zzutpralik
Product
Uptime & performanceSSL, domain & securityContent & keyword checksDNS & networkIncident managementClient portalPlans & invoice billingReports & analyticsAlerts across channelsAll features →
How it worksPricingSecurityContactFAQ
Log inSign up
  1. Home
  2. Legal
  3. Data Processing Agreement
Legal · GDPR Article 28

Data Processing Agreement

When you record your own clients in zutpralik, you are the controller of their personal data and we are your processor. This agreement sets out exactly what we may do with it, how it is protected, who else touches it, and what happens when you leave.

Last updated: 13 August 2026Status: Draft
!
Draft — not legal advice

This document is a draft. It must be reviewed by a qualified lawyer and every [[PLACEHOLDER]] must be completed before it is published or relied upon by anyone.

Contents
  1. 1.Parties, roles and scope
  2. 2.Subject matter, duration, nature and purpose
  3. 3.Categories of data subjects and personal data
  4. 4.Processing only on documented instructions
  5. 5.Confidentiality
  6. 6.Security of processing (Art. 32)
  7. 7.Sub-processors
  8. 8.International transfers
  9. 9.Assistance with data-subject requests
  10. 10.Assistance with Articles 32 to 36
  11. 11.Personal data breach notification
  12. 12.Return and deletion of data
  13. 13.Audits and information
  14. 14.Liability, precedence and changes

1.Parties, roles and scope

This Data Processing Agreement (“DPA”) is entered into between [[COMPANY_LEGAL_NAME]], registered at [[REGISTERED_ADDRESS]], company number [[COMPANY_NUMBER]] (“zutpralik”, the “Processor”) and the customer that holds a zutpralik account (“Customer”, the “Controller”). It forms part of the Terms of Service and applies automatically to every account, without separate signature, from the moment the Customer enters personal data about its own clients into the platform.

It is concluded under Article 28(3) of Regulation (EU) 2016/679 (GDPR).

Which data this DPA covers

DataRole of zutpralikGoverned by
Data the Customer enters about its own clients and their sites, and the monitoring data generated for those sitesProcessor (Customer is Controller)This DPA
The Customer’s own account data, its users, its subscription and the invoices zutpralik issues to itControllerThe Privacy Policy

The Customer confirms that it has a lawful basis for the personal data it enters, has provided the necessary information to the data subjects, and is responsible for the accuracy and lawfulness of that data and of the instructions it gives us.

2.Subject matter, duration, nature and purpose

ItemDetail
Subject matterProvision of the zutpralik website-monitoring platform to the Controller.
DurationFor as long as the Controller has an account, plus the deletion window in section 12 and the backup rotation period described there.
Nature of the processingCollection, storage, structuring, retrieval, use, transmission (alerts and reports), erasure and backup — all by automated means.
PurposeMonitoring the availability, response time, content, SSL/domain expiry and DNS configuration of the sites the Controller registers; recording incidents; delivering alerts; producing reports; and supporting the Controller’s billing of its own clients.
InstructionsThe Terms of Service, this DPA, and the configuration the Controller makes in the application constitute the Controller’s documented instructions.

3.Categories of data subjects and personal data

Data subjects

  • the Controller’s users (agency staff with a login);
  • the Controller’s clients and their contact persons;
  • recipients of alerts — the people behind the e-mail addresses, Telegram chat ids and webhook endpoints configured in the workspace.

Categories of personal data

CategoryFields
Identity and contactName, e-mail address, role; client company name, contact e-mail and company details such as an address.
Authenticationbcrypt password hash, invitations (e-mail address, 7-day expiry), password-reset tokens (stored as hashes, 60-minute expiry).
Assets under monitoringSite URLs and check configuration (keyword, TCP port).
Monitoring resultsHTTP status codes, response times, error text returned by the target, SSL certificate and domain expiry dates, DNS records.
Operational historyIncidents, activity events, notification delivery logs.
BillingInvoices and the billing details the Controller enters for its clients.
Notification endpointsE-mail addresses, Telegram chat ids, webhook URLs, Slack and Discord incoming-webhook URLs, PagerDuty integration keys.
Security recordsImpersonation audit log entries, including the administrator’s IP address and user-agent.

No special categories. The platform is not designed for GDPR Art. 9 data or criminal-offence data, and the Controller must not enter any.

4.Processing only on documented instructions

We process personal data only on the Controller’s documented instructions, including on transfers to a third country, unless EU or member state law requires otherwise. In that case we will inform the Controller of the requirement before processing, unless the law prohibits that notification on important grounds of public interest.

We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law. We may refuse to carry out an instruction that is unlawful or that is technically incompatible with the platform.

We do not use the Controller’s personal data for our own purposes, do not sell it, and do not use it to train models or to build profiles.

5.Confidentiality

Access to personal data is limited to personnel who need it to provide or support the service. Everyone with access is bound by a duty of confidentiality — contractual or statutory — that survives the end of their engagement, and is instructed to process personal data only as this DPA allows. Administrator access to a Controller’s workspace via “view as user” is logged (see section 6).

6.Security of processing (Art. 32)

The technical and organisational measures below are the ones actually implemented. This is the annex the Controller can rely on in its own records of processing.

AreaMeasure in place
CredentialsPasswords hashed with bcrypt; never stored or displayed in clear. Password-reset links are single-use, expire after 60 minutes and are stored only as hashes.
Encryption in transitTLS between the user’s browser and the platform, terminated by Cloudflare.
Tenant isolationStrict multi-tenant separation: every database query is scoped by tenant, so one workspace cannot read another’s data.
Access controlRole-based access inside the application. Server access by SSH key only; password login disabled. Firewall restricted to SSH, HTTP and HTTPS.
Abuse resistanceRate-limited authentication endpoints.
AccountabilityAdministrator “view as user” sessions recorded in an immutable audit log with identity, IP address, user-agent, start and end time; the session token expires after 60 minutes. Workspace changes recorded in an activity feed.
Availability and resilienceDaily database backups (14 daily and 8 weekly copies) with restores verified, not assumed.
Data minimisationRaw check history pruned nightly to the plan’s retention window: 30 days (Basic), 180 days (Pro), 365 days (Business).
Limitations the Controller must factor into its own risk assessment

Cloudflare-to-origin traffic is not yet encrypted. TLS protects the leg between the user and Cloudflare. We do not claim end-to-end encryption, and the Controller should not represent it as such. Enabling origin TLS is on our roadmap.

Backups are compressed but not encrypted, and are stored on the same server as the production database. There is no off-site copy today, which means the backups protect against data corruption and accidental deletion, but not against loss of the server itself.

Single server, single region, no redundancy. See the Service Level Description for what that means for availability.

Some records are currently kept indefinitely — see section 12.

7.Sub-processors

The Controller gives general written authorisation for the sub-processors listed below. Each is engaged under a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable to the Controller for their performance.

Sub-processorPurposeLocation
Xorek.Cloud (DpkgSoft International Limited)Server hosting: application, database and database backupsAmsterdam, Netherlands (EU)
Cloudflare, Inc.CDN and reverse proxy; TLS termination — all traffic passes through itGlobal edge; company established in the United States

Conditional sub-processors. The platform can send alerts by e-mail, Telegram, webhook, Slack, Discord and PagerDuty. If and when an outbound SMTP provider or the Telegram Bot API is configured for delivery, that provider becomes a sub-processor for the alert content routed through it, and this table will be updated before it starts processing. Webhook, Slack, Discord and PagerDuty alerts are delivered to an endpoint the Controller itself chooses — including, in those last three cases, to Slack, Discord or PagerDuty as the Controller’s own provider. Those recipients are not our sub-processors and the Controller is responsible for them.

We will give the Controller at least 30 days’ notice by e-mail before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.

8.International transfers

All personal data is stored on a server in Amsterdam, the Netherlands (EU), including backups. The only transfer outside the EEA arises because traffic in transit passes through Cloudflare, a US company. That transfer relies on the European Commission’s Standard Contractual Clauses and Cloudflare’s data-processing addendum, supplemented by the measures described in section 6. Copies of the relevant safeguards are available on request at [[CONTACT_EMAIL]].

9.Assistance with data-subject requests

Taking into account the nature of the processing, we assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests under GDPR Chapter III — access, rectification, erasure, restriction, portability and objection.

In practice, most requests the Controller receives can be satisfied directly in the application: client and site records can be viewed, edited and deleted by the Controller itself. Where they cannot, we will help within a reasonable time, at no charge for reasonable volumes of requests.

If a data subject contacts us directly about data we process on the Controller’s behalf, we will not respond to the substance ourselves. We will forward the request to the Controller without undue delay and tell the data subject we have done so.

10.Assistance with Articles 32 to 36

Taking into account the nature of the processing and the information available to us, we assist the Controller in ensuring compliance with its obligations on security of processing (Art. 32), personal data breach notification (Art. 33 and 34), data protection impact assessments (Art. 35) and prior consultation with a supervisory authority (Art. 36). Section 6 of this DPA, including its stated limitations, is intended to give the Controller what it needs for a DPIA without having to ask.

11.Personal data breach notification

We notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf. The notification goes by e-mail to the Controller’s account administrators.

So far as it is available to us, the notification will describe:

  • the nature of the breach and, where possible, the categories and approximate number of data subjects and records affected;
  • the likely consequences;
  • the measures taken or proposed to address it and to mitigate its effects;
  • a contact point for further information.

Where the full picture is not available at once, we will provide information in phases without further undue delay. It is the Controller who notifies the supervisory authority and, where required, the data subjects; we do not do so on the Controller’s behalf, but we will provide the information the Controller needs to do it.

12.Return and deletion of data

On termination of the account, and at the Controller’s choice, we delete or return all personal data processed on its behalf and delete existing copies, unless EU or member state law requires us to keep it.

  • The Controller can export its data at any time while the account is active, and may request an export for 30 days after termination.
  • After that window, production data is deleted on request or, at the latest, when we close the account.
  • Backups. Deleted data persists in rotating backups until they age out — up to 8 weeks (14 daily plus 8 weekly copies). We do not selectively edit backups; we let them expire. During that period the data remains subject to this DPA and is not restored into production except in a disaster recovery scenario.
Retention that is currently indefinite

Raw monitoring checks are pruned nightly to the plan’s window (30 / 180 / 365 days). However, incidents, invoices, activity events, notification delivery logs and impersonation logs are currently kept indefinitely for as long as the workspace exists. We state this rather than claim a period we do not enforce. The Controller may request their deletion at [[CONTACT_EMAIL]], subject to any statutory retention obligation on invoices.

13.Audits and information

We make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

  • Ordinarily this obligation is met by the information in section 6 and by answering the Controller’s written questions, including security questionnaires.
  • An on-site or remote inspection may be requested at most once per calendar year, on at least 30 days’ written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or the confidentiality of other customers’ data. Additional audits may be requested where a supervisory authority requires one or after a confirmed breach.
  • The auditor must not be a competitor of ours. The Controller bears the cost of audits beyond the first in any year, unless the audit reveals a material breach of this DPA.

We hold no third-party security certification (such as ISO 27001 or SOC 2) today, and we do not imply otherwise.

14.Liability, precedence and changes

Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise — in particular Art. 82, which cannot be contracted away.

Where this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA prevails on matters of data protection.

We may update this DPA to reflect changes in the platform, in our sub-processors or in the law. Material changes are notified at least 30 days in advance to account administrators. This DPA is governed by the law of [[GOVERNING_LAW_COUNTRY]], without prejudice to mandatory provisions of the GDPR. Questions: [[CONTACT_EMAIL]].

Related documents
Privacy PolicyTerms of ServiceCookiesService Level Description
zzutpralik

Website monitoring, incidents and billing — built for agencies and the clients they answer to.

Hosted in the EU · Amsterdam

Product

  • Product
  • Features
  • How it works
  • Pricing
  • Security
  • FAQ
  • Documentation

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Cookies
  • Service Level Description

Get in touch

  • Contact us
  • [email protected]
  • Log in
© 2026 zutpralik. All rights reserved.Made for people who hate finding out from a client’s email.