Data Processing Agreement
Last updated: March 9, 2026
1. Definitions
For the purposes of this Data Processing Agreement ("DPA"), the following terms apply:
- Controller: The Customer (you), who determines the purposes and means of processing Personal Data through the Service
- Processor: GoPinger ("we," "us," or "our"), who processes Personal Data on behalf of the Controller pursuant to the Terms of Service
- Personal Data: Any information relating to an identified or identifiable natural person, as defined under applicable data protection laws including the EU General Data Protection Regulation (GDPR)
- Processing: Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction
- Sub-processor: Any third party engaged by GoPinger to process Personal Data on behalf of the Controller
- Data Subject: An identified or identifiable natural person to whom Personal Data relates
- Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data
2. Scope and Purpose of Processing
This DPA applies to all Personal Data processed by GoPinger on behalf of the Controller in connection with the provision of the Service. GoPinger processes Personal Data solely as instructed by the Controller through the Controller's configuration and use of the Service.
Categories of Personal Data Processed
- Endpoint URLs and configuration data provided by the Controller
- HTTP response data, headers, and content from monitored endpoints
- SSL/TLS certificate details from monitored endpoints
- Email metadata processed through email monitoring features
- IP addresses and technical data of visitors to Controller's public status pages
- Team member information (names, email addresses, roles) within the Controller's organization
- Visual screenshot images of monitored web pages, which may incidentally capture personal data displayed on those pages (e.g., user names, profile information, or other content visible at the time of capture)
Categories of Data Subjects
- Controller's end-users whose data may appear in monitored endpoint responses
- Visitors to Controller's public status pages
- Controller's team members and organization personnel
- Individuals whose personal data may be incidentally visible in screenshot captures of the Controller's monitored endpoints
3. GoPinger's Obligations as Processor
GoPinger shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by applicable law. In such a case, GoPinger shall inform the Controller of that legal requirement before processing, unless prohibited by law
- Ensure that all persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement and maintain appropriate technical and organizational security measures as described in Section 4
- Assist the Controller, taking into account the nature of the processing and on a commercially reasonable basis, in responding to requests from Data Subjects exercising their rights under applicable data protection laws
- Assist the Controller in ensuring compliance with obligations related to security of processing, data breach notification, data protection impact assessments, and prior consultations with supervisory authorities, taking into account the nature of processing and information available to GoPinger
- At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of the Service, and delete existing copies unless applicable law requires retention
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 9
4. Security Measures
GoPinger implements and maintains the following technical and organizational security measures to protect Personal Data:
Technical Measures
- Encryption in Transit: All data transmitted between the Controller and GoPinger is encrypted using TLS 1.2 or higher
- Encryption at Rest: Sensitive data fields including passwords, API keys, and authentication tokens are encrypted at rest
- Access Controls: Role-based access controls (RBAC) are implemented for all internal systems. Access is granted on a least-privilege basis
- Authentication: Passwords are hashed using Argon2id. Multi-factor authentication is available for all accounts
- Regular Backups: Automated backups with encryption are performed regularly to prevent data loss
- Network Security: Firewalls, intrusion detection systems, and network segmentation are used to protect infrastructure
Organizational Measures
- Incident Response: Documented incident response procedures are maintained and regularly tested
- Employee Training: Personnel with access to Personal Data receive regular security and privacy training
- Vendor Assessment: Sub-processors undergo security assessment before engagement
- Physical Security: Infrastructure is hosted with cloud providers that maintain SOC 2 Type II or equivalent physical security certifications
5. Sub-processors
The Controller provides general authorization for GoPinger to engage Sub-processors for the processing of Personal Data, subject to the following conditions:
- GoPinger maintains a current list of Sub-processors, which includes infrastructure hosting, payment processing, and email delivery providers
- GoPinger shall notify the Controller of any intended changes to the list of Sub-processors at least 30 days prior to the engagement of a new Sub-processor
- The Controller may object to a new Sub-processor by notifying GoPinger in writing within 14 days of receiving notice. If the objection cannot be resolved to the Controller's reasonable satisfaction, the Controller may terminate the affected Service by providing written notice
- GoPinger shall impose equivalent data protection obligations on all Sub-processors through written contracts
- GoPinger remains fully liable to the Controller for the performance and compliance of its Sub-processors
6. International Data Transfers
Personal Data is primarily processed within the European Union. Where Personal Data is transferred to a country outside the EU/EEA that has not been deemed to provide an adequate level of data protection:
- GoPinger shall ensure appropriate safeguards are in place, including the execution of Standard Contractual Clauses (SCCs) approved by the European Commission
- The Controller consents to the transfer of Personal Data to Sub-processors in jurisdictions listed in GoPinger's Sub-processor list
- GoPinger shall conduct transfer impact assessments where required and implement supplementary measures as necessary
7. Data Breach Notification
In the event of a confirmed Data Breach affecting Personal Data processed on behalf of the Controller:
- GoPinger shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of the confirmed breach
- The notification shall include, to the extent available: the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences of the breach, and the measures taken or proposed to be taken to address the breach
- GoPinger shall cooperate with the Controller's breach investigation and response efforts
- GoPinger is not responsible for notifying individual Data Subjects or supervisory authorities; this obligation rests solely with the Controller
- GoPinger shall document all Data Breaches, including the facts surrounding the breach, its effects, and the remedial actions taken
8. Data Subject Rights
- GoPinger shall assist the Controller, on a commercially reasonable basis, in responding to requests from Data Subjects to exercise their rights under applicable data protection laws (including rights of access, rectification, erasure, portability, objection, and restriction of processing)
- GoPinger may charge reasonable fees for assistance that requires significant effort beyond standard Service functionality
- GoPinger shall not independently respond to Data Subject requests unless required by applicable law. If GoPinger receives a direct request from a Data Subject, it shall promptly redirect the request to the Controller
9. Audit Rights
- The Controller may audit GoPinger's compliance with this DPA no more than once per year, with at least 30 days' prior written notice, and during GoPinger's normal business hours
- GoPinger may satisfy the Controller's audit request by providing relevant third-party audit reports, certifications (such as SOC 2, ISO 27001), or written attestations of compliance, at GoPinger's discretion
- All costs associated with an on-site or independent audit shall be borne by the Controller, unless the audit reveals a material breach of this DPA by GoPinger
- All information obtained through an audit is subject to strict confidentiality obligations. The Controller shall not disclose audit findings to third parties without GoPinger's prior written consent, except as required by law
- Audits shall be conducted in a manner that minimizes disruption to GoPinger's operations
10. Liability
- Each party's liability under this DPA is subject to the limitation of liability provisions set forth in the Terms of Service
- This DPA does not expand, modify, or override the liability cap established in the Terms of Service
- The Controller is solely responsible for ensuring the lawfulness of its processing instructions. GoPinger shall not be liable for any claim arising from the Controller's unlawful processing instructions
- The Controller shall indemnify GoPinger against any claims, damages, or expenses arising from the Controller's breach of applicable data protection laws or this DPA
11. Term and Termination
- This DPA is effective for the duration of the service agreement between the Controller and GoPinger
- This DPA survives termination of the service agreement until all Personal Data processed under it has been deleted or returned to the Controller
- Upon termination of the service agreement, GoPinger shall delete all Personal Data within 30 days, unless applicable law requires continued retention. The Controller may request a copy of its data in a standard machine-readable format prior to deletion
- GoPinger shall provide written confirmation of data deletion upon the Controller's request
12. Contact
For questions or requests related to this Data Processing Agreement, please contact us at [email protected].