1.Parties, roles and scope
This Data Processing Agreement (“DPA”) is entered into between [[COMPANY_LEGAL_NAME]], registered at [[REGISTERED_ADDRESS]], company number [[COMPANY_NUMBER]] (“zutpralik”, the “Processor”) and the customer that holds a zutpralik account (“Customer”, the “Controller”). It forms part of the Terms of Service and applies automatically to every account, without separate signature, from the moment the Customer enters personal data about its own clients into the platform.
It is concluded under Article 28(3) of Regulation (EU) 2016/679 (GDPR).
Which data this DPA covers
| Data | Role of zutpralik | Governed by |
|---|---|---|
| Data the Customer enters about its own clients and their sites, and the monitoring data generated for those sites | Processor (Customer is Controller) | This DPA |
| The Customer’s own account data, its users, its subscription and the invoices zutpralik issues to it | Controller | The Privacy Policy |
The Customer confirms that it has a lawful basis for the personal data it enters, has provided the necessary information to the data subjects, and is responsible for the accuracy and lawfulness of that data and of the instructions it gives us.
2.Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the zutpralik website-monitoring platform to the Controller. |
| Duration | For as long as the Controller has an account, plus the deletion window in section 12 and the backup rotation period described there. |
| Nature of the processing | Collection, storage, structuring, retrieval, use, transmission (alerts and reports), erasure and backup — all by automated means. |
| Purpose | Monitoring the availability, response time, content, SSL/domain expiry and DNS configuration of the sites the Controller registers; recording incidents; delivering alerts; producing reports; and supporting the Controller’s billing of its own clients. |
| Instructions | The Terms of Service, this DPA, and the configuration the Controller makes in the application constitute the Controller’s documented instructions. |
3.Categories of data subjects and personal data
Data subjects
- the Controller’s users (agency staff with a login);
- the Controller’s clients and their contact persons;
- recipients of alerts — the people behind the e-mail addresses, Telegram chat ids and webhook endpoints configured in the workspace.
Categories of personal data
| Category | Fields |
|---|---|
| Identity and contact | Name, e-mail address, role; client company name, contact e-mail and company details such as an address. |
| Authentication | bcrypt password hash, invitations (e-mail address, 7-day expiry), password-reset tokens (stored as hashes, 60-minute expiry). |
| Assets under monitoring | Site URLs and check configuration (keyword, TCP port). |
| Monitoring results | HTTP status codes, response times, error text returned by the target, SSL certificate and domain expiry dates, DNS records. |
| Operational history | Incidents, activity events, notification delivery logs. |
| Billing | Invoices and the billing details the Controller enters for its clients. |
| Notification endpoints | E-mail addresses, Telegram chat ids, webhook URLs, Slack and Discord incoming-webhook URLs, PagerDuty integration keys. |
| Security records | Impersonation audit log entries, including the administrator’s IP address and user-agent. |
No special categories. The platform is not designed for GDPR Art. 9 data or criminal-offence data, and the Controller must not enter any.
4.Processing only on documented instructions
We process personal data only on the Controller’s documented instructions, including on transfers to a third country, unless EU or member state law requires otherwise. In that case we will inform the Controller of the requirement before processing, unless the law prohibits that notification on important grounds of public interest.
We will inform the Controller if, in our opinion, an instruction infringes the GDPR or other EU or member state data protection law. We may refuse to carry out an instruction that is unlawful or that is technically incompatible with the platform.
We do not use the Controller’s personal data for our own purposes, do not sell it, and do not use it to train models or to build profiles.
5.Confidentiality
Access to personal data is limited to personnel who need it to provide or support the service. Everyone with access is bound by a duty of confidentiality — contractual or statutory — that survives the end of their engagement, and is instructed to process personal data only as this DPA allows. Administrator access to a Controller’s workspace via “view as user” is logged (see section 6).
6.Security of processing (Art. 32)
The technical and organisational measures below are the ones actually implemented. This is the annex the Controller can rely on in its own records of processing.
| Area | Measure in place |
|---|---|
| Credentials | Passwords hashed with bcrypt; never stored or displayed in clear. Password-reset links are single-use, expire after 60 minutes and are stored only as hashes. |
| Encryption in transit | TLS between the user’s browser and the platform, terminated by Cloudflare. |
| Tenant isolation | Strict multi-tenant separation: every database query is scoped by tenant, so one workspace cannot read another’s data. |
| Access control | Role-based access inside the application. Server access by SSH key only; password login disabled. Firewall restricted to SSH, HTTP and HTTPS. |
| Abuse resistance | Rate-limited authentication endpoints. |
| Accountability | Administrator “view as user” sessions recorded in an immutable audit log with identity, IP address, user-agent, start and end time; the session token expires after 60 minutes. Workspace changes recorded in an activity feed. |
| Availability and resilience | Daily database backups (14 daily and 8 weekly copies) with restores verified, not assumed. |
| Data minimisation | Raw check history pruned nightly to the plan’s retention window: 30 days (Basic), 180 days (Pro), 365 days (Business). |
7.Sub-processors
The Controller gives general written authorisation for the sub-processors listed below. Each is engaged under a written contract imposing data protection obligations no less protective than this DPA, and we remain fully liable to the Controller for their performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Xorek.Cloud (DpkgSoft International Limited) | Server hosting: application, database and database backups | Amsterdam, Netherlands (EU) |
| Cloudflare, Inc. | CDN and reverse proxy; TLS termination — all traffic passes through it | Global edge; company established in the United States |
Conditional sub-processors. The platform can send alerts by e-mail, Telegram, webhook, Slack, Discord and PagerDuty. If and when an outbound SMTP provider or the Telegram Bot API is configured for delivery, that provider becomes a sub-processor for the alert content routed through it, and this table will be updated before it starts processing. Webhook, Slack, Discord and PagerDuty alerts are delivered to an endpoint the Controller itself chooses — including, in those last three cases, to Slack, Discord or PagerDuty as the Controller’s own provider. Those recipients are not our sub-processors and the Controller is responsible for them.
We will give the Controller at least 30 days’ notice by e-mail before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.
8.International transfers
All personal data is stored on a server in Amsterdam, the Netherlands (EU), including backups. The only transfer outside the EEA arises because traffic in transit passes through Cloudflare, a US company. That transfer relies on the European Commission’s Standard Contractual Clauses and Cloudflare’s data-processing addendum, supplemented by the measures described in section 6. Copies of the relevant safeguards are available on request at [[CONTACT_EMAIL]].
9.Assistance with data-subject requests
Taking into account the nature of the processing, we assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests under GDPR Chapter III — access, rectification, erasure, restriction, portability and objection.
In practice, most requests the Controller receives can be satisfied directly in the application: client and site records can be viewed, edited and deleted by the Controller itself. Where they cannot, we will help within a reasonable time, at no charge for reasonable volumes of requests.
If a data subject contacts us directly about data we process on the Controller’s behalf, we will not respond to the substance ourselves. We will forward the request to the Controller without undue delay and tell the data subject we have done so.
10.Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to us, we assist the Controller in ensuring compliance with its obligations on security of processing (Art. 32), personal data breach notification (Art. 33 and 34), data protection impact assessments (Art. 35) and prior consultation with a supervisory authority (Art. 36). Section 6 of this DPA, including its stated limitations, is intended to give the Controller what it needs for a DPIA without having to ask.
11.Personal data breach notification
We notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf. The notification goes by e-mail to the Controller’s account administrators.
So far as it is available to us, the notification will describe:
- the nature of the breach and, where possible, the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address it and to mitigate its effects;
- a contact point for further information.
Where the full picture is not available at once, we will provide information in phases without further undue delay. It is the Controller who notifies the supervisory authority and, where required, the data subjects; we do not do so on the Controller’s behalf, but we will provide the information the Controller needs to do it.
12.Return and deletion of data
On termination of the account, and at the Controller’s choice, we delete or return all personal data processed on its behalf and delete existing copies, unless EU or member state law requires us to keep it.
- The Controller can export its data at any time while the account is active, and may request an export for 30 days after termination.
- After that window, production data is deleted on request or, at the latest, when we close the account.
- Backups. Deleted data persists in rotating backups until they age out — up to 8 weeks (14 daily plus 8 weekly copies). We do not selectively edit backups; we let them expire. During that period the data remains subject to this DPA and is not restored into production except in a disaster recovery scenario.
13.Audits and information
We make available to the Controller all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.
- Ordinarily this obligation is met by the information in section 6 and by answering the Controller’s written questions, including security questionnaires.
- An on-site or remote inspection may be requested at most once per calendar year, on at least 30 days’ written notice, during business hours, subject to confidentiality, and conducted so as not to disrupt the service or the confidentiality of other customers’ data. Additional audits may be requested where a supervisory authority requires one or after a confirmed breach.
- The auditor must not be a competitor of ours. The Controller bears the cost of audits beyond the first in any year, unless the audit reveals a material breach of this DPA.
We hold no third-party security certification (such as ISO 27001 or SOC 2) today, and we do not imply otherwise.
14.Liability, precedence and changes
Liability under this DPA is subject to the limitations in the Terms of Service, except where the GDPR provides otherwise — in particular Art. 82, which cannot be contracted away.
Where this DPA conflicts with the Terms of Service or any other agreement between the parties, this DPA prevails on matters of data protection.
We may update this DPA to reflect changes in the platform, in our sub-processors or in the law. Material changes are notified at least 30 days in advance to account administrators. This DPA is governed by the law of [[GOVERNING_LAW_COUNTRY]], without prejudice to mandatory provisions of the GDPR. Questions: [[CONTACT_EMAIL]].