Trust

Data processing agreement

Template that governs how MonitoraWeb processes personal data on behalf of its customers. Ask us for a signed copy with your company details.

This is a template, not legal advice. Before signing, have it reviewed by your lawyer: the final text may need changes for your jurisdiction and your industry.

1. Parties and purpose

The customer (the controller) decides what personal data is processed and why. MonitoraWeb (the processor) processes it only to provide the monitoring service the customer contracted, following the customer's documented instructions. Using the service is such an instruction.

2. What data is processed

  • Account data: name, email address, language, time zone, billing details.
  • Service data: the addresses monitored, check results, incidents, alert channels (email addresses, phone numbers, webhook URLs) and the technical metadata of the monitored sites.
  • Usage data: sign-in dates, IP address of the session, and the audit log of intrusive checks.
  • We do not process special categories of data, and the service is not meant to receive any.

3. How long it is kept

  • Checks and incidents: as long as the plan's retention says, and then deleted automatically every night.
  • Anonymous X-ray reports: 30 days.
  • Account data: while the account exists. On deletion, personal data is removed and only what tax law requires is kept (invoices).

4. Security measures

The measures in force are listed, and kept up to date, on the security page: https://monitoraweb.com/seguridad

5. Subprocessors

SubprocessorWhat forWhere
Contabo GmbHHosting of the application and the databaseGermany (servers in the United States)
Email delivery providerTransactional email: alerts, reports, confirmationsUnited States
Cloudflare, Inc.DNS and protection of our own domainUnited States
Payment processors (PayPal, Culqi)Billing. They receive only what a payment needs; we never see card numbersUnited States / Peru

We tell customers before adding or replacing a subprocessor, and they may object.

6. Rights of data subjects

The customer can export and delete their data from the panel at any time. If a data subject writes to us directly, we forward the request to the customer and help them answer it.

7. Data breaches

If we suffer a breach affecting the customer's data, we notify them without undue delay and in any case within 72 hours of becoming aware, with what we know, what we are doing and what they should do.

8. Confidentiality and staff

Everyone with access to the systems is bound by confidentiality and only sees what their work requires.

9. Audits

We answer reasonable questionnaires and give the documentation needed to show compliance. On-site audits are agreed in advance and paid by the requester.

10. End of the contract

When the contract ends, the customer may export their data. Thirty days later we delete it, except what the law requires us to keep.

11. Applicable law

Peruvian law on personal data protection (Law 29733 and its regulations) applies. For customers in the European Union, the standard clauses of the GDPR apply to the processing described here.

Template version of 2026-09-14. Contact: https://monitoraweb.com/contact