When your workspace holds other people's personal data, such as teammates, alert recipients or status-page subscribers, we process it for you under these terms.
Last updated: October 1, 2026
1. Scope and roles
This addendum applies when we process personal data on your behalf as part of the Service ("Customer Personal Data"). That includes data under the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws such as the CCPA. It forms part of our terms of service, and you accept it when you accept those terms.
For Customer Personal Data, you are the controller (or a processor acting for your own client), and Online Creative Network, operating UPKira, is your processor (or subprocessor). For our own account, billing and security data, we are an independent controller under our privacy policy.
2. Details of processing
Details of processing
Subject matter
Providing the UPKira monitoring, alerting and status page service.
Duration
For as long as you use the Service, and until the data is deleted when the account closes.
Nature and purpose
Storing, organizing, transmitting and displaying Customer Personal Data to run checks, confirm incidents, deliver alerts, publish status pages and produce reports.
Types of personal data
Names and email addresses of people you invite. Email addresses and chat or incident tool destinations used for alerts. Status-page subscriber email addresses. Any personal data in monitor names, URLs, request settings, incident updates or status-page content.
Data subjects
Your staff and contractors, your clients and end users who subscribe to your status pages, and anyone identified in content you add.
Special categories
None intended. Do not put sensitive personal data into UPKira.
3. Our obligations
Process Customer Personal Data only on your documented instructions. The terms, your settings, and how you use the Service are those instructions. If an instruction appears to break data protection law, we will tell you.
Make sure everyone who can access the data is bound by confidentiality.
Apply appropriate technical and organizational security measures, as described below.
Help you respond to data subject requests, carry out data protection impact assessments, and consult regulators, as far as is reasonable given the nature of the processing.
Never sell Customer Personal Data or use it for our own purposes beyond running and securing the Service.
4. Security measures
Our current measures include:
Encryption of secrets. AES-256-GCM encryption for monitor authorization headers, request bodies and alert secrets.
Hashed tokens. Heartbeat, invitation and subscription tokens are stored as hashes.
Accounts. scrypt password hashing, required email verification, HttpOnly session cookies, and rate limits on authentication.
Access control. Role-based access within each workspace, and isolation between workspaces.
Outbound requests. Probes and webhooks pass a request guard that blocks private and metadata addresses.
Data minimization. Logs and error messages are redacted, and response bodies are not stored.
The security page has more detail. We may update these measures as long as the overall level of protection does not go down.
5. Subprocessors
You authorize us to use the subprocessors listed in our privacy policy. Each one is bound by written data protection terms that are at least as protective as these. Before we add or replace a subprocessor, we will update that list and email workspace owners at least 14 days in advance. You may object on reasonable data protection grounds. If we cannot address your objection, you may cancel the affected Service without penalty. Destinations you configure yourself, such as Slack, Microsoft Teams, Telegram, PagerDuty or your own webhooks, are not our subprocessors.
6. International transfers
If Customer Personal Data leaves the EEA, the United Kingdom or Switzerland for a country without an adequacy decision, the transfer is covered by the EU Standard Contractual Clauses (Module 2 or 3, as appropriate). These are incorporated by reference, together with the UK International Data Transfer Addendum and Swiss amendments where they apply.
7. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify the workspace owner without undue delay and within 72 hours where feasible. The notice will cover what we know about the breach, its likely consequences, and the steps we are taking. We will follow up as we learn more.
8. Return and deletion
Self-service export and deletion are not available in the product yet. To get a copy of Customer Personal Data or have it deleted, email us. When your account or workspace closes, or at your request, we delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in backups are deleted as the backups rotate out.
9. Audits
We will give you the information reasonably needed to show that we comply with this addendum. If that information is not enough, or a regulator requires it, you may audit our compliance once a year. You must give at least 30 days' written notice, cover your own costs, and use an auditor bound by confidentiality. The audit must avoid disrupting the Service or exposing other customers' data.
10. Liability and precedence
The limitation of liability in our terms of service applies to this addendum. If this addendum conflicts with the terms, this addendum wins for matters of personal data protection. If the Standard Contractual Clauses conflict with either, the Standard Contractual Clauses win.
11. Signed copies and questions
If your organization needs a countersigned copy of this addendum, or has questions about it, email hello@upkira.com with your workspace name and legal entity details.