This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between updown.io and the customer ("you"). It applies whenever updown.io processes personal data on your behalf and is required by Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
You accept this DPA when you accept the Terms of Service, so no signature or return copy is required. We do not negotiate changes to this text. If your organisation needs a signed copy for its records, contact support@updown.io and we will send a PDF of this standard version, signed on our side.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them in the GDPR. "Applicable Data Protection Law" means the GDPR and any national law implementing or supplementing it, as well as the UK GDPR and the Swiss FADP where relevant to the processing.
2. Roles of the parties
-
You are the controller of the personal data described in section 3. You determine the purposes and means of the processing, and you are responsible for having a lawful basis for it.
-
updown.io is the processor and processes that personal data only on your behalf.
-
For the personal data we collect as a controller in our own right (your account, billing and contact details, log and location data), this DPA does not apply; that processing is governed by our Privacy Policy.
3. Details of the processing
-
Subject matter, nature and purpose: collection, storage, consultation, transmission (to alert recipients and sub-processors as instructed) and erasure of data, for the purpose of monitoring the availability and performance of the URLs and endpoints you configure, diagnosing downtime, and delivering the alerts, reports and status pages you request.
-
Categories of data subjects: the people you designate as alert recipients; and any visitors or users of the sites you monitor whose data may incidentally appear in a monitored response.
-
Categories of personal data: alert recipient details (email, phone number); credentials you enter to reach a protected endpoint (basic-auth, custom headers, API keys); response headers and body retained for the requests around a downtime, which may incidentally contain personal data; and technical metadata (target hostnames, IP addresses, approximate location, TLS certificate details, timings, status codes).
-
Special categories: none requested or intended (see section 7).
-
Duration: for as long as your account is active, subject to the deletion rules in section 10 and the "Retention" section of the Privacy Policy.
4. updown.io's obligations
We will:
-
Process on documented instructions. Process the personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by EU or member state law (in which case we will inform you before processing, unless that law prohibits it). Your instructions are this DPA, the Agreement, and your use of the configuration options in the service. We will inform you if, in our opinion, an instruction infringes Applicable Data Protection Law.
-
Ensure confidentiality. Ensure that the persons authorised to process the personal data are bound by an appropriate obligation of confidentiality and only access it on a need-to-know basis.
-
Implement security measures. Implement and maintain, in accordance with Article 32 GDPR and appropriate to the risk, technical and organisational measures such as the following:
-
Encryption in transit (TLS/HTTPS) for the website and the API.
-
Production system access limited to the operator of the service (and any contractor explicitly authorised to assist), over authenticated, encrypted channels using key-based SSH authentication with strong, modern key algorithms (currently Ed25519).
-
Host-level firewalling and IP filtering on all servers; rate limiting (Rack::Attack) against abuse.
-
A multi-node MongoDB replica set across datacenters for resilience and availability, with database access controlled by authentication and IP allow-listing, and regular backups with tested restore.
-
Operating-system security updates applied automatically on all servers (Ubuntu LTS with unattended-upgrades); application dependencies monitored for known vulnerabilities through GitHub security alerts and updated on a roughly weekly basis.
-
Per-server logging with centralised monitoring and alerting on node and service health; logs are rotated automatically and any log that may contain personal data (e.g. IP addresses) is kept for no more than one month.
-
Data minimisation and automatic purging: response bodies retained only for downtime diagnosis, metrics progressively aggregated, inactive checks and accounts deleted after 3 years.
-
Instant deletion of account data on account or monitor deletion, with backup copies purged within one week.
-
Confidentiality obligations on all personnel and contractors with data access.
-
Assist you with data subject requests. Taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. Most such data is accessible and deletable directly from your account; for anything else we will help on request.
-
Assist you with compliance. Assist you in ensuring compliance with your obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to us.
-
Notify personal data breaches. Notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide you with the information you reasonably need to meet your own notification obligations.
-
Delete or return data. At your choice, delete or return all the personal data after the end of the provision of the service, and delete existing copies unless EU or member state law requires storage. See section 10 (Term, deletion and return).
-
Demonstrate compliance. Make available to you all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as described in section 8.
5. Sub-processors
-
You give us a general authorisation to engage sub-processors. The current list, with each sub-processor's location and the safeguard in place for any transfer outside the EEA, is maintained in the "List of sub-processors" section of the Privacy Policy.
-
We will impose on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to you for the performance of each sub-processor's obligations.
-
Before adding or replacing a sub-processor we will update the list in the Privacy Policy and, if you have asked us to (email support@updown.io with the subject "DPA sub-processor notice"), notify you by email at least 30 days in advance. If you have a reasonable, data-protection-related objection you may raise it during that period; if we cannot address it, you may terminate the affected part of the service and receive a pro-rata refund of any unused prepaid credits.
6. International transfers
Where we transfer personal data processed on your behalf outside the EEA, we rely on a mechanism recognised under Chapter V of the GDPR: the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), the EU-US Data Privacy Framework, or, where neither applies, another lawful basis. The mechanism used for each sub-processor is set out in the "International transfers" section of the Privacy Policy. Where the Standard Contractual Clauses apply and you are established in the EEA, you instruct us to enter into them (module 3, processor-to-processor) with the relevant sub-processor on your behalf.
7. Your obligations
-
You warrant that you have a lawful basis for the processing and that your instructions comply with Applicable Data Protection Law.
-
You warrant that you own, or are authorised by the owner of, the URLs and endpoints you monitor.
-
You must not deliberately route special categories of personal data (Article 9 GDPR) or criminal-offence data through the monitoring features (for example via the text-search feature), as the service is not designed to safeguard such data.
-
You are responsible for configuring the available options (retention, string checks, alert recipients, credentials) in a way that matches your own compliance requirements.
8. Audits
We will make available, on written request and no more than once per 12-month period (unless required more often by a supervisory authority), the information reasonably necessary to demonstrate compliance with this DPA, typically our current security documentation and third-party reports. To the extent that is insufficient, you may conduct, or mandate an independent auditor to conduct, an audit of the relevant processing activities, on at least 30 days' notice, during business hours, without disrupting our operations or those of our other customers, and subject to confidentiality. Each party bears its own costs.
9. Liability
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
10. Term, deletion and return
-
This DPA takes effect when you accept the Agreement and continues for as long as we process personal data on your behalf.
-
Deletion and automatic compaction of data during and at the end of the service follow the "Retention" section of the Privacy Policy: on monitor or account deletion the data is removed from the database instantly, with residual copies in logs and backups gone within one week.
-
On request made before deletion, we will return the personal data to you in a commonly used electronic format instead of, or in addition to, deleting it.
11. Order of precedence
In case of conflict between this DPA and the rest of the Agreement on a data protection matter, this DPA prevails. In case of conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
12. Governing law
This DPA is governed by the law of France and subject to the jurisdiction of the French courts, in line with the Agreement, without prejudice to any mandatory data subject rights under Applicable Data Protection Law.
Changelog
-
Sept 7th, 2026: Initial web version.