifically ask support to perform. You remain responsible for the configuration, patching and security of everything above the hypervisor or the rack rail. This DPA still applies to that processing.

3.4 Where you are a processor

If you host data for your own clients, you are a processor and we are your sub-processor. You confirm that you are authorized to appoint us, that your agreement with your controller permits it, and that your instructions to us reflect that controller's instructions. Module Three of the Standard Contractual Clauses applies to any restricted transfer.

4. Scope of the processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

Because you control what you upload, we do not know the specific categories of personal data in your environment unless you tell us. Annex I therefore describes the outer boundary of what our services are capable of processing. If your use case involves special category data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation) or genetic data, open a ticket before you upload it so we can confirm whether the service is suitable and whether additional terms are needed.

Data we do not accept. Accounts are limited to individuals aged eighteen or over, and the services are not intended for personal data about children.

5. Our obligations as processor

We will:

  1. Process only on your instructions. We process Customer Data only on your documented instructions, including for international transfers, unless required otherwise by law. Your instructions are: this DPA, our Terms of Service, the configuration choices you make in our control panels, and support requests submitted by an authorized account contact. If we are legally required to process beyond your instructions, we will tell you first unless the law prohibits it.
  2. Tell you if an instruction looks unlawful. If we believe an instruction infringes Data Protection Laws, we will inform you promptly and may suspend that instruction until it is resolved.
  3. Keep the data confidential and bind everyone we authorize to access it (Section 7).
  4. Secure the data in line with Article 32 GDPR and the measures in Annex II.
  5. Control sub-processors as described in Section 9.
  6. Help you respond to data subjects as described in Section 11.
  7. Assist you with security, breach notification, impact assessments and prior consultation under Articles 32 to 36, taking into account the nature of the processing and the information available to us.
  8. Delete or return the data at the end of the services (Section 14).
  9. Make available the information you need to demonstrate compliance with Article 28, and allow audits (Section 15).
  10. Maintain records of the categories of processing we carry out on your behalf, as required by Article 30(2).

6. Your obligations as controller

You are responsible for:

  1. Having a valid lawful basis for the processing, and giving the notices or collecting the consents that Data Protection Laws require of you.
  2. The accuracy, quality and legality of the Customer Data and of the instructions you give us.
  3. Configuring and securing everything under your control: operating systems, applications, databases, encryption, user accounts, access rights, firewall rules, and backups on unmanaged services.
  4. Keeping account and technical contacts current in the client area, so our breach and sub-processor notices reach the right people.
  5. Not uploading personal data the service is not designed to hold, without first agreeing it with us under Section 4.
  6. Responding to your own data subjects, controllers and regulators. We support you; we do not stand in your place.

7. Confidentiality and government access

Access to Customer Data is limited to personnel who need it to deliver or support the services. Everyone with such access is bound by a written confidentiality obligation that survives the end of their engagement with us, and is instructed on their obligations under this DPA. We do not disclose Customer Data to any third party except to the sub-processors in Annex III, or where we are compelled by law.

If we receive a subpoena, warrant, court order or other binding demand for Customer Data, then unless legally prohibited we will: notify you without undue delay so you can seek protective relief; disclose only what the demand actually requires; and challenge demands that appear overbroad or unlawful. We do not give any government or law enforcement body direct, unrestricted or bulk access to Customer Data, and we do not maintain back doors into customer environments.

8. Security of processing

We implement and maintain appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Those measures are described in Annex II and take account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing.

We may update the measures in Annex II as technology and threats change, provided the overall level of security is not reduced. Material changes are published in this article and announced under Section 18.

Security here is shared. Annex II covers the facility, the network, the hypervisor and the platforms we operate. Guest operating systems, application code, in-application encryption, credential hygiene and access control inside your environment are yours.

9. Sub-processors

You give us general authorization to appoint sub-processors. The complete current list is in Annex III. It is short by design: we own and operate our own hardware, network and virtualization platforms, so the only parties that receive personal data from us are our data center operator and our two payment processors.

Before we add or replace a sub-processor that will process Customer Data, we will update Annex III and notify account contacts at least 30 days in advance. If you have a reasonable, documented data protection objection, raise it by ticket within those 30 days. We will work with you in good faith on an alternative configuration or a commercially reasonable workaround. If we cannot find one, you may terminate the affected service without early termination fees and receive a pro-rata refund of prepaid fees for the unused term. That is your sole remedy for an objection.

Every sub-processor is bound by a written contract imposing data protection obligations no less protective than this DPA. We remain fully liable to you for each sub-processor's performance.

10. International data transfers

Customer Data is stored and processed on our Michigan infrastructure and is not replicated to any other country. There is one exception to note, and it concerns access rather than storage: one member of our team works from the United Kingdom and holds administrative access to customer environments, through the same authenticated and logged interfaces as our US personnel.

The United Kingdom holds a European Commission adequacy decision, so that access needs no additional safeguards for personal data originating in the EEA.

10.1 Transfers from the EEA

Where you transfer personal data subject to the GDPR to us, the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and completed as set out in Annex IV. Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you are a processor acting for another controller. Annexes I, II and III of this DPA serve as Annexes I, II and III to the Clauses.

10.2 Transfers from the United Kingdom

Transfers subject to the UK GDPR are governed by the Standard Contractual Clauses as amended by the UK Information Commissioner's International Data Transfer Addendum, completed as set out in Annex IV.

10.3 Transfers from Switzerland

For transfers subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the adaptations published by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the Swiss FADP, the competent authority is the FDPIC, and the Clauses also protect data relating to legal entities until the Swiss FADP is amended to remove that protection.

10.4 Transfer risk

We have assessed the laws of the United States as they apply to our services and consider that we can comply with the Standard Contractual Clauses. We will help you complete a transfer impact assessment on request. Our position on government demands is in Section 7, and we will report the number of binding demands we have received on request.

We rely on the Standard Contractual Clauses rather than an adequacy decision, so our transfer position does not depend on the continued validity of the EU–US Data Privacy Framework.

11. Assistance with data subject requests

Because we do not routinely access the contents of your environment, you are normally best placed to answer requests from data subjects yourself, using the administrative access we provide.

If a data subject contacts us directly about data we process for you, we will not respond substantively. We will direct them to you and forward the request to your account contacts without undue delay.

If you need help that only we can provide to answer a request for access, rectification, erasure, restriction, portability or objection, open a ticket. We will give reasonable assistance taking into account the nature of the processing. Assistance requiring significant engineering effort beyond the tools available to you may be chargeable at our standard professional services rate, quoted before we start.

12. Personal data breaches

If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay and in any event within 72 hours of confirming it. Notice goes to the contacts registered on your account, so keep them current.

Our notice will include, so far as known at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records affected, where we can determine this;
  • the likely consequences;
  • the measures taken or proposed to address the breach and mitigate its effects;
  • a contact point for further information.

Where we cannot provide all of that at once, we will provide it in phases as the investigation progresses. We will preserve relevant logs and evidence, cooperate with your investigation, and support your notifications to supervisory authorities and data subjects. Notifying you is not an admission of fault or liability.

Notifying regulators and data subjects is your responsibility as controller. We will not notify on your behalf unless you instruct us in writing.

Report a suspected breach or security issue by opening a priority ticket in the client area.

13. Impact assessments and prior consultation

On request we will give reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, limited to processing we carry out and to information we hold. In most cases Annex I, Annex II and Annex III are sufficient. We also complete customer security questionnaires once per twelve month period at no charge.

14. Retention, return and deletion

We keep Customer Data only as long as needed to provide the services, and no longer.

14.1 During the term

You control retention inside your environment. You can delete, export or overwrite Customer Data at any time using the tools we provide. If you need us to delete a specific dataset or service, open a ticket and we will action it within 5 business days and confirm in writing.

14.2 On termination or cancellation

Export your data before you cancel. Termination destroys Customer Data immediately. We do not hold a post-termination copy, so there is nothing for us to restore afterwards, at any price.

When a service is terminated or canceled, the Customer Data associated with it is deleted immediately as part of the termination process:

  • Virtual machine disks are destroyed and the underlying storage is reclaimed.
  • Hosting accounts, mailboxes, databases and game server volumes are purged.
  • Associated snapshots and platform backups are removed at the same time.
  • Physical media that reaches end of life is sanitized or destroyed in line with NIST SP 800-88 before disposal or reuse.
  • Colocation customers remove their own equipment and media. We do not access, image or wipe customer-owned drives unless you instruct us in writing.

Two narrow exceptions apply, and both are short. Where a service lapses without a cancellation request, we hold the data for a further 2 days so you can renew before permanent deletion. Where you have told us you are resolving a payment problem, we hold the data while that is being resolved. Both are described in our Privacy Policy.

Reclaimed storage blocks may persist in an unallocated state until overwritten by normal platform activity. They are not accessible through any customer-facing or administrative interface once the service is destroyed.

We will confirm deletion in writing on request.

14.3 Account data

Account data is the information covered by Section 3.1, where we act as controller rather than processor: your name, business name, billing and contact details, and your ticket and account history. It is not Customer Data and is not deleted at termination, because we need it for billing records, tax and accounting obligations, fraud prevention and dispute handling.

We retain account data while your account is active, and for 36 months after your last account activity, meaning the most recent of any active service, support ticket, or client area login. After that period it is deleted. Financial records such as invoices and payment records are retained for the longer periods that tax and accounting law require, as set out in our Privacy Policy.

Identity and eligibility verification documents are an exception and are deleted immediately once verification is complete, as described in Section 3.1.

15. Audit rights

We make available the information necessary to demonstrate compliance with Article 28 GDPR and allow for audits, on these terms:

  1. Documentation first. Most audit needs are met by this DPA, its annexes, our security documentation and a completed security questionnaire. We provide these free of charge once per twelve month period, along with any current third party attestations we hold.
  2. On-site or remote audit. If documentation is genuinely insufficient, you may audit us once per twelve month period on at least 30 days written notice, during business hours, to a scope agreed in advance, without unreasonable disruption to our operations.
  3. Additional audits are permitted where a supervisory authority requires one, or following a confirmed personal data breach affecting your data.
  4. Limits. An audit must not compromise the security or privacy of other customers. It does not extend to other customers' data, systems or equipment, to shared infrastructure where isolation cannot be maintained, or to our commercially sensitive information. Auditors must sign a confidentiality agreement, must not be a competitor of ours, and are escorted at all times in the data center.
  5. Facilities. Our data center space is provided by a third party operator. Physical access for audit purposes is subject to that operator's security and scheduling policies, and we will use reasonable efforts to arrange it.
  6. Cost. You bear your own audit costs. We bear ours for the first audit in any twelve month period; reasonable personnel time for additional or expedited audits is chargeable at our standard rate.
  7. Findings. Audit reports are confidential, may be used only to assess our compliance with this DPA, and must be shared with us. We will remediate confirmed material findings within a reasonable agreed timeframe.

16. Liability and indemnity

Each party's total aggregate liability arising out of or related to this DPA, in contract, tort or any other theory, is limited to the greater of the fees you paid us for the affected service in the twelve months before the event giving rise to the claim, or US$100. Claims under this DPA and claims under our Terms of Service or any master services agreement count together toward that single cap. The cap is not multiplied by the existence of this DPA. This cap does not apply to your indemnification obligations below.

The disclaimers and exclusions in our Terms of Service continue to apply, except where they conflict with a right a data subject or a supervisory authority has under Data Protection Laws that cannot be excluded by contract.

Neither party is liable to the other for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill or data, arising out of this DPA.

You will indemnify us against claims, fines and reasonable costs arising from: Customer Data you had no lawful basis to process; instructions that breach Data Protection Laws; special category, regulated or unlawful data uploaded contrary to Section 4; and your failure to secure the parts of the environment under your control.

We will indemnify you against claims, fines and reasonable costs arising from our processing of Customer Data in breach of this DPA or of our obligations as a processor under Data Protection Laws, subject to the cap above.

Nothing in this DPA limits either party's liability to a data subject under Article 82 GDPR, or any other liability that cannot be limited by law. Where one party pays compensation for damage caused by processing, it may claim back from the other the part corresponding to that party's responsibility, as provided in Article 82(5).

17. US state privacy laws

This section applies where you are subject to the California Consumer Privacy Act as amended, or to comparable state privacy laws including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana. Terms here have the meanings given in those laws.

You disclose personal information to us only for the limited and specified business purpose of providing the services. We act as a service provider or processor, and we:

  • do not sell or share personal information, and receive no monetary or other valuable consideration for it;
  • do not retain, use or disclose it for any purpose other than performing the services, except as permitted by law;
  • do not retain, use or disclose it outside our direct business relationship with you;
  • do not combine it with personal information received from another source, except as permitted for a service provider;
  • comply with the applicable obligations of those laws and provide the same level of privacy protection they require;
  • notify you if we determine we can no longer meet these obligations, and on notice from you will stop or remediate the unauthorized processing;
  • allow you to take reasonable and appropriate steps to confirm we use the personal information consistently with your obligations, through the mechanisms in Section 15;
  • engage sub-contractors only under written terms imposing the same restrictions.

We certify that we understand and will comply with these restrictions. Where consumers exercise rights under those laws we will assist you as described in Section 11, and we will delete or de-identify personal information on your verified instruction as described in Section 14.

18. Term, changes and governing law

This DPA takes effect when you first use the services and continues until all services are terminated and all Customer Data has been deleted or returned. Sections 7, 12, 14, 15 and 16 survive termination.

We may update this DPA to reflect changes in law, our services or our sub-processors. For material changes that reduce your rights we will give at least 30 days notice to account contacts and update this article, and you may terminate the affected service without penalty before the change takes effect if you do not accept it. Changes required by law may take effect immediately.

This DPA is governed by the laws of the State of Michigan, United States, without regard to conflict of laws rules, and the parties submit to the state and federal courts serving Muskegon County, Michigan. This does not affect the governing law and jurisdiction of the Standard Contractual Clauses in Annex IV, which prevail for transfers to which they apply, and does not deprive a data subject of the protection of mandatory law in their country of residence.

If any provision is held invalid or unenforceable, the rest stays in force.

19. How to execute this DPA

This DPA applies automatically to your use of our services. No signature is required.

If your compliance team needs a countersigned copy, open a ticket from the client area with:

  • your RackGenius client ID;
  • the full legal entity name and registered address of the contracting party;
  • the name, title and email of your signatory;
  • your data protection officer or privacy contact, and your EU or UK Article 27 representative if you have one;
  • whether you act as a controller or as a processor for your own clients, so we select the correct Standard Contractual Clauses module.

We return an executed PDF, normally within 5 business days, and we accept electronic signature. We will consider customer-provided DPA templates, but they are reviewed case by case and non-standard terms may attract a review fee.

Annex I – Details of processing

This Annex also serves as Annex I to the Standard Contractual Clauses.

A. List of parties

Data exporter The Customer identified on the RackGenius billing account. Role: controller, or processor where Section 3.4 applies. Contact: the account and privacy contacts registered in the client area. Activities relevant to the transfer: use of hosting, compute, storage, network and colocation services.
Data importer Snakecraft Hosting, LLC d/b/a RackGenius, 1887 Holton Rd Ste D PMB 171, Muskegon, MI 49445, United States. Role: processor, or sub-processor where Section 3.4 applies. Contact: the RackGenius privacy contact, whose name and direct details are provided in the executed copy of this DPA and on request through the client area. Activities relevant to the transfer: provision of hosting, compute, storage, network, colocation and support services.

B. Description of the transfer

Categories of data subjects Determined by the Customer. Typically the Customer's own customers and end users, employees and contractors, website and application visitors, email correspondents, game server players, and any other individuals whose data the Customer chooses to store or transmit.
Categories of personal data Determined by the Customer. Our services can hold any data the Customer uploads, which may include names, usernames, email addresses, postal addresses, phone numbers, IP addresses and other network identifiers, account credentials and authentication tokens, transaction and order records, support and chat content, files, media, log data and database contents. RackGenius neither requires nor requests any particular category.
Special category data Not expected, and not permitted without prior written agreement under Section 4. Where agreed, any restrictions are recorded in the applicable order form.
Frequency of the transfer Continuous, for the duration of the services.
Nature and purpose of processing Hosting, storage, backup, transmission and routing of Customer Data on RackGenius infrastructure; provision of virtualization, web hosting, game hosting, dedicated server, colocation and IP transit services; technical support at the Customer's request; monitoring, capacity management, abuse handling and security operations needed to keep the services running.
Duration of processing The term of the services. Customer Data is deleted on termination as set out in Section 14.
Sub-processor processing As set out in Annex III, for the duration of the services.
Processing locations 123Net DC4, Grand Rapids, Michigan and 123Net DC1, Detroit, Michigan, United States. Customer Data is not stored outside the United States. Administration and support are performed from the United States and, for one member of our team, from the United Kingdom.

C. Competent supervisory authority

The supervisory authority of the EEA Member State in which the data exporter is established. Where the exporter is not established in an EEA Member State but has designated an Article 27 representative, the supervisory authority of the Member State in which that representative is established. Where neither applies, the supervisory authority of the Member State in which the affected data subjects are located. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Annex II – Technical and organizational measures

This Annex also serves as Annex II to the Standard Contractual Clauses. It describes the measures RackGenius applies to the infrastructure we operate. Measures inside customer-administered operating systems, applications and colocated equipment are the Customer's responsibility.

1. Physical security

  • All RackGenius equipment is housed in carrier-grade data centers operated by 123Net in Grand Rapids and Detroit, Michigan.
  • Facility controls include monitored premises, perimeter security, badge-controlled access, CCTV coverage, and visitor logging with escort requirements.
  • RackGenius equipment sits in locked cabinets or dedicated cages, with access limited to named RackGenius personnel and authorized customer representatives.
  • Facilities provide redundant utility feeds, UPS, generator backup, redundant cooling, and fire detection and suppression.

2. Access control

  • Administrative accounts are individually named. Shared logins are not used for administrative access.
  • Server access uses SSH key-based authentication. Password authentication is disabled on RackGenius-managed hosts.
  • Multi-factor authentication is enforced on administrative interfaces that support it, including the billing platform, virtualization control panels and infrastructure vendor portals.
  • Access follows least privilege, is reviewed periodically, and is revoked promptly on role change or departure.
  • Management and out-of-band interfaces are isolated from customer traffic in a separate management context and are not reachable from the public internet without authenticated access.
  • Personnel located outside the United States use the same named accounts, key-based authentication and multi-factor requirements as our US personnel, and their access is logged identically.

3. Network security

  • RackGenius operates its own autonomous system, AS32002, across two Michigan sites with redundant upstream transit and internet exchange connectivity.
  • RPKI origin validation and IRR-based prefix filtering are applied to BGP sessions, with automated filter refresh, to prevent route hijack and leak.
  • Customer networks are logically segregated. Virtual machines, hosting accounts and game servers are isolated at the hypervisor or container boundary, and by per-customer VLAN or virtual network where applicable.
  • Access control lists and filtering policy are applied at the network edge.
  • Administrative traffic is carried out of band and encrypted in transit.

4. Encryption

  • The client area, control panels and API endpoints are served over TLS with modern cipher suites and HSTS.
  • Administrative sessions and file transfers use SSH or TLS.
  • Encryption at rest is available on supported storage platforms and enabled where it forms part of the service. Customers requiring guaranteed at-rest encryption should enable full disk or application level encryption inside their own environment, which we support and recommend.

5. Availability and resilience

  • Clustered virtualization hosts with replicated storage for supported products, allowing workloads to recover on surviving nodes.
  • Redundant power and network paths at rack and facility level, and independent points of presence in Grand Rapids and Detroit.
  • Backups are taken for products where backup forms part of the service, stored separately from primary storage, and destroyed with the service on termination under Section 14. Customers on unmanaged products are responsible for their own backups.
  • Restore procedures are tested periodically.

6. Logging and monitoring

  • Infrastructure, network and authentication logs are shipped to a centralized logging and metrics platform, retained for a limited period appropriate to security and operational needs, and accessible only to authorized personnel.
  • Automated monitoring and alerting covers availability, capacity and anomalous administrative activity.
  • Configuration and inventory are tracked in a source-of-truth system, and changes to managed hosts are made through version-controlled automation held in a private repository.

7. Vulnerability and change management

  • Operating systems, hypervisors and control panel software on RackGenius-managed infrastructure are patched on a regular cycle, with critical security patches applied on an expedited basis.
  • Changes to production infrastructure follow a documented process with peer review for high-impact work and a rollback plan.
  • Customer-administered systems are patched by the customer.

8. Personnel

  • All personnel with access to Customer Data are bound by written confidentiality obligations that survive their engagement.
  • Personnel are instructed on the data protection and security responsibilities relevant to their role.
  • Access is provisioned on a need-to-know basis and removed on termination.

9. Incident response

  • Documented incident response procedure covering detection, triage, containment, eradication, recovery and post-incident review.
  • Customer notification within the timeframe in Section 12, with log and evidence preservation for investigation.

10. Data minimization and segregation

  • We do not copy, index, mine or analyze the contents of customer environments, and we do not use Customer Data to train models or build products.
  • Support personnel access customer environments only when the customer requests it, when required for a specific fault or abuse investigation, or where necessary to protect the platform. Such access is logged.
  • Test and development activity does not use live Customer Data.
  • Identity and eligibility verification documents submitted for free or subsidized programs are deleted immediately after verification.

11. Sub-processor governance

  • Sub-processors are assessed before engagement and bound by written data protection terms no less protective than this DPA.
  • The list is maintained in Annex III and changes are notified under Section 9.

Annex III – Authorized sub-processors

This Annex also serves as Annex III to the Standard Contractual Clauses. Last updated August 31, 2026.

RackGenius owns and operates its own servers, network and virtualization platforms. We do not use a public cloud provider, and we do not disclose personal data to advertisers, data brokers, analytics vendors or any other third party. The complete list of sub-processors is:

Sub-processor Purpose Data processed Location
123Net, Inc. Data center space, power, cooling and physical security at DC4 Grand Rapids and DC1 Detroit Physical custody of the servers that hold Customer Data. No logical or administrative access to Customer Data. Michigan, United States
Stripe, Inc. Card payment processing and fraud screening Billing contact details and payment information. No Customer Data. United States
Stripe, Inc. (Stripe Identity) Identity verification where we need to confirm account ownership Government-issued identification, a verification photograph, and partial identifying numbers. Redacted immediately after review. No Customer Data. United States
PayPal, Inc. Payment processing Billing contact details and payment information. No Customer Data. United States

Payment card data is submitted directly to Stripe or PayPal and is not stored on RackGenius systems.

Software we license and run on our own hardware, including our virtualization, hosting, game hosting and billing platforms, is not a sub-processor because the vendor has no access to Customer Data. Upstream network carriers that transport traffic act as conduits rather than sub-processors and are not listed.

Annex IV – Transfer mechanism details

Standard Contractual Clauses (EU)

Decision Commission Implementing Decision (EU) 2021/914 of 4 June 2021
Modules Module Two (controller to processor) where the Customer is a controller. Module Three (processor to processor) where the Customer is a processor under Section 3.4.
Clause 7 (docking) Included
Clause 9 (sub-processors) Option 2, general written authorization, with the 30 day notice period in Section 9.
Clause 11 (redress) The optional independent dispute resolution body language is not used.
Clause 17 (governing law) Option 1. The law of the EEA Member State in which the data exporter is established. Where the exporter is not established in an EEA Member State, the law of Ireland.
Clause 18 (forum) The courts of the Member State whose law governs under Clause 17.
Annexes Annexes I, II and III of this DPA are the Annexes to the Clauses. Acceptance of the services under Section 19, or signature of this DPA, constitutes signature of the Clauses.

UK International Data Transfer Addendum

Table 1 – Parties Exporter: the Customer, as identified in Annex I. Importer: Snakecraft Hosting, LLC d/b/a RackGenius, as identified in Annex I. Key contacts as stated there.
Table 2 – Addendum EU SCCs The Standard Contractual Clauses as completed above, including the modules and options selected.
Table 3 – Appendix information Annex 1A and 1B: Annex I of this DPA. Annex II: Annex II. Annex III: Annex III.
Table 4 – Ending the Addendum The Exporter may end the Addendum as set out in Section 19 of the Addendum.

Questions about this DPA, sub-processor notices, audit requests and signed copies: open a ticket from the client area, or use our contact form.

這篇文章有幫助嗎? 0 用戶發現這個有用 (0 投票)