1. Definitions

1.1 Applicable Data Protection Law: all laws and regulations applicable to the processing of Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and the California Consumer Privacy Act as amended (“CCPA”).

1.2 Personal Data: any information relating to an identified or identifiable natural person that Site Qwality processes on Your behalf in connection with the Services.

1.3 Processing, Controller, Processor, Data Subject, and Supervisory Authority have the meanings given to them in Applicable Data Protection Law.

1.4 Subprocessor: any third party engaged by Site Qwality to process Personal Data on Your behalf.

2. Roles and Scope

2.1 As between the parties, You are the Controller (or, where You act on behalf of Your Clients as an MSP, a Processor) and Site Qwality is a Processor of Personal Data submitted to the Services.

2.2 Site Qwality will process Personal Data only on Your documented instructions, including with regard to transfers, unless required to do otherwise by law; in such a case, Site Qwality will inform You of that legal requirement before processing unless the law prohibits it. The Agreement, this DPA, and Your configuration and use of the Services constitute Your documented instructions.

3. Details of Processing

3.1 Subject matter and duration: the provision of the Services for the Term of the Agreement, until deletion of Personal Data in accordance with Section 9.

3.2 Nature and purpose: hosting, monitoring, alerting, observability ingestion and display (uptime checks, logs, metrics, traces, real user monitoring, session replay), status pages, notification delivery, billing, and support.

3.3 Categories of Data Subjects: Your Users (employees, contractors, consultants); end users of Your monitored websites and applications to the extent You configure the Services (for example real user monitoring or session replay) to collect data about them; recipients of notifications You configure.

3.4 Categories of Personal Data: account and contact details (name, email address, phone number); authentication identifiers; notification destinations; IP addresses, device and browser metadata, page URLs, and session interaction data collected by the SDK where You enable it; any Personal Data contained in logs, metrics, traces, or other content You submit to the Services. The Services are not designed for and must not be used to submit special categories of data as defined in Article 9 GDPR.

4. Confidentiality

Site Qwality ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security

Site Qwality implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures include encryption of data in transit, encryption at rest for primary data stores, access controls with role separation, audit logging of administrative access, and network isolation. Further detail is published on the Security page.

6. Subprocessors

6.1 You provide general authorization for Site Qwality to engage Subprocessors. Site Qwality will impose data protection obligations on Subprocessors that are no less protective than those in this DPA and remains liable for their performance.

6.2 The Subprocessors currently engaged are:

Amazon Web Services, Inc. (United States): cloud infrastructure, data storage, email and SMS delivery.
Stripe, Inc. (United States): payment processing and billing.
Stytch, Inc. (United States): authentication and identity management.
Twilio Inc. (SendGrid) (United States): transactional email delivery.

6.3 Site Qwality will provide notice of any intended addition or replacement of Subprocessors by updating this page at least 14 days before the change takes effect. If You object on reasonable data protection grounds and the parties cannot resolve the objection, You may terminate the affected Services in accordance with the Agreement.

7. Assistance

7.1 Taking into account the nature of the processing, Site Qwality will assist You by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Your obligation to respond to requests from Data Subjects exercising their rights. If Site Qwality receives such a request directly, it will redirect the Data Subject to You where lawful to do so.

7.2 Site Qwality will assist You in ensuring compliance with Your obligations regarding security, breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities, taking into account the nature of processing and the information available to Site Qwality.

8. Personal Data Breach

Site Qwality will notify You without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Personal Data processed under this DPA, and will provide information reasonably available to it to support Your notification obligations.

9. Deletion and Return

Upon termination or expiry of the Agreement, Site Qwality will, at Your choice, delete or return all Personal Data processed on Your behalf, and delete existing copies, unless retention is required by law. Absent a request, Personal Data is deleted in the ordinary course pursuant to the retention behavior of the Services.

10. Audits

Site Qwality will make available to You information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by You or an auditor mandated by You, no more than once per year, on at least 30 days notice, during normal business hours, and subject to reasonable confidentiality obligations. The parties agree that audits are first satisfied by written responses and available third-party documentation.

11. International Transfers

The Services are operated in the United States. Where Personal Data protected by the GDPR or UK GDPR is transferred to Site Qwality in the United States, the parties rely on the European Commission Standard Contractual Clauses (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable), which are incorporated into this DPA by reference, with Site Qwality as data importer and You as data exporter, and the technical and organizational measures described in Section 5. The UK Addendum to the Standard Contractual Clauses applies to transfers subject to the UK GDPR.

12. Liability and Order of Precedence

The liability of each party under this DPA is subject to the limitations of liability set out in the Agreement. In case of conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.