UPnator Data Processing Addendum (DPA)
Version: 2026-08-10.1 Effective date: 10 August 2026
1. Parties and subject matter
- This DPA is a data processing agreement under Article 28 GDPR between the organization using UPnator (the “Controller”) and Jarosław Staroń, carrying on business as 9ne.pl Jarosław Staroń, Polish tax identification number (NIP) 8942787122, ul. Starobielawska 32a, 54-061 Wrocław, Poland, operator of the UPnator brand (the “Processor”); contact:
privacy@upnator.com. - This DPA applies to the extent that UPnator processes personal data on the Controller’s behalf in providing the service. It does not cover data for which the Operator is an independent controller, as described in the Privacy Policy.
- This DPA remains in force while the service is used and until data is deleted or returned under section 11.
2. Nature and purpose of processing
Processing consists of storing, organizing, accessing, transmitting and deleting data required to run monitors, detect incidents, send notifications, publish status pages, generate reports, operate integrations, provide support and secure the service. The Processor acts only on the Controller’s documented instructions, represented by the configuration and use of UPnator in accordance with the agreement, Terms and documentation.
3. Categories of individuals and data
- Individuals: the Controller’s employees, contractors, administrators and users; alert recipients; contacts at providers or customers; and persons identified in controlled voice tests where lawfully configured by the Controller.
- Data: identity and contact data, roles and account identifiers, IP addresses and device identifiers, configuration and log data, email addresses or other recipient identifiers, support-request content, and technical metadata relating to monitored communications and incidents.
- UPnator is not intended to process special-category data or criminal-conviction data. The Controller must not submit such data without prior written agreement on additional safeguards.
4. Controller obligations
The Controller:
- ensures that its instructions and monitoring comply with law and that it has a lawful basis for processing;
- provides required information to individuals and handles their rights;
- limits data to what is necessary and appropriately configures retention, roles and recipients;
- does not instruct the monitoring of resources or voice testing without the required authorization;
- is responsible for the lawfulness of data sent to integrations it configures.
5. Confidentiality and personnel
The Processor ensures that persons authorized to access data are bound by confidentiality, receive access on a need-to-know basis and are trained in security. Administrative access is restricted, authenticated and logged.
6. Technical and organizational measures
Measures appropriate to the risk include:
- logical organization isolation and authorization controls;
- TLS for public traffic and database connections, plus mTLS and separate service identities for internal communications;
- password and token hashing, secret encryption and key-material rotation;
- MFA/passkeys, step-up authentication and session controls for sensitive operations;
- protection against SSRF, DNS rebinding and access to private networks by public probes;
- allowlists and cost guardrails for Voice tests;
- audit logging, monitoring, restricted container privileges, updates and vulnerability scanning;
- automated retention, backups, backup verification and restore procedures;
- incident-management, change-management and business-continuity procedures.
7. Subprocessors
- The Controller gives general authorization for the subprocessors listed below:
| Subprocessor | Purpose | Primary location |
|---|---|---|
| OVHcloud | VPS, network, DNS, infrastructure backups and transactional email | European Union |
- Integrations added by the Controller (for example, an external webhook, messaging service or identity provider) operate on its instructions and do not become the Operator’s subprocessors solely because they are configured in the application.
- The Processor will give at least 14 days’ notice of a planned addition or replacement of a subprocessor. The Controller may raise a reasoned data-protection objection; the parties will take reasonable remedial steps, and where this is not possible, the Controller may stop using the feature affected by the change.
- The Processor imposes data-protection obligations on each subprocessor that are no less protective than this DPA and remains responsible for their performance in accordance with Article 28 GDPR.
8. Individual rights and assistance to the Controller
- Taking account of the nature of the processing, the Processor assists the Controller with requests for access, rectification, erasure, restriction, portability and objection through application features, exports and reasonable support.
- A request received directly from an individual will be forwarded to the Controller unless law prohibits this. The Processor will not respond independently without the Controller’s instructions.
- The Processor also assists with impact assessments, supervisory-authority consultations and demonstrating compliance, to the extent of information available to it.
9. Personal data breaches
- The Processor notifies the Controller of a confirmed personal data breach without undue delay, aiming to do so within 48 hours after confirmation.
- To the extent available, the notice describes the nature of the breach, categories of data and individuals, likely consequences, measures taken and a contact point. Information may be provided in stages.
- The Controller is responsible for notifying the supervisory authority and affected individuals unless the parties agree otherwise.
10. International transfers
The Processor does not transfer entrusted data outside the EEA without a documented instruction or appropriate legal mechanism. Where a transfer is necessary, it will use, in particular, an adequacy decision or the European Commission’s Standard Contractual Clauses and implement supplementary measures where required by the transfer assessment.
11. Return and deletion of data
- While using the service, the Controller may export data through available features. The export scope depends on the plan and technical availability of the relevant data type.
- After the service ends, the Processor will, at the Controller’s choice, delete or return the data unless law requires continued retention.
- Data is removed from active systems during the account-closure process and from rotating backups no later than the end of the 14-day cycle. Irreversibly aggregated or anonymized statistics are not personal data.
12. Audits and information
- The Processor provides information reasonably necessary to demonstrate compliance with Article 28 GDPR, primarily through documentation, test results, security reports or questionnaire responses.
- The Controller may conduct one audit per year on at least 30 days’ notice, during working hours, without accessing other customers’ data or disrupting service security. A more frequent audit is permitted after a breach or at the request of a supervisory authority.
- The Controller bears the costs of a non-standard audit unless it identifies a material breach of this DPA by the Processor.
- If a Controller instruction infringes the GDPR or other data-protection law, the Processor will promptly inform the Controller and may suspend performance until the matter is clarified.
13. Precedence and amendments
For entrusted processing, this DPA prevails over the Terms. Amendments to the DPA must be recorded in documentary form, except for subprocessor-list updates made under section 7. The current version is published at https://upnator.com/legal/dpa.
Questions about this document: legal@upnator.com