Data Processing Agreement
Draft, not lawyer-reviewed. Prepared September 13, 2026. This proposed SaaS annex requires completion and legal review before execution; publication does not establish an executed DPA.
Proposed annex between the subscribing customer (the Controller) and UptimeVanguard, registered address not configured, KvK 42017143, VAT not configured (the Processor). The contracting customer and its privacy contact must be identified in the executed agreement.
1. Scope and precedence
This annex applies to personal data entrusted to UptimeVanguard for hosted monitoring, alert delivery, status pages and related support. The customer determines which services and recipients are monitored and acts as Controller; the vendor acts as Processor for that monitoring data. Account administration, fraud prevention and the vendor's own billing records are described separately in the Privacy Policy. For entrusted monitoring data, this annex takes precedence over conflicting processing terms in the main agreement.
2. Instructions, purpose and duration
The Processor collects, transmits, stores, analyses and deletes data only to provide the configured service and follow documented customer instructions. Configuration in the application and the executed agreement form those instructions. Processing lasts for the subscription and the agreed return/deletion period. If an instruction appears unlawful, the Processor informs the Controller; legally required processing is notified beforehand unless prohibited. Entrusted data is not used for unrelated purposes.
3. Confidentiality and security
People authorised to process entrusted data must be bound by confidentiality and given access appropriate to their role. The parties agree appropriate technical and organisational measures, including the measures and deployment checks in Annex B. Changes must preserve the agreed level of protection.
4. Sub-processors and customer-selected recipients
The proposed arrangement permits the providers listed in Annex C for their stated purposes. Before execution, the vendor must confirm their legal entities, processing locations and contractual safeguards. Proposed additions or replacements require 30 days' advance notice to the customer's nominated contact. The customer may raise a reasoned objection; if no reasonable alternative is available, the affected service may be terminated. The Processor must impose equivalent processing obligations on its sub-processors and remains responsible for their performance.
Slack, Telegram, webhook destinations and other channels selected by the customer receive the alert payloads the customer instructs us to send. The customer must assess and authorise those recipients and their terms separately.
5. International transfers
Core SaaS hosting is at Hetzner in the EU, while pollers operate in the regions configured for monitoring, including regions outside the EEA. Probe requests may contain URLs, request headers, credentials and response data. This draft does not promise EEA-only processing. The executed annex must identify each destination and establish the appropriate transfer mechanism, such as an applicable adequacy decision or standard contractual clauses, before relevant transfers take place.
6. Assistance and data-subject requests
The Processor promptly forwards requests concerning entrusted data to the Controller and assists with access, correction, erasure, security assessments, DPIAs and regulatory consultation, taking account of the nature of the service. It does not determine the response on the Controller's behalf unless instructed or legally required. Any charges for assistance beyond normal support must be agreed in advance.
7. Personal data breaches
The proposed notification commitment is without undue delay and, where reasonably possible, within 48 hours of discovery, to the customer's nominated privacy contact. The notice describes the nature, affected data and people where known, likely consequences, contact point and mitigation. Missing information is supplied as it becomes available. The Processor documents the breach and assists the Controller with its notification obligations. Notification alone is not an admission of liability.
8. Information and audits
The Processor supplies information reasonably needed to demonstrate compliance. Audits may be arranged annually, after a relevant breach or where otherwise required, with reasonable notice and safeguards for other customers' data. The parties agree practical scope and costs without preventing legally required oversight.
9. Return, retention and deletion
At termination, the Controller may request return of available data in a commonly used format, followed by deletion, subject to applicable retention obligations. The parties must agree and verify a deletion timetable, including backups, before executing this annex. The source draft's 30-day deletion target is a proposed contractual target requiring operational confirmation.
The application prunes configured data categories through a daily task and records account analytics erasure requests for background processing. ClickHouse mutations finish asynchronously. Backup expiry, late-arriving writes and external recipients need separate operational handling. These mechanisms do not establish that every copy has already been deleted; confirmation must follow verification. Billing records held for the vendor's own obligations are handled separately.
10. Liability and survival
The main agreement's applicable liability provisions govern between the parties without limiting mandatory rights of data subjects. Confidentiality, assistance and deletion obligations survive for as long as relevant data is retained.
Annex A — Processing specification
- Data: monitored URLs and hostnames, configured request headers/bodies and credentials, IP/DNS/certificate data, response headers and captured results, timings, incident updates, alert addresses and channel identifiers, subscriber email addresses, and support material supplied by the customer.
- People: customer staff, contractors, alert recipients, status-page subscribers and people whose information appears in customer-selected endpoints or diagnostics.
- Purpose: check availability and performance, diagnose failures, communicate incidents and publish customer-selected status information.
- Minimisation: customers should avoid sensitive or special-category personal data in targets, request bodies, responses and support files. Send only what the check requires.
Annex B — Measures and deployment verification
The application provides password hashing, optional two-factor authentication, team roles, encrypted check settings and protection against unsafe outbound targets. HTTPS, access controls, patching and incident handling must be maintained operationally. Production access, at-rest encryption, provider agreements, backups and restore tests, retention completion and transfer safeguards must be documented and verified before this draft is executed. No certification or unverified backup guarantee is asserted here.
Annex C — Providers and roles to confirm
| Provider | Purpose and data | Location / role |
|---|---|---|
| Hetzner Online GmbH | Core SaaS hosting, databases and monitoring infrastructure | EU; hosting sub-processor |
| Mollie B.V. | Checkout, mandates, payment references and billing identity | Payment provider for the vendor's billing relationship; confirm its independent-controller and any processor roles in the executed documents |
| Cloudflare | SMTP/outbound email and DNS infrastructure; recipient addresses, message content and DNS metadata as applicable | Provider locations and transfer safeguards must be confirmed; no claim that all application traffic is reverse-proxied |
| Poller hosting providers | Operate regional probes receiving configured targets and request data and returning results | Worldwide regions; legal provider names, locations and safeguards must be listed in the executed annex. The generated help-center poller IP/region list describes fleet addresses and does not replace that legal inventory. |
For the completed provider inventory, proposed execution or a privacy request, contact privacy@uptimevanguard.com.