DRAFT — not in force yet.
This document is being prepared and does not apply yet. Highlighted notes are open decisions.
Data Processing Agreement
This agreement is part of the Terms of Service and applies when we process personal data on your behalf as your processor under Art. 28 GDPR (and the UK GDPR where applicable). You are the controller of that data.
1. Subject matter and details
| Nature and purpose | Monitoring the websites and systems you add; sending alerts and reports; hosting status pages and client portals. |
|---|---|
| Duration | For the term of your account, then deletion as described below. |
| Categories of data | Contact details you enter (client emails, on-call contacts, team members, status page subscribers); personal data that appears on monitored pages, in screenshots, snapshots and check results. |
| Data subjects | Your clients, staff and contacts; visitors or authors whose data appears on monitored websites; subscribers of your status pages. |
2. Our obligations
- Process the data only on your documented instructions — these terms and your settings in the Service — unless the law requires otherwise, in which case we will tell you unless prohibited.
- Ensure that people authorised to process the data are bound by confidentiality.
- Apply appropriate technical and organisational measures (Art. 32), including encryption in transit, hashed credentials, encrypted monitor secrets, access control and two-factor sign-in.
- Help you respond to data subject requests and meet your obligations under Articles 32–36, taking into account the nature of processing.
- Notify you without undue delay after becoming aware of a personal data breach affecting your data.
- At the end of the service, delete the data (you can export it first), unless law requires storage.
- Make available the information needed to demonstrate compliance with Art. 28 and allow for audits, in a reasonable manner and frequency.
To decide: Pick the breach notification period (48 hours is common) and audit terms (for example, once a year on 30 days’ notice, at the customer’s cost).
3. Sub-processors
You authorise us to use the sub-processors listed on the Sub-processors page. We will announce new sub-processors in advance; you may object on reasonable grounds, and if we cannot address the objection you may terminate the affected service. We impose data protection obligations on sub-processors equivalent to this agreement.
Integrations you connect yourself (chat apps, incident tools, webhooks) receive data on your instruction and are not our sub-processors.
4. International transfers
Where personal data is transferred outside the EEA/UK to a country without an adequacy decision, the Standard Contractual Clauses (Module 2 or 3, as applicable) are incorporated into this agreement by reference.
To decide: If you rely on SCCs, fill in their annexes (parties, description of the transfer, security measures) and keep a short transfer risk assessment for Russia.