Data Processing Addendum
This Addendum governs the personal data of your websites' visitors that we process on your behalf. It applies automatically to every account; no signature is required.
Last updated: 25 August 2026
1. Scope and Roles
This Data Processing Addendum ("Addendum") forms part of the Terms of Service between the account holder (the "Customer", "you") and one9x ("we", "us", "our"). It governs only the personal data of visitors to the websites you host with us that we process in the course of providing the Services.
It does not govern your own account data, in respect of which we are the Data Fiduciary in our own right and the Privacy Policy applies.
In respect of visitor data, you are the Data Fiduciary and we are the Data Processor, processing such data solely because you have engaged us to serve your website. Section 8(2) of the Digital Personal Data Protection Act, 2023 requires a valid contract between a Data Fiduciary and its Data Processor; this Addendum constitutes that contract.
You remain responsible for the lawful basis of the data you collect, for the notice and consent provided to your visitors, and for the content of your website.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter
- The serving of your website to its visitors over HTTPS, and the operation of the platform that does so.
- Duration
- The term of your account, together with the retention periods set out in Section 6. Processing ends upon closure of the account, subject to those periods.
- Nature of the processing
- Receiving, routing, caching, serving, logging and storing. We do not read, analyse, profile or enrich your visitors' data, do not use it to train any system, and do not use it for our own purposes.
- Purpose
- Delivery of the website, the application of rate limits and abuse controls, fault diagnosis, security monitoring, and compliance with the record-keeping obligations placed on us as a hosting provider under Indian law.
3. Categories of Data and Data Principals
Data Principals: visitors to the websites you host with us.
Categories of personal data processed on your behalf:
- Access log records — visitor IP address, timestamp, requested path (query string removed), user agent, response status and bytes served.
- Personal data contained in the files you deploy — where your website's content includes personal data, we store and serve it as opaque bytes without inspecting it.
We do not set cookies on your visitors, do not run analytics on your website, and do not inject content into your responses. Any data collected by your website itself — through a form, an embedded third-party service, or your own analytics — is collected by you and is outside the scope of this Addendum.
Pages is a static hosting service: no database and no server-side code of yours runs on the platform, and accordingly we hold no store of visitor records beyond the logs described above.
4. Processing on Documented Instructions
We process visitor data only to provide the Services and only on your documented instructions, which comprise your configuration of the Services and this Addendum. We shall not process visitor data for any other purpose.
The sole exception is processing required of us by Indian law: the log retention set out in Section 6, and disclosure pursuant to a lawful order. Where legally permitted, we will inform you before acting on such an order.
5. Confidentiality and Security
- Access to production systems is limited to named individuals who require it, is available only over a private network, and is subject to obligations of confidentiality.
- Access to internal tooling is recorded in an audit log retained for 365 days.
- Traffic is served over TLS, with certificates issued and renewed automatically.
- Data is stored in India and is not transferred outside Indian jurisdiction.
- Backups are maintained under the same controls as production systems.
6. Retention and Deletion
- Operational logs: 7 days.
- Site access logs: 180 days, as required by the directions issued by CERT-In under section 70B of the Information Technology Act, 2000. This is a statutory period: we cannot delete these records on your instruction before it ends, and we do not retain them beyond it.
- Security and audit records: 365 days.
Upon termination: your deployed files are deleted when you delete the files, the site, or the account, subject to a short window before backups roll off. Your content may be retrieved at any time before deletion through the dashboard, the CLI or the API. Log records already written run out their statutory periods and are then deleted; nothing is retained beyond them.
7. Sub-processors
No sub-processor is engaged for visitor data: the logs and files described in Section 3 do not leave our systems.
The third parties listed in the Privacy Policy (the payment gateways, the email service provider and Let's Encrypt) receive your account data in your capacity as our customer, not your visitors' data. Let's Encrypt receives the domain names you connect for the purpose of issuing certificates for them.
Should we engage a sub-processor for visitor data in future, we will publish it on this page and notify account holders by email before the engagement takes effect, allowing you to object or to terminate the Services.
8. Assistance with Data Principal Requests
Where a visitor makes a request to you for access to, correction of, or erasure of their personal data, and responding requires information held only by us, you may write to contact@one9x.com identifying the site and the relevant details. We will provide reasonable assistance, at no charge, to the extent the request does not require us to breach a retention obligation under Section 6.
Where a visitor approaches us directly, we will not respond on your behalf; we will direct them to you as the Data Fiduciary and inform you of the request.
9. Personal Data Breach
If we become aware of a personal data breach affecting data processed on your behalf, we will notify you without undue delay by email to the account address. The notification will describe the nature of the breach, the categories and approximate number of Data Principals concerned, the measures taken, and our recommendations.
Notification of the breach to the Data Protection Board of India and to affected Data Principals is your obligation as the Data Fiduciary; we will provide the information reasonably necessary for you to discharge it.
10. Audit and Information
Upon reasonable written request, and not more than once in any twelve-month period unless required by a breach or by a regulator, we will respond to your enquiries concerning the processing of visitor data and provide the supporting evidence we hold. On-site inspection of shared infrastructure is not offered, as physical access by one customer would compromise the security of the infrastructure serving all customers.
11. Changes to this Addendum
This Addendum may be updated as the Services and applicable law evolve. Material changes are notified by email before they take effect; the date at the top of this page reflects the most recent revision.
12. Contact
Questions concerning this Addendum, or any data-protection matter concerning your visitors, may be addressed to grievance@one9x.com. The name and contact details of our Grievance Officer are published on the Privacy Policy page.