This section governs how Hex processes personal data on behalf of clients in connection with the services provided. It forms part of the agreement between Hex and the client and satisfies the requirements of UK GDPR Article 28, which requires a written contract between data controllers and data processors.
9.1 Roles
Where Hex hosts a website on behalf of a client, the client is the data controller for any personal data collected through their website (such as form submissions or visitor information). Hex acts as a data processor, processing that data only as necessary to provide the hosting and related services.
9.2 What We Process
In the course of providing our services, Hex may process the following categories of personal data on behalf of clients:
- IP addresses of visitors to hosted websites, for the purposes of DDoS protection and rate limiting.
- Form submissions from hosted websites (which may include names, email addresses, phone numbers, and any other information entered by visitors), solely to forward them to the client via ZeptoMail.
9.3 Instructions
Hex will only process personal data on behalf of a client in accordance with these Terms and any reasonable written instructions provided by the client. If Hex is required by law to process data in a way that goes beyond those instructions, we will notify the client unless prohibited from doing so by law.
9.4 Sub-Processors
By agreeing to these Terms, clients consent to Hex using the following sub-processors where necessary to deliver the services:
- ZeptoMail — used to forward form submissions from hosted websites to clients. Privacy policy: zoho.com/privacy
- Twilio — used to deliver SMS-based authentication codes to Hex platform users. Privacy policy: twilio.com/legal/privacy
- Stripe — used to process payments made to Hex. Privacy policy: stripe.com/privacy
Hex will notify clients of any material changes to sub-processors that may affect the processing of their data.
9.5 Security
Hex implements appropriate technical and organisational measures to protect personal data processed on behalf of clients, including encryption, access controls, and regular security assessments. Full details are set out in our Privacy Policy.
9.6 Data Retention & Deletion
Visitor IP addresses are retained for up to 90 days for security purposes, after which they are deleted. Form submissions are not stored by Hex — they are forwarded immediately to the client and discarded. Upon termination of a client's subscription, Hex will delete all associated data in accordance with section 8.4 of these Terms.
9.7 Data Subject Rights
Clients are responsible for handling any requests from their website visitors exercising rights under UK GDPR (such as access, erasure, or portability). Where Hex holds any relevant data on behalf of a client, we will assist the client in responding to such requests within a reasonable timeframe.
9.8 Data Breaches
In the event of a personal data breach affecting data processed on behalf of a client, Hex will notify the affected client without undue delay and provide reasonable assistance in meeting any notification obligations the client may have under UK GDPR.