Data Processing Addendum
Last Updated: 2026-08-11
This Data Processing Addendum ("DPA") forms part of the agreement between devdata AB ("Processor", "we", "our", or "us") and the customer agreeing to our Terms of Service ("Controller" or "you") to the extent that we process Customer Personal Data on your behalf in connection with the Service.
1. Scope and Roles
This DPA applies where you act as a controller of Customer Personal Data and we act as your processor. You appoint us to process Customer Personal Data only as necessary to provide, secure, maintain, support, back up, restore, and improve the Service in accordance with your documented instructions, the Terms of Service, and this DPA.
2. Subject Matter and Duration
The subject matter of the processing is the provision of our hosted Uptime-Kuma service. Processing will continue for the duration of your use of the Service and any limited post-termination period during which we retain Customer Personal Data in accordance with the Terms of Service, this DPA, or applicable law.
3. Nature and Purpose of Processing
We process Customer Personal Data for the purpose of hosting customer instances, storing and transmitting customer-configured monitoring data, performing automated backups and restores, troubleshooting incidents, providing customer support, maintaining service security, and carrying out other processor activities necessary to provide the Service.
4. Categories of Data and Data Subjects
The categories of Customer Personal Data processed under this DPA depend on how you use the Service and may include monitor configuration data, notification destinations, status page content, logs, metadata, and any personal data you or your authorized users choose to store or transmit through the Service.
Data subjects may include your employees, contractors, end users, notification recipients, website visitors, customers, and other individuals whose personal data is included in your use of the Service.
5. Controller Instructions
We will process Customer Personal Data only on your documented instructions, including as described in the Terms of Service, this DPA, and your use and configuration of the Service, unless we are required to do otherwise by applicable law. If we believe an instruction violates applicable data protection law, we will notify you unless prohibited from doing so by law.
6. Confidentiality
We will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
7. Security Measures
We will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature of the processing and the information available to us.
8. Subprocessors
You authorize us to use subprocessors to provide the Service, including hosting, infrastructure, communications, security, and payment-related providers. Our current subprocessors include Hetzner, Cloudflare, Stripe, SendGrid, and Twilio to the extent they are used in providing the Service. We will remain responsible for the performance of our subprocessors' obligations to the extent required by applicable law.
9. International Transfers
Where Customer Personal Data is transferred to a country that does not provide an adequate level of data protection under applicable law, we will implement an appropriate transfer mechanism to the extent required by applicable law.
10. Assistance
Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you respond to data subject requests, personal data breaches, data protection impact assessments, and consultations with supervisory authorities where required by applicable law.
11. Personal Data Breaches
We will notify you without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and will provide information reasonably available to us to help you meet your notification obligations.
12. Audits and Compliance Information
We will make available to you information reasonably necessary to demonstrate our compliance with this DPA. If you require additional audit rights beyond the information we make generally available, the parties will work in good faith to agree on a reasonable, proportionate, and confidential audit process.
13. Return and Deletion
Upon termination of the Service, we will delete or return Customer Personal Data in accordance with the Terms of Service and our standard retention practices, unless applicable law requires retention.
14. Liability
This DPA is subject to the limitations and exclusions of liability set out in the Terms of Service unless applicable law requires otherwise.
15. Order of Precedence
If there is a conflict between this DPA and the Terms of Service with respect to the processing of Customer Personal Data, this DPA will control to the extent of that conflict.
16. Contact Information
If you have any questions about this DPA, please contact us at:
devdata AB
Email: support@uptime-kuma.com