Skip to content
Looking Glass Service Status
Client Login Register
VM6 Networks
  • Home
  • Web Hosting
    • cPanel HostingLiteSpeed · CloudLinux
    • UK Web HostingFast cPanel alternative
    • Reseller HostingWhite-label + WHMCS Module
  • VPS Hosting
    • UK VPS HostingRyzen 9 9950X · from £6/mo
    • UK Budget VPSIntel Xeon · from £1.75/mo
    • UK Managed VPSWe monitor · patch · respond
    • UK Forex VPSMT4 · MT5 · low latency
    • Windows VPS UKServer 2019 · 2022 · 2025
  • Dedicated Servers
  • Company
    • About VM6
    • Our Datacentres
    • Promotions
    • Affiliate Programme
    • Our Blog
    • Webdeck Panel

    • Knowledgebase
    • Service Status
    • Report Abuse
  • Contact Us
0 Deploy a VPS
VM6 Networks
Home
cPanel Hosting UK Web Hosting Reseller Hosting
UK VPS Hosting UK Budget VPS UK Managed VPS UK Forex VPS Windows VPS UK
Dedicated Servers
About VM6 Our Datacentres Promotions Affiliate Programme Our Blog Webdeck Panel Knowledgebase Service Status
Contact Us
Deploy a VPS Sign in to client area
Service status Looking glass

Data Processing Agreement

How we handle the data you host with us. Our Article 28 UK GDPR terms as your processor, covering security, sub-processors, breach notification and UK data residency.

Company Information

VM6 Networks LTD

Company Number: 16553775 (registered in England & Wales)

Registered Office: Unit A, 82 5 Canon Court, Institute St, Bolton, BL1 1PZ, United Kingdom

In short

  • You are the controller of the data you put on your server. We are your processor.
  • This DPA applies automatically when you accept our Terms of Service. No signature needed, but we will countersign a copy on request.
  • Customer Data in our UK locations stays in the UK.
  • We do not look inside your server unless you ask us to, you have ordered a managed service, or there is a security, abuse or legal reason.
  • Our sub-processor list is available on request (Annex C).

This summary is for convenience only. The clauses below are what apply.

Contents

  • 1. Parties and scope
  • 2. Definitions
  • 3. Roles of the parties
  • 4. Processing instructions
  • 5. Confidentiality
  • 6. Security
  • 7. Sub-processors
  • 8. Data subject rights
  • 9. Personal data breaches
  • 10. Data protection impact assessments
  • 11. International transfers
  • 12. Deletion and return
  • 13. Audit
  • 14. Liability
  • 15. General
  • Annex A — Details of processing
  • Annex B — Technical and organisational measures
  • Annex C — Sub-processors and data locations

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of, and is subject to, the VM6 Networks Ltd Terms of Service ("Agreement") between:

  • VM6 Networks Ltd, a company registered in England and Wales under company number 16553775, whose registered office is at Unit A, 82 5 Canon Court, Institute St, Bolton, BL1 1PZ ("VM6", "we", "the Processor"); and
  • the Customer identified in the Agreement ("you", "the Controller").

This DPA applies where, and only to the extent that, VM6 processes Personal Data on your behalf in the course of providing the Services. It is entered into under Article 28(3) of the UK GDPR.

Where you have accepted the Agreement, you are also taken to have accepted this DPA. No signature is required, but VM6 will execute a countersigned copy on request.

2. Definitions

  • "UK Data Protection Law" means the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018), the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003, each as amended from time to time, including by the Data (Use and Access) Act 2025.
  • "EU GDPR" means Regulation (EU) 2016/679. Where the EU GDPR applies to your processing of Customer Data, references in this DPA to the UK GDPR and UK Data Protection Law include the corresponding provisions of the EU GDPR.
  • "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in UK Data Protection Law.
  • "Services" means the virtual private server, dedicated server, colocation, web hosting, reseller hosting, backup, managed and related services provided by VM6 under the Agreement.
  • "Managed Services" means any Services for which you have ordered a semi-managed or fully managed service level, and shared or reseller web hosting, where VM6 administers the operating system, control panel or other software on your behalf.
  • "Customer Data" means all data, including Personal Data, that you or your end users store, transmit or process using the Services.
  • "Sub-processor" means any third party engaged by VM6 to process Personal Data on your behalf.

3. Roles of the parties

3.1 You are the Controller (or, where you process on behalf of a third party, the Processor acting on that third party's instructions). VM6 is the Processor (or sub-processor, as applicable).

3.2 You determine the purposes and means of processing Customer Data. You are solely responsible for establishing a lawful basis for that processing, for providing all required notices to Data Subjects, and for the accuracy, quality and legality of Customer Data.

3.3 Nature of the Services. Unless you have ordered Managed Services, the Services are unmanaged infrastructure. VM6 provides compute, storage, network and hypervisor facilities. VM6 does not access, inspect, index, analyse or otherwise process the contents of Customer Data in the ordinary course of providing the Services. VM6's processing is limited to hosting, storing, backing up and transmitting Customer Data as an automated and incidental consequence of operating the infrastructure on which you run your own systems.

3.4 Managed Services. Where you have ordered Managed Services, VM6 will additionally access and administer your environment to the extent needed to perform the tasks included in that service (for example monitoring, patching, configuration, troubleshooting and, where included, database backups). Your order for Managed Services is your documented instruction for that access. VM6 will not inspect the contents of Customer Data beyond what is necessary to perform those tasks.

3.5 Your responsibilities. Except to the extent VM6 has expressly agreed to perform them as part of Managed Services, you are responsible for the guest operating system, all applications, all configuration, all user accounts within your environment, all security patching within your environment, all encryption of Customer Data at rest and in transit within your environment, and the backup and recoverability of Customer Data beyond the infrastructure-level facilities described in Annex B.

3.6 VM6 acts as an independent Controller in respect of Personal Data it processes for its own purposes — account administration, billing, support ticketing, abuse handling and legal compliance. That processing is governed by the VM6 Privacy Policy and not by this DPA.

4. Processing instructions

4.1 VM6 will process Personal Data only on your documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law. The Agreement, this DPA, your orders and your use of the Services constitute your complete documented instructions.

4.2 Where VM6 is required by law to process Personal Data otherwise than on your instructions, VM6 will inform you of that legal requirement before processing, unless the law prohibits such disclosure on important grounds of public interest.

4.3 VM6 will inform you if, in its opinion, an instruction infringes UK Data Protection Law. VM6 is not obliged to provide legal advice and this does not constitute a warranty that any instruction is compliant.

4.4 Access to Customer environments. Outside Managed Services, VM6 will not access the guest operating system or application layer of your environment except:

  • (a) where you expressly request it in writing (including by support ticket) for the purpose of diagnosing or resolving a fault;
  • (b) where strictly necessary to investigate a security incident, abuse report, or breach of the Agreement affecting the integrity or availability of VM6's infrastructure or other customers; or
  • (c) where required by law.

VM6 will keep a record of such access (which may be the relevant support ticket) and will provide details to you on request.

5. Confidentiality

5.1 VM6 will ensure that all persons authorised to process Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory, that survives termination of their engagement.

5.2 VM6 will limit access to Personal Data to those personnel who require it to deliver the Services.

6. Security

6.1 VM6 will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. The measures in place as at the date of this DPA are set out in Annex B.

6.2 You acknowledge that the measures in Annex B are infrastructure-level measures. Except to the extent covered by Managed Services, they do not secure the contents of your environment, which remains your responsibility under clause 3.5.

6.3 VM6 may update the measures in Annex B from time to time provided the overall level of security is not materially reduced.

6.4 You are responsible for assessing whether the measures in Annex B are appropriate to the risk presented by your processing, and for implementing any additional measures you require.

7. Sub-processors

7.1 You give VM6 general written authorisation to engage Sub-processors. VM6 maintains a current list of its Sub-processors, including their role and location, which is provided to Customers on request by email to info@vm6.co.uk or by support ticket. VM6 may require a reasonable confidentiality undertaking before providing the list, as it contains commercially confidential supplier information.

7.2 VM6 will impose on each Sub-processor data protection obligations no less protective than those in this DPA, by written contract.

7.3 VM6 remains fully liable to you for the performance of each Sub-processor's obligations.

7.4 VM6 will give you at least 30 days' written notice before adding or replacing a Sub-processor. Where a change is urgently required to maintain the security or continuity of the Services, VM6 may make it with shorter notice and will notify you as soon as reasonably practicable. Notice will be given by email to your account address. You may opt out of these notifications, in which case you are taken to have waived your objection rights under clause 7.5.

7.5 If you reasonably object to a new Sub-processor on data protection grounds within 15 days of notice, you may terminate the affected Services on written notice without penalty, with a pro-rata refund of prepaid fees for the unexpired term. This is your sole remedy.

8. Data subject rights

8.1 Taking into account the nature of the processing, VM6 will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligations to respond to Data Subject requests under Chapter III of the UK GDPR.

8.2 You acknowledge that VM6 does not have visibility of the contents of Customer Data and therefore cannot identify, locate, extract, rectify or erase individual Data Subject records within your environment. VM6's assistance obligation is discharged by maintaining your access to your environment so that you can action requests yourself.

8.3 If VM6 receives a request directly from a Data Subject relating to Customer Data, VM6 will not respond substantively and will refer the Data Subject to you, notifying you promptly.

9. Personal data breaches

9.1 VM6 will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data that arises from a compromise of VM6's infrastructure or of any Sub-processor.

9.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of affected records or environments, the likely consequences, and the measures taken or proposed. Where not all of this is known at first, VM6 will provide it in phases as it becomes available.

9.3 Except to the extent arising from VM6's performance of Managed Services, VM6 is not required to notify you of, and is not responsible for, incidents arising within your environment — including compromise of your guest operating system, applications, credentials or user accounts — as VM6 has no visibility of these.

9.4 Notification is not an acknowledgement of fault or liability.

9.5 You are responsible for any notification to the Information Commissioner's Office or to Data Subjects.

10. Data protection impact assessments

10.1 VM6 will provide reasonable assistance with your data protection impact assessments and prior consultations under Articles 35 and 36 of the UK GDPR, taking into account the nature of processing and the information available to VM6.

10.2 This assistance is limited to providing information about VM6's infrastructure, security measures, Sub-processors and data locations. VM6 may charge its reasonable costs for assistance beyond the provision of its standard documentation.

11. International transfers

11.1 Customer Data for Services deployed in a United Kingdom location is stored and processed on infrastructure located in the United Kingdom. Specific data centre locations are provided to Customers on request under clause 7.1.

11.2 VM6 will not transfer such Customer Data outside the United Kingdom without your prior written consent, save where you or your end users initiate such a transfer through your own use of the Services.

11.3 Where VM6 offers Services in a location outside the United Kingdom and you choose that location, your choice is your documented instruction to store and process the relevant Customer Data there.

11.4 Where any restricted transfer is made by VM6 or a Sub-processor, it will be made under an adequacy regulation, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.

12. Deletion and return

12.1 On termination or expiry of the Services, VM6 will, at your choice, delete or return Customer Data.

12.2 Unless you request return in writing before termination, VM6 will delete Customer Data — including virtual machine disk images and any snapshots or backups — within 30 days of termination.

12.3 Where you request return, VM6 will maintain your access to your environment for a reasonable period, at VM6's then-current rates, to allow you to extract Customer Data. VM6 does not provide data extraction as a service.

12.4 VM6 may retain Personal Data to the extent required by law, and will continue to protect it in accordance with this DPA for as long as it is retained.

12.5 Deletion of Customer Data on termination is irreversible. You are responsible for maintaining your own backups.

13. Audit

13.1 VM6 will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.

13.2 VM6's obligation under clause 13.1 is ordinarily discharged by providing this DPA, Annex B and its other current security documentation, including any security certification VM6 holds at the time.

13.3 Where that documentation is insufficient to meet a specific regulatory obligation you can evidence, you may request an audit. Any audit will be:

  • subject to 30 days' written notice;
  • conducted no more than once in any 12-month period (except following a Personal Data Breach or at the direction of a Supervisory Authority);
  • conducted during business hours;
  • subject to confidentiality undertakings;
  • scoped so as not to compromise the security or privacy of other VM6 customers; and
  • at your cost, including VM6's reasonable time at its then-current rates.

13.4 VM6 cannot grant physical access to third-party data centres operated by its Sub-processors. VM6 will pass on the relevant Sub-processor's own certifications or audit reports where available.

14. Liability

14.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

14.2 Nothing in this DPA limits either party's liability where it cannot lawfully be limited.

15. General

15.1 This DPA takes effect on the earlier of your acceptance of the Agreement and VM6's first processing of Personal Data on your behalf, and continues for as long as VM6 processes Personal Data on your behalf.

15.2 In the event of conflict between this DPA and the Agreement, this DPA prevails in respect of data protection matters.

15.3 If any provision is held invalid or unenforceable, the remainder continues in full force.

15.4 This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

15.5 VM6 may update this DPA on 30 days' notice where required to reflect changes in law, the Services, or its Sub-processors. Material changes that reduce your rights will entitle you to terminate the affected Services without penalty.

Annex A — Details of processing

Subject matterProvision of virtual private server, dedicated server, colocation, web hosting and related hosting infrastructure services, including Managed Services where ordered.
DurationFor the term of the Agreement, plus the deletion period in clause 12.2.
Nature of processingHosting, storage, backup and transmission of Customer Data as an automated function of operating virtualised and physical server infrastructure. Creation and retention of infrastructure-level backups and snapshots. For Managed Services only, administration of your environment as described in clause 3.4. No content-level inspection or analysis otherwise.
PurposeTo provide the Services requested by the Controller.
Types of Personal DataDetermined solely by the Controller. VM6 does not control, and has no visibility of, what categories of Personal Data the Controller chooses to process using the Services. The Controller will not use the Services to process special category data under Article 9 of the UK GDPR, or criminal offence data under Article 10, without first notifying VM6 in writing and agreeing any additional measures required.
Categories of Data SubjectsDetermined solely by the Controller.

Annex B — Technical and organisational measures

Physical security

Infrastructure is located in UK data centres operated by VM6's Sub-processors, with controlled physical access, environmental controls and redundant power.

Network security

Host-level firewalling on hypervisor nodes. Per-environment firewall controls available to customers via the control panel. Outbound port restrictions applied to mitigate abuse. DDoS mitigation at the network edge at supported locations.

Access control

Administrative access to infrastructure is restricted to authorised VM6 personnel. Access is authenticated and logged.

Segregation

Each customer virtual server runs as an isolated virtual machine under hardware-assisted virtualisation with separate virtual disks. Customers have no access to other customers' environments.

Backups

VM6 takes daily infrastructure-level backups of customer virtual servers, retaining four daily copies, stored at a separate UK location from the primary server. Backups are a disaster-recovery facility and are not a substitute for the Controller's own backups. VM6 gives no warranty as to the recoverability of any individual backup.

Patch management

Hypervisor host operating systems and VM6 management systems are maintained with vendor security updates, with critical updates prioritised. Guest operating systems are the Controller's responsibility unless covered by Managed Services.

Monitoring

Infrastructure availability and capacity monitoring across the fleet, with alerting to VM6 personnel.

Encryption

Customer-facing management interfaces are served over TLS. VM6 does not encrypt virtual machine disk images at rest. Controllers requiring encryption at rest must implement it within their own environment.

Personnel

VM6 is a small operator. Administrative access is limited to a small number of named personnel, all of whom are bound by confidentiality obligations.

Annex C — Sub-processors and data locations

Customer Data for Services deployed in UK locations is processed on infrastructure located in the United Kingdom.

VM6 engages a limited number of Sub-processors providing data centre facilities, colocation, network transit and rented server infrastructure. A current list naming each Sub-processor, its role and its location is provided to Customers on request under clause 7.1. VM6 may require a confidentiality undertaking before providing it.

Questions, sub-processor list or a signed copy?

To request our sub-processor list, a countersigned copy of this DPA, or to ask about a custom DPA for your organisation:

  • Support Portal: Submit a ticket through your client area
  • Email: info@vm6.co.uk

Version 1.0. This page was published on 27th September 2026.

Follow Us

Stay connected with VM6 Networks on social media for updates, tips, and community support.

Facebook X.com LinkedIn Tumblr WhatsApp Google

Useful Links

  • VPS Hosting
  • Dedicated Servers
  • Web Hosting
  • Promotions
  • Looking Glass
  • Knowledgebase
  • Contact Support
  • Client Area

Company Info

VM6 Networks LTD

Company Number: 16553775

Address:
Unit A, 82 5 Canon Court, Institute St
Greater Manchester, BL1 1PZ
United Kingdom
Email:
info@vm6.co.uk
Support Hours:
24/7 Technical Support
VM6 Networks

Independent UK hosting. AMD Ryzen 9 and EPYC nodes in UK datacentres, built and supported by the engineers who run them.

VM6 Networks Ltd · Company No. 16553775
Registered in England & Wales

Hosting
  • UK VPS Hosting
  • WordPress VPS
  • High-Traffic Hosting
  • Game Server VPS
  • Dedicated Servers
  • UK Budget Hosting
Specialist
  • Docker VPS
  • Linux VPS
  • DirectAdmin VPS
  • VPN & Proxy VPS
  • Student Discount
  • UK Forex VPS
  • UK Managed VPS
Company
  • Our Blog
  • Promotions
  • Affiliate Programme
  • Service Status
  • Looking Glass
Support & Legal
  • Submit a Ticket
  • Knowledgebase
  • Legal & Policies
  • Terms of Service
  • Refund Policy
  • Privacy Policy
  • Cookie Settings
© 2026 VM6 Networks Ltd. All rights reserved. UK datacentres · Coventry · Maidenhead · Norwich

Cookies

We use essential cookies to run the site, and analytics cookies to understand how it's used. Analytics stay off unless you accept. Privacy Policy · Cookie Policy