Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between WatchTower15 Ltd ("Processor", "we", "us") and the customer identified in the applicable order or account ("Controller", "you") for the use of the WatchTower15 monitoring platform (the "Service"). It governs the processing of personal data carried out by us on your behalf and reflects the requirements of Article 28 of the UK and EU GDPR.
A standard DPA is available to all customers at account sign-up. No negotiation is required to accept the standard form. Where you require a signed copy, contact privacy@watchtower15.com. This DPA should be read together with our Privacy Policy and Terms of Service.
1. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor" and "sub-processor" have the meanings given in the UK GDPR and the EU GDPR. "Data Protection Laws" means all laws applicable to the processing of personal data under this DPA. "Customer Data" means the monitoring data and any personal data we process on your behalf through the Service.
2. Roles of the parties
For Customer Data processed through the Service, you act as the Controller and WatchTower15 acts as the Processor. Where you are itself a processor for a third party, we act as a sub-processor and your instructions must be consistent with your own controller's instructions. WatchTower15 remains an independent controller only for account, billing and contact data, as described in our Privacy Policy.
3. Scope & instructions
We process Customer Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case we will inform you, unless prohibited). Your use of the Service, together with this DPA and the Terms of Service, constitutes your complete and documented instructions. We will inform you if, in our opinion, an instruction infringes Data Protection Laws.
4. Details of processing
| Subject matter | Provision of the WatchTower15 monitoring platform. |
|---|---|
| Duration | For the term of your subscription, plus the retention and deletion periods in section 11. |
| Nature & purpose | Collection, storage, analysis and presentation of monitoring telemetry, logs and security data to operate the Service. |
| Types of data | Server and infrastructure telemetry, container metrics, forwarded log lines, DNS and SSL/TLS metadata, service reachability data, and any personal data incidentally contained therein. |
| Categories of data subjects | Your personnel, end users and any individuals whose personal data appears in the monitoring data you send to the Service. |
5. Confidentiality
We ensure that personnel authorised to process Customer Data are bound by appropriate confidentiality obligations and are trained on their data protection responsibilities. Access to Customer Data is limited to those who need it to provide the Service.
6. Security measures
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Customer Data in transit and at rest.
- A zero-privilege agent architecture — the
wt15-server-agentruns withNoNewPrivileges=yes,ProtectSystem=strictand no Linux capabilities. - Role-based access control (RBAC) and single sign-on (SSO) support.
- Comprehensive audit logging of actions within the platform.
- Regular review of the effectiveness of these measures.
7. Sub-processors
You provide general authorisation for us to engage sub-processors to provide the infrastructure that hosts the Service in your chosen region. We maintain a current list of sub-processors, available on request. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA and remain responsible for their performance. We will give you reasonable notice of any intended addition or replacement of a sub-processor, giving you the opportunity to object on reasonable grounds.
8. International transfers
Data residency is a default option: you select the region in which Customer Data is stored (UK, EU, USA, Latam or SE-Asia). We will not transfer personal data of EU or UK data subjects outside the EEA or the UK, or to a country without an adequacy decision, without your instruction and an appropriate transfer mechanism — such as the EU Standard Contractual Clauses or the UK International Data Transfer Agreement — in place.
9. Assistance & data subject rights
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights, and to meet your obligations regarding security, breach notification, data protection impact assessments and prior consultation. If we receive a request directly from your data subject, we will refer them to you and not respond substantively without your authorisation.
10. Breach notification
We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, its likely consequences and the measures taken or proposed to address it, so that you can meet your own notification obligations.
11. Return & deletion of data
Customer Data is retained according to the retention settings you configure within the Service. On termination or expiry of your subscription, and at your choice, we will delete or return all Customer Data and delete existing copies, unless applicable law requires continued storage. Standard backups are purged on our routine backup cycle.
12. Audits
We will make available to you the information necessary to demonstrate compliance with the obligations in this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to reasonable notice, confidentiality undertakings and frequency limits.
13. Term & contact
This DPA remains in effect for as long as we process Customer Data on your behalf. To request a signed copy or ask a question about processing, contact privacy@watchtower15.com. See also our Privacy Policy, Terms of Service, and the GDPR & compliance section of our About page.