Data Processing Agreement
1. What this agreement is
This Data Processing Agreement is Annex 1 to our Terms of Service and forms part of the Agreement between you and us. Words defined in the Terms have the same meaning here.
It applies whenever we process personal data on your behalf while providing the Service. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them in the General Data Protection Regulation (EU) 2016/679, the GDPR.
You accept this agreement together with the Terms. No separate signature is needed.
2. Who is who
For the personal data described in section 15, you are the controller and we are your processor. If you process that data for someone else, for example for your own clients, you are their processor and we are your sub-processor, and you confirm that you are allowed to engage us.
For some personal data we are a controller ourselves, because we decide why and how it is used. This is the case for the details of your Account owner, your billing and payment details, and what we need to secure the Platform and to meet our legal obligations. This agreement does not apply to that data. Our Privacy Policy does.
3. Processing on your instructions
We process the personal data only on your documented instructions. The Agreement, and the way you and your Users configure and use the Service, are your instructions.
We do not use the personal data for purposes of our own, do not sell it, and do not combine it with data from other customers, except as set out in section 2.2.
If we believe an instruction of yours breaks data protection law, we will tell you. If the law of the European Union or of a member state requires us to process the personal data in another way, we will inform you beforehand, unless that law forbids it.
You are responsible for having a lawful basis for the personal data you enter into the Service, and for informing the people concerned.
4. Confidentiality
Everyone who has access to the personal data on our side is bound by a duty of confidentiality, and has access only to the extent needed to provide and support the Service.
5. Security
We take appropriate technical and organisational measures to protect the personal data, taking into account the state of the art, the cost of implementation, and the nature of the processing and its risks. The measures in place are described in section 16.
We may change these measures as technology and risks develop, provided the level of protection does not go down.
You are responsible for the security on your side, as described in the Terms. This includes the mailboxes your Users sign in with.
6. Sub-processors
You give us general permission to engage sub-processors. The ones we use at the date of this version are listed in section 17.
We will inform you by email at least 30 days before we add or replace a sub-processor. If you object on reasonable grounds relating to data protection, tell us within that period. If we cannot resolve your objection, you may cancel your Subscription with effect from the date of the change, and we refund the prepaid fees for the period after that date.
We impose on every sub-processor data protection obligations that offer at least the protection of this agreement, and we remain responsible towards you for their performance.
7. Transfers outside the EEA
Our own servers, databases and backups are located within the European Economic Area.
If personal data is transferred outside the European Economic Area, by us or by a sub-processor, this only happens where the GDPR allows it: to a country the European Commission has found to offer adequate protection, or on the basis of appropriate safeguards such as the Commission's standard contractual clauses.
8. Requests from individuals
If a person asks us to exercise a right under the GDPR concerning personal data we process for you, we pass the request on to you without delay and do not answer it ourselves, unless you ask us to.
Much of what such a request needs you can do yourself in the Platform, such as viewing, correcting or removing a User or a viewer. Where you cannot, we help you with appropriate technical and organisational measures, to the extent this is reasonably possible.
9. Personal data breaches
If we become aware of a personal data breach that affects the personal data we process for you, we will inform you without undue delay, and where feasible within 48 hours.
We will tell you what we know at that moment: the nature of the breach, the kind and approximate amount of data and people concerned, the likely consequences, and what we have done and intend to do about it. Where not everything is known yet, we will follow up as more becomes clear.
Deciding whether to notify a supervisory authority or the people concerned is your responsibility as controller. We will give you the information you reasonably need to do so.
10. Other assistance
Taking into account the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and with prior consultations of a supervisory authority that concern the Service.
If assistance under this agreement goes beyond what can reasonably be expected as part of the Service, we may charge our reasonable costs for it, after telling you in advance.
11. Return and deletion
When the Agreement ends, we handle the personal data as described in the Terms: we keep the data in your Account for 30 days, during which you can ask us for a copy, and then delete it. Copies in our backups are overwritten on a rolling schedule and are gone within about 90 days after that.
We keep personal data longer only where the law requires us to, and then only for that purpose.
12. Information and audits
On request we give you the information you reasonably need to show that the obligations of article 28 of the GDPR are met.
If that information is not sufficient, you may have an audit carried out, by yourself or by an independent auditor who is bound by confidentiality. An audit takes place at most once a year, is announced at least 30 days in advance, is carried out during business hours and in a way that does not disturb the Service or endanger the data of other customers, and is at your expense.
If an audit shows that we do not meet this agreement, we will put that right without delay.
13. Liability
The limitations and exclusions of liability in the Terms apply to this agreement as well, to the extent the law allows. Nothing in this agreement limits the rights that data subjects have against either of us under the GDPR.
14. Duration and precedence
This agreement applies for as long as we process personal data on your behalf, and ends when that processing has ended under section 11.
If this agreement and the Terms contradict each other on the subject of personal data, this agreement takes precedence.
We may change this agreement in the same way as the Terms. Questions about it can be sent to [email protected].
15. Schedule 1: the processing
Subject matter and purpose. Providing the Service to you: giving your Users access to your Account, showing your Status Pages to the people you allow to see them, and sending alerts and other messages of the Service.
Nature of the processing. Collecting, storing, displaying, transmitting and deleting.
Duration. For the duration of the Agreement, and afterwards as described in section 11.
Categories of data subjects.
- your Users: the people in your organisation to whom you give access to your Account;
- viewers: the people, for example at your own clients, whom you allow to see a private Status Page;
- people who are mentioned in content you enter yourself, such as an Incident update.
Categories of personal data.
- names and email addresses of Users and viewers;
- their role in your Account, and which Status Pages they may see;
- sign-in and session records, including IP address, browser type and times;
- records in the audit log of actions they took in your Account;
- any personal data that is contained in what you configure or write, such as a monitored address, an Incident update or the text on a Status Page.
Special categories. The Service is not intended for special categories of personal data, such as data about health, or for data about criminal convictions. You must not enter such data.
16. Schedule 2: security measures
Access. Signing in works through single-use links that expire, sent to the User's email address. There are no passwords to leak or reuse. Session tokens are stored only as a hash. Access to an Account is limited by role, and viewers can see only the Status Pages they were invited to.
Separation. Each application of the Platform connects to the database with its own account, limited to the tables and actions that application needs. The data of different customers is separated in the application on every request.
Network. All traffic to the Platform is encrypted in transit. The applications are not exposed to the internet directly. They are reached only through an outbound tunnel to our network provider. The applications run in containers with a read-only file system.
Browser. The Platform loads no scripts, fonts or other resources from third parties, and enforces this with a content security policy.
Backups. The databases are backed up every night. Each backup is checked for readability, and a copy is stored encrypted at a separate location within the European Union. Restoring from a backup has been tested.
Logging. Actions in an Account, and administrative actions on our side, are recorded in an audit log.
Deletion. Monitoring history is deleted automatically when the retention period of the plan has passed, and the data of an Account is deleted automatically 30 days after the Agreement ends.
Organisation. Access to the production systems and to customer data is limited to the people who operate Lunolyte, and is used only to provide and support the Service.
17. Schedule 3: sub-processors
These are the sub-processors that may process personal data we process on your behalf.
| Sub-processor | What it does for the Service | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the servers and databases the Service runs on | Nuremberg, Germany |
| Cloudflare, Inc. | Network delivery and protection of the Platform, and storage of encrypted backups | Backups are stored in the European Union. Network traffic is handled at the Cloudflare location nearest the visitor. |
| Zoho Corporation B.V. | Delivery of the emails the Service sends, such as sign-in links and alerts | European Union, in the data centres of the Zoho EU service (zoho.eu) |
Our payment provider, Stripe, is not in this list. It handles your own billing and payment details, for which we are a controller and not your processor. See our Privacy Policy.