Data Processing Agreement (DPA)

Version: DPA-2026-09-08

This Data Processing Agreement (the DPA) applies to the use of the database backup functionality of the WebShield service and forms part of the agreement governing the WebShield service provided by WebShield IT Security Kft.

Controller: the customer ordering the WebShield service, or the person or organisation authorised to determine the purposes and means of processing personal data on the website or application operated by that customer, as identified by the relevant order, subscription or WebShield account (the Controller).

Processor: WebShield IT Security Kft., registered office: Dombhát u. 14., 2080 Pilisjászfalu, Hungary; company registration number: 13-09-219848; tax number: 27830374-2-13; email: info@webshield.hu (WebShield or the Processor).

The Controller and the Processor are together referred to as the Parties.

1. Subject matter and scope

1.1. This DPA applies to the processing of personal data carried out by WebShield on behalf of the Controller when WebShield creates a backup or database dump of a database belonging to a website or application operated by the Controller, securely transfers that backup and stores it on infrastructure controlled by WebShield.

1.2. This DPA sets out the rights and obligations of the Parties under Regulation (EU) 2016/679 of the European Parliament and of the Council (the GDPR), in particular Article 28.

1.3. This DPA applies only to processing performed as part of the database backup functionality. Where WebShield processes data for its own purposes as an independent controller, including for contractual communication, invoicing or compliance with legal obligations, the WebShield Privacy Notice applies.

2. Definitions and roles

2.1. Data protection terms used in this DPA have the meanings assigned to them in the GDPR.

2.2. The Controller determines the purposes and essential means of processing the personal data held in its database. WebShield acts as a Processor in respect of such personal data.

2.3. WebShield shall process personal data only on documented instructions from the Controller. The Controller's activation of the backup functionality and electronic acceptance of this DPA constitute documented instructions to commence and perform the backup operations described in this DPA.

2.4. The Controller may issue further documented instructions electronically. Instructions must be consistent with the scope of the service, this DPA and applicable law. The Parties shall separately agree on the performance of any instruction outside the scope of the service or involving additional cost.

3. Subject matter, purpose, nature and duration of processing

3.1. The subject matter of the processing is the backup of the database of a website or application designated by the Controller and protected or managed by WebShield.

3.2. The processing operations may include:

3.3. Processing may take place solely for backup, prevention of data loss, disaster recovery, recovery following a security incident, and the provision of related WebShield security and recovery functionality.

3.4. WebShield shall not use personal data contained in backups for marketing, advertising, profiling, its own business purposes, independent statistical or analytical purposes, training machine learning or artificial intelligence models, or any purpose other than the Controller's instructions.

3.5. Processing begins when the backup functionality is activated and continues until that functionality is disabled or the underlying service ends, together with the deletion period set out in Section 12.

4. Categories of data subjects and personal data

4.1. WebShield does not determine and may not know in advance the contents of the Controller's database. The Controller determines and controls the database contents and the purposes and lawful basis of the underlying processing.

4.2. Depending on the actual use of the relevant website or application, a backup may contain names, email addresses, telephone numbers, IP addresses, user account data, user-submitted content, order data, billing data, contact details, log data, WordPress or other CMS user data, and other personal data created or stored by the Controller. This list does not mean that WebShield processes every listed data type in every case.

4.3. Categories of data subjects may include website visitors, registered users, clients, customers, prospective customers, contact persons, employees, website administrators, authors, and other natural persons whose personal data the Controller processes in the database.

4.4. A backup may contain special categories of personal data, personal data relating to criminal convictions and offences, or children's data only where the Controller lawfully processes such data in the database. The Controller shall assess the necessity, lawful basis and appropriate safeguards for such processing and inform WebShield to the extent necessary for secure performance of the service.

5. Rights and obligations of the Controller

5.1. The Controller is responsible for ensuring that the collection and processing of personal data in the database, activation of the backup functionality, and instructions given to WebShield are lawful, and that data subjects receive the required information.

5.2. The Controller may issue lawful documented instructions, request information about processing and verify compliance with this DPA in accordance with Section 14.

5.3. The Controller shall provide accurate information and technical access required for performance, appropriately protect its own systems and access credentials, and notify WebShield without undue delay of any error, incident or material change affecting the backups.

5.4. The Controller is responsible for assessing and responding to data subject requests and, where required by the GDPR, for carrying out data protection impact assessments, prior consultations and personal data breach notifications. WebShield shall assist the Controller as set out in this DPA.

6. Obligations of the Processor

6.1. WebShield shall process personal data only on documented instructions from the Controller, including instructions regarding transfers outside the EEA, unless processing is required by Union or Member State law to which WebShield is subject. In that case, WebShield shall inform the Controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

6.2. WebShield shall ensure confidentiality, implement the measures described in Section 8, comply with the requirements governing subprocessors and, taking into account the nature of processing and the information available to it, assist the Controller with:

6.3. If WebShield considers that an instruction infringes the GDPR or other applicable Union or Member State data protection law, it shall inform the Controller without undue delay. WebShield may suspend the unlawful instruction until the legal position has been clarified.

6.4. WebShield shall not use backups as an active data source in the ordinary course of business and shall access their contents only where and to the extent necessary to provide the service.

7. Confidentiality

7.1. WebShield shall ensure that persons authorised to access personal data are bound by an appropriate contractual or statutory duty of confidentiality.

7.2. Such persons may access backups only to the extent necessary to perform their duties and in accordance with the principle of least privilege. They may process the data only in accordance with the Controller's instructions, this DPA and applicable law.

8. Technical and organisational measures

8.1. In accordance with Article 32 of the GDPR, WebShield shall implement appropriate technical and organisational measures, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of data subjects.

8.2. The measures shall address, in particular:

8.3. Specific measures may evolve as technology and risks change, provided that no change reduces the overall level of data protection and information security.

9. Subprocessors

9.1. WebShield does not engage a subprocessor for the database backup service governed by this DPA.

9.2. If this changes in the future, a subprocessor may be engaged only in accordance with Article 28 of the GDPR. Before engaging a subprocessor, WebShield shall amend this DPA or the applicable terms, appropriately inform the Controller and, where required, publish and obtain acceptance of a new DPA version. The subprocessor must be bound by data protection obligations that provide at least the same level of protection as this DPA.

10. Assistance with data subject rights

10.1. The Controller is primarily responsible for receiving, assessing and responding to data subject requests. If WebShield receives such a request directly, it shall, unless otherwise required by law, forward it to the Controller without undue delay and shall not independently determine the response.

10.2. Taking into account the nature of processing, WebShield shall assist the Controller through appropriate technical and organisational measures, insofar as technically possible, in fulfilling data subject rights.

10.3. Erasing or modifying an individual record within a backup may not always be technically appropriate or feasible and may jeopardise the integrity of the backup. Such intervention may not be necessary where the backup is held in a closed, appropriately protected system solely for restoration, is not used as an active data source and is automatically deleted through the 14-day rotation.

10.4. If an earlier backup is restored, the Controller, with WebShield's assistance where necessary, shall ensure that personal data previously erased, rectified or restricted do not unlawfully remain active again.

11. Personal data breaches

11.1. If WebShield becomes aware of a personal data breach affecting personal data processed by it, WebShield shall notify the Controller without undue delay.

11.2. Based on the information available, the notice shall, where possible, describe the nature of the breach; the affected or estimated categories and scope of data subjects and personal data; the likely consequences; and the measures taken or proposed by WebShield, including measures to mitigate possible adverse effects. Where not all information is available at the same time, it may be provided in phases without undue further delay.

11.3. Within the limits of its role as Processor and the information available to it, WebShield shall support the investigation and the Controller's compliance with Articles 33 and 34 of the GDPR. WebShield shall not notify a supervisory authority or data subjects directly unless required to do so by law or by the Controller's documented instructions.

12. Retention, erasure and return

12.1. Each database backup is retained for no longer than 14 days. WebShield manages backups using a rolling backup and automatic rotation model.

12.2. A backup may be automatically deleted when the 14-day retention period expires. In normal operation, database backups older than 14 days are not retained. A short transitional period of a strictly technical nature may occur due to technical deletion and replication processes. It shall not result in unjustified or indefinite storage, and the affected copy shall not be restored to ordinary use during that period.

12.3. When the service or backup functionality ends, no new backup will be created. Existing backups may remain only until the end of their normal 14-day retention period and shall then be automatically deleted, unless Union or Member State law requires retention.

12.4. At the Controller's choice, before the service ends the Controller may request the return or export of an available backup where technically feasible. Return does not extend the retention of copies held by WebShield, which are deleted through the rotation described in Sections 12.1 to 12.3. Immediate, individual manual deletion following termination is not part of the standard service where it would conflict with the technical operation of the closed rotation system.

13. International transfers

13.1. WebShield may transfer personal data to a country outside the EEA or to an international organisation only on documented instructions from the Controller and where the conditions of Chapter V of the GDPR are met.

13.2. This provision does not in itself mean that the service involves a transfer to a third country.

14. Audits and compliance

14.1. WebShield shall make available to the Controller all reasonably available information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA.

14.2. Verification shall, where possible, be carried out by providing documentation, audit reports, compliance statements or other appropriate evidence. If this is insufficient, the Controller or an independent auditor appointed by it and bound by appropriate confidentiality obligations may conduct an audit at an agreed time and within an agreed scope.

14.3. An audit must be proportionate to the processing risk, must not compromise the security or confidentiality of other clients' data or systems, must not extend to other clients' data, and must not cause unreasonable disruption to WebShield's operations. The auditing party shall comply with WebShield's reasonable security requirements.

14.4. The Controller shall bear the evidenced and reasonable costs of an audit that goes beyond standard documentary assurance and is not initiated by a supervisory authority, unless the audit identifies a material breach of this DPA or applicable data protection law by WebShield.

15. Term and termination

15.1. This DPA takes effect upon electronic acceptance and remains effective for as long as WebShield processes personal data covered by this DPA on behalf of the Controller.

15.2. When the backup functionality or underlying service ends, the erasure and return provisions in Section 12 apply. Confidentiality, security and accountability obligations continue until the personal data have been permanently deleted.

16. Electronic acceptance

16.1. This DPA may be accepted electronically, without a handwritten signature, as a binding agreement in electronic form for the purposes of Article 28(9) of the GDPR.

16.2. The action labelled "I accept and enable backups" in the WebShield interface, or an equivalent unambiguous affirmative action, simultaneously constitutes:

  1. acceptance of this DPA;
  2. conclusion of the data processing agreement between the Parties; and
  3. the Controller's documented instruction authorising WebShield to commence database backups.

16.3. For evidence and auditability of acceptance, WebShield may record the customer or subscription identifier, the exact date and time of acceptance, the accepted DPA version and technical audit data, including the IP address and related system log data.

16.4. WebShield may archive previous versions of the DPA to demonstrate the terms accepted by the Controller at a particular time.

17. Version management

17.1. The version of this document is DPA-2026-09-08.

17.2. If this DPA is materially amended in a way that substantially affects the processing terms or the Controller's rights or obligations, WebShield shall create a new version, appropriately inform the Controller and, where required, request renewed acceptance.

17.3. WebShield shall keep previously accepted versions retrievable. A correction limited to language, typographical errors, formatting, references or other editorial matters that does not materially alter the Parties' rights or obligations does not automatically require renewed acceptance.

18. Miscellaneous and final provisions

18.1. This DPA shall be read together with the underlying service agreement and the Terms and Conditions. In the event of a conflict concerning processing of personal data on behalf of the Controller, this DPA prevails.

18.2. This DPA is governed by applicable European Union data protection law and the laws of Hungary. Disputes shall be resolved in accordance with the underlying agreement or, where it contains no applicable provision, under the generally applicable rules of jurisdiction and venue.

18.3. The Hungarian and English versions have the same intended legal effect. In the event of a discrepancy in interpretation, the Hungarian version shall prevail, unless mandatory law requires otherwise.

18.4. If any provision of this DPA is invalid or unenforceable, the remaining provisions remain effective. The Parties shall replace the affected provision with a valid provision that most closely reflects its purpose and applicable law.


GDPR Article 28(3) compliance checklist

This table is provided as an informational compliance aid and does not form part of the substantive contractual provisions of this DPA.

GDPR requirement Relevant DPA section
Processing only on documented instructions Sections 2.3-2.4, 6.1 and 16
Subject matter, duration, nature and purpose of processing Sections 1 and 3
Categories of personal data and data subjects Section 4
Rights and obligations of the Controller Section 5
Confidentiality Section 7
Security under Article 32 GDPR Section 8
Conditions governing subprocessors Section 9
Assistance with data subject rights Section 10
Assistance with compliance under Articles 32-36 GDPR Sections 6.2, 8, 10 and 11
Erasure or return of personal data Sections 12 and 15
Information necessary to demonstrate compliance Sections 14.1-14.2
Allowing and contributing to audits Section 14
Informing the Controller of an unlawful instruction Section 6.3
Written agreement in electronic form Section 16