Watchfox

Legal & trust

Watchfox Data Processing Addendum

Data Processing Addendum for customer personal data processed by Watchfox.

Last updated: 2026-04-25

This Data Processing Addendum (“DPA”) forms part of the Watchfox Terms of Service or other written agreement between the customer (“Customer”) and Watchfox (“Watchfox”) for use of the Watchfox service.

This DPA applies when Watchfox processes personal data on behalf of Customer as a processor.


1. Parties

Customer

The legal entity or person using Watchfox for business or professional purposes and determining the purposes and means of processing Customer Personal Data.

Watchfox


2. Definitions

“Applicable Data Protection Law” means the GDPR and other data protection laws applicable to the processing of Customer Personal Data.

“Customer Personal Data” means personal data processed by Watchfox on behalf of Customer through the Watchfox service.

“Controller”, “processor”, “personal data”, “processing”, “data subject”, and “sub-processor” have the meanings given in Applicable Data Protection Law.

“Service” means the Watchfox website monitoring, alerting, reporting, status page, workspace, API, and related features.


3. Roles

For Customer Personal Data processed through the Service:

Watchfox may act as an independent controller for account administration, billing metadata, security, abuse prevention, support, legal compliance, and business operations, as described in the Watchfox Privacy Policy.


4. Subject matter and duration

Subject matter

Watchfox processes Customer Personal Data to provide the Service.

Duration

Processing continues for the duration of the customer relationship and for any retention period described in the Privacy Policy or required by law, unless earlier deletion is requested and legally/technically possible.


5. Nature and purpose of processing

Watchfox processes Customer Personal Data to:

Processing operations may include collection, storage, retrieval, organization, transmission, deletion, aggregation, and analysis required to operate the Service.


6. Categories of data subjects

Customer Personal Data may relate to:

Customer should avoid placing unnecessary personal data in Watchfox.


7. Categories of personal data

Customer Personal Data may include:

Watchfox does not intentionally store full HTTP response bodies as normal monitoring history and does not intentionally collect sensitive categories of data through normal product use.

Customer must not submit special category data, secrets, private keys, passwords, or regulated data unless explicitly agreed in writing.


8. Customer instructions

Watchfox will process Customer Personal Data only:

If Watchfox believes an instruction violates Applicable Data Protection Law, Watchfox may notify Customer.


9. Confidentiality

Watchfox will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations or appropriate statutory confidentiality duties.


10. Security measures

Watchfox will implement appropriate technical and organizational measures designed to protect Customer Personal Data, including:

Security measures may evolve as the Service develops.


11. Sub-processors

Customer authorizes Watchfox to use sub-processors to provide the Service.

Current expected sub-processors include:

ProviderPurpose
CloudflareHosting, edge routing, Workers, Pages, DNS/security, caching, rate limiting
SupabasePostgreSQL database, authentication, primary app persistence
PostmarkTransactional email and alert email delivery
PaddleMerchant of Record, subscription billing, invoices, tax/payment processing
SentryError monitoring and diagnostics

Customer-configured notification integrations, such as Slack, Microsoft Teams, Discord, Google Chat, or generic webhook endpoints, may receive alert data when Customer enables those integrations.

Watchfox may update sub-processors as needed. Material changes should be reflected in the Privacy Policy, sub-processor list, or other customer notice mechanism.


12. International transfers

Where processing involves transfers outside the EU/EEA, Watchfox will rely on appropriate safeguards where required, such as:


13. Assistance with data subject requests

Taking into account the nature of processing, Watchfox will provide reasonable assistance to Customer for data subject requests relating to Customer Personal Data.

Customer can contact [email protected] or use the in-app Contact support flow with category Privacy.

Watchfox may require verification of authority and scope before acting on deletion/export requests.


14. Assistance with security and breach obligations

Watchfox will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data, where required by Applicable Data Protection Law.

Notifications should include available information about:


15. Deletion or return

Upon termination or valid deletion request, Watchfox will delete or return Customer Personal Data where technically and legally feasible.

Some records may be retained where required for:

Retention windows are described in the Privacy Policy.


16. Audits and information

Watchfox will make reasonable information available to demonstrate compliance with this DPA.

For a small SaaS provider, this may include:

Any audit must be reasonable, non-disruptive, protect other customers, and avoid exposing secrets or sensitive internal implementation details.


17. Customer obligations

Customer is responsible for:


18. Precedence

If there is a conflict between this DPA and the Terms of Service regarding processing of Customer Personal Data, this DPA controls to the extent of the conflict.


19. Contact

Privacy questions: [email protected] Security reports: [email protected] Support: [email protected]

Use the right mailbox so we can route your request quickly.