Last updated: August 19, 2026
This Data Processing Agreement (DPA) applies automatically to every AlertKick customer whose use of the service involves personal data. It is incorporated into the Terms of Service; you do not need to sign anything. If your procurement process needs a countersigned copy, email privacy [at] alertkick [dot] com and we will send one.
This DPA is between AlertKick Ltd (company number 17201100, 25 Watery Lane, Northolt, UB5 6QL, United Kingdom) ("AlertKick", "we") and the customer that has accepted the Terms of Service ("Customer", "you"). It governs the processing of personal data contained in Customer Data by AlertKick on the Customer's behalf in the course of providing the Service.
"Data Protection Law" means all laws that apply to the processing of personal data under this DPA, including the UK GDPR and the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), and, where applicable, US state privacy laws. "Personal data", "processing", "controller", "processor", "data subject", "personal data breach", and "supervisory authority" have the meanings given in the UK GDPR and EU GDPR. "Customer Personal Data" means personal data within Customer Data. Other capitalised terms have the meaning given in the Terms of Service.
For Customer Personal Data, the Customer is the controller (or a processor acting on behalf of its own controller customers, in which case it warrants it has authority to appoint AlertKick as a sub-processor on these terms) and AlertKick is the processor. Each party will comply with its obligations under Data Protection Law.
The Customer is responsible for the lawfulness of the Customer Personal Data it sends to the Service, including having a lawful basis, providing notices to and obtaining any necessary consents from the individuals whose activity is monitored (for example staff and contractors who access monitored servers), and deciding which hosts, events, and integrations to connect.
AlertKick is an independent controller of the account, billing, and usage data it collects about Customer's users and of its own business records; that processing is described in the Privacy Policy and is outside this DPA.
AlertKick will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by law to which AlertKick is subject, in which case AlertKick will inform the Customer of that requirement before processing unless the law prohibits it on important grounds of public interest. The Customer's instructions are: the Terms of Service, this DPA, the configuration the Customer and its users apply in the Service (including which agents are installed, which monitors and integrations are enabled, which Automated Actions are configured, and retention settings), and any further written instructions agreed between the parties. AlertKick will tell the Customer if, in its opinion, an instruction infringes Data Protection Law; it is not obliged to carry out a legal review.
AlertKick ensures that people authorised to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory), are given access only as needed to perform their role, and receive appropriate training on data protection and security.
AlertKick implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risk to individuals. AlertKick may update those measures from time to time provided the overall level of protection is not reduced. The Customer is responsible for the security measures within its control, including user access management, credential hygiene, the systems on which the agent is installed, and the configuration of its account.
The Customer gives AlertKick general written authorisation to engage sub-processors to process Customer Personal Data. The current list, including each sub-processor's purpose and location, is published at alertkick.com/sub-processors and forms Annex III.
AlertKick will give at least 30 days' prior notice of any intended addition or replacement of a sub-processor that processes Customer Personal Data, by email to the Customer's account administrators and by updating that page. The Customer may object within that period on reasonable, documented data-protection grounds by emailing privacy [at] alertkick [dot] com . If the parties cannot resolve the objection in good faith, and AlertKick cannot reasonably offer a way to avoid the new sub-processor, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused period as its sole remedy.
AlertKick will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract, and remains fully liable to the Customer for the performance of that sub-processor's obligations.
Taking into account the nature of the processing, AlertKick will assist the Customer, through the Service's built-in features (search, export, deletion of users and hosts, account deletion) and, where those are insufficient, through reasonable further help, in responding to requests by data subjects to exercise their rights under Data Protection Law. If AlertKick receives such a request directly and can identify the Customer, it will promptly forward the request to the Customer and will not respond except to acknowledge it or direct the individual to the Customer, unless required by law.
AlertKick will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will go to the Customer's account administrators by email and will describe, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point. Information may be provided in phases as it becomes available. AlertKick will take reasonable steps to contain and remediate the breach and will cooperate with the Customer's own notification obligations. Notification is not an admission of fault.
AlertKick will provide reasonable assistance to the Customer with data protection impact assessments and prior consultation with supervisory authorities, to the extent they relate to the Service and the Customer cannot obtain the information from this DPA, the Privacy Policy, the security documentation, or the Service itself. AlertKick may charge a reasonable fee for assistance that goes materially beyond this.
During the term the Customer can export Customer Data through the Service and the API, and can delete users, hosts, events, and whole accounts itself. On termination of a paid plan AlertKick keeps Customer Data available for export for 30 days. On account deletion, or at the end of that period at the Customer's choice, AlertKick deletes Customer Personal Data from its live systems and replicas within 30 days, and from any residual system copies within 90 days, unless retention is required by law (for example billing records). Aggregated or de-identified data that does not identify any individual is not Customer Personal Data and may be retained. AlertKick will confirm deletion in writing on request.
AlertKick will make available the information reasonably necessary to demonstrate compliance with this DPA, including this DPA, the security overview, the sub-processor list, and written answers to a reasonable security questionnaire no more than once per year.
Where that is not sufficient to meet a requirement of Data Protection Law or a supervisory authority, the Customer (or an independent auditor appointed by it, bound by confidentiality and not a competitor of AlertKick) may audit AlertKick's compliance with this DPA once in any 12-month period, on at least 30 days' written notice, during normal business hours, for a scope and duration agreed in advance, in a way that does not disrupt AlertKick's business or compromise the security of other customers, and at the Customer's cost. Audits will be remote unless the parties agree otherwise. The Customer will share findings with AlertKick and keep them confidential.
Customer Data is stored in the data region the Customer selects (EU or US; see the sub-processor list for locations). AlertKick is established in the United Kingdom and may access Customer Data from the United Kingdom to operate and support the Service.
Where the processing involves a transfer of personal data that is restricted under Data Protection Law (a "Restricted Transfer"), the parties rely on, in order of preference: (a) an adequacy decision or regulations covering the destination (including the UK-EEA arrangements and, for US sub-processors certified under it, the EU-US Data Privacy Framework and its UK Extension); (b) otherwise, the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914 (Module Two, controller to processor, or Module Three where the Customer is itself a processor), and for transfers subject to UK GDPR the UK International Data Transfer Addendum issued by the Information Commissioner (together, the "SCCs"), which are incorporated by reference into this DPA and are completed as follows: the parties' details and the description of processing are those in Annex I; the security measures are those in Annex II; clause 7 (docking) is included; option 2 of clause 9(a) applies with the 30-day notice period in section 6; the optional language in clause 11(a) is not included; clause 13 is completed by the supervisory authority of the Customer's member state or, for the UK Addendum, the Information Commissioner; clause 17 and 18 select the law and courts of Ireland for EU transfers and of England and Wales for UK transfers. Where the SCCs conflict with this DPA, the SCCs prevail for the Restricted Transfer. AlertKick will ensure equivalent safeguards are in place for onward transfers to its sub-processors.
Each party's liability under this DPA is subject to the exclusions and cap in section 17 of the Terms of Service, except where Data Protection Law does not permit this. Nothing in this DPA limits the rights of data subjects under the SCCs or Data Protection Law.
This DPA takes effect when the Customer first uses the Service and lasts as long as AlertKick processes Customer Personal Data. Where it conflicts with the Terms of Service on the subject of personal data, this DPA prevails; where it conflicts with the SCCs, the SCCs prevail. AlertKick may update this DPA to reflect changes in Data Protection Law, guidance, or the Service, giving at least 30 days' notice of material changes as described in the Terms of Service; changes will not reduce the overall level of protection. This DPA is governed by the law of England and Wales, except where Data Protection Law or the SCCs require otherwise.
Data exporter / controller: the Customer, as identified in its AlertKick account, acting as controller (or as processor on behalf of its own customers).
Data importer / processor: AlertKick Ltd, 25 Watery Lane, Northolt, UB5 6QL, United Kingdom. Contact: privacy [at] alertkick [dot] com .
Provision of the AlertKick monitoring, security, alerting, incident-response, and compliance-evidence service under the Terms of Service, for the duration of the Customer's use of the Service plus the deletion periods in section 10.
Collection (via agents, pollers, and integrations), storage, analysis (including automated and AI-assisted analysis), alerting and notification, display, export, and deletion of Customer Data, and execution of Automated Actions the Customer configures, in order to monitor the availability, performance, security, and compliance posture of the Customer's systems and to notify and assist the Customer's team.
Special category data: none is intended. The Service is not designed to process special categories of personal data or data about criminal convictions; the Customer should not direct such data to it. Because log and command content is determined by the Customer's systems, incidental inclusion cannot be excluded, and the Customer is responsible for limiting it.
Continuous, for as long as agents and monitors are active. Event and metric data is retained for the period of the Customer's plan (see pricing) and then removed; account and configuration data for the life of the account; all as described in section 10 on termination.
The measures below are those in place at the date of this DPA. They will evolve; AlertKick will not reduce the overall level of protection. A plain-language overview is also on the security page.
The authorised sub-processors, their purposes, the data they process, and their locations are listed at alertkick.com/sub-processors, which is incorporated into this DPA and updated in accordance with section 6.
AlertKick Ltd
25 Watery Lane, Northolt, UB5 6QL, United Kingdom
Privacy and data protection: privacy [at] alertkick [dot] com
Security: security [at] alertkick [dot] com
Legal: legal [at] alertkick [dot] com
To request a countersigned copy of this DPA, email privacy [at] alertkick [dot] com with your account subdomain and the legal name and address of your organisation.