star-1
star-2

Effective date: 20 August, 2026

This Data Processing Addendum (“DPA”) is entered into between:

Processor: Dane Commercial Services Ltd, trading as Funny Monitors, a company registered in England and Wales under company number 16193091, with registered office at 61 Bridge Street, Kington, United Kingdom, HR5 3DJ (“Funny Monitors,” “we,” “us,” or “our”); and

Customer: the person or entity that has accepted the Funny Monitors Terms of Service or entered into another written agreement governing use of the Services (“Customer,” “you,” or “your”).

Funny Monitors is registered with the UK Information Commissioner’s Office under registration number ZB896242.

This DPA forms part of and is incorporated into the Funny Monitors Terms of Service, or another written service agreement between the parties (the “Agreement”). The Privacy Policy describes our processing as a controller and provides additional information about the Services. The Refund Policy applies to fees, cancellation, and refunds but does not limit obligations that cannot lawfully be limited under Applicable Data Protection Law.

This DPA applies where Funny Monitors Processes Customer Personal Data on Customer’s behalf in connection with the Services. It does not apply to Personal Data for which Funny Monitors acts as an independent Controller, such as its own billing, tax, account-security, legal-compliance, or direct-marketing records.

Table of contents

  1. Definitions and interpretation
  2. Scope, term, and precedence
  3. Roles and responsibilities
  4. Customer instructions
  5. Funny Monitors’ processor obligations
  6. Confidentiality and personnel
  7. Security of processing
  8. Personal Data Breaches
  9. Subprocessors
  10. Data Subject requests
  11. DPIAs and regulatory cooperation
  12. International transfers
  13. Return and deletion
  14. Information and audits
  15. Liability
  16. Termination
  17. General provisions
  18. Contact information
  19. Annex 1 — Details of Processing
  20. Annex 2 — Technical and organizational measures
  21. Annex 3 — Subprocessors
  22. Annex 4 — International transfer terms

1. Definitions and interpretation

1.1 Definitions

In this DPA:

  • “Applicable Data Protection Law” means data-protection and privacy law applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the UK GDPR, the Data Protection Act 2018, the EU GDPR, national laws implementing or supplementing those instruments, and applicable electronic-communications or ePrivacy law.
  • “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processed,” “Processing,” “Processor,” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law.
  • “Customer Personal Data” means Personal Data Processed by Funny Monitors on Customer’s behalf through the Services, excluding Personal Data for which Funny Monitors determines the purposes and means of Processing as an independent Controller.
  • “EU GDPR” means Regulation (EU) 2016/679.
  • “Services” has the meaning given in the Agreement and includes the Funny Monitors websites, dashboard, applications, APIs, monitoring, reporting, status pages, notifications, integrations, support, and related services purchased or configured by Customer.
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, as amended or replaced.
  • “Subprocessor” means a third party appointed by Funny Monitors to Process Customer Personal Data on Customer’s behalf.
  • “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, as amended or replaced.
  • “UK GDPR” has the meaning given in section 3(10) of the Data Protection Act 2018.

1.2 Interpretation

Capitalized terms not defined in this DPA have the meanings given in the Agreement. “Including” means “including without limitation.” A reference to law includes amendments, replacements, and subordinate legislation. Headings do not affect interpretation.

2. Scope, term, and precedence

2.1 Scope

This DPA applies to Processing of Customer Personal Data by Funny Monitors as Processor on behalf of Customer under the Agreement where Applicable Data Protection Law requires written processor terms.

2.2 Effective date and term

This DPA begins when the Agreement becomes effective or when Funny Monitors first Processes Customer Personal Data on Customer’s behalf, whichever is earlier. It continues until Funny Monitors has ceased Processing Customer Personal Data, except for provisions that must survive to remain effective.

2.3 Incorporation without separate signature

This DPA applies automatically to every Customer for whom Funny Monitors Processes Customer Personal Data as a Processor or Subprocessor under the Agreement. It becomes binding when Customer accepts or enters into the Agreement; no separate signature is required. A countersigned copy is available on request by emailing [email protected], subject to reasonable identity, account, and authority verification.

2.4 Order of precedence

If this DPA conflicts with the Agreement regarding Processing of Customer Personal Data, this DPA controls to the extent of the conflict. If the SCCs or UK Addendum apply and conflict with this DPA or the Agreement, the applicable SCCs or UK Addendum control. The Agreement controls all other matters, including Service scope, fees, refunds, disclaimers, and general liability, subject to mandatory law.

3. Roles and responsibilities

3.1 Roles

For Customer Personal Data:

  • Customer is the Controller, or a Processor acting for another Controller;
  • Funny Monitors is the Processor, or a Subprocessor where Customer acts as a Processor; and
  • each party will comply with the obligations applicable to its role under Applicable Data Protection Law.

3.2 Customer responsibilities

Customer represents, warrants, and undertakes that:

  • it has a valid lawful basis for Processing Customer Personal Data and for instructing Funny Monitors to Process it;
  • it has provided all required privacy information and obtained any required consent;
  • it has all rights, permissions, and authority necessary to submit or make Customer Personal Data available to Funny Monitors;
  • its instructions, configurations, monitoring targets, alert recipients, status pages, integrations, and use of the Services comply with Applicable Data Protection Law;
  • Customer Personal Data is adequate, relevant, accurate, and limited to what is necessary;
  • it will not submit special-category, criminal-offence, health, biometric, payment-card, government-identifier, or similarly sensitive data unless the relevant Service is expressly designed for it and the parties have agreed appropriate written terms;
  • it is responsible for responding to Data Subjects and for determining whether the Services and security measures are appropriate for its Processing; and
  • it will secure credentials, API keys, team-member access, integrations, devices, and data transmitted to or from the Services.

3.3 Customer acting as Processor

Where Customer is a Processor acting for another Controller, Customer confirms that it is authorized to appoint Funny Monitors as a Subprocessor and to give the instructions contained in the Agreement and this DPA. Customer is the sole point of contact for the relevant Controller unless Applicable Data Protection Law requires otherwise.

4. Customer instructions

4.1 Documented instructions

Funny Monitors will Process Customer Personal Data only on Customer’s documented instructions, unless required by law. The Agreement, this DPA, Customer’s configuration and use of the Services, enabled integrations, support requests, and other written instructions accepted by Funny Monitors constitute Customer’s documented instructions.

Customer instructs Funny Monitors to Process Customer Personal Data as necessary to:

  • provide, operate, secure, maintain, and support the Services;
  • perform customer-configured monitoring and store or display resulting data;
  • provide reports, status pages, APIs, integrations, incidents, and maintenance information;
  • send customer-configured email, SMS, voice, webhook, push, or integration notifications;
  • prevent fraud, abuse, and security incidents;
  • comply with the Agreement and Applicable Data Protection Law; and
  • perform the Processing described in Annex 1.

4.2 Unlawful instructions

Funny Monitors will inform Customer if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law. We may suspend the affected Processing until Customer modifies or confirms the instruction or the parties otherwise resolve the issue. Funny Monitors is not required to perform an instruction that is technically infeasible, outside the Services, unlawful, or inconsistent with the Agreement unless separately agreed in writing.

4.3 Processing required by law

If law requires Funny Monitors to Process Customer Personal Data contrary to Customer’s instructions, we will notify Customer before Processing unless the law prohibits notification on important grounds of public interest.

5. Funny Monitors’ processor obligations

Funny Monitors will:

  • Process Customer Personal Data only as described in Section 4;
  • comply with obligations directly applicable to Processors under Applicable Data Protection Law;
  • maintain records of categories of Processing where legally required;
  • reasonably assist Customer with compliance as described in this DPA, taking account of the nature of Processing and information available to Funny Monitors;
  • not sell Customer Personal Data;
  • not retain, use, or disclose Customer Personal Data outside the parties’ direct business relationship except as instructed, required to provide the Services, or required by law; and
  • cooperate with a competent Supervisory Authority as required by Applicable Data Protection Law.

Assistance outside standard Service functionality may be subject to reasonable fees based on the work required, unless the assistance is necessary because Funny Monitors breached this DPA or charging is prohibited by law. We will inform Customer of material anticipated fees before beginning chargeable work where practicable.

6. Confidentiality and personnel

Funny Monitors will ensure that persons authorized to Process Customer Personal Data:

  • are bound by contractual or statutory confidentiality obligations;
  • receive access only where reasonably necessary for their duties;
  • are informed of the confidential nature of Customer Personal Data; and
  • receive appropriate privacy and security guidance relevant to their roles.

Access will be removed when no longer required. Confidentiality obligations will continue after the person’s engagement ends.

7. Security of processing

7.1 Appropriate measures

Taking into account the state of the art, implementation cost, nature, scope, context and purposes of Processing, and risks to Data Subjects, Funny Monitors will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

The measures currently described in Annex 2 form part of this DPA. Funny Monitors may update them where the overall level of protection is not materially reduced.

7.2 Customer responsibilities

Customer is responsible for securely configuring and using the Services, including:

  • maintaining unique credentials and protecting authentication factors and API keys;
  • managing unlimited team-member access, roles, and removal;
  • restricting monitor payloads, headers, responses, screenshots, and support submissions to necessary data;
  • securing its networks, endpoints, devices, integrations, and notification destinations;
  • exporting data before cancellation where Customer wishes to retain it; and
  • promptly notifying [email protected] of suspected unauthorized access involving its account.

8. Personal Data Breaches

8.1 Notification

Funny Monitors will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

8.2 Information provided

To the extent known and reasonably available, notification will describe:

  • the nature of the breach;
  • affected categories of Data Subjects and Customer Personal Data;
  • likely consequences;
  • measures taken or proposed to contain, investigate, remediate, or mitigate the breach; and
  • a contact point for further information.

Information may be supplied in phases as it becomes available. Notification does not constitute an admission of fault or liability.

8.3 Cooperation

Taking account of the nature of Processing and information available, Funny Monitors will reasonably assist Customer with its breach-assessment, documentation, regulator-notification, and Data Subject notification obligations. Customer remains responsible for determining whether and how to notify a Supervisory Authority or Data Subject unless law provides otherwise.

9. Subprocessors

9.1 General authorization

Customer gives Funny Monitors general written authorization to appoint and replace Subprocessors necessary to provide the Services.

9.2 Current Subprocessors

Named Subprocessors are listed in Annex 3 and in our Privacy Policy. We may also use additional infrastructure, hosting, storage, database, backup, security, logging, and similar technical providers without publicly identifying each provider where permitted by Applicable Data Protection Law.

9.3 Subprocessor obligations

Before a Subprocessor Processes Customer Personal Data, Funny Monitors will enter into a written agreement requiring data-protection obligations appropriate to the Processing and materially consistent with those imposed on Funny Monitors by this DPA, as required by Applicable Data Protection Law.

Funny Monitors remains responsible for a Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law.

9.4 Changes and objections

Funny Monitors may update the Subprocessor list from time to time. We will provide notice of an intended addition or replacement of a Subprocessor by email to the address associated with Customer’s account and by publishing the change online. Where Applicable Data Protection Law requires advance notice, notice will be provided before the relevant Subprocessor begins Processing Customer Personal Data.

Customer may object on reasonable, documented grounds relating specifically to data protection by contacting [email protected] promptly after notice. The parties will work in good faith to seek a commercially reasonable resolution, which may include additional safeguards or disabling an affected optional feature. If no reasonable resolution is available, Customer may stop using or cancel the affected Service under the Agreement. Fees remain governed by the Refund Policy except where a refund is required by mandatory law.

10. Data Subject requests

10.1 Customer responsibility

Customer is responsible for responding to requests from Data Subjects concerning Customer Personal Data.

10.2 Requests received by Funny Monitors

If Funny Monitors receives a request concerning Customer Personal Data, we will, where legally permitted:

  • notify Customer or direct the Data Subject to Customer;
  • not respond substantively on Customer’s behalf unless instructed or required by law; and
  • provide reasonable assistance, taking account of the nature of Processing and Service functionality.

10.3 Service functionality

Customer should use available account, export, correction, deletion, configuration, and access-control functionality to respond to requests where possible. Additional assistance may be subject to Section 5.

11. DPIAs and regulatory cooperation

Taking account of the nature of Processing and information available to Funny Monitors, we will provide reasonable assistance where Customer is required to:

  • conduct a data protection impact assessment concerning use of the Services;
  • carry out a prior consultation with a competent Supervisory Authority; or
  • provide information to a competent Supervisory Authority about Funny Monitors’ Processing on Customer’s behalf.

Customer must provide sufficient context and reasonable notice. Assistance may be subject to Section 5.

12. International transfers

12.1 Processing regions

Customer Personal Data may be stored, Processed, or accessed in the United Kingdom, European Union, North America, and Australia, including where Funny Monitors’ Subprocessors operate.

12.2 Restricted transfers

The parties will ensure that a transfer subject to international-transfer restrictions has a lawful mechanism. Depending on the transfer, this may include:

  • applicable adequacy regulations or decisions;
  • the SCCs;
  • the UK Addendum;
  • the UK International Data Transfer Agreement; or
  • another mechanism permitted by Applicable Data Protection Law.

12.3 EEA transfers

Where Customer Personal Data protected by the EU GDPR is transferred by Customer to Funny Monitors in a country not covered by an applicable adequacy decision, the SCCs are incorporated by reference as described in Annex 4. Module Two applies where Customer is a Controller and Funny Monitors is a Processor. Module Three applies where Customer is a Processor and Funny Monitors is a Subprocessor.

12.4 UK transfers

Where Customer Personal Data protected by the UK GDPR is transferred in a restricted transfer and no adequacy regulation applies, the UK Addendum applies to the SCCs as described in Annex 4, or the parties may rely on another valid UK transfer mechanism.

12.5 Supplementary measures

Where required, Funny Monitors will assess transfers and implement supplementary contractual, technical, or organizational measures appropriate to the risk. If a transfer mechanism becomes invalid, the parties will cooperate in good faith to implement an alternative lawful mechanism or suspend the affected transfer.

13. Return and deletion

13.1 Export before cancellation

Customer is responsible for exporting Customer Personal Data it wishes to retain before cancelling. Because cancellation is immediate, Customer must complete any export before confirming the “Cancel Subscription” action.

13.2 Immediate operational deletion

When Customer confirms “Cancel Subscription,” access and Processing for Service delivery end immediately. Operational Customer Personal Data—including monitors, configurations, monitoring history, reports, status pages, incidents, integrations, contact and notification settings, API credentials, and related Service data—is permanently deleted from Funny Monitors’ active servers and Services. Monitoring and alerts stop immediately, and deleted operational data cannot be restored or recovered.

13.3 Backups and residual copies

Customer Personal Data contained on the central backup server is automatically deleted or overwritten no later than three days after cancellation or the applicable deletion instruction. During that period, backup data is isolated from ordinary use, protected under this DPA, and used only where necessary for disaster recovery, security, or legal compliance. If backup data is restored during that period, the deletion instruction will be reapplied.

13.4 Legally retained records

Funny Monitors may retain only Customer Personal Data that applicable law requires it to retain. Retained data will be isolated and Processed only for the legal retention purpose, protected under this DPA, and deleted when retention is no longer required.

Records that Funny Monitors Processes as an independent Controller—including limited invoice, tax, transaction, fraud-prevention, dispute, contract-acceptance, or legal-claims records—are governed by the Privacy Policy rather than this DPA.

13.5 Written confirmation

On reasonable written request, Funny Monitors will confirm completion of deletion required by this Section, subject to reasonable identity and account verification.

14. Information and audits

14.1 Compliance information

Funny Monitors will make available information reasonably necessary to demonstrate compliance with the Processor obligations in this DPA and Applicable Data Protection Law, subject to confidentiality, security, legal, and third-party restrictions.

14.2 Audit process

Customer may conduct an audit where required by Applicable Data Protection Law, subject to the following:

  • Customer must first review information, policies, questionnaires, certifications, or independent assessment summaries that Funny Monitors makes reasonably available;
  • if that information is insufficient, Customer must give at least 30 days’ written notice, unless a confirmed breach or regulator requires shorter notice;
  • audits are limited to once per 12-month period unless there are reasonable grounds to suspect material non-compliance or a Supervisory Authority requires another audit;
  • audits must occur during normal business hours, be appropriately scoped, and avoid unreasonable disruption;
  • auditors must be independent, suitably qualified, not a competitor, and bound by confidentiality;
  • audits must not expose another customer’s data, compromise security, or require disclosure prohibited by law or third-party duties; and
  • Customer bears its audit costs and Funny Monitors’ reasonable assistance costs unless the audit identifies a material breach by Funny Monitors.

14.3 Remediation

If an audit identifies a material breach of this DPA by Funny Monitors, we will take reasonable steps to remediate it without undue delay.

15. Liability

Each party remains liable for its own compliance with obligations directly imposed by Applicable Data Protection Law.

Subject to liability that cannot lawfully be limited or excluded, liability arising from this DPA is subject to the exclusions, limitations, procedures, and aggregate liability cap in the Agreement. Nothing limits Data Subject rights or regulatory powers under Applicable Data Protection Law.

Customer will indemnify Funny Monitors as provided in the Agreement for third-party claims arising from Customer’s unlawful instructions, lack of lawful basis or authority, unlawful Customer Personal Data, or breach of this DPA, except to the extent caused by Funny Monitors’ breach.

16. Termination

Upon expiry or termination of the Agreement:

  • Funny Monitors will stop Processing Customer Personal Data for Service delivery;
  • Customer Personal Data will be handled under Section 13;
  • Customer’s payment and refund rights remain governed by the Agreement and Refund Policy, subject to mandatory law; and
  • provisions that by their nature must survive—including confidentiality, deletion, audit, international-transfer, liability, and general provisions—will survive.

17. General provisions

17.1 Changes

Funny Monitors may update this DPA to reflect changes in law, regulatory guidance, the Services, or Processing. Material changes will be notified as described in the Agreement or Privacy Policy. An update will not materially reduce protection for Customer Personal Data without a lawful basis or valid agreement.

17.2 Severability

If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary and the remainder will continue in effect.

17.3 Governing law and courts

Except where the SCCs, UK Addendum, or Applicable Data Protection Law require otherwise, this DPA is governed by the laws of England and Wales and disputes are subject to the courts of England and Wales, consistent with the Agreement.

17.4 Assignment

Assignment of this DPA follows assignment of the Agreement. Any permitted successor remains bound by this DPA.

17.5 Entire agreement

This DPA, the Agreement, and incorporated transfer terms constitute the parties’ agreement regarding Processing of Customer Personal Data and supersede prior terms on that subject.

17.6 Language

This DPA is written in English. If translated, the English version controls to the extent permitted by law.

18. Contact information

Privacy and DPA enquiries should be sent to:

Dane Commercial Services Ltd
Company number: 16193091
61 Bridge Street
Kington
United Kingdom
HR5 3DJ
Email: [email protected]
ICO registration number: ZB896242

Funny Monitors has not appointed a separate Data Protection Officer. Responsibility for privacy and data-protection compliance remains internal to Dane Commercial Services Ltd, and all DPA and privacy enquiries should be sent to [email protected].

19. Annex 1 — Details of Processing

A. Parties

Data exporter: Customer

  • Name, address, and contact: as stated in Customer’s account or Agreement
  • Role: Controller or Processor, as applicable

Data importer: Dane Commercial Services Ltd trading as Funny Monitors

  • Address: 61 Bridge Street, Kington, United Kingdom, HR5 3DJ
  • Contact: [email protected]
  • Role: Processor or Subprocessor, as applicable

B. Subject matter

Processing Customer Personal Data to provide customer-configured uptime and service monitoring, measurements, alerts, reports, APIs, status pages, incidents, integrations, support, security, and related Services.

C. Duration

Processing continues for the term of the Agreement and the limited deletion or legal-retention period described in Section 13.

D. Nature and purposes

Processing may include collection, recording, organization, structuring, storage, retrieval, consultation, use, analysis, transmission, display, restriction, deletion, and destruction for the following purposes:

  • creating and administering Customer’s Service workspace;
  • monitoring Customer-specified websites, servers, endpoints, domains, DNS, certificates, ports, scheduled jobs, content, or other configured resources;
  • recording availability, response, performance, incident, and maintenance information;
  • providing dashboards, reports, public or private status pages, APIs, and integrations;
  • delivering email, SMS, voice, webhook, push, or integration alerts;
  • managing notification seats, recipients, and preferences;
  • responding to Customer support instructions and troubleshooting the Services;
  • securing the Services and preventing fraud or abuse; and
  • deleting Customer Personal Data on Customer’s instruction or termination.

E. Categories of Customer Personal Data

Depending on Customer configuration, Customer Personal Data may include:

  • names, business contact details, email addresses, telephone numbers, roles, and permissions;
  • team-member invitations, identifiers, access and activity data;
  • alert-recipient and status-page subscriber contact details and preferences;
  • URLs, domains, IP addresses, ports, endpoints, DNS information, certificate data, monitor names, tags, and settings;
  • request headers, payloads, authentication values, keywords, response metadata or content, screenshots, and monitored-page images;
  • monitoring results, timestamps, response times, incidents, maintenance events, reports, and status-page content;
  • API keys, integration identifiers, webhook destinations, and customer-selected integration data;
  • email, SMS, voice, webhook, push, and integration message content and delivery records;
  • IP addresses, device, browser, session, security, diagnostic, usage, API, and activity logs; and
  • support communications, attachments, diagnostic material, and feedback.

Payment-card numbers are processed by Stripe as described in the Privacy Policy and are not intended to form part of Customer Personal Data Processed by Funny Monitors on Customer’s behalf.

F. Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer’s account owners, administrators, employees, contractors, agents, and team members;
  • alert, escalation, maintenance, or incident-notification recipients;
  • status-page subscribers and visitors;
  • individuals whose Personal Data appears in monitored content, requests, responses, incidents, reports, screenshots, logs, or support material; and
  • other individuals whose Personal Data Customer submits or makes available through the Services.

G. Sensitive data

The Services are not designed for special-category, criminal-offence, health, biometric, government-identifier, payment-card, or similarly sensitive Personal Data. Customer must not submit such data unless expressly agreed in writing with appropriate safeguards.

H. Frequency

Processing is continuous or recurring for the Agreement term according to Customer’s monitor intervals, account activity, notification settings, API and integration use, status-page activity, and support interactions.

I. Processing regions

Customer Personal Data may be Processed in the United Kingdom, European Union, North America, and Australia, subject to Section 12.

20. Annex 2 — Technical and organizational measures

Funny Monitors will maintain measures appropriate to the risks of Processing. Depending on the relevant system and risk, these may include:

A. Governance and confidentiality

  • documented privacy, security, access, incident, and retention procedures appropriate to the organization;
  • confidentiality duties for personnel and contractors;
  • privacy and security awareness appropriate to personnel responsibilities; and
  • assignment of responsibility for security and incident response.

B. Identity and access management

  • unique user or personnel accounts where appropriate;
  • authentication and credential protections;
  • role- or need-based access and least-privilege principles;
  • removal or adjustment of access when roles or engagements change; and
  • controls for privileged or administrative access.

C. Network and application security

  • network, firewall, content-delivery, rate-limit, and security controls appropriate to the Services;
  • secure development, change, dependency, and patch-management practices appropriate to risk;
  • protections against common web and application attacks;
  • monitoring, logging, error detection, and investigation capabilities; and
  • vulnerability identification and remediation processes.

D. Data protection

  • encryption in transit where appropriate;
  • protection of stored Customer Personal Data appropriate to sensitivity and risk;
  • logical separation of customer workspaces in a multi-tenant environment;
  • minimization and purpose limitation;
  • secure credential, token, secret, and key handling; and
  • secure deletion or rendering inaccessible when data is no longer required.

E. Availability, backup, and recovery

  • availability, backup, restoration, and recovery measures appropriate to Service risk;
  • safeguards for backup copies;
  • business-continuity and incident-recovery procedures; and
  • testing or review of relevant recovery processes at intervals appropriate to risk.

F. Security monitoring and incidents

  • logging and monitoring appropriate to detect operational and security events;
  • procedures to assess, contain, investigate, document, and remediate incidents;
  • escalation and notification processes; and
  • preservation of appropriate incident evidence.

G. Provider management

  • risk-based assessment of relevant Subprocessors;
  • written data-protection and confidentiality obligations;
  • international-transfer safeguards where required; and
  • review of provider changes appropriate to the Processing risk.

H. Customer controls

  • individual team-member credentials and permissions;
  • monitor, notification, status-page, API, and integration configuration;
  • account export and immediate cancellation controls; and
  • customer-managed recipient, content, and data-minimization choices.

I. Assurance and certifications

The technical and organizational measures described in this Annex reflect Funny Monitors’ current operational practices. Dane Commercial Services Ltd is currently working toward SOC 2 and ISO/IEC 27001 certification and presently expects the certification process to be completed within approximately one month. Funny Monitors is not represented as SOC 2 or ISO/IEC 27001 certified until the relevant independent assessment has been completed and the formal report or certificate has been issued.

Once formally issued, relevant SOC 2 and ISO/IEC 27001 certification evidence or customer-appropriate assurance documentation will be made available to Funny Monitors customers on request at no additional charge, subject to reasonable confidentiality, security, and distribution restrictions.

21. Annex 3 — Subprocessors

Customer generally authorizes the following named Subprocessors:

SubprocessorProcessing purpose
StripePayment processing, subscription billing, transaction management, and fraud prevention
TermlyCookie consent, privacy notices, and preference management
TwilioVoice-call and SMS notification delivery
MailgunTransactional email, system notification, and email-delivery services
ZendeskCustomer-support query management and support communications
BrevoCustomer-sales query management and sales communications
SentryError and bug logging, diagnostics, and application monitoring
Google FontsLoading and displaying custom website fonts
CloudflareDNS, content delivery, security, and storage of screenshots and backups

Not every provider Processes Customer Personal Data in every case. Processing depends on Customer’s features, configuration, communications, and use of the Services.

Additional infrastructure, hosting, storage, database, backup, security, logging, and similar technical providers may be used without public identification where permitted by Applicable Data Protection Law, subject to Section 9.

22. Annex 4 — International transfer terms

A. EU SCC selections

Where the SCCs apply:

  • Module Two applies to Controller-to-Processor transfers;
  • Module Three applies to Processor-to-Processor transfers;
  • Clause 7, optional docking clause, applies;
  • Clause 9, Option 2, general written authorization, applies, with notice and objection handled under Section 9;
  • the optional language in Clause 11 does not apply;
  • for Module Two, the competent Supervisory Authority is determined under Clause 13 by reference to the Data Exporter and Applicable Data Protection Law;
  • the law selected under Clause 17 will be the law of Ireland, provided that law permits third-party beneficiary rights; and
  • courts under Clause 18 will be the courts of Ireland.

Annex I.A to the SCCs is completed by Annex 1.A of this DPA. Annex I.B is completed by Annex 1.B–I. Annex I.C is determined as stated above. Annex II is completed by Annex 2. Annex III is completed by Annex 3.

B. UK Addendum

Where the UK Addendum applies:

  • the SCCs identified in Part 2 of this Annex are the “Approved EU SCCs”;
  • Table 1 is completed using the party information in Annex 1.A;
  • Table 2 is completed using the Module, clause selections, and annex information in Part A above;
  • Table 3 is completed using Annexes 1, 2, and 3 of this DPA;
  • in Table 4, either party may end the UK Addendum as permitted by Section 19 of the UK Addendum; and
  • the mandatory clauses of the UK Addendum are incorporated by reference and control in the event of conflict.

C. Updates and alternative mechanisms

If the SCCs or UK Addendum are replaced, amended, or no longer valid for a transfer, the successor clauses or another lawful mechanism will apply where legally effective. The parties will execute or implement further documentation reasonably necessary to preserve a lawful transfer.