Legal
Data Processing Agreement
The terms that govern MonoDuty's processing of customer personal data on behalf of account owners.
Last updated: August 25, 2026
1. Overview
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between MonoDuty ("Processor", "we", "us") and the customer ("Controller", "you") using our incident management and alerting services.
This DPA reflects the parties' agreement with regard to the processing of personal data by the Processor on behalf of the Controller in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
This DPA applies automatically to all customers using MonoDuty services. By using our services, you agree to the terms of this DPA. Enterprise customers may request a custom DPA by contacting [email protected].
2. Definitions
In this DPA, the following terms shall have the meanings set out below:
- "Controller" means the customer who determines the purposes and means of the processing of personal data.
- "Processor" means MonoDuty, which processes personal data on behalf of the Controller.
- "Sub-processor" means any third party engaged by MonoDuty to process personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
- "Data Subject" means the individual whose personal data is being processed.
- "Standard Contractual Clauses (SCCs)" means the clauses adopted by the European Commission for the transfer of personal data to countries outside the EEA.
3. Scope of Processing
3.1 Subject Matter
MonoDuty processes personal data to provide incident management, alerting, on-call scheduling, and monitoring services as described in the Agreement.
3.2 Nature and Purpose
The processing includes:
- Receiving and routing incident alerts via webhooks
- Delivering notifications via email, SMS, voice call, and push notifications
- Managing on-call schedules and escalation policies
- Providing dashboards, analytics, and audit logs
- Uptime monitoring and heartbeat checks
3.3 Categories of Data Subjects
- Controller's employees and team members
- On-call engineers and incident responders
- System administrators and account managers
3.4 Types of Personal Data
- Contact information (name, email, phone number)
- Authentication data (hashed passwords, session tokens)
- Usage data (login history, activity logs, IP addresses)
- Incident data (titles, descriptions, metadata from webhook payloads)
- Notification delivery data (delivery status, timestamps)
3.5 Duration
Processing continues for the duration of the Agreement plus 90 days for account data retention, unless a longer retention period is required by law or agreed upon.
4. Controller Obligations
The Controller shall:
- Ensure it has a lawful basis for processing personal data and sharing it with MonoDuty
- Provide data subjects with required privacy notices
- Ensure the accuracy and quality of personal data provided
- Not send sensitive personal data (special categories) through webhook payloads unless absolutely necessary and appropriately protected
- Cooperate with MonoDuty in relation to data subject rights requests
- Comply with all applicable data protection laws
5. Processor Obligations
MonoDuty shall:
- Process personal data only on documented instructions from the Controller
- Ensure persons authorized to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage sub-processors without prior authorization (see Section 6)
- Assist the Controller in fulfilling data subject rights requests
- Assist the Controller with data protection impact assessments where required
- Delete or return personal data upon termination of the Agreement
- Make available all information necessary to demonstrate compliance
- Immediately inform the Controller if an instruction violates GDPR
6. Sub-processors
MonoDuty uses the following sub-processors to deliver our services. Each sub-processor is bound by data processing agreements ensuring GDPR-compliant handling of personal data.
| Sub-processor | Purpose | Location | Data Types |
|---|---|---|---|
| Google Cloud Platform | Cloud infrastructure hosting, analytics and authentication services | EU (Frankfurt) | All service data, usage analytics, authentication tokens |
| Contabo GmbH | Cloud infrastructure hosting | Germany (EU) | All service data |
| Sentry (Functional Software) | Error tracking and monitoring | EU | Error logs, anonymized user context |
| Nodemailer / SMTP Provider | Transactional email delivery | EU | Email addresses, notification content |
| Twilio | SMS and voice call notifications | EU / US | Phone numbers, SMS content |
| Stripe | Payment processing | EU / US | Billing information, payment details |
6.1 Changes to Sub-processors
MonoDuty will notify the Controller of any intended changes to sub-processors at least 30 days in advance. The Controller may object to such changes by contacting us at [email protected]. If the objection cannot be resolved, the Controller may terminate the Agreement.
6.2 Sub-processor Obligations
All sub-processors are contractually required to:
- Process data only as instructed by MonoDuty
- Implement appropriate security measures
- Delete data upon termination of the sub-processing agreement
- Allow audits and inspections by MonoDuty
7. International Data Transfers
MonoDuty primarily stores and processes data within the European Union (EU/EEA). Where transfers to third countries are necessary (e.g., for certain sub-processors), we ensure adequate protection through:
- Adequacy decisions: Transfers to countries with an EU adequacy decision
- Standard Contractual Clauses (SCCs): EU-approved contractual safeguards
- Supplementary measures: Additional technical and organizational safeguards where necessary
Our primary infrastructure is hosted on Google Cloud Platform (EU) and Contabo GmbH (Germany, EU).
8. Security Measures
MonoDuty implements the following technical and organizational measures to ensure the security of personal data:
8.1 Technical Measures
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Secure password hashing (bcrypt with salt)
- Rate limiting and DDoS protection
- Regular security patches and vulnerability scanning
- Automated backups with encryption
- Network segmentation and firewall protection
- Session management with secure cookies
8.2 Organizational Measures
- Access control on a need-to-know basis
- Employee confidentiality agreements
- Regular security awareness training
- Incident response procedures
- Business continuity and disaster recovery plans
- Regular review and audit of security measures
9. Breach Notification
In the event of a personal data breach, MonoDuty shall:
- Notify the Controller without undue delay, and no later than 48 hours after becoming aware of the breach
- Provide sufficient details to enable the Controller to fulfill its obligation to notify the supervisory authority within 72 hours (GDPR Article 33)
- Cooperate with the Controller in investigating and mitigating the breach
- Document the breach including facts, effects, and remedial actions taken
The notification shall include:
- Nature of the breach and categories of data affected
- Approximate number of data subjects and records affected
- Likely consequences of the breach
- Measures taken or proposed to address and mitigate the breach
10. Data Subject Rights
MonoDuty provides tools and assistance to help Controllers fulfill data subject rights requests:
- Right of Access (Art. 15): Data export functionality available in account settings
- Right to Rectification (Art. 16): Profile editing tools in the dashboard
- Right to Erasure (Art. 17): Account deletion with 30-day grace period and PII anonymization
- Right to Restriction (Art. 18): Processing restriction toggle in privacy settings
- Right to Data Portability (Art. 20): JSON data export for all user data
- Right to Object (Art. 21): Granular opt-out controls for marketing, analytics, and profiling
For requests that cannot be fulfilled through self-service tools, contact [email protected].
11. Audit Rights
The Controller has the right to audit MonoDuty's compliance with this DPA. Audits may be conducted:
- No more than once per year, unless a data breach or regulatory investigation necessitates additional audits
- With at least 30 days' written notice
- During normal business hours
- Subject to reasonable confidentiality restrictions
MonoDuty may also provide relevant compliance certifications, audit reports, or third-party assessments as alternatives to on-site audits.
12. Termination & Data Return
Upon termination of the Agreement:
- MonoDuty will cease processing personal data on behalf of the Controller
- The Controller may export their data using our self-service data export tools within 90 days
- After the 90-day period, MonoDuty will delete all personal data unless retention is required by law
- MonoDuty will provide written confirmation of data deletion upon request
13. Contact
For questions about this DPA, data processing, or to exercise your rights:
Related pages: Privacy Policy | GDPR Compliance | Cookie Policy | Terms of Service | Security