Cookie preferences

We use necessary cookies to keep the service secure and working properly. With your permission, we also use Google cookies for analytics, conversion measurement, and ads personalization and retargeting. Read more in our Cookie Policy.

Logo

Data Processing Addendum

Last Updated: 2026-08-11

This Data Processing Addendum ("DPA") forms part of the agreement between devdata AB ("Processor", "we", "our", or "us") and the customer agreeing to our Terms of Service ("Controller" or "you") to the extent that we process Customer Personal Data on your behalf in connection with the Service.

1. Scope and Roles

This DPA applies where you act as a controller of Customer Personal Data and we act as your processor. You appoint us to process Customer Personal Data only as necessary to provide, secure, maintain, support, back up, restore, and improve the Service in accordance with your documented instructions, the Terms of Service, and this DPA.

2. Subject Matter and Duration

The subject matter of the processing is the provision of our hosted Uptime-Kuma service. Processing will continue for the duration of your use of the Service and any limited post-termination period during which we retain Customer Personal Data in accordance with the Terms of Service, this DPA, or applicable law.

3. Nature and Purpose of Processing

We process Customer Personal Data for the purpose of hosting customer instances, storing and transmitting customer-configured monitoring data, performing automated backups and restores, troubleshooting incidents, providing customer support, maintaining service security, and carrying out other processor activities necessary to provide the Service.

4. Categories of Data and Data Subjects

The categories of Customer Personal Data processed under this DPA depend on how you use the Service and may include monitor configuration data, notification destinations, status page content, logs, metadata, and any personal data you or your authorized users choose to store or transmit through the Service.

Data subjects may include your employees, contractors, end users, notification recipients, website visitors, customers, and other individuals whose personal data is included in your use of the Service.

5. Controller Instructions

We will process Customer Personal Data only on your documented instructions, including as described in the Terms of Service, this DPA, and your use and configuration of the Service, unless we are required to do otherwise by applicable law. If we believe an instruction violates applicable data protection law, we will notify you unless prohibited from doing so by law.

6. Confidentiality

We will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

7. Security Measures

We will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access, taking into account the nature of the processing and the information available to us.

8. Subprocessors

You authorize us to use subprocessors to provide the Service, including hosting, infrastructure, communications, security, and payment-related providers. Our current subprocessors include Hetzner, Cloudflare, Stripe, SendGrid, and Twilio to the extent they are used in providing the Service. We will remain responsible for the performance of our subprocessors' obligations to the extent required by applicable law.

9. International Transfers

Where Customer Personal Data is transferred to a country that does not provide an adequate level of data protection under applicable law, we will implement an appropriate transfer mechanism to the extent required by applicable law.

10. Assistance

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance to help you respond to data subject requests, personal data breaches, data protection impact assessments, and consultations with supervisory authorities where required by applicable law.

11. Personal Data Breaches

We will notify you without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data and will provide information reasonably available to us to help you meet your notification obligations.

12. Audits and Compliance Information

We will make available to you information reasonably necessary to demonstrate our compliance with this DPA. If you require additional audit rights beyond the information we make generally available, the parties will work in good faith to agree on a reasonable, proportionate, and confidential audit process.

13. Return and Deletion

Upon termination of the Service, we will delete or return Customer Personal Data in accordance with the Terms of Service and our standard retention practices, unless applicable law requires retention.

14. Liability

This DPA is subject to the limitations and exclusions of liability set out in the Terms of Service unless applicable law requires otherwise.

15. Order of Precedence

If there is a conflict between this DPA and the Terms of Service with respect to the processing of Customer Personal Data, this DPA will control to the extent of that conflict.

16. Contact Information

If you have any questions about this DPA, please contact us at:

devdata AB
Email: support@uptime-kuma.com