Data Processing Agreement

Last updated: August 28, 2026 · Sub-processor list effective 2026-08-28

Template pending legal review. This DPA is provided as a working draft. It has not yet been reviewed by counsel and must not be relied on as an executed agreement. If you need a signed DPA today, email [email protected].

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer", "Controller") and Gestión Desarrollo e Innovación SAS, Manzana 24 Casa 40, Samaria I, Pereira, Colombia ("MonitorKit", "Processor"), and applies to the extent MonitorKit processes Personal Data on Customer's behalf in the course of providing the Service.

1. Definitions

"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA/CPRA"), and Colombian Law 1581 of 2012 and its implementing decrees. "Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data contained in metrics, logs, APM traces, uptime data and account data that Customer transmits to or generates within the Service.

2. Roles of the Parties

The Customer is the Controller (or a Processor acting on behalf of a third-party Controller) of Customer Personal Data. MonitorKit is the Processor. Where MonitorKit processes account and connection metadata for its own billing, security and service-improvement purposes, MonitorKit acts as an independent Controller and its Privacy Policy governs that processing.

3. Scope and Instructions

4. Confidentiality

MonitorKit ensures that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality and process the data only on MonitorKit's instructions.

5. Security

MonitorKit implements and maintains the technical and organizational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects.

6. Sub-processing

7. Assistance to the Controller

8. Personal Data Breach

MonitorKit will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. MonitorKit will cooperate with Customer and take reasonable steps to mitigate the breach.

9. Deletion and Return

On termination of the Service, MonitorKit will delete Customer Personal Data within 30 days, except telemetry already removed earlier under the plan retention limits, and except to the extent retention is required by law. Backups containing Customer Personal Data are overwritten on their normal rotation cycle within 60 days. Customer is responsible for exporting any data it wishes to keep before termination.

10. Audit

MonitorKit will make available to Customer information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, no more than once per year (unless required by a supervisory authority), on reasonable prior notice, during business hours, and subject to confidentiality obligations. MonitorKit may satisfy an audit request by providing a current third-party report or its security documentation where that reasonably addresses the request.

11. International Transfers

MonitorKit is established in Colombia and its primary infrastructure is located in the United States (Chicago, Illinois), operated by the sub-processor identified in Annex III. Where MonitorKit or a sub-processor transfers Customer Personal Data outside the EEA, the UK or Colombia to a country without an adequacy decision — including the transfer to the United States described above — the transfer is governed by the applicable Standard Contractual Clauses:

12. CCPA / CPRA

To the extent the CCPA/CPRA applies, MonitorKit is a "service provider". MonitorKit will not sell or share Customer Personal Data, will not retain, use or disclose it for any purpose other than performing the Service, and will not combine it with Personal Data from other sources except as permitted for a service provider.

13. Liability and Term

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. This DPA takes effect when Customer accepts the Terms of Service or begins using the Service, whichever is earlier, and remains in force for as long as MonitorKit processes Customer Personal Data.


Annex I — Description of Processing

A. List of Parties

Data exporter: the Customer identified in the account, acting as Controller. Data importer: Gestión Desarrollo e Innovación SAS, Manzana 24 Casa 40, Samaria I, Pereira, Colombia, acting as Processor, providing SaaS server monitoring, log aggregation, APM and uptime monitoring.

B. Description

Categories of Data SubjectsCustomer's personnel and end users whose personal data appears in server logs, request traces, or connection metadata (e.g. IP addresses in access logs); Customer's own users of the MonitorKit dashboard.
Categories of Personal DataAccount data (name, email, organization); IP addresses (agent hosts and dashboard users); user agents and request metadata contained in logs; database query text and timings in APM traces (SQL parameters are removed before transmission); log line content as configured by Customer.
Special category dataNot intentionally collected. Customer must not route special category data into logs or traces; MonitorKit provides line-exclusion controls in the agent for this purpose.
FrequencyContinuous, for the duration of the subscription.
Nature and purposeStorage, indexing, aggregation, alerting and visualization of infrastructure and application telemetry to provide the monitoring Service.
RetentionPer plan limits (metrics 30 days; logs 14–90 days base, up to 365 with the retention add-on; APM traces up to 30 days). Account data: subscription term plus 30 days.

Annex II — Technical and Organizational Measures

Annex III — Sub-processors

The following sub-processors are engaged as of 2026-08-28. Items marked "on enable" are engaged only if Customer activates that integration.

Sub-processorPurposeDataLocationEngagement
Paddle.com Market Ltd Payment processing and Merchant of Record (checkout, billing, VAT/tax remittance) Account email, organization name, billing country, subscription status United Kingdom Always
The Constant Company, LLC (Vultr) Cloud infrastructure hosting (all application servers and databases) All Service data: account data, server metrics, logs, APM traces, uptime data United States (Chicago, IL) Always
Twilio Inc. (SendGrid) Transactional and notification email delivery (alerts, digests, verification) Recipient email address and the content of the notification United States Always
Slack Technologies, LLC Delivery of alert notifications to a customer-configured Slack incoming webhook Alert payload content (host name, metric, threshold) sent to the customer's own workspace United States On enable
PagerDuty, Inc. Delivery of alert events to a customer-configured PagerDuty integration Alert event content (host name, metric, severity) sent to the customer's own PagerDuty account United States On enable

Contact

Questions about this DPA or to request a signed copy: [email protected]
Gestión Desarrollo e Innovación SAS — Manzana 24 Casa 40, Samaria I, Pereira, Colombia