GDPR · UK GDPR · CCPA

    Data Processing Agreement

    Version 2.0 · Effective: July 10, 2026

    Opens your browser's print dialog — choose "Save as PDF".

    No signature required

    This DPA is incorporated by reference into the Terms of Service and takes effect automatically when the Customer accepts those terms. Customers who require a countersigned copy on Xitoring letterhead can request one through our contact form.

    This Data Processing Agreement ("DPA") forms part of the Terms of Service between Xitoring, LLC ("Xitoring", "Processor") and the customer entity that has accepted those terms ("Customer", "Controller"). It governs Xitoring's processing of Personal Data on the Customer's behalf and reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA").

    1. Definitions and Interpretation

    Capitalised terms not defined in this DPA have the meaning given to them in the Terms of Service. In this DPA:

    • "Applicable Data Protection Law" means all privacy and data protection laws and regulations applicable to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the CCPA and the other United States state privacy laws in force from time to time, and any other privacy or data protection law applicable to either party in respect of the processing carried out under this DPA, in each case as amended, superseded or replaced.
    • "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.
    • "Customer Personal Data" means Personal Data that Xitoring processes on the Customer's behalf in the course of providing the Services, as further described in Annex I.
    • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
    • "Services" means the Xitoring infrastructure and uptime monitoring platform, including the Xitogent agent, alerting and notification delivery, status pages, dashboards, APIs, and associated support.
    • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
    • "Sub-processor" means any third party engaged by Xitoring to process Customer Personal Data in connection with the Services.

    2. Scope and Roles of the Parties

    The parties acknowledge that, with respect to Customer Personal Data, the Customer acts as Controller and Xitoring acts as Processor. Where the Customer is itself acting as a processor on behalf of a third-party controller, Xitoring acts as a sub-processor and the Customer warrants that it has the authority of that controller to enter into this DPA.

    Xitoring acts as an independent Controller in respect of data it processes for its own legitimate business purposes — account administration, billing and invoicing, service security and abuse prevention, and aggregated product analytics. That processing is governed by the Xitoring Privacy Policy rather than this DPA.

    This DPA applies to the entire term during which Xitoring processes Customer Personal Data, and survives termination of the Terms of Service until all Customer Personal Data has been returned or deleted in accordance with Section 11.

    3. Processing of Customer Personal Data

    Xitoring processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers of Customer Personal Data to a third country, unless required to do so by Union or Member State law to which Xitoring is subject. In that case Xitoring will inform the Customer of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

    The Customer's documented instructions consist of: (a) this DPA and the Terms of Service; (b) the Customer's configuration and use of the Services, including the monitoring checks, alert rules, notification channels, integrations, and team members it configures; and (c) any further written instructions agreed between the parties.

    Xitoring will immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Xitoring is not obliged to carry out an instruction it reasonably believes to be unlawful, and may suspend the affected processing until the instruction is confirmed, amended, or withdrawn.

    Xitoring will not sell, rent, or otherwise disclose Customer Personal Data to any third party, and will not use Customer Personal Data for its own marketing, profiling, or advertising purposes, or to train machine learning models made available outside the Customer's own account.

    The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.

    4. Customer Obligations

    The Customer is responsible for the accuracy, quality and legality of Customer Personal Data, for the means by which it acquired that data, and for establishing a valid legal basis under Applicable Data Protection Law for the processing carried out under this DPA.

    The Customer is responsible for providing any notices to, and obtaining any consents from, Data Subjects that are required for Xitoring to process Customer Personal Data as contemplated by this DPA.

    The Services are designed to process infrastructure telemetry and the contact details of the Customer's own personnel. The Customer must not upload, submit, or configure the Services to collect special categories of Personal Data within the meaning of Article 9 GDPR, data relating to criminal convictions and offences, payment card numbers, government identification numbers, or the Personal Data of children under 16. Xitoring's security measures are not designed for these data types and the Customer bears the risk of submitting them.

    The Customer is responsible for managing access to its account, including the provisioning and de-provisioning of team members, the use of strong authentication, and the safeguarding of API tokens and agent keys.

    5. Confidentiality

    Xitoring treats all Customer Personal Data as confidential information. Xitoring ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality under a written agreement, or are under an appropriate statutory obligation of confidentiality, and that this obligation survives the termination of their engagement.

    Access to Customer Personal Data is limited to personnel who require it to perform their duties in providing, securing or supporting the Services. Access is granted on a least-privilege basis, reviewed periodically, and revoked promptly on role change or departure.

    Xitoring personnel receive data protection and information security training at onboarding and periodically thereafter.

    6. Security Measures

    Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, Xitoring implements and maintains the technical and organisational measures set out in Annex II to ensure a level of security appropriate to that risk.

    Xitoring may update the measures in Annex II from time to time, provided that any update does not materially reduce the overall level of security afforded to Customer Personal Data.

    The Customer is responsible for independently determining whether the measures in Annex II meet its own requirements and regulatory obligations, and for securing the components under its control — including the servers on which the Xitogent agent is installed, the credentials it supplies to Xitoring, and the third-party notification channels it configures.

    7. Sub-processors

    The Customer grants Xitoring general authorisation to engage Sub-processors for the provision of the Services. The Sub-processors engaged as at the effective date of this DPA are listed in Annex III.

    Xitoring will give the Customer at least thirty (30) days' prior notice of the addition or replacement of any Sub-processor, by email to the account's registered administrative contact. The Customer may object to a proposed change on reasonable data protection grounds by notifying Xitoring in writing within that notice period.

    If the Customer objects and the parties cannot agree a resolution within thirty (30) days of the objection, the Customer may terminate the affected Services on written notice and receive a pro-rata refund of any prepaid fees covering the period after termination. This is the Customer's sole remedy in respect of such an objection.

    Xitoring imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those set out in this DPA. Xitoring remains fully liable to the Customer for the performance of each Sub-processor's obligations.

    8. Data Subject Rights

    The Services provide the Customer with self-service controls to access, correct, export and delete Customer Personal Data held in its account, which in most cases will allow the Customer to respond to Data Subject requests without Xitoring's involvement.

    Taking into account the nature of the processing, Xitoring will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III of the GDPR.

    If Xitoring receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond to that request other than to acknowledge receipt and direct the Data Subject to the Customer, unless legally required to do otherwise. Xitoring will notify the Customer of the request without undue delay.

    9. Personal Data Breach Notification

    Xitoring will notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice is given to the account's registered administrative contact.

    The notification will describe, to the extent known at the time and supplemented as further information becomes available:

    • the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
    • the likely consequences of the Personal Data Breach;
    • the measures taken or proposed to be taken to address the breach and mitigate its possible adverse effects; and
    • the name and contact details of the Xitoring point of contact for further information.

    Xitoring will cooperate with the Customer and take such reasonable steps as are directed by the Customer to assist in the investigation, mitigation and remediation of the Personal Data Breach, including as necessary to allow the Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects.

    Xitoring's notification of, or response to, a Personal Data Breach is not an acknowledgement by Xitoring of any fault or liability in respect of that breach.

    10. Data Protection Impact Assessments

    Taking into account the nature of the processing and the information available to it, Xitoring will provide reasonable assistance to the Customer in carrying out data protection impact assessments under Article 35 GDPR and in prior consultations with Supervisory Authorities under Article 36 GDPR, where such assessment or consultation relates to the processing of Customer Personal Data under this DPA.

    Xitoring may charge a reasonable fee for assistance that goes materially beyond the provision of its standard documentation, security information and completed questionnaires.

    11. Return and Deletion of Customer Personal Data

    The Customer may export Customer Personal Data from the Services at any time during the term using the export functionality and APIs made available within the platform.

    On termination or expiry of the Services, Xitoring will delete all Customer Personal Data within thirty (30) days, unless the Customer requests its return within that period, or Union or Member State law requires continued storage. Backup copies are deleted in accordance with Xitoring's documented backup rotation schedule, and in any event within ninety (90) days of termination.

    Where Xitoring is required to retain Customer Personal Data by law — for example, billing records retained for tax and accounting purposes — it will isolate that data, protect it from further processing beyond the purpose of the legal requirement, and delete it once the retention period expires.

    Xitoring will certify deletion in writing on the Customer's reasonable written request.

    12. Audits and Certifications

    Xitoring makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

    To satisfy this obligation, Xitoring will in the first instance make available its security documentation, architecture and data flow descriptions, penetration test summaries, and responses to reasonable security questionnaires.

    Xitoring does not currently hold a SOC 2 or ISO/IEC 27001 certification, and makes no representation that it does. Xitoring commissions independent penetration testing of the Services and will make a summary of the most recent report available to the Customer on request, subject to a non-disclosure agreement. If Xitoring obtains a third-party audit report or certification covering the Services, it will make that report or certificate available on request, and it will serve as the primary evidence of compliance under this Section to the extent it covers the scope of the Customer's enquiry.

    If that documentation is not sufficient to demonstrate compliance, the Customer may request an on-site or remote audit no more than once in any twelve (12) month period, on at least thirty (30) days' prior written notice, conducted during normal business hours, subject to confidentiality obligations, and carried out in a manner that does not disrupt Xitoring's operations or compromise the security or confidentiality of other customers' data. An additional audit may be requested where required by a Supervisory Authority or following a confirmed Personal Data Breach affecting the Customer.

    The Customer bears the costs of any audit it requests, including Xitoring's reasonable costs of participation. Xitoring bears its own costs where the audit follows a Personal Data Breach arising from Xitoring's breach of this DPA, or where the audit identifies a material failure by Xitoring to comply with its obligations under this DPA.

    13. International Data Transfers

    Xitoring operates monitoring infrastructure in multiple regions worldwide, and Customer Personal Data may therefore be processed outside the country in which the Customer is established, including in the United States.

    Regional data residency is not a standard feature of the Services. Where a Customer on an Enterprise plan requires Customer Personal Data to be stored and processed within a defined region, the parties may record that requirement in a written addendum to this DPA specifying the region, the components of the Services in scope, and any resulting changes to the Services or the fees. Absent such an addendum, processing takes place in the regions described in Annex III.

    Where Xitoring transfers Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to a country that has not been the subject of an adequacy decision, that transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference on the following basis:

    • Module Two (Controller to Processor) applies where the Customer is a Controller, and Module Three (Processor to Processor) applies where the Customer is itself a processor;
    • in Clause 7, the optional docking clause applies;
    • in Clause 9, Option 2 (general written authorisation) applies, with a notice period of thirty (30) days as set out in Section 7 of this DPA;
    • in Clause 11, the optional independent dispute resolution language does not apply;
    • in Clause 17, the Clauses are governed by the law of Ireland;
    • in Clause 18(b), disputes are resolved before the courts of Ireland;
    • Annexes I, II and III to this DPA populate Annexes I, II and III to the Standard Contractual Clauses respectively.

    For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies, with the information required by Part 1 of that Addendum drawn from this DPA and its Annexes. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

    Xitoring will conduct a transfer impact assessment where required and will notify the Customer if it becomes unable to comply with the Standard Contractual Clauses.

    14. Government and Law Enforcement Access Requests

    Xitoring has not created, and will not create, any backdoor or programmatic means of circumventing the security measures protecting Customer Personal Data, and does not grant any government, law enforcement or intelligence authority direct, blanket, unrestricted or unmediated access to Customer Personal Data or to the systems on which it is held.

    If Xitoring receives a legally binding request from a public authority for the disclosure of Customer Personal Data, it will notify the Customer without undue delay so that the Customer can seek protective relief, unless it is prohibited from doing so by law. Where notification is prohibited, Xitoring will use reasonable efforts to obtain a waiver of that prohibition, will document the efforts it made so that it can demonstrate them to the Customer, and will provide the information to the Customer as soon as it is lawfully able.

    Xitoring will review the lawfulness of each request and will challenge it, including by pursuing available avenues of appeal, where it considers the request to be unlawful, overbroad, or inconsistent with Applicable Data Protection Law. Where a request is valid and binding and no challenge succeeds, Xitoring will disclose only the minimum amount of Customer Personal Data necessary to respond to it.

    Xitoring maintains a record of the government and law enforcement requests it receives. On the Customer's written request, and to the extent it is lawfully permitted to do so, Xitoring will confirm whether it has received any request relating to that Customer's Personal Data.

    This Section supplements, and does not limit, Clause 15 of the Standard Contractual Clauses where those Clauses apply to a transfer under Section 13.

    15. California Consumer Privacy Act Addendum

    This Section applies where Xitoring processes Personal Information (as defined in the CCPA) on behalf of a Customer that is a "business" under the CCPA. In that context, Xitoring acts as a "service provider".

    Xitoring will:

    • not sell or share Personal Information as those terms are defined in the CCPA;
    • not retain, use or disclose Personal Information for any purpose other than performing the Services specified in the Terms of Service, or as otherwise permitted by the CCPA;
    • not retain, use or disclose Personal Information outside the direct business relationship between Xitoring and the Customer;
    • not combine Personal Information received from the Customer with Personal Information received from or on behalf of any other party, except as permitted by the CCPA;
    • comply with the obligations applicable to service providers under the CCPA and provide the same level of privacy protection as the CCPA requires of the Customer; and
    • notify the Customer if it determines that it can no longer meet these obligations.

    The Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Information by Xitoring, and has the right, on notice, to take such steps under Section 12 of this DPA.

    16. Liability, Term and Order of Precedence

    Each party's liability arising out of or in connection with this DPA is limited, in aggregate, to the total fees paid or payable by the Customer for the Services in the twelve (12) months preceding the event giving rise to the claim. Claims under this DPA count towards, and do not increase, that limit, so that a party's total combined liability under this DPA and the Terms of Service taken together does not exceed it.

    The limitation in this Section does not apply to:

    • either party's liability to a Data Subject under the third-party beneficiary provisions of the Standard Contractual Clauses;
    • any liability that cannot be limited or excluded under Applicable Data Protection Law; or
    • a party's fraud or wilful misconduct.

    This DPA takes effect on the date the Customer accepts the Terms of Service and continues for as long as Xitoring processes Customer Personal Data.

    In the event of a conflict, the following order of precedence applies: (1) the Standard Contractual Clauses; (2) this DPA; (3) the Terms of Service; (4) any other agreement between the parties relating to the Services.

    Except as amended by this DPA, the Terms of Service remain in full force and effect. If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect.

    Xitoring may update this DPA to reflect changes in Applicable Data Protection Law, the Services, or its Sub-processors, provided that no update materially reduces the protections afforded to Customer Personal Data. Material changes will be notified to the account's registered administrative contact at least thirty (30) days before they take effect.

    17. Contact

    Data protection enquiries, Data Subject request assistance, security questionnaires and requests for a countersigned copy of this DPA should be directed to:

    Xitoring will appoint a representative in the European Union under Article 27 GDPR and a representative in the United Kingdom under Article 27 UK GDPR, and will publish the name and contact details of each on this page once appointed. Until then, enquiries from Data Subjects and Supervisory Authorities in those territories should be directed to the contact details above, and Xitoring will respond to them directly.

    Annexes

    Annex I — Details of the Processing

    A. List of Parties

    RolePartyContact
    Data Exporter / ControllerThe Customer entity that accepted the Xitoring Terms of ServiceThe administrative contact registered on the Customer's Xitoring account
    Data Importer / ProcessorXitoring, LLC (Delaware, United States)hello@xitoring.com

    B. Description of the Processing

    ItemDescription
    Subject matterProvision of the Xitoring infrastructure and uptime monitoring platform, including server and website monitoring, SSL and cron job monitoring, alerting, status pages and dashboards.
    Nature of the processingCollection, recording, organisation, structuring, storage, retrieval, analysis, transmission, display, erasure and destruction of Customer Personal Data, by automated means, for the purpose of delivering the Services.
    Purpose of the processingMonitoring the availability and performance of the Customer's infrastructure; generating and delivering alerts and notifications to the Customer's designated recipients; producing dashboards, reports and status pages; and providing technical support.
    Categories of Data SubjectsThe Customer's employees, contractors and other authorised users of the Customer's account; the Customer's designated alert and notification recipients; and, where the Customer configures status page subscriptions, the subscribers to those pages.
    Categories of Personal DataIdentification and contact data (name, email address, telephone number for SMS and voice alerts, job role, account username); account and authentication data (hashed credentials, multi-factor settings, API tokens, session and login records); usage and audit data (IP address, browser and device information, timestamps, actions taken in the platform); communication data (support correspondence); and any Personal Data incidentally contained in monitoring configuration or telemetry submitted by the Customer, such as hostnames, URLs, process names or log excerpts.
    Special categories of dataNone. The Services are not intended for, and the Customer must not submit, special categories of Personal Data within the meaning of Article 9 GDPR.
    Frequency of the transferContinuous, for the duration of the Services.
    Duration of the processingFor the term of the Terms of Service, plus the retention and deletion periods set out in Section 11 of this DPA.
    Sub-processorsAs set out in Annex III, for the duration and purposes stated there.

    C. Competent Supervisory Authority

    Where the Standard Contractual Clauses apply, the competent Supervisory Authority is the authority of the EEA Member State in which the Data Exporter is established. Where the Data Exporter is not established in the EEA but has appointed a representative under Article 27 GDPR, it is the authority of the Member State in which that representative is established.

    D. Retention Periods

    The following retention periods apply while the Services are being provided. On termination or expiry, all Customer Personal Data is deleted in accordance with Section 11 regardless of the periods below.

    Data categoryRetention period
    Monitoring check results, metrics and telemetryOne (1) month on the Free plan; one (1) year on all paid plans; for the life of the account on Enterprise. Deletion on termination follows Section 11 in every case.
    Account, profile and monitoring configuration dataRetained for the term of the Customer's account, then deleted in accordance with Section 11.
    Authentication, session and login recordsRetained for the term of the Customer's account, then deleted in accordance with Section 11.
    Security and administrative audit logsRetained for ninety (90) days, and protected against unauthorised modification throughout that period.
    Support correspondenceRetained for one (1) year from the close of the correspondence.
    Billing, invoicing and tax recordsRetained for the period required by applicable tax, accounting and company law, and isolated from further processing in accordance with Section 11.

    Xitoring confirms these retention periods in responses to security questionnaires.

    Annex II — Technical and Organisational Measures

    Xitoring maintains the following measures to ensure a level of security appropriate to the risk. These measures apply to the systems Xitoring operates in providing the Services.

    AreaMeasures
    Encryption in transitTLS 1.2 or higher for all connections between customers, monitoring agents, monitoring nodes and the Xitoring platform. Modern cipher suites only; deprecated protocols disabled. HSTS enforced on web endpoints.
    Encryption at restAES-256 full-disk encryption on servers storing Customer Personal Data. Credentials are stored using salted, computationally expensive one-way hashes; API tokens and integration secrets are stored encrypted.
    Access controlRole-based access control with least-privilege provisioning. Administrative access requires multi-factor authentication and is restricted to named personnel. Access rights are reviewed periodically and revoked promptly on role change or departure.
    Authentication (customer-facing)Password complexity enforcement, optional multi-factor authentication, session expiry and revocation, team roles and per-user permissions, and scoped API tokens that can be rotated or revoked by the Customer at any time.
    Network securitySegmented network architecture, firewalling and default-deny ingress rules, DDoS mitigation at the network edge, and continuous monitoring of the Xitoring platform by the Xitoring platform itself.
    Logging and auditCentralised, time-synchronised logging of administrative and security-relevant events, retained for the period set out in Annex I and protected against unauthorised modification. Customer-visible audit trails of account activity.
    Pseudonymisation and minimisationThe Services collect infrastructure telemetry and the contact details required to deliver alerts. Data collection is limited to what is necessary for the configured checks and notification channels.
    Resilience and availabilityRedundant, geographically distributed monitoring nodes; automated failover; capacity monitoring; and documented business continuity and disaster recovery procedures.
    BackupsEncrypted, regularly scheduled backups of production data, stored separately from primary systems, with periodic restoration testing and a documented rotation and destruction schedule.
    Secure developmentVersion-controlled change management, peer review of code changes, separation of development, staging and production environments, dependency vulnerability scanning, and security testing prior to release.
    Vulnerability managementRegular patching of operating systems and application dependencies, periodic vulnerability scanning, and penetration testing with remediation tracked to closure.
    Incident responseDocumented incident response plan covering detection, triage, containment, eradication, recovery and post-incident review, with defined escalation paths and the customer notification process set out in Section 9.
    Physical securityProduction systems are hosted in datacenter facilities operating industry-standard physical access controls, including 24/7 staffing or surveillance, access logging, and environmental protection against fire and power loss.
    PersonnelConfidentiality undertakings for all personnel with access to Customer Personal Data, background screening where lawful and appropriate, and data protection and security awareness training at onboarding and periodically thereafter.
    Sub-processor governanceDue diligence prior to engagement, written data protection terms no less protective than this DPA, and periodic review of each Sub-processor's security posture.
    Deletion and disposalDocumented procedures for the deletion of Customer Personal Data on termination, including from backups, and for the secure destruction or wiping of decommissioned storage media.
    Certifications and assuranceXitoring does not currently hold a SOC 2 or ISO/IEC 27001 certification. Independent penetration testing is commissioned and summary reports are made available under a non-disclosure agreement, as set out in Section 12.

    Annex III — Approved Sub-processors

    The following Sub-processors are authorised to process Customer Personal Data in connection with the Services. This list was last updated on July 10, 2026. Additions and replacements are notified in accordance with Section 7.

    Sub-processorPurpose of processingLocation of processing
    Stripe, Inc.Payment processing, subscription billing and invoicing. Receives billing contact and transaction data; Xitoring does not store payment card numbers.United States and European Economic Area
    Microsoft Corporation (Microsoft Azure)Hosting of the Xitoring platform. Does not access Customer Personal Data in the ordinary course; data is encrypted at rest and in transit.Multiple regions worldwide
    Leaseweb Global B.V. (Amsterdam, Netherlands)Hosting of the Xitoring platform and operation of the monitoring node network. Does not access Customer Personal Data in the ordinary course; data is encrypted at rest and in transit.European Economic Area and other regions worldwide
    Hivelocity, Inc. (Tampa, Florida, United States)Operation of the monitoring node network. Does not access Customer Personal Data in the ordinary course; data is encrypted at rest and in transit.United States and other regions worldwide
    Twilio Inc. (Twilio SendGrid)Delivery of transactional messages and monitoring alerts by email to the recipients configured by the Customer. Receives recipient email address and message content.United States and European Economic Area
    MessageBird B.V. (Amsterdam, Netherlands)Delivery of monitoring alerts by SMS to the recipients configured by the Customer. Receives recipient telephone number and message content.European Economic Area and other regions worldwide

    A current list of monitoring node locations is published at https://xitoring.com/monitoring-nodes. To register one or more additional recipients for Sub-processor change notices, or to request notification of changes to the monitoring node list, email hello@xitoring.com.

    Third-party services that the Customer chooses to connect to its account — such as Slack, Microsoft Teams, PagerDuty, Telegram, Discord, or webhook endpoints operated by the Customer — are not Xitoring Sub-processors. Where the Customer configures such an integration, it instructs Xitoring to transmit data to that service, and the Customer's relationship with that service is governed by its own terms.

    Need a countersigned copy? We'll send one over.

    Procurement or legal team requires an executed DPA, a security questionnaire, or our Standard Contractual Clauses on file? Get in touch and we'll turn it around.