Data Processing Agreement
Last updated: August 28, 2026 · Sub-processor list effective 2026-08-28
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer", "Controller") and Gestión Desarrollo e Innovación SAS, Manzana 24 Casa 40, Samaria I, Pereira, Colombia ("MonitorKit", "Processor"), and applies to the extent MonitorKit processes Personal Data on Customer's behalf in the course of providing the Service.
1. Definitions
"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA/CPRA"), and Colombian Law 1581 of 2012 and its implementing decrees. "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data contained in metrics, logs, APM traces, uptime data and account data that Customer transmits to or generates within the Service.
2. Roles of the Parties
The Customer is the Controller (or a Processor acting on behalf of a third-party Controller) of Customer Personal Data. MonitorKit is the Processor. Where MonitorKit processes account and connection metadata for its own billing, security and service-improvement purposes, MonitorKit acts as an independent Controller and its Privacy Policy governs that processing.
3. Scope and Instructions
- MonitorKit will process Customer Personal Data only (a) to provide the Service in accordance with the Terms of Service, (b) as further instructed by Customer through the Service's configuration and features, and (c) as required by applicable law, in which case MonitorKit will inform Customer of that legal requirement before processing unless prohibited from doing so.
- MonitorKit will inform Customer if, in its opinion, an instruction infringes Data Protection Law.
- The subject matter, duration, nature and purpose of the processing, and the categories of Personal Data and Data Subjects, are described in Annex I.
4. Confidentiality
MonitorKit ensures that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality and process the data only on MonitorKit's instructions.
5. Security
MonitorKit implements and maintains the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.
6. Sub-processing
- Customer authorizes MonitorKit to engage the sub-processors listed in Annex III.
- MonitorKit imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to Customer for a sub-processor's performance.
- MonitorKit will give Customer at least 30 days' notice (by email to the account's administrative contact and by updating this page) before adding or replacing a sub-processor. If Customer reasonably objects on data protection grounds within that period, the parties will work in good faith to resolve the concern; if they cannot, Customer may terminate the affected part of the Service.
7. Assistance to the Controller
- Data Subject requests. Taking into account the nature of the processing, MonitorKit will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data Subject rights. Customer can access, export and delete Customer Personal Data directly through the Service; MonitorKit will provide additional assistance on request.
- DPIAs and consultation. MonitorKit will provide reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities, taking into account the information available to MonitorKit.
8. Personal Data Breach
MonitorKit will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. MonitorKit will cooperate with Customer and take reasonable steps to mitigate the breach.
9. Deletion and Return
On termination of the Service, MonitorKit will delete Customer Personal Data within 30 days, except telemetry already removed earlier under the plan retention limits, and except to the extent retention is required by law. Backups containing Customer Personal Data are overwritten on their normal rotation cycle within 60 days. Customer is responsible for exporting any data it wishes to keep before termination.
10. Audit
MonitorKit will make available to Customer information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, no more than once per year (unless required by a supervisory authority), on reasonable prior notice, during business hours, and subject to confidentiality obligations. MonitorKit may satisfy an audit request by providing a current third-party report or its security documentation where that reasonably addresses the request.
11. International Transfers
MonitorKit is established in Colombia and its primary infrastructure is located in the United States (Chicago, Illinois), operated by the sub-processor identified in Annex III. Where MonitorKit or a sub-processor transfers Customer Personal Data outside the EEA, the UK or Colombia to a country without an adequacy decision — including the transfer to the United States described above — the transfer is governed by the applicable Standard Contractual Clauses:
- EEA: the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor) and, where applicable, Module Three (Processor to Processor), incorporated by reference. Annex I, II and III of the SCCs are populated by Annex I, Annex II and Annex III of this DPA. The supervisory authority and governing law are those of Ireland unless another Member State's law applies.
- UK: the International Data Transfer Addendum issued by the ICO, appended to the EU SCCs above.
- Colombia: the parties rely on the SCCs above as the appropriate safeguard for transfers involving the Colombian entity, together with the declarations required by Superintendencia de Industria y Comercio External Circular guidance.
12. CCPA / CPRA
To the extent the CCPA/CPRA applies, MonitorKit is a "service provider". MonitorKit will not sell or share Customer Personal Data, will not retain, use or disclose it for any purpose other than performing the Service, and will not combine it with Personal Data from other sources except as permitted for a service provider.
13. Liability and Term
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA takes effect when Customer accepts the Terms of Service or begins using the Service, whichever is earlier, and remains in force for as long as MonitorKit processes Customer Personal Data.
Annex I — Description of Processing
A. List of Parties
Data exporter: the Customer identified in the account, acting as Controller. Data importer: Gestión Desarrollo e Innovación SAS, Manzana 24 Casa 40, Samaria I, Pereira, Colombia, acting as Processor, providing SaaS server monitoring, log aggregation, APM and uptime monitoring.
B. Description
| Categories of Data Subjects | Customer's personnel and end users whose personal data appears in server logs, request traces, or connection metadata (e.g. IP addresses in access logs); Customer's own users of the MonitorKit dashboard. |
|---|---|
| Categories of Personal Data | Account data (name, email, organization); IP addresses (agent hosts and dashboard users); user agents and request metadata contained in logs; database query text and timings in APM traces (SQL parameters are removed before transmission); log line content as configured by Customer. |
| Special category data | Not intentionally collected. Customer must not route special category data into logs or traces; MonitorKit provides line-exclusion controls in the agent for this purpose. |
| Frequency | Continuous, for the duration of the subscription. |
| Nature and purpose | Storage, indexing, aggregation, alerting and visualization of infrastructure and application telemetry to provide the monitoring Service. |
| Retention | Per plan limits (metrics 30 days; logs 14–90 days base, up to 365 with the retention add-on; APM traces up to 30 days). Account data: subscription term plus 30 days. |
Annex II — Technical and Organizational Measures
- Encryption in transit: all agent-to-server and browser-to-server traffic over HTTPS/TLS.
- Pseudonymization: SQL query parameters in APM traces are replaced with placeholders before transmission; API keys are stored only as SHA-256 hashes; passwords are stored with bcrypt.
- Access control: production infrastructure access restricted to authorized personnel; per-organization data isolation enforced at the application layer on every query; JWT session cookies (httpOnly, Secure); rate limiting on authentication endpoints.
- Application hardening: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options security headers; SSRF protection on all server-side fetches; request-size and ingestion-rate quotas.
- Resilience: cloud-hosted infrastructure with provider-level redundancy; automated database backups; time-partitioned high-volume tables with automated retention enforcement.
- Monitoring and review: application and access logging; periodic security audits; a responsible-disclosure process (/security).
- Sub-processor management: written data protection terms with each sub-processor; the list at Annex III kept current.
Annex III — Sub-processors
The following sub-processors are engaged as of 2026-08-28. Items marked "on enable" are engaged only if Customer activates that integration.
| Sub-processor | Purpose | Data | Location | Engagement |
|---|---|---|---|---|
| Paddle.com Market Ltd | Payment processing and Merchant of Record (checkout, billing, VAT/tax remittance) | Account email, organization name, billing country, subscription status | United Kingdom | Always |
| The Constant Company, LLC (Vultr) | Cloud infrastructure hosting (all application servers and databases) | All Service data: account data, server metrics, logs, APM traces, uptime data | United States (Chicago, IL) | Always |
| Twilio Inc. (SendGrid) | Transactional and notification email delivery (alerts, digests, verification) | Recipient email address and the content of the notification | United States | Always |
| Slack Technologies, LLC | Delivery of alert notifications to a customer-configured Slack incoming webhook | Alert payload content (host name, metric, threshold) sent to the customer's own workspace | United States | On enable |
| PagerDuty, Inc. | Delivery of alert events to a customer-configured PagerDuty integration | Alert event content (host name, metric, severity) sent to the customer's own PagerDuty account | United States | On enable |
Contact
Questions about this DPA or to request a signed copy: [email protected]
Gestión Desarrollo e Innovación SAS — Manzana 24 Casa 40, Samaria I, Pereira, Colombia