Want to know how much website downtime costs, and the impact it can have on your business?
Find out everything you need to know in our new uptime monitoring whitepaper 2021
Monitoring
Status Pages
Pricing
Last updated: 01 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and TrafficCake Limited and/or ChangeCrab Limited, or the relevant group company providing the services (“Processor”).
This DPA applies where the Processor processes Personal Data on behalf of the Controller in the course of providing the services, including services branded as StatusCake and ChangeCrab.
Terms used in this DPA have the meanings given to them in applicable data protection laws, including the UK General Data Protection Regulation (“UK GDPR”) and, where applicable, the EU General Data Protection Regulation (“EU GDPR”).
“Personal Data”, “Processing”, “Controller”, and “Processor” shall have the meanings set out in those laws.
2.1 The Controller determines the purposes and means of the Processing of Personal Data.
2.2 The Processor processes Personal Data only on behalf of the Controller and in accordance with the Controller’s documented instructions, including as set out in this DPA and the applicable agreement, unless required to do so by applicable law.
2.3 This DPA applies only where the Processor acts as a data processor. Where the Processor acts as a data controller in its own right, this DPA does not apply.
The subject matter, nature, and purpose of the Processing, the types of Personal Data, and the categories of data subjects are described in Annex 1.
4.1 The Processor shall:
a) process Personal Data only on documented instructions from the Controller, unless required by applicable law;
b) ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations;
c) implement appropriate technical and organisational measures to protect Personal Data, taking into account the nature of the Processing;
d) assist the Controller, taking into account the nature of the Processing, in responding to requests from data subjects to exercise their rights under applicable data protection laws;
e) assist the Controller, to the extent required by applicable data protection laws, with compliance relating to security, breach notifications, and data protection impact assessments;
f) delete or return Personal Data to the Controller upon termination of the services, subject to applicable legal requirements; and
g) make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, in accordance with Section 8 below, and as required by applicable data protection laws.
5.1 The Controller provides a general authorisation for the Processor to engage sub-processors to process Personal Data.
5.2 Where the Processor engages a sub-processor, the Processor shall impose on that sub-processor, by way of a written contract, data protection obligations no less protective than those set out in this DPA, in accordance with Article 28(4) GDPR.
5.3 The Processor remains responsible for the performance of its sub-processors’ obligations in relation to the Processing of Personal Data.
5.4 A current list of sub-processors used by the Processor is set out in Annex 2 or otherwise made available on the Processor’s website or within the services.
5.5 The Processor may appoint or replace sub-processors from time to time. The Processor will provide prior notice of any intended addition or replacement of a sub-processor by posting the change in the StatusCake change log, updating its published sub-processor list, or by another reasonable electronic notice mechanism.
5.6 The Controller may object to the appointment or replacement of a sub-processor within the notice period on reasonable data protection grounds. Any objection must identify the specific data protection concern relating to the proposed sub-processor. The Processor will consider the objection in good faith and may, where commercially and technically reasonable, take steps to address the concern.
5.7 If the Processor is unable to resolve the objection without unreasonable burden, or if the proposed sub-processor is required for the continued provision of the services, the Controller may terminate the affected services before the relevant sub-processor is used.
5.8 The Controller is responsible for ensuring that its account owner, administrator, billing contact, legal contact, or other relevant contact details and notification preferences are accurate and kept up to date.
5.9 The notice period under Section 5.5 above will be fourteen (14) days, unless a shorter period is required for security, legal, service continuity, or other urgent reasons.
6.1 The Processor shall notify the Controller of a personal data breach without undue delay where such notification is required by applicable data protection law.
6.2 The Processor shall provide information reasonably required to enable the Controller to meet its legal obligations in relation to such a breach.
7.1 Personal Data may be processed or accessed outside the United Kingdom or European Economic Area.
7.2 Where required by applicable data protection laws, the parties shall ensure that appropriate safeguards are in place, including the use of approved standard contractual clauses or equivalent lawful transfer mechanisms.
8.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate the Processor’s compliance with this DPA and applicable data protection laws, including Article 28 GDPR, taking into account the nature of the services and the processing.
8.2 The Processor may satisfy an audit or information request by providing relevant documentation, policies, security summaries, technical and organisational measures, responses to reasonable questionnaires, third-party certifications or reports, or other information reasonably sufficient to demonstrate compliance. Any such information may be subject to appropriate confidentiality obligations, non-disclosure terms, identity and authority verification, redactions, and safeguards to protect security, confidentiality, trade secrets, privileged information, and the data of other customers.
8.3 If the information provided under Section 8.2 is not reasonably sufficient to demonstrate compliance, the Controller may request an audit. Any audit shall be subject to reasonable prior written notice, no more than once in any twelve (12) month period unless required by a supervisory authority or following a confirmed personal data breach affecting Controller Personal Data, and shall be limited to the processing of Controller Personal Data under this DPA.
8.4 Audits shall be conducted remotely unless an on-site inspection is legally required and reasonably necessary. Any audit or inspection shall be conducted during normal business hours, in a manner that does not disrupt the services, compromise the security or confidentiality of the Processor’s systems, or expose the data of other customers.
8.5 The Controller shall bear its own costs of any audit and reimburse the Processor for reasonable costs incurred in supporting any audit, unless prohibited by applicable law or agreed otherwise in writing.
8.6 The Processor may refuse, limit, or suspend any audit request to the extent it would compromise security, confidentiality, legal privilege, trade secrets, service availability, or the rights of other customers or third parties.
9.1 This DPA does not create any additional liability, warranties, or indemnities beyond those set out in the applicable agreement between the parties.
This DPA shall be governed by and construed in accordance with the laws of England and Wales, and the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with this DPA.
Provision of software-as-a-service products, including website monitoring, status communications, and changelog / release note services.
Processing Personal Data as necessary to provide, operate, secure, and support the services in accordance with the Controller’s instructions.
Contact details (such as names, email addresses, and telephone numbers), account and user information, usage and technical data, communications data, and customer-generated content, as determined by the Controller.
Customers, users, subscribers, and other individuals whose Personal Data is provided by or on behalf of the Controller.
As at the date of this DPA, the Processor uses the following third-party sub-processors to assist in providing the services. These sub-processors may process Personal Data on behalf of the Controller.
| Purpose | Sub-processor | Categories of data processed |
|---|---|---|
| Cloud hosting & infrastructure | DigitalOcean | Hosted service data, which may include personal data |
| Cloud hosting & infrastructure | Google Cloud Platform (GCP) | Hosted service data, which may include personal data |
| Cloud hosting & infrastructure | Amazon Web Services (AWS) | Hosted service data, which may include personal data |
| Email delivery | SparkPost | Email addresses, message content, delivery metadata |
| Email delivery | Mailchimp | Email addresses, subscription preferences, campaign metadata |
| Payment processing | Stripe | Billing contact details and transaction metadata |
| Payment processing | PayPal | Billing contact details and transaction metadata |
| Analytics | Google Analytics | Usage data, IP address, device and browser information |
| Analytics | Mixpanel | Usage and interaction data, identifiers |
| Analytics | Hotjar | Usage data, interaction data, device information |
| Customer support | Intercom | Contact details, support communications, usage metadata |
| SMS delivery | Twilio | Telephone numbers, message delivery metadata |
| Status communications | Atlassian Statuspage | Service status communications data |
This list is current as at the date of this DPA and may be updated from time to time in accordance with Section 5. The Processor will provide notice of intended additions or replacements of sub-processors as described in Section 5.
The Processor shall ensure that any sub-processors are subject to contractual obligations no less protective than those set out in this DPA, in accordance with Article 28(4) GDPR.
Find out everything you need to know in our new uptime monitoring whitepaper 2021