Data processing agreement

When you use Vitrina Engine you decide what to monitor and what to put into it, so for that content you are the controller and we are your processor. This sets out how we handle it. It applies to every customer automatically — nothing needs signing for it to bind us — and we will sign a copy if your own process requires one. Write to privacy@vitrinaengine.com.

It sits alongside the privacy policy, which covers the data we hold as controller: your account, your billing, your sign-in. Two different roles, deliberately kept apart.

1. What we process, and why

Subject matter and purpose. Providing the monitoring, alerting, status page and error tracking described in the terms, and nothing else.

Duration. While your account is open, plus the retention periods in section 7.

Categories of data subject. Your team members who use the product; people who subscribe to a status page you publish; and any individual whose personal data appears in what you send us.

Types of personal data. In practice:

  • Email addresses of status page subscribers, and the fact that they subscribed.
  • Whatever is inside a monitor’s configuration — a request header or body you set, which may contain credentials or identifiers.
  • Error events sent by your applications. These are the ones worth thinking about: a stack trace, its context and its breadcrumbs can carry user identifiers, email addresses or request contents, depending on what your code passes to the SDK. We do not inspect them and cannot know in advance what they contain.
  • Notification destinations you configure — addresses, webhook URLs, chat IDs, phone numbers.

2. We act only on your instructions

We process this data to provide the service, to keep it secure, and where a law we are subject to requires otherwise — in which case we tell you first, unless that law forbids it. Using your content to train models, to build a profile, or for our own analytics is not something we do and not something this agreement permits.

If an instruction from you appears to breach data protection law, we will say so rather than quietly comply.

3. Confidentiality

Access is limited to the people who need it to run the service, each under a duty of confidentiality. Administrative access to production is a small number of people, and every configuration change made through the product is written to an audit log you can read.

4. Security

The measures we take under Article 32, stated specifically rather than as a list of adjectives:

  • Everything in transit is encrypted, including the link between our own servers.
  • Credentials you store — a webhook signing secret, an SMTP password, a Twilio token — are sealed with AES-256-GCM under a key held separately from the database.
  • Backups are encrypted before they leave the server, to a key held on none of them. A copy of a machine, or of the backup bucket, is not a copy of your data.
  • Tenancy is enforced in code on every read and write, and a cross-tenant reference answers “not found” rather than “forbidden” so it cannot be used to discover whether a record exists.
  • Checks whose configuration could contain personal data run only from inside the EEA. Enforced by the scheduler and tested against a real database on every build.
  • Backups are restored and verified on a schedule rather than assumed to work.

5. Sub-processors

You give us general authorisation to use the sub-processors on the sub-processor page, which names each one, what it does, where it processes and on what basis. We impose the same obligations on them that we take on here, and we remain responsible to you for what they do.

Before adding or replacing one we will update that page and give you reasonable notice. If you object on reasonable data protection grounds, tell us: we will either find another route or you may terminate the affected part of the service.

6. Helping you meet your own obligations

Data subject requests. The product lets you read, export, correct and delete the content you hold in it. Where you need more than it provides, we will help you within the time you have to answer. If a request reaches us directly we will not answer it on your behalf — we will pass it to you.

Breach notification. If we become aware of a personal data breach affecting your data we will tell you without undue delay, with what we know and what we are doing, and keep telling you as we learn more. We will not wait until we have a complete picture.

Assessments. We will give you what you reasonably need for a data protection impact assessment or a prior consultation.

7. Deletion and return

You can export your data through the product at any time. When your account closes we delete it, except where a law requires us to keep something — billing records, for instance. Monitoring history is deleted on its retention schedule while the account is open as well: the check results behind a 90-day uptime figure do not live for ever.

Backups age out on their own schedule and are encrypted throughout.

8. Audit

We will give you the information needed to demonstrate compliance with this agreement and allow an audit where the law entitles you to one. Most reviews are satisfied by this page, the sub-processor list and answers in writing, and we would rather answer a hard question directly than send a certificate that does not address it.

9. International transfers

Your data is stored and processed in the European Union. The servers holding it, the database, the backups, and the email that leaves it are all inside the EEA.

Infinity Curve LLC is established in Georgia and administers the service from there. Our own staff therefore access personal data from outside the EEA, which is an international transfer even though the data is stored in the EU. We would rather say that plainly than let the sentence about EU servers imply something it does not.

For controllers in the EEA that transfer is made under the European Commission’s standard contractual clauses, Module Two (controller to processor), incorporated into this agreement with you as data exporter and us as data importer; the descriptions in sections 1, 4 and 5 serve as their Annexes. For controllers in the UK the same clauses apply as amended by the UK International Data Transfer Addendum. Ask and we will send a signed copy.

For your own transfer impact assessment, the relevant facts about Georgia: it has no European Commission adequacy decision, which is why the clauses above are needed. It is a member of the Council of Europe and has ratified Convention 108 and its modernising protocol, it has a domestic personal data protection law modelled on the GDPR, and it has an independent supervisory authority — the Personal Data Protection Service — that people can complain to. None of that is adequacy, and we are not going to present it as though it were; it is the material a reviewer would otherwise have to go and find.

Checks against your systems run from several countries, some outside the EEA. Where a check’s configuration could contain personal data it runs only inside the EEA, and that restriction is enforced rather than promised.

10. Order of precedence

Where this agreement and the terms conflict on the handling of personal data, this agreement wins. Where this agreement and the standard contractual clauses conflict, the clauses win.

Questions, or a signed copy: privacy@vitrinaengine.com.

Last updated 31 August 2026.