This Data Processing Agreement ("DPA") forms part of the agreement between [legal name not configured] ("Processor") and the business customer that accepts it ("Controller") for the use of HopLogs. It applies where the Processor processes personal data on the Controller's behalf.
1. Subject and duration
The Processor processes personal data only to provide the Service described in the terms of service, for as long as the Controller uses the Service, and for the deletion period after it ends.
2. Nature and purpose of processing
| Item | Description |
|---|---|
| Categories of data subjects | The Controller's users and team members; people whose contact details the Controller adds as alert contacts; people whose personal data appears on the Controller's monitored targets or status pages |
| Categories of personal data | Names, email addresses, chat or webhook identifiers, IP addresses, and any personal data contained in monitored pages or screenshots |
| Purpose | Monitoring, alerting, status pages, support and billing for the Controller |
| Special categories | None intended. The Controller must not configure the Service to process them |
3. Processor obligations
The Processor will:
- process personal data only on the Controller's documented instructions, including these terms and the Controller's configuration of the Service;
- ensure that people authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures, including encryption in transit, encryption of sensitive fields at rest, access control, audit logging and regular review;
- assist the Controller, as far as reasonably possible, in responding to data subject requests and in meeting its security, breach-notification and impact-assessment obligations;
- notify the Controller without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting the Controller's data;
- at the end of the Service, delete the personal data after the retention period, unless the law requires it to be kept;
- make available the information reasonably necessary to demonstrate compliance, and allow for audits as set out below.
4. Sub-processors
The Controller authorises the sub-processors listed on the sub-processors page. The Processor will give notice of any new sub-processor before it begins processing, and the Controller may object on reasonable data protection grounds. The Processor remains responsible for its sub-processors' performance.
5. International transfers
Where personal data is transferred to a country without an adequacy decision, the parties rely on the European Commission's standard contractual clauses (and the United Kingdom addendum where applicable), which are incorporated by reference.
6. Audits
The Processor will answer reasonable written questions about its security and compliance, and share summaries of relevant reports where available. On-site audits may be agreed in writing, at the Controller's cost, with reasonable notice and confidentiality.
7. Liability and precedence
Each party's liability under this DPA is subject to the limits in the terms of service. If this DPA conflicts with the terms of service about personal data, this DPA prevails.