Data processing agreement
The GDPR processor terms that apply whenever we handle personal data on your behalf. No signature needed.
Last updated 2026-09-14
This agreement applies whenever Pinger processes personal data on your behalf. It forms part of the Terms of service and takes effect when you create an account — there is nothing to sign and nothing to request.
You are the controller. You decide what to monitor and what to configure. Apostrof SRL is the processor, acting on your instructions.
Where we process data about you — your name, your billing details, how you use the service — we are the controller ourselves, and the Privacy policy covers that.
What we process for you
| Subject matter | Monitoring the endpoints you nominate, and notifying the people you nominate |
| Duration | For as long as your account exists, plus the retention windows below |
| Nature and purpose | Fetching URLs on a schedule, recording the responses, evaluating your assertions, opening incidents and delivering alerts |
| Types of personal data | Whatever your configuration causes us to record: names and email addresses of the people you alert; anything personal that appears in a response body, header, URL or certificate you monitor |
| Categories of data subject | Your colleagues and anyone you add as an alert recipient; any individual whose data appears in a monitored response |
You choose what we see. Pinger records what an endpoint returns. If you point a monitor at a URL whose response contains personal data, we store that response for the retention window below. If you would rather we did not, monitor an endpoint that does not return it — a health check rather than a live page — or use assertions against a status code rather than body content.
Special-category data (health, biometrics, political opinion and the rest of Article 9) must not be put into Pinger. The service is not designed for it and is not assessed for it.
Our obligations
We will:
- process personal data only on your documented instructions, which are the configuration in your account and anything you send us in writing, unless the law requires otherwise — in which case we will tell you first unless the law forbids that too;
- make sure everyone with access is bound by confidentiality;
- keep the security measures set out below;
- use subprocessors only as described in the next section;
- help you respond to data-subject requests, using the tools in the product and, where those are not enough, by hand;
- help you with impact assessments and with breach notification, given the information we hold;
- notify you without undue delay after becoming aware of a personal-data breach affecting your data, with what we know and what we are doing about it;
- on termination, delete your data — see How long we keep it — or return it, if you ask before deletion happens;
- give you the information you need to demonstrate we are meeting these obligations, and allow an audit no more than once a year on reasonable notice, or after a breach.
Subprocessors
You give general authorisation for the subprocessors below. Each is bound by terms no less protective than these.
| Subprocessor | What they do | Where they process |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing, subscription billing and tax determination | Ireland (EU), with onward transfers to the United States under Stripe's standard contractual clauses |
| [TO BE COMPLETED] | Application hosting, database storage and backups | [TO BE COMPLETED] |
| [TO BE COMPLETED] | Delivery of alert, billing and account email | [TO BE COMPLETED] |
| Oblio Software SRL | Issuing fiscal invoices and filing them with the Romanian e-Factura system | Romania (EU) |
We will give you notice before adding or replacing a subprocessor. If you object on reasonable data-protection grounds, you may terminate the affected part of the service and we will refund the unused portion of anything you have already paid.
Security measures
- Data in transit is encrypted with TLS. Data at rest is encrypted at the storage layer.
- Monitor credentials (
auth_config) and notification channel configuration are encrypted by the application before they are stored. They are never logged, never returned to a browser, and never included in an error message. - Every account-owned record carries an account identifier. The application limits every query to the signed-in account automatically, rather than relying on each feature to remember to, and automated tests check that one account cannot reach another's records. This separation is enforced by the application; the database keeps records tied to their account but does not itself separate one customer from another.
- Access to production is limited to named individuals, requires multi-factor authentication, and is logged.
- Backups are encrypted and access to them is separately controlled.
- Outbound requests are validated before every fetch and re-validated after every redirect, so a monitor cannot be used to reach a system it was not pointed at.
- Changes are reviewed and covered by an automated test suite before they reach production.
Where we process
Inside the European Economic Area. Where a subprocessor transfers data outside it, that transfer is covered by the European Commission's standard contractual clauses, and the table above says which subprocessors those are.
How long we keep it
- Raw check results — shown for 90 days and deleted at most 122 days after they were recorded. They are stored in month-long partitions, and a partition is dropped once the newest result in it is past 90 days.
- Aggregated daily figures — kept indefinitely; they contain no response content.
- Configuration, incidents and notification history — while the account exists.
- After account deletion — removed within 30 days, including from backups.
Records we are legally required to keep — invoices and accounting documents — are retained for 10 years under Romanian accounting law. Those contain your billing details, not your monitoring data.
Liability
Liability under this agreement is subject to the limits in the Terms of service.
Contact
Data protection questions go to office@apostrof.ro. Suspected security issues go to office@apostrof.ro.