1. Scope, definitions, and roles
This Data Processing Addendum (the "Addendum") supplements the Uptime Basics Terms of Service or another written agreement between StackResolve and the customer that incorporates this Addendum (the "Agreement"). "StackResolve" means Shane-Andrew Syring, carrying on business as StackResolve, a sole proprietorship registered in Ontario, Canada. This Addendum applies only to the extent StackResolve processes Customer Personal Data on behalf of Customer in providing Uptime Basics.
"Customer Personal Data" means personal data, personal information, or equivalent regulated information that Customer submits to the Service or directs StackResolve to process on Customer's behalf. "Data Protection Law" means privacy and data-protection law applicable to that processing, including, where applicable, PIPEDA, substantially similar Canadian provincial laws, the EU GDPR, and the UK GDPR.
Customer is the controller, business, or equivalent decision-maker for Customer Personal Data. StackResolve is the processor, service provider, or equivalent recipient. If Customer acts as a processor for another controller, StackResolve acts as Customer's sub-processor and Customer confirms it has authority to appoint StackResolve.
Each party remains independently responsible for personal data it processes as a controller for its own purposes, including account administration, billing, security, fraud prevention, legal compliance, and business communications as described in the Privacy Policy.
2. Documented instructions and compliance
StackResolve will process Customer Personal Data only:
- to provide, secure, maintain, and support the Service under the Agreement;
- according to Customer's documented configuration and lawful instructions;
- as necessary to prevent fraud, abuse, or harm and maintain Service integrity; or
- where required by applicable law, in which case StackResolve will notify Customer before processing unless the law prohibits notice.
The Agreement, this Addendum, Customer's use of Service controls, and written support instructions are Customer's documented instructions. StackResolve will notify Customer if, in its reasonable opinion, an instruction infringes applicable Data Protection Law and may suspend the affected processing while the parties address it.
Customer is responsible for the lawfulness, accuracy, quality, and necessity of Customer Personal Data and instructions; providing required notices; obtaining required consents; establishing a lawful basis; and avoiding prohibited or unnecessary personal data in monitor URLs, names, custom headers, status pages, and support messages.
The Service is not designed for special-category, highly sensitive, health, biometric, government-identifier, payment-card, or children's data. Customer must not submit that data unless StackResolve has expressly agreed in writing to the specific processing and required safeguards.
3. Confidentiality and security
StackResolve will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only as needed for their responsibilities.
Taking into account the state of the art, implementation cost, scope and context of processing, and risks to individuals, StackResolve will maintain appropriate technical and organizational measures. The measures currently maintained are summarized in Annex II and may evolve without materially reducing the overall protection of Customer Personal Data.
Customer is responsible for securing its accounts, credentials, endpoints, alert destinations, integrations, and authorized users; enabling available security features; and promptly reporting suspected compromise.
4. Sub-processors
Customer gives StackResolve general written authorization to engage the sub-processors listed on the Sub-processors page. StackResolve will impose data-protection obligations appropriate to each sub-processor's processing and remains responsible for its sub-processors to the extent required by Data Protection Law and the Agreement.
StackResolve intends to provide at least 30 days' advance notice of a material new sub-processor when reasonably practical. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, Customer may discontinue the affected feature or terminate the affected Service in accordance with the Agreement.
StackResolve may use shorter notice where necessary to address an urgent security, availability, legal, or provider risk. Customer remains responsible for third-party destinations and providers it independently connects to the Service.
5. Rights requests, assessments, and incidents
5.1 Individual rights
Taking into account the nature of processing, StackResolve will provide reasonable assistance through Service functionality or support so Customer can respond to valid requests to access, correct, delete, restrict, object to, or export Customer Personal Data. If StackResolve receives a request relating primarily to Customer Personal Data, it may direct the requester to Customer unless prohibited by law.
5.2 Assessments and regulator inquiries
StackResolve will provide information reasonably available to help Customer with required data-protection impact assessments, regulator consultations, and demonstrations of compliance, considering the nature of processing and information available to StackResolve.
5.3 Personal-data incidents
StackResolve will notify Customer without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by StackResolve (a "Customer Data Incident").
As information becomes reasonably available, the notice will describe the nature of the incident, affected data and individuals where known, likely consequences, mitigation, and a contact point. StackResolve may provide information in phases and will take reasonable steps to contain, investigate, and remediate the incident. Notice is not an admission of fault or liability.
Customer is responsible for determining whether it must notify individuals, regulators, or others, except for notifications StackResolve is independently required to make.
6. Return, retention, and deletion
During an active account, Customer may use available Service tools to access or export supported Customer Personal Data. Upon termination or a valid deletion request, StackResolve will delete or render inaccessible Customer Personal Data according to the published retention schedule, unless law requires retention.
Deletion from active systems may not immediately remove encrypted backups, immutable security or financial records, or data under a legal hold. Remaining copies are isolated from ordinary use, protected, and deleted or anonymized when their applicable retention period ends. StackResolve may retain data it processes as an independent controller where required for billing, tax, fraud prevention, security, dispute resolution, or legal compliance.
7. Compliance information and audits
StackResolve will make available information reasonably necessary to demonstrate compliance with this Addendum, including this Addendum, the Security and Trust page, and relevant independent reports or questionnaires when available.
If that information is insufficient and Data Protection Law gives Customer an audit right, Customer may request a reasonable audit no more than once in any 12-month period, unless a confirmed Customer Data Incident or regulator requires more. Audits must:
- be preceded by reasonable written notice and a specific scope;
- occur during normal business hours without disrupting operations;
- protect other customers, confidential information, and system security;
- avoid penetration testing, source-code access, and access to other customers' data; and
- be performed by an independent qualified auditor bound by confidentiality.
Customer bears reasonable audit costs unless the audit identifies a material breach by StackResolve. Nothing requires disclosure that would weaken security, violate law, or breach another party's rights.
8. International transfers
Customer authorizes processing in Canada, the United States, and the locations identified on the Sub-processors page. Where Data Protection Law requires a transfer safeguard, the parties will use an applicable adequacy decision, approved contractual clauses, or another lawful mechanism.
8.1 EEA transfers
Where Customer Personal Data protected by the EU GDPR is transferred to StackResolve in a country not covered by an applicable adequacy decision, the European Commission's 2021 Standard Contractual Clauses are incorporated by reference. Module Two applies where Customer is a controller and StackResolve is a processor; Module Three applies where Customer is a processor and StackResolve is a sub-processor.
For those clauses: the optional docking clause applies; general authorization and the notice period in Section 4 apply to sub-processors; the optional independent dispute-resolution language in Clause 11 does not apply; Option 1 in Clause 17 applies with the law of Ireland; and the courts of Ireland have jurisdiction under Clause 18. Annexes I through III of this Addendum complete the corresponding SCC annexes. The official clauses remain unmodified and control over conflicting commercial terms.
8.2 United Kingdom transfers
Where the UK GDPR requires an international transfer safeguard, the then-current UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner is incorporated by reference. The information in the Agreement and Annexes I through III completes the applicable tables. Neither party may terminate the Addendum solely because the UK Information Commissioner issues a revised approved addendum; the lawful replacement applies as required.
8.3 Transfer cooperation
Each party will provide information reasonably needed for a transfer assessment and implement supplementary measures reasonably required by applicable law. If a lawful transfer mechanism becomes unavailable, the parties will work in good faith to adopt a replacement or suspend the affected transfer.
9. Liability, term, and order of precedence
This Addendum begins when the Agreement becomes effective and continues while StackResolve processes Customer Personal Data. The limitations and exclusions of liability in the Agreement apply to this Addendum to the maximum extent permitted by law. Nothing limits responsibility that Data Protection Law prohibits the parties from limiting.
If documents conflict regarding Customer Personal Data, the order is: applicable mandatory law; applicable SCCs or UK transfer addendum; this Addendum; the Agreement; then other documentation. Except as modified here, the Agreement remains in effect.
StackResolve may update this Addendum to reflect legal, regulatory, or Service changes. Material reductions in customer protections will receive reasonable notice where required. The governing-law and dispute terms in the Agreement apply except where transfer clauses require otherwise.
Annex I. Parties and processing details
A. Parties
| Party | Identity and role | Contact |
|---|---|---|
| Customer / data exporter | The Uptime Basics account holder identified in the Agreement or checkout; controller or processor according to its use of Customer Personal Data. | The account contact or authorized privacy contact recorded by Customer. |
| StackResolve / data importer | Shane-Andrew Syring, carrying on business as StackResolve, operator of Uptime Basics, 65 Leitch Avenue, North York, Ontario M3J 0E2, Canada; processor or sub-processor. | Shane-Andrew Syring, Privacy Officer privacy@uptimebasics.com |
B. Processing
- Subject matter: website uptime, response-time, HTTP content, SSL certificate, domain registration, alerting, incident, logging, API, integration, support, and public status-page services selected by Customer.
- Duration: the Agreement term plus applicable deletion, backup, legal-hold, and retention periods.
- Nature and purpose: receiving, storing, organizing, retrieving, testing endpoints, generating results and diagnostics, transmitting alerts, displaying customer-selected information, supporting users, and securing the Service.
- Data subjects: Customer personnel and authorized users; alert recipients; support contacts; visitors represented in customer-supplied status-page or integration data; and other individuals whose data Customer lawfully submits.
- Data categories: names, business contact details, account identifiers, IP and device data, monitor names and URLs, status-page content, alert destinations and preferences, support content, integration metadata, audit events, and encrypted credentials or request headers submitted for monitoring.
- Sensitive data: not intended or authorized unless expressly agreed in writing.
- Frequency: continuous or recurring according to Customer's monitor intervals, settings, support requests, and use of the Service.
- Return and deletion: as described in Section 6 and the Privacy Policy retention schedule.
C. Competent supervisory authority
For the EU SCCs, the competent supervisory authority is determined under Clause 13 based on the data exporter's establishment, representative, or affected individuals. For UK transfers, the UK Information Commissioner is the supervisory authority.
Annex II. Technical and organizational measures
| Control area | Measures |
|---|---|
| Identity and access | Role-based access, least-privilege permissions, separate customer and administrative identity paths, multi-factor authentication support, session controls, privileged-action logging, and periodic access review. |
| Encryption and secrets | TLS for network transport; encryption at rest for production storage where supported; managed keys for sensitive monitor credentials; write-only handling for protected headers and credentials; and secrets kept out of frontend code and ordinary logs. |
| Application and network security | Input validation, bot and abuse protection, private-address and redirect revalidation for monitor targets, bounded retries, rate and plan enforcement, dependency review, security headers, and separated production roles. |
| Availability and recovery | Managed cloud infrastructure, queue isolation, retries and dead-letter handling, backups and point-in-time recovery for eligible data stores, health alarms, incident procedures, and tested deletion/restoration workflows. |
| Logging and monitoring | Operational, security, support-access, billing, and administrative audit records with role-restricted access, defined retention, alerting, and protection against ordinary alteration. |
| Data minimization and lifecycle | Purpose-limited collection, bounded log content, plan-based and documented retention, account-deletion workflows, legal holds, and separation of retained compliance records from active customer data. |
| Personnel and vendors | Confidentiality duties, need-to-know production access, administrative role separation, vendor review, data-processing terms, sub-processor oversight, and access removal when responsibilities end. |
| Incident management | Security monitoring, escalation and containment procedures, breach assessment and records, customer notification procedures, remediation tracking, and post-incident review. |
Annex III. Authorized sub-processors
The authorized sub-processors, their purposes, data categories, and primary processing locations are maintained at uptimebasics.com/subprocessors. That list is incorporated into this Addendum and updated under Section 4.
Questions about this Addendum may be sent to privacy@uptimebasics.com.
