Legal

Data Processing Addendum

Last updated: August 28, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer identified on the account ("Customer") and Concepcion.Work ("Provider"). It applies whenever Provider processes personal data on Customer's behalf in the course of providing Site Monitor (the "Service") and that processing is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss Federal Act on Data Protection (together, "Data Protection Law").

This DPA is incorporated automatically into the agreement for every Customer to whom Data Protection Law applies. Customers who need a signed copy for their records can request one from support@concepcion.work.

1. Roles

Customer is the controller (or, where Customer acts for its own clients, a processor acting on the instructions of those clients) and Provider is the processor of the personal data described in Annex A. Each party will comply with its own obligations under Data Protection Law.

2. Subject matter, nature and purpose

Provider processes personal data only to provide the Service: checking the availability of URLs Customer configures, storing the results, and delivering alerts, reports and status pages to the recipients and channels Customer configures. The duration of processing is the term of the agreement plus the deletion period in Section 8. Full details of the processing are set out in Annex A.

3. Instructions

Provider will process personal data only on Customer's documented instructions, which consist of the agreement, this DPA, and the configuration Customer makes in the Service, unless required to do otherwise by law that applies to Provider, in which case Provider will inform Customer of that requirement before processing unless the law prohibits it. Provider will inform Customer promptly if, in its opinion, an instruction infringes Data Protection Law.

4. Confidentiality

Provider ensures that any person it authorizes to process personal data is bound by a duty of confidentiality, whether contractual or statutory, and processes personal data only as needed to perform their role. Access to production data is limited to personnel who need it to operate or support the Service.

5. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, Provider implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. The current measures are described in Annex C and on the Security page. Provider may update the measures from time to time provided the overall level of security is not reduced.

6. Sub-processors

Customer gives general authorization for Provider to engage the sub-processors listed in Annex B. Provider will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible to Customer for the sub-processor's performance.

Provider will give Customer at least 30 days' notice by email before adding or replacing a sub-processor. Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected part of the Service and receive a prorated refund of prepaid fees for the remainder of the term.

7. Assistance

  • Provider will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to requests from data subjects exercising their rights under Chapter III GDPR. Provider will forward any such request it receives directly to Customer without responding to it, unless required by law.
  • Provider will assist Customer in meeting its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of processing and the information available to Provider.
  • Provider may charge reasonable fees for assistance that goes materially beyond the Service's standard features.

8. Deletion and return

Customer can delete individual sites or the whole account at any time from the Service. On termination of the agreement, Provider will delete all personal data processed on Customer's behalf within 30 days, and will delete existing copies from backups on their normal expiry, unless Union or Member State law requires storage of the personal data. On written request made before deletion, Provider will provide a copy of Customer's configuration data in a common machine-readable format.

9. Audits and information

Provider will make available to Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the Security page, and summaries or certifications of its sub-processors' audits where available. Provider will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, provided that: the audit is requested with at least 30 days' notice, no more than once per year unless required by a supervisory authority or following a personal data breach, is conducted during business hours without unreasonable disruption, and is subject to reasonable confidentiality obligations. Customer bears its own audit costs.

10. Personal data breach

Provider will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data processed on Customer's behalf. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Provider will provide further information as it becomes available and will cooperate with Customer's own notification obligations. Notifications are sent to the account owner's email address.

11. International transfers

Provider and its sub-processors are located in the United States. Where personal data protected by the GDPR is transferred to a country that has not received an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this DPA, with Customer as data exporter and Provider as data importer, the optional docking clause included, Option 2 of Clause 9 with the notice period in Section 6, the governing law and forum of Ireland, and Annexes A, B and C of this DPA serving as the Annexes to the Clauses. For transfers subject to the UK GDPR the International Data Transfer Addendum issued by the UK Information Commissioner applies, and for Swiss transfers the Clauses are read with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms of Service with respect to the processing of personal data. This DPA lasts as long as Provider processes personal data on Customer's behalf.

Annex A — Details of processing

Categories of data subjects
Customer's staff and team members; Customer's clients and their staff who are configured as alert or report recipients; visitors to public status pages Customer publishes.
Categories of personal data
Names, email addresses, usernames and hashed passwords of users; email addresses, phone numbers, Slack and webhook URLs of alert recipients; URLs of monitored websites and the results of availability checks; IP addresses and technical logs.
Special categories of data
None. The Service fetches only public pages and is not designed to process health, financial or other special-category data. Customer must not configure the Service in a way that causes such data to be processed.
Nature and purpose of processing
Storage, retrieval and transmission of the data above in order to monitor website availability, deliver alerts and reports, and display dashboards and status pages, as configured by Customer.
Duration
Check history for the retention period of Customer's plan or the shorter period Customer selects; other data for the term of the agreement plus 30 days.

Annex B — Sub-processors

Sub-processorLocationPurpose
Vercel Inc.USAApplication hosting and scheduled check execution
Upstash Inc.USADatabase storage of account, configuration and check data
Resend Inc.USADelivery of alert and report email where Customer has not connected its own SMTP
Stripe Inc.USASubscription billing (Customer's own billing contact only)
Twilio Inc.USASMS alert delivery, only where Customer enables SMS

Services Customer connects itself (its own SMTP server, Slack workspace, webhook endpoints) are Customer's own processors, not Provider's sub-processors.

Annex C — Technical and organizational measures

  • Encryption: TLS for all data in transit between users, the Service, and sub-processors; encryption at rest provided by the hosting and database providers.
  • Access control: passwords hashed with bcrypt; optional TOTP two-factor authentication; screening of new passwords against known breach lists; rate limiting on authentication endpoints; session cookies that are HTTP-only and signed.
  • Tenant isolation: every record is scoped to an account and every API request is checked against the signed-in user's account.
  • Data minimization: only public pages are fetched; response bodies are not stored; check history expires automatically per the retention setting.
  • Infrastructure: hosted on Vercel (SOC 2 Type 2, ISO 27001) with Upstash for storage over TLS and Resend (SOC 2 Type II) for email.
  • Operations: production access limited to named personnel; dependencies updated regularly; vulnerability reports accepted at security@concepcion.work.
  • Deletion: self-serve deletion of sites and accounts; automatic expiry of history; deletion within 30 days of termination.

Contact

Concepcion.Work · support@concepcion.work