DATA PROCESSING
Data Processing Addendum (DPA)
Core terms for processing customer personal data in UpBot.
Effective from 2026-09-111. Roles
Where a customer uploads personal data on its own behalf, the customer is controller and UpBot is processor. This addendum forms part of the service agreement for the duration of processing.
2. Scope and instructions
UpBot processes data only to provide monitoring, collaboration, alerts, status pages, support and related security functions under documented customer instructions and applicable law.
3. Data and people
- Data subjects: customer users, invitees, notification contacts, status-page subscribers and people identified in customer data.
- Data: identity and contact data, roles, technical identifiers, configuration, IP addresses, logs, incidents and message content.
- UpBot is not intended for special-category data and customers must not upload it.
4. Confidentiality and security
Authorised personnel are bound by confidentiality. Measures appropriate to risk include access control, encrypted transit, secure passwords, tenant isolation, auditing, updates, backups and incident procedures.
5. Subprocessors
The customer grants general authorisation to engage subprocessors. We will provide reasonable notice of material changes and impose required data-protection obligations.
- Hetzner Online GmbH – EU hosting and infrastructure when production deployment is activated.
- Stripe Payments Europe, Limited and affiliates – payments, billing and fraud prevention for paid plans.
- Websupport s. r. o. – domain hosting and production transactional email.
6. International transfers
Where a subprocessor processes outside the EEA, UpBot will use a valid transfer mechanism and appropriate supplementary measures. Locations and mechanisms must be verified against current provider agreements before launch.
7. Assistance
Taking account of the processing, we assist with data-subject requests, security, breach notifications, impact assessments and authority consultations. Requests belonging to the customer are forwarded without undue delay.
8. Breaches
We notify the customer without undue delay of a confirmed breach involving customer personal data and provide available information needed for its obligations.
9. Return, deletion and audit
After termination, data is deleted or made available for export according to product capabilities, except where law requires retention. We provide reasonable compliance information and allow proportionate audits by agreement without compromising other customers.
10. Contact
Send DPA questions and requests to privacy@upbot.eu.