Skip to content
All legal documents

Data Processing Addendum

Last updated August 27, 2026


This document is a template intended to be reviewed by legal counsel before launch. Customers who require a signed DPA can request one from us.

Scope

This Data Processing Addendum (“DPA”) describes how EverUptime processes personal data on behalf of a customer (“Controller”) when providing the service. It supplements our Terms of Service.

Roles

For personal data processed in the course of providing the service, the customer is the Controller and EverUptime is the Processor. EverUptime processes personal data only on documented instructions from the Controller.

Processing details

  • Subject matter: provision of the EverUptime incident operations platform.
  • Duration: for the term of the customer’s subscription.
  • Nature and purpose: hosting and processing operational and account data to deliver monitoring, incident, on-call, and status capabilities.
  • Categories of data subjects: the customer’s personnel and responders.

Subprocessors

EverUptime uses vetted subprocessors to deliver the service. A current list is available on request, and we provide a mechanism to be notified of changes.

Security measures

EverUptime maintains technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, tenant isolation, and least-privilege internal access. See our Security page.

International transfers

Where personal data is transferred across borders, EverUptime relies on appropriate safeguards as required by applicable law.

Assistance and breach notification

EverUptime assists the Controller with data-subject requests and, in the event of a personal data breach affecting the service, notifies the Controller without undue delay.

Deletion

On termination, EverUptime deletes or returns personal data in accordance with the Terms and applicable law.

Contact

To request a signed DPA or ask questions, contact hello@everuptime.com.