Data Processing Agreement (DPA)

This agreement sets out how we process personal data on your behalf when you use Uptimeify.

pursuant to Art. 28 GDPR

Zaskoku & Haupt GbR, Lange Str. 54 - 56, 48683 Ahaus, Germany Version 1.0 · As of 3 August 2026

This agreement sets out how we process personal data on your behalf when you use Uptimeify. It forms part of our Terms and Conditions and applies to you as soon as your contract for the use of Uptimeify is formed.

This is a translation. The German version of this agreement is the authoritative one and prevails in the event of any discrepancy (Section 16.3). References to German statutes keep their original citation because German law applies. BGB is the German Civil Code.


Section 1 Parties, roles and formation

1.1 Parties. This agreement is between you, the Uptimeify customer (also the controller), and Zaskoku & Haupt GbR, Lange Str. 54 - 56, 48683 Ahaus, Germany, trading as Uptimeify (referred to as "we", "us", also the processor).

1.2 Roles. You are the controller within the meaning of Art. 4 no. 7 GDPR for the personal data you bring into Uptimeify or have generated there. We are the processor within the meaning of Art. 4 no. 8 GDPR and process that data solely on your documented instructions.

1.3 Use for your end customers. Where you use Uptimeify for your own customers and your end customer is the controller, you are the processor and we are a sub-processor. In that case you ensure that you are authorised by your end customer to engage sub-processors and that the requirements of Art. 28 (4) GDPR are met. No direct contractual relationship arises between us and your end customer (Section 8.2 of the Terms).

1.4 Formation. This agreement takes effect when the contract for the use of Uptimeify is formed, without any further declaration and without a signature. It thereby satisfies the written form requirement of Art. 28 (9) GDPR in electronic form. On request we will provide you with a separately signed counterpart; contact hello@uptimeify.io.

1.5 Precedence. This agreement takes precedence over the Terms on data protection matters. In all other respects the Terms apply, in particular on term, termination and liability.


Section 2 Subject matter and duration

2.1 Subject matter. The subject matter of the processing is the operation of the Uptimeify monitoring, incident, escalation and reporting platform for the technical monitoring of websites, APIs, DNS resources, heartbeat and cron jobs, SSL and TLS certificates, domain expiry, DNSBL entries and protocol endpoints such as ICMP, SMTP, SSH, FTP and IMAP or POP. Data is also collected and processed for notifications, maintenance windows, status pages, white label configurations, API access and reports. To carry out checks we resolve the target hostnames you configure using our own resolvers; where those are at capacity we use the fallback resolvers listed in Annex 2. For notifications by SMS and by voice call we use the gateways listed in Annex 2; where the primary gateway is disrupted or at capacity we use the fallback gateway listed there.

2.2 Duration. The term of this agreement matches the term of the contract for the use of Uptimeify, unless this agreement provides for obligations extending beyond it. Section 12 continues to apply after the contract ends.


Section 3 Nature and purpose of the processing

3.1 Nature of the processing. The processing includes in particular collecting, receiving, storing, structuring, enriching, retrieving, comparing, evaluating, aggregating, transmitting and erasing data. It also includes the automated querying of technical target systems, the generation of incident and availability data, the triggering of notifications, the provision of status pages and the creation of technical reports.

3.2 Purposes. The purposes of the processing are:

  • Ensuring availability: automated checking of the reachability of infrastructure components
  • Performance measurement: determination of technical metrics such as TTFB and latency
  • Security auditing and technical resilience: detection of certificate expiry, DNS anomalies and authentication failures
  • Incident and escalation management: documentation of disruptions and alerting
  • Transparency towards end customers: presentation of states on status pages, including under white label
  • Contractual service documentation: production of SLA evidence and reports
  • Multi-tenant and white label operation: provision of individualised monitoring contexts
  • Minimum technical purpose for credentials: use of access credentials solely to carry out technical checks

3.3 No change of purpose. We do not process the data for our own purposes. In particular we do not use it to train AI models (Section 14.1 of the Terms). Where we process data for our own purposes, for example contract administration, billing, security and aggregated operational statistics, we act as controller; details are set out in our privacy policy.


Section 4 Types of data and categories of data subjects

4.1 Categories of data. The processing covers:

  • Master data: organisation, customer and contact person data such as email, telephone and address
  • User and access management data: user accounts, roles, API tokens
  • Infrastructure metadata: URLs, hostnames, IP addresses, DNS configurations, heartbeat tokens
  • Performance and availability data: check results, response times, status codes, certificate data
  • Diagnostic and evidence data: error messages, technical details, screenshots of the interfaces checked
  • Status and communication data: incident histories, notification channels and their recipients
  • Reporting data: availability statistics, SLA metrics
  • Credentials and other access data: HTTP auth, SSH keys and passwords, FTP, SMTP and IMAP or POP logins and technical secrets
  • Potentially personal content data of target systems: response content or HTML output

4.2 Special categories. Processing of special categories of personal data under Art. 9 GDPR is not a purpose of this agreement. Under Section 13.4 of the Terms you do not bring such data into the Service. Technically it cannot be excluded that such data is captured incidentally in screenshots or response content. You configure your monitors so as to avoid this, in particular through your choice of pages checked and by not using content and screenshot checks on pages with sensitive content. We provide the corresponding settings for this.

4.3 Categories of data subjects.

  • Staff of the controller, for example administration, support and operations
  • End customers of the controller, for example customer administrators and billing and notification contacts
  • Staff or users of the end customers, where accounts are stored for monitoring or status pages
  • Visitors to the monitored websites, where data becomes visible in content checks or screenshots
  • Recipients of notifications
  • Visitors to public status pages

Section 5 Instructions

5.1 Processing on instructions. We process personal data solely within the scope of this agreement and on your documented instructions. Your configuration within the Service, for example the monitors you create, check intervals, notification channels and status pages, constitutes a documented instruction.

5.2 Form. You give instructions in text form to hello@uptimeify.io or through the functions provided in the Service. You confirm oral instructions in text form without undue delay.

5.3 Duty to notify. Where we consider that an instruction infringes the GDPR or other data protection provisions of the Union or of a member state, we inform you without undue delay (Art. 28 (3) sentence 3 GDPR). Until you confirm or amend the instruction we may suspend its execution.

5.4 Legal obligations. Where we are required to process data under Union or member state law, we inform you of that requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.5 Requests from authorities. Where we receive an order from an authority or a court to disclose data we process on your behalf, we inform you without undue delay to the extent legally permitted and limit any disclosure to what is legally required.


Section 6 Confidentiality

6.1 We engage only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) lit. b GDPR). This obligation continues after their activity ends.

6.2 We make the persons engaged aware of data protection requirements to the necessary extent and familiarise them with the instructions applicable to them.

6.3 Address data protection enquiries to hello@uptimeify.io. On request we will name the person responsible for data protection. We will appoint a data protection officer as soon as we are legally required to do so and will then provide the contact details.


Section 7 Technical and organisational measures

7.1 We implement the technical and organisational measures required under Art. 32 GDPR to ensure the confidentiality, integrity, availability and resilience of the systems and services on an ongoing basis. The measures are described in Annex 1.

7.2 The measures are subject to technical progress. We may implement alternative, equivalent measures provided the agreed level of security is not reduced. We document material changes and communicate them to you on request.

7.3 Before processing begins and at regular intervals thereafter, you assess whether the measures in Annex 1 are appropriate for your processing context.


Section 8 Sub-processors

8.1 General authorisation. You give us general authorisation to engage sub-processors under Art. 28 (2) sentence 2 GDPR. The sub-processors engaged at the time this agreement is formed are listed in Annex 2 and are authorised by the conclusion of this agreement.

8.2 Current list. We publish the current list at https://uptimeify.io/subprocessors. We additionally publish changes to our infrastructure and our sub-processors in our infrastructure changelog at https://uptimeify.io/changelog, with an RSS feed.

8.3 Notice of changes. We announce the engagement of a new sub-processor or a change of an existing one at least four weeks before it takes effect, in text form to the address stored in your account. The announcement states the name, registered office, role and processing location.

8.4 Right to object. You may object to the change on data protection grounds in text form within four weeks of receiving the announcement. If you object, we will look for a mutually acceptable solution with you, for example through additional safeguards or an alternative configuration. If no solution is reached within a further four weeks, you may terminate the contract for the use of Uptimeify with effect from the date the change takes effect; Section 12 of the Terms on export and the transition period applies accordingly. Until the termination takes effect we will not use the new sub-processor for your data, to the extent this is technically and economically reasonable for us.

8.5 Urgent cases. Where an immediate change of sub-processor is necessary to avert an acute risk to security, availability or lawfulness, we may make it without observing the notice period in Section 8.3. We inform you afterwards without undue delay; your right to object under Section 8.4 remains.

8.6 Passing on obligations. We contractually bind sub-processors to data protection obligations at least equivalent to those in this agreement, in particular the requirements of Art. 28 (4) GDPR. We are liable to you for their compliance as for our own conduct.

8.7 Not sub-processing. Ancillary services with no connection to the main service, for example cleaning services, postal services or telecommunications services, are not sub-processing within the meaning of this agreement.

8.7.1 Queries to public bodies. Queries we make to public bodies and official registers in order to meet our own statutory obligations are not sub-processing. This applies in particular to the verification of your VAT identification number through the European Commission's VIES system under Section 10.2 of the Terms. We act as controller for that processing; it takes place before the contract is formed and not on your behalf. Details are set out in our privacy policy.

8.8 Optional integrations are not sub-processors. Where you or your end customer connects optional third party services for alerting, for example Slack, Discord, Telegram, PagerDuty, Opsgenie, Microsoft Teams, Jira, Matrix or your own webhooks, we transmit alert data such as monitor name, status and error details to the provider you have chosen. The basis for this is your own agreement with that provider. Those providers are therefore not our sub-processors; responsibility under data protection law for that transmission lies with you. A current overview of the available integrations is at https://uptimeify.io/subprocessors.


Section 9 Processing locations and third country transfers

9.1 Processing in the EU. We operate our core infrastructure exclusively in data centres within the European Union. The monitoring check locations are likewise within the EU or the EEA.

9.2 Transfers to third countries. Where personal data is processed outside the EEA, we ensure appropriate safeguards under Chapter V GDPR, in particular through:

  • adequacy decisions of the European Commission
  • the EU-US Data Privacy Framework for certified US providers
  • standard contractual clauses approved by the European Commission
  • supplementary technical and organisational measures

9.3 Sub-processors established outside the EEA, and those with a group connection to a third country, are marked in Annex 2 together with the respective basis for the transfer. None of those providers processes monitoring data. All sub-processors that process monitoring data are established in the European Union or the EEA and process there.


Section 10 Assistance and data subject rights

10.1 Data subject requests. Where a data subject contacts us directly to request access, rectification, erasure or restriction of processing, we forward the request to you without undue delay and do not answer it ourselves.

10.2 Assistance. We assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests from data subjects (Art. 28 (3) lit. e GDPR) and in complying with the obligations under Art. 32 to 36 GDPR (Art. 28 (3) lit. f GDPR), in particular data protection impact assessments and prior consultations.

10.3 Self-service. Where you can carry out the necessary actions yourself through the functions of the Service, in particular access, rectification, export and erasure, you use those functions first.

10.4 No unilateral changes. We do not rectify, erase or restrict the data processed on your behalf on our own initiative, but only on your documented instruction or in accordance with the periods agreed in Section 12.

10.5 Remuneration. Assistance that goes beyond the contractually owed scope and beyond the functions available in the Service, and that is not attributable to circumstances for which we are responsible, is remunerated on a time and materials basis. We notify you of the charge before starting and agree the effort with you.


Section 11 Personal data breaches

11.1 Where we become aware of a personal data breach affecting the data processed on your behalf, we inform you without undue delay so that you can meet your obligations under Art. 33 and 34 GDPR.

11.2 The notification includes, as far as possible at that point, a description of the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken or proposed. We provide any missing information without undue delay thereafter.

11.3 We assist you in investigating the breach, limiting the damage and meeting your notification and communication obligations.

11.4 We do not notify the supervisory authority or data subjects on your behalf unless you expressly instruct us to do so.


Section 12 Erasure and return

12.1 Your choice. After the end of the provision of processing services we erase the personal data processed on your behalf or return it to you, as you choose (Art. 28 (3) lit. g GDPR).

12.2 Export. You can export your data yourself throughout the term of the contract and within the periods under Section 12.3, through the web interface and through the API, in a structured, commonly used and machine readable format (CSV and JSON). We do not charge for this.

12.3 Periods. The periods set out in the Terms apply:

CaseRetrieval periodErasure from productionBackups
Cancelled trial account (Section 3.4.3 of the Terms)30 days from deactivationafter 30 daysin the course of rotation
End of contract (Section 12.4 of the Terms)30 days from the end of the contractafter 30 daysno later than a further 90 days
Switching providers (Section 12.2 of the Terms)30 day transition period, extendable to six months on requestthereafterno later than a further 90 days

12.4 Early erasure. On your express instruction in text form we erase earlier. The loss of the data is then at your risk.

12.5 Exceptions. Excluded from erasure is data we are required to retain under statutory retention obligations, in particular invoicing and accounting data, as well as aggregated operational statistics with no connection to you or your end customers. The confidentiality obligation continues to apply to such data and processing is limited to the retention purpose.

12.6 Evidence. On request we confirm the erasure to you in text form.


Section 13 Evidence and audit rights

13.1 Evidence. We make available to you the information necessary to demonstrate compliance with our obligations (Art. 28 (3) lit. h GDPR). We do so primarily through Annex 1, the subprocessors page, the infrastructure changelog, our security documentation and current certificates or audit reports where available.

13.2 Additional audit. Where this evidence is not sufficient in an individual case, you may request a further audit, including by an independent auditor you appoint who is not in competition with us. You announce the audit in text form at least four weeks in advance, carry it out during normal business hours and without avoidable disruption to operations, and place the auditor under an obligation of confidentiality.

13.3 Scope. Audits do not extend to the data of other customers, to trade and business secrets not necessary for the audit, or to the premises of our sub-processors where their own audit reports or certificates are sufficient.

13.4 Frequency and costs. Absent a specific cause, one additional audit per calendar year is provided for. Further audits are permitted where there is good cause, in particular following a personal data breach or at the request of a supervisory authority. Each party bears its own costs; our effort for additional audits without specific cause that go beyond providing the evidence under Section 13.1 is remunerated on a time and materials basis.

13.5 Supervisory authorities. We permit and cooperate with inspections by a competent supervisory authority. These are not subject to the restrictions in Sections 13.2 to 13.4.


Section 14 Liability

14.1 Liability is governed by Section 16 of the Terms. Liability towards data subjects under Art. 82 GDPR remains unaffected.

14.2 As between the parties, each party bears the share of the loss corresponding to its contribution to the cause.


Section 15 Changes to this agreement

15.1 We may change this agreement where there is an objective reason, in particular changes in the law, in case law, in supervisory authority guidance, or technical developments. The procedure in Section 20 of the Terms applies, including the notice period and your right to object.

15.2 Changes to Annex 2 are governed exclusively by Sections 8.3 to 8.5 of this agreement.

15.3 We keep earlier versions available with version number and date.


Section 16 Final provisions

16.1 German law applies. The place of jurisdiction is Ahaus, Germany, in accordance with Section 22.2 of the Terms.

16.2 If any provision of this agreement is invalid, the validity of the remaining provisions is unaffected.

16.3 This agreement exists in German and English. In the event of discrepancies, the German version prevails.

16.4 Annex 1 and Annex 2 form part of this agreement.


Annex 1: Technical and organisational measures

This annex sets out the measures owed under Section 7 of this agreement and Art. 32 GDPR. The current state of the art applies; equivalent measures are permitted under Section 7.2.

1. Confidentiality (Art. 32 (1) lit. b GDPR)

1.1 Physical access control

  • Data centres: processing exclusively in EU data centres of our sub-processors (Hetzner, Germany; OVH, France and EEA; netcup, Germany; UpCloud, Germany and Finland; IONOS, Germany). We operate database instances exclusively at German locations. Physical security is provided by the operators: access only for authorised personnel, security turnstiles, round the clock guarding, video surveillance, logged access. The operators engaged hold ISO 27001 certification or equivalent evidence.
  • Our own premises: access only for authorised persons; visitors are accompanied.

1.2 System access control

  • Authentication: personal, individual user accounts; no shared accounts for administrative access. Two-factor authentication available for administrative access and for the customer dashboard.
  • Passwords: enforcement of password policies on minimum length and complexity; storage exclusively as salted hashes in line with the state of the art.
  • Administrative access: servers are reachable only through a private VPN and with a registered SSH key. Access without VPN access or without an SSH key is technically impossible. Password login is disabled. Management interfaces are not reachable from the public internet.
  • Network separation: check and processing nodes communicate with each other exclusively within a closed VPN mesh. Access is withdrawn without undue delay when a person leaves.

1.3 Data access control

  • Roles and permissions: role based access control on a need to know basis; tenant separation between you and your end customers.
  • Target system credentials: technical access credentials such as SSH, FTP, SMTP, IMAP or POP logins, HTTP auth and API and heartbeat tokens are stored in the database in encrypted form only. Decryption happens in the check worker at the moment the check runs. Masking in logs, reports and interfaces.
  • No credentials in queues: the job queues never contain access credentials at any point. They carry job references only; the worker retrieves the associated credentials encrypted and directly from the database.
  • Logging: administrative access and security relevant events are logged.

1.4 Separation control

  • Tenant separation: logical separation of data per tenant and sub-account at application and database level. Every access is checked against the tenant context; access across tenant boundaries is excluded.
  • One database, several locations: application data resides in a single logical database cluster with one writing instance and replicas maintained across several providers. The database instances are located exclusively in Germany. Tenant separation applies unchanged across all instances.
  • Distributed processing: the application, the queues and the check nodes run at several providers within the EU (Annex 2). This distribution does not affect tenant separation.
  • Environment separation: separation of production, test and development environments. Production data is not used in test or development environments.

1.5 Pseudonymisation and encryption

  • Transport encryption: encrypted transmission in line with the state of the art (TLS 1.2 and 1.3).
  • Storage encryption: encryption of sensitive data and secrets at rest.

2. Integrity (Art. 32 (1) lit. b GDPR)

2.1 Transfer control

  • Transmission: data is transmitted to sub-processors only in encrypted form and on the basis of data processing agreements or standard contractual clauses.
  • Media: controlled, data protection compliant disposal and erasure of storage media.

2.2 Input control

  • Traceability: logging of entry, modification and erasure in the relevant systems, so that it can subsequently be verified by whom data was processed.

3. Availability and resilience (Art. 32 (1) lit. b and c GDPR)

3.1 Availability control

  • Backups: regular, automated, encrypted backups. Stored exclusively within the EU and separately from the production system. Retention is governed by Section 12.3 of this agreement.
  • Database high availability: the database cluster maintains instances at several locations that are able to take over the writing role. If the writing instance fails, a replica takes over automatically; the decision is made by a distributed consensus service. The aim is failover without manual intervention.
  • Infrastructure: redundant distribution of check nodes across several providers and locations within the EU. Checks and alerting run independently of the web application and continue to operate when it is unreachable. Protection against power failure and overload is provided by the data centre operators.
  • Decoupled processing: check jobs, notifications, reports and billing runs are distributed through queues. Jobs that must run only once are protected against duplicate execution.
  • Protective measures: firewalls, mandatory VPN for administrative access (section 1.2), monitoring of our own systems.

3.2 Recoverability

  • Recovery: defined procedures for restoring the availability of data after a physical or technical incident.

4. Regular review (Art. 32 (1) lit. d GDPR)

  • Review: regular review, assessment and evaluation of the effectiveness of the measures.
  • Processing control: processing on your behalf only on documented instructions (Sections 5 and 10.4); sub-processors are bound to corresponding measures (Section 8.6).
  • Incident response: process for detecting and reporting personal data breaches (Section 11), with the controller informed without undue delay.
  • Staff: commitment to confidentiality and data secrecy; data protection awareness and training.
  • Security reports: reporting channel for security vulnerabilities under Section 19.3 of the Terms.

Annex 2: Sub-processors

This annex is as of 3 August 2026. The current list at https://uptimeify.io/subprocessors is authoritative.

The Monitoring data column indicates whether customer account or monitoring data, such as monitored URLs, check results, alert content or notification recipients, is processed by that sub-processor.

Service sub-processors

These providers are involved in operating the Uptimeify platform.

Sub-processorRoleLocationMonitoring dataBasis for third country
Hetzner Online GmbHhosting of the application, databases, object storage, error monitoring (self-hosted) and monitoring infrastructureGermanyYesnot applicable
OVH SASserver infrastructure for monitoring check locations and backupsFrance / EEAYesnot applicable
netcup GmbHhosting for monitoring check nodes, Redis queues and databasesGermanyYesnot applicable
UpCloud Ltdhosting for monitoring check nodes, Redis queues and databasesGermany, registered in Finland (EU)Yesnot applicable
IONOS SE (IONOS Cloud)hosting for monitoring check nodes (worker nodes)GermanyYesnot applicable
Whalebone s.r.o. (DNS4EU)fallback DNS resolver for resolving monitored target hostnames, used only when our own primary resolvers are at capacity. Unfiltered public EU resolver of the DNS4EU initiative, no content filteringCzech Republic (EU)Yesnot applicable
xTom GmbH (DNS.SB)fallback DNS resolver for resolving monitored target hostnames, used only when our own primary resolvers are at capacity. Unfiltered public resolver, no content filtering and no query loggingGermany (EU)Yesnot applicable
BunnyWay d.o.o. (bunny.net)EU based CDN for delivering static website assetsSlovenia (EU)Nonot applicable
Lettermint B.V.sending of transactional email: alerts, reports, account emailNetherlands (EU)Yesnot applicable
seven communications GmbH & Co. KG (seven.io)sending of SMS alert notifications and voice calls for alertingGermanyYesnot applicable
LOX24 GmbHfallback gateway for SMS alert notifications and voice calls for alerting, used when the primary gateway is disrupted or at capacityGermanyYesnot applicable
Mollie B.V.payment processing for subscriptions, billing data onlyNetherlands (EU)Nonot applicable
fastmon labs UG (haftungsbeschränkt)real user monitoring: collection of performance and load time telemetry from visitors to the Uptimeify web application in order to measure and improve front end performanceGermanyNonot applicable
Google (Tag Manager, Analytics, Ads)consent based analytics on our public website only, never within the monitoring applicationUSA / EEANoEU-US Data Privacy Framework
Dealfront Group GmbH (Leadfeeder)cookieless identification of visiting companies on our public website for sales and marketing, based on our legitimate interest, never within the monitoring applicationGermanyNonot applicable

Business operations

These providers support our internal business operations and do not process monitoring data.

Sub-processorRoleLocationMonitoring dataBasis for third country
GitHub, Inc.source code hosting, version control and CI/CD pipelinesUSANoEU-US Data Privacy Framework
Ubicloud B.V.managed GitHub Actions runners for our CI/CD pipelines, processes source code and build secretsNetherlands (EU), US parent companyNostandard contractual clauses
Haufe-Lexware GmbH & Co. KG (Lexware)financial administration, accounting and invoicingGermanyNonot applicable
Google Workspace (Google Ireland Limited)email hosting for staff and shared mailboxes, support enquiries received by emailIreland / USANoEU-US Data Privacy Framework
easybell GmbHbusiness telephony via SIP trunk and cloud PBX for our company number, processes call metadata and voice content of inbound and outbound callsGermanyNonot applicable

Optional integrations

Optional alerting integrations are not sub-processors (Section 8.8). They become active only if you configure them yourself. The current overview is at https://uptimeify.io/subprocessors.


Zaskoku & Haupt GbR Lange Str. 54 - 56, 48683 Ahaus, Germany Represented by Florian Zaskoku and Pascal Haupt Email: hello@uptimeify.io

Version 1.0 · As of 3 August 2026