Data Processing Agreement (AVV)
In force 18 September 2026 · version 2026-09-18
Data Processing Agreement (Auftragsverarbeitungsvertrag)
This Data Processing Agreement ("DPA") is the Art. 28 GDPR contract between you (the controller) and Julian Achter, trading as Aluy, Am Hang 55, 85737 Ismaning, Germany (the processor) when you use Aluy hosting, LIR, or related infrastructure to process personal data of your own end users.
It applies automatically to every business customer who processes personal data on our services. No separate signature is required for the published version to take effect; material changes follow the 30-day notice rule in our Terms.
1. Subject and duration
The processor provides virtual servers, dedicated servers, storage, IP/ASN resources, and related operational services as described in the Terms of Service. Processing lasts for the term of each service and any statutory retention that follows.
2. Nature and purpose
Processing is limited to hosting, routing, billing, abuse handling, and legal compliance. We do not access customer content except (a) as you instruct, (b) to keep the platform running, or (c) where EU or German law requires it (DSA, StPO, tax, RIPE).
3. Types of data and data subjects
You determine the categories. Typical categories on a hosted server include identification, contact, usage, and content data of your customers, employees, or visitors. We do not decide those categories.
4. Obligations of the processor
We:
- process personal data only on documented instructions, including this DPA, your panel actions, and tickets;
- ensure persons authorised to process are bound to confidentiality;
- take appropriate technical and organisational measures (Art. 32 GDPR) — access control, encryption in transit, least-privilege admin access, backups, and logging as described in the Privacy Policy;
- engage sub-processors only as listed in the Privacy Policy (Hetzner, VirtFusion, Trivox, PayPal, Heleket, Bunny, Telegram for staff alerts) and will notify you of material replacements;
- assist you, taking into account the nature of processing, with data-subject requests, Art. 32–36 duties, and a data-protection impact assessment where reasonably possible;
- delete or return personal data after the end of the service, subject to statutory retention (invoices, RIPE assignment records, DSA accountability);
- make available the information necessary to demonstrate compliance and allow audits that do not endanger other customers or our security.
5. Your obligations
You remain the controller. You warrant a lawful basis for the data you place on the service, configure access, and handle end-user requests that we cannot fulfil from infrastructure logs alone.
6. International transfers
Some locations (notably Hong Kong) sit outside the EU/EEA. Where you choose such a location, you instruct that transfer. Supplementary measures and the SCC position are described in the Privacy Policy.
7. Sub-processors
Current sub-processors are listed under "Data processors & third parties" in the Privacy Policy. We remain responsible for their processing under Art. 28(4) GDPR.
8. Security incidents
We notify you without undue delay after becoming aware of a personal-data breach that affects your processing on our systems, with the facts we reasonably have at that time.
9. Liability and governing law
Liability follows the Terms of Service. German law applies. Venue is Munich, Germany, to the extent permitted.
10. Changes
Material changes to this DPA are published at least 30 days before they take effect, the same way as the Terms.
Updated 18 September 2026