Data Processing Agreement (DPA) — Statuo
Annex to the Terms and Conditions of Service — Rev. 3 — Last updated: 9 July 2026
Courtesy translation. In case of any discrepancy, the Italian version prevails (statuo.io/dpa).
1. Parties and roles
This agreement (the "DPA") is entered into between the Customer (as defined in the Terms of Service), acting as data controller, and Apdsoftware of Carlo Zuffetti (apdsoftware.it), VAT IT03835250162 (the "Provider"), acting as data processor under art. 28 GDPR.
The DPA applies only to personal data the Provider processes on behalf of the Customer in supplying the Statuo Service. For the Customer's account data the Provider acts as an independent controller (see the Privacy Notice).
2. Subject matter, duration, nature and purpose of processing
- Subject matter: uptime monitoring of the Monitored Sites, sending of alerts, publication of status pages.
- Duration: equal to the duration of the Terms of Service, plus the post-termination retention period under art. 8.
- Nature: collection, recording, storage, consultation, transmission, erasure, in electronic and automated form.
- Purpose: exclusively the provision of the Service according to the configurations set by the Customer.
3. Categories of data subjects and data (Annex 1)
Data subjects: employees and collaborators of the Customer; the Customer's end users whose contact details are added as notification channels; persons whose data appears in the URLs or names of the Monitored Sites.
Categories of data: contact data (e-mail addresses, Telegram identifiers); names and URLs attributable to natural persons; technical check data (results, latencies, timestamps). No special-category data (art. 9 GDPR) is required or envisaged by the Service; the Customer undertakes not to enter any.
4. Obligations of the Processor
The Provider undertakes to:
a) process data only on the Customer's documented instructions — instructions are deemed given through the configuration of the Service in the panel — save for legal obligations, in which case it will inform the Customer where permitted;
b) ensure that persons authorized to process the data are bound by confidentiality;
c) adopt the security measures under art. 32 GDPR, as described in Annex 2;
d) assist the Customer, taking into account the nature of the processing, in responding to data subjects' requests (arts. 15-22 GDPR) and with the obligations under arts. 32-36 GDPR, including — where requested — the information needed for impact assessments (DPIA) and prior consultations;
e) notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach, providing the information useful for notification under art. 33 GDPR;
f) make available the information necessary to demonstrate compliance and allow, with reasonable notice of at least 30 days and at the Customer's expense, documentary verifications; any on-site audits are limited to once a year and conducted so as not to compromise the security of other customers.
4-bis. Obligations and warranties of the Controller
The Customer, as controller, warrants: (a) that it has an appropriate legal basis for the processing entrusted to the Provider; (b) that it has provided data subjects (including its own End Users) with the notices required by arts. 13-14 GDPR; (c) that the instructions given — including through the configuration of the Service — are lawful and do not place the Provider in breach of the GDPR or other rules. The Customer shall hold the Provider harmless from the consequences of any breach of these warranties.
5. Sub-processors
5.1. The Customer gives general authorization to the sub-processors listed in Annex 2. The Provider will give at least 15 days' notice of any addition or replacement; in case of reasoned objection, the Customer may withdraw from the Service without penalty.
5.2. The Provider imposes on each sub-processor, by contract, obligations equivalent to those of this DPA and remains liable towards the Customer for the sub-processors' performance.
6. Transfers outside the EU
Data is processed predominantly on infrastructure within the European Economic Area (Hetzner in Germany for core and database, with continuous backups and a disaster-recovery standby on Google Cloud, always within the EU — Belgium). Exceptions: notification delivery via Telegram (enabled only at the Customer's choice); and execution of monitoring checks from Google Cloud's US location, which processes the URL and check outcome in memory only — even when a check includes a keyword match against the page, the content is read only for the comparison and never written to disk or logs — with no data storage on the non-EEA system. In both cases the transfer is based on adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or Standard Contractual Clauses.
7. Assistance and costs
Ordinary assistance under art. 4.d is included in the fee. Extraordinary, disproportionate or repetitive requests may be billed at an hourly rate communicated to the Customer in advance.
8. Termination and deletion
Upon termination of the Service, the Provider retains the data for 30 days to allow export from the panel, after which it permanently deletes it from active systems; backup copies are overwritten according to the rotation cycle within a further 30 days. Upon request, the Provider certifies deletion in writing.
9. Liability
Claims based on this DPA are subject to the limitation of liability under art. 9 of the Terms of Service, to the maximum extent permitted by law. Each party's liability towards data subjects under art. 82 GDPR, and the recourse regime provided therein, remain unaffected and cannot be contractually derogated.
10. Final provisions
For anything not provided herein, the Terms of Service apply. In case of conflict between the DPA and the Terms, the DPA prevails for data-protection matters. Italian law; Court of Bergamo.
Annex 1 — Details of processing
As per art. 3 of this DPA.
Annex 2 — Security measures and sub-processors
Technical and organizational measures (art. 32 GDPR):
- Encryption in transit (TLS 1.2+) on all communications, including probes.
- Authentication with hashed passwords (bcrypt) and signed tokens.
- Application-level multi-tenant isolation: every query is bound to the agency's identity.
- Internal endpoints not publicly exposed; server access exclusively via SSH keys; firewall with minimal ports.
- Daily encrypted backups with rotation and periodic restore testing.
- Automatic security updates on the infrastructure; system logs retained max 12 months.
- Minimization principle: the Service requires neither special categories of data nor end-user data beyond notification contact details.
Authorized sub-processors:
| Sub-processor | Activity | Region |
|---|---|---|
| Hetzner Online GmbH | Hosting and delivery (core/database) | EU |
| Google Cloud | Continuous backup and disaster-recovery standby of the database; execution of monitoring checks (probe) | EU (Belgium, Milan) + USA (Iowa; in-memory execution only, no data storage) |
| Resend, Inc. | Notification e-mail delivery | EU |
| Telegram FZ-LLC (only if enabled by the Customer) | Notification delivery | Non-EU |
(Paddle is not a sub-processor: for payments it acts as an independent controller in its capacity as merchant of record.)
Execution: the DPA is deemed accepted by the Customer upon acceptance of the Terms of Service at registration.