Template for agencies and other customers that add sites or contact details of their own clients to Heedly. It is a starting point for counsel, not a signed agreement.
1. Parties and roles
Controller: the customer who instructs Heedly to process personal data of their clients. Processor: [seller details not filled in yet].
2. Subject matter, nature and duration
Subject matter: the processor stores and uses personal data to provide uptime, SSL, domain, feed and page monitoring, alerts, reports and status pages to the controller. Nature and purpose: storage, retrieval, display, e-mailing of alerts and deletion, only for providing the service.
Duration: for as long as the controller uses the service plus the retention periods in the Privacy Policy.
3. Data and data subjects
- Data: email addresses and names of recipients, site and incident data that may include personal data contained in error messages, page titles or URLs, and text the controller publishes on status pages.
- Data subjects: the controller’s staff and clients who receive alerts, and the controller’s customers whose data appears in monitored pages or published text.
4. Processor obligations
- Process data only on documented instructions of the controller, and tell the controller at once if an instruction appears to breach data protection law.
- Ensure that people with access are bound by confidentiality.
- Apply the technical and organisational measures in the annex below.
- Assist the controller with data subject requests, security obligations, impact assessments and prior consultation with authorities.
- Notify the controller of a personal data breach without undue delay (target: within 72 hours of becoming aware).
- Delete or return data when the service ends, unless the law requires retention.
- Make available the information needed to show compliance and allow reasonable audits with notice.
5. Sub-processors
The controller gives general authorisation for these sub-processors: Hetzner (hosting and database, European Union); Cloudflare (content delivery and the Turnstile human check, United States, EU–US Data Privacy Framework); GitHub (storage of encrypted backup copies that its operator cannot read, United States, EU–US Data Privacy Framework); an SMTP email delivery provider (to be named here before launch).
The processor will announce any addition or replacement by email at least 14 days in advance. The controller may object on reasonable data protection grounds; if the parties cannot agree, the controller may end the service and receive a refund of any unused prepaid period.
6. International transfers
The processor is established in Ukraine, which has no EU adequacy decision. For controllers in the EU or UK, the parties will rely on the EU standard contractual clauses (processor-to-controller or controller-to-processor module as applicable), to be attached by counsel before paid plans start.
7. Security measures (annex)
- Passwords hashed with Argon2id; session and API-key tokens stored only as hashes; two-factor secrets encrypted.
- Encryption in transit; strict transport and content-security headers; rate limiting and flood protection.
- Access to customer data limited to the founder, with two-factor authentication; administrative actions recorded in an audit log.
- Encrypted backups, kept for the period stated in the Privacy Policy.
8. Signatures
Signature blocks to be added by counsel.