Data Processing Agreement
Last updated: 2026-08-30
Published in full, not available on request. This is the agreement under which we process personal data on your behalf — including where it physically lives, which is India and Southeast Asia.
1. Parties, and how this takes effect
This Data Processing Agreement (DPA) is between you (the Controller) and Nancy Sahu, Bengaluru, Karnataka, India (the Processor, “we”), and forms part of our Terms & Conditions (the Agreement).
It takes effect automatically when you create an organisation — no signature is required for it to bind us. If your own process requires a countersigned copy, see clause 12.
Where you are processing personal data of individuals in the EEA, the UK or Switzerland, terms such as controller, processor, data subject and personal data have the meanings given in the GDPR (Regulation (EU) 2016/679) and, as applicable, the UK GDPR.
2. Roles, and what we do with the data
You are the controller of the personal data you and your subscribers put into IsItStillUp. We are your processor for it, and we process it only to provide the service described in the Agreement and on your documented instructions — your use of the product being the ordinary way you give them.
We are an independent controller for a narrow, separate set of data: the account and billing records we need to run a business and meet our own legal obligations. That processing is described in our Privacy Policy, not here.
What we never do
- We do not sell personal data, and we have no advertising business to sell it to.
- We do not use your content or your subscribers’ data to train machine-learning models.
- We do not place analytics or tracking on your published status page. There are two daily counters per page and nothing else — no cookies, no per-visitor records.
3. What we process, and for how long
| Whose data | What it includes | Retention |
|---|---|---|
| Your team | Email address, display name, organisation role, sign-in and session records, audit-log entries attributing actions to a person | For as long as the account exists |
| Your status-page subscribers | Email address or phone number, chosen components, locale, confirmation and unsubscribe state, delivery and bounce events | Until they unsubscribe or you delete them |
| Visitors to your status page | No visitor-level data. Two daily counters per page — views, and problem reports where the operator shows that button — and nothing else. No cookies, no identifiers, no per-visitor records | Aggregate counts only |
| Content you publish | Whatever your team writes into incidents, updates, postmortems and component names — which may incidentally contain personal data if you put it there | Until you delete it |
The duration of processing is the term of your subscription plus the deletion window in clause 8. The nature and purpose is the operation of a status page: storing what you publish, rendering it, and notifying the people who asked to be notified.
4. Confidentiality and our people
Everyone with access to personal data processed under this DPA is bound by a duty of confidentiality. Access to production data is limited to those who need it to operate or support the service.
We are a very small team, and we will not pretend otherwise: the number of people who can reach production data is in the low single digits. That is a meaningful security property — a small blast radius — but it also means we do not have separated duties in the way a large organisation does. You should know that before you decide, rather than after.
5. Security measures
We maintain technical and organisational measures appropriate to the risk. The specifics, with the reasoning and the known gaps, are on our trust page. In summary:
- Isolation between customers is enforced in the database itself with Postgres row-level security, which fails closed: a query run without an organisation context returns nothing rather than everything.
- Encryption in transit (TLS) and at rest (provider-managed AES-256 for the database and object storage).
- No passwords exist. Sign-in is a single-use emailed link, or your own SAML identity provider. There is no password database to breach.
- Secrets — API keys are stored only as SHA-256 hashes and shown once at creation.
- Audit — every state-changing operation is recorded with actor, action and time, in the same database transaction as the change itself, so the log cannot silently disagree with reality.
- Backups are taken daily and replicated to a second region. Our recovery objectives are stated on the trust page.
6. Subprocessors
We use the subprocessors listed in the Privacy Policy, which names each provider, what it does, the data involved and where it operates. That table is the authoritative list and is maintained in one place so it cannot drift from this page.
You give general authorisation for these. We will give you at least 30 days’ notice by email to the organisation’s owners before adding or replacing a subprocessor that processes personal data on your behalf. If you reasonably object on data-protection grounds within that period, you may terminate the affected subscription and receive a pro-rata refund of the unused term.
Each subprocessor is bound by a written contract imposing data-protection obligations no less protective than those in this DPA, and we remain liable to you for their performance.
About the AI subprocessor specifically
Content reaches Anthropic only when a person in your organisation uses an AI feature — drafting an update, generating a postmortem, translating a page, or answering a question on your public page. It is not used to train models. If you would rather no content ever left for that purpose, an organisation owner can turn AI features off entirely in settings, and that switch is enforced centrally rather than per-feature.
7. International transfers, and where your data actually is
This is the clause most vendors keep vague, so here it is plainly. IsItStillUp runs in one deployment. Personal data processed under this DPA is stored in:
- Central India — the application, the Postgres database, and the primary copy of rendered pages.
- Southeast Asia — the replicated copy of rendered status pages and database backups.
Some subprocessors operate elsewhere, as their rows in the subprocessor table say: payment data with Paddle in the UK, EU and US; email and SMS in the US or EU; AI drafting in the US; and Cloudflare’s global edge for delivering public pages.
We do not currently offer EU or US data residency. If your organisation requires personal data to remain in a specific region, IsItStillUp is not the right product for you today, and we would rather you knew that in the first ten minutes than in the fourth week. Ask us — a dedicated regional deployment is technically possible under a Custom agreement, and we will tell you honestly what it would take.
Transfer mechanism
For transfers of personal data from the EEA, the UK or Switzerland, we rely on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated into this DPA by reference and completed as follows: you are the data exporter and we are the data importer; the appendices are populated by clauses 3, 5 and 6 of this DPA and by the subprocessor table; the optional docking clause applies; and the governing law and forum are those in the Agreement, to the extent the SCCs permit. For UK transfers, the UK International Data Transfer Addendum applies to those SCCs.
8. Deletion and return
You can export your data at any time without asking us, in machine-readable form, from your dashboard and via the API. There is no export queue and no request form — this is deliberate, because a vendor who makes leaving slow is telling you something.
An organisation owner can delete the whole organisation from settings. When they do:
- The organisation is immediately deactivated and its published status pages are taken down and removed from our storage and CDN.
- The underlying records are held for 30 days so that an accidental or malicious deletion can be reversed, and are then permanently and irreversibly erased. Reversal works at any point until the erasure actually begins — we will not tell you a cancellation succeeded while the deletion is already running.
- Backups age out on their own retention cycle, after which no copy remains. We will tell you the current cycle on request rather than printing a number here that we might quietly change.
Where we are legally required to retain something — a billing record for tax purposes, for instance — we retain only that, only for as long as required, and it stays subject to this DPA.
9. Helping you meet your own obligations
- Data subject requests. Most are self-serve: subscribers can see and change their own preferences or unsubscribe from a link in every message, and your team can find, export and delete subscriber records directly. If a request reaches us instead of you, we will not respond to it ourselves — we will forward it to you promptly, because it is your decision to make.
- Breach notification. We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what we know, what we are doing, and what we do not yet know. We would rather send you an incomplete notification quickly than a tidy one late.
- Impact assessments. We will give reasonable assistance with DPIAs and prior consultations, using the information on the trust page as the starting point.
10. Audit
We will make available the information necessary to demonstrate compliance with this DPA, and will respond to a reasonable written security questionnaire once in any twelve-month period.
We do not hold a SOC 2 report or an ISO 27001 certificate, and we will not imply that our hosting provider’s certifications are our own. What we offer instead is unusual candour: the trust page describes the actual design, including its known weaknesses, in more detail than most audit summaries would.
On-site audits are not practical for a team of our size. Where a controller has a genuine regulatory requirement for one, contact us and we will discuss what is workable, including an independent assessor at the controller’s cost.
11. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Agreement. If this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails. If it conflicts with the SCCs, the SCCs prevail.
12. Signature, and getting a copy for your files
This DPA is effective without signature. If your process requires an executed copy, email support@isitstillup.com from an address on your organisation’s domain, telling us the legal entity name and address to name as controller, and we will return a countersigned PDF of this document.
If your legal team needs to redline these terms rather than accept them, that is a Custom agreement — say so and we will quote it. We would rather price that work honestly than agree to redlines we lack the capacity to honour.