Skip to content
UptimeAlien

Data Processing Agreement

pursuant to Art. 28 GDPR

This data processing agreement (DPA) is concluded automatically upon your registration with UptimeAlien between you as the controller and Heiko Stuhrmann as the processor, and applies for the duration of your use of the service. A separate signature is not required. If you need an individually signed version, contact us at heiko@uptimealien.de.

Parties

The controller within the meaning of this agreement is the user registered with UptimeAlien (natural or legal person or organization). Identification is based on the master data stored in the account (display name, email address, billing data where applicable).

Processor: Heiko Stuhrmann, c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Germany, email: heiko@uptimealien.de.

§ 1 Subject matter and duration

  1. The subject matter of this agreement is the processing of personal data by the processor to provide the UptimeAlien service, in particular the storage of monitoring configurations and check results, the receipt and storage of submitted error events, and the sending of notifications on behalf of the controller.
  2. The agreement begins with the controller's registration and applies for the duration of the main service relationship. It ends automatically upon deletion of the account.
  3. Processing takes place exclusively on documented instructions of the controller, unless the processor is required to process by Union law or the law of a member state. Instructions are generally given through actions in the UptimeAlien customer area and may be specified by written additions (email is sufficient).

§ 2 Nature and purpose of processing

  1. Nature of processing: collection, storage, structuring, transmission, retrieval, use, restriction, deletion, or destruction of personal data within the monitoring and notification functions and user administration.
  2. Purpose: provision of the UptimeAlien service, i.e. monitoring of the check targets configured by the controller, storage of check results and submitted error events, and sending of notifications via the configured channels.

§ 3 Type of personal data

The following categories of data in particular may be subject to processing:

  • Master data (display name, email address, password hash)
  • Monitoring configuration (check targets such as URLs, hostnames, ports)
  • Check and incident data (status, response times, incident history)
  • Error events (message, stack trace, tags, context) — may contain personal data insofar as transmitted by the controller
  • Notification content and recipient data (notify contacts, channel configuration such as email addresses or webhook URLs)
  • Device and token data (FCM token for the Android app)
  • Usage data (timestamps, IP address, user agent in logs)
  • 2FA data (TOTP secret), if enabled

§ 4 Categories of data subjects

  • Employees of the controller who use the service
  • Recipients of notifications (e.g. notify contacts) initiated by the controller
  • Persons whose personal data may be contained in the error events transmitted by the controller

§ 5 Obligations of the processor

  1. The processor processes personal data exclusively within the scope of this agreement and on documented instructions of the controller, unless legally required to process otherwise.
  2. The processor ensures that persons authorized to process are committed to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
  3. The processor supports the controller, taking into account the nature of processing, in complying with the obligations set out in Art. 32 to 36 GDPR.
  4. Personal data is processed exclusively within the EU/EEA, with the exception of the sub-processors listed in Annex 2, for which an adequate level of data protection (Art. 46 GDPR, EU-US Data Privacy Framework, standard contractual clauses) is ensured.

§ 6 Technical and organizational measures (TOM)

The processor implements the technical and organizational measures described in Annex 1 pursuant to Art. 32 GDPR and ensures their compliance during the term of the contract. Changes that do not lower the level of security are permitted.

§ 7 Rectification, restriction, and erasure

  1. The processor may rectify, erase, or restrict the processing of personal data only on the instructions of the controller.
  2. The processor forwards requests from data subjects to the controller without delay and does not respond to them independently.

§ 8 Sub-processing

  1. By registering, the controller grants general written authorization for the engagement of the sub-processors listed in Annex 2.
  2. The processor will notify intended changes (new or replacement sub-processors) with reasonable notice (at least 30 days) in advance via the email address stored in the account or by publishing a new version of this DPA. The controller has a right to object for good cause; in the event of a justified objection, both parties are entitled to extraordinary termination.
  3. The processor ensures by contractual arrangements that the obligations of this agreement are imposed on the sub-processors.

§ 9 Audit rights of the controller

  1. The controller has the right to verify compliance with this agreement, regularly by requesting a self-disclosure or the presentation of a current audit report of an independent expert.
  2. On-site inspections are permitted only in justified exceptional cases and after coordination with reasonable advance notice (at least 4 weeks); the associated effort may be charged at customary rates.

§ 10 Notification of breaches

The processor reports any breach of the protection of personal data to the controller without delay, at the latest within 72 hours of becoming aware, providing the information required under Art. 33 (3) GDPR. Notification is made to the email address stored in the account.

§ 11 Controller's right to issue instructions

  1. Instructions are given through actions in the UptimeAlien customer area as well as by supplementary written instructions (email is sufficient).
  2. If the processor considers an instruction to be in breach of data protection law, it informs the controller without delay and is entitled to suspend execution until the instruction is confirmed or changed.

§ 12 Deletion and return after end of processing

  1. After the end of the main service relationship (account deletion), the processor deletes all personal data of the controller, unless statutory retention obligations apply.
  2. The standard deletion periods are documented in the privacy policy. Backups are overwritten within 30 days.
  3. The controller can export their data independently via the account functions before deletion or request it by email.

§ 13 Liability

Art. 82 GDPR applies. The parties are liable to data subjects in accordance with the provisions set out therein. Internally, each party is liable for the breaches attributable to it; internal liability is limited to gross negligence and intent, unless mandatory statutory provisions provide otherwise.

§ 14 Amendments to this agreement

  1. The processor is entitled to amend this DPA insofar as this is necessary due to a changed legal situation, new sub-processors, or changed processing operations. Material changes are announced with reasonable notice (at least 30 days) in advance.
  2. If the controller does not object within the period, the changes are deemed accepted. In the event of a justified objection, both parties are entitled to terminate.
  3. The current version of this DPA is available at /avv.

§ 15 Miscellaneous

  1. If the controller's ownership or control over the data is jeopardized by measures of third parties (e.g. seizure, confiscation, insolvency proceedings), the processor informs the controller without delay.
  2. German law applies. The exclusive place of jurisdiction is, where legally permissible, the registered office of the processor.
  3. Should any provision of this agreement be or become invalid, the validity of the remaining provisions remains unaffected.

Annex 1: Technical and organizational measures (Art. 32 GDPR)

1. Confidentiality

  • Physical access control: operation on the processor's own server infrastructure in Germany; physical access is restricted.
  • Access control: SSH access via public-key authentication, no password login; admin accounts with mandatory 2FA.
  • Authorization control: role-based permissions (platform and organization roles), tenant separation per organization, API and ingest keys with limited scope.
  • Separation control: strict tenant separation in the database via organization assignment; separate production and development systems.
  • Pseudonymization: passwords stored exclusively as an Argon2id hash; session tokens stored only as a hash.

2. Integrity

  • Transfer control: all data transmission exclusively encrypted via TLS 1.2+ (HTTPS, outgoing webhooks).
  • Input control: server and audit logs for security-relevant events with IP address and timestamp; retention max. 30 days.

3. Availability and resilience

  • Availability control: regular, encrypted database backups within the EU.
  • Recoverability: restore procedure is tested regularly.
  • Abuse protection: rate limiting of public endpoints.

4. Procedures for regular review

  • Data protection management: privacy by design; regular review of processing activities.
  • Incident response: defined reporting path for data breaches (cf. § 10).
  • Order control: contractual obligation of sub-processors (see Annex 2).

Annex 2: Approved sub-processors

The following sub-processors are used with the consent of the controller:

ProviderLocationPurposeTransfer mechanism
Google LLC (Firebase Cloud Messaging)USADelivery of Android push notificationsEU-US Data Privacy Framework + SCC
Polar Software, Inc. (paid plans only)USAPayment processing as Merchant of RecordEU-US Data Privacy Framework + SCC
Strato AG (SMTP delivery)Germany (EU)Sending verification, invitation, and notification emailsEU / no third-country transfer

Updates to this list are communicated in accordance with § 8 of this agreement.

DPA · UptimeAlien