This Data Processing Agreement ("DPA") is entered into between LTFI Tech, LLC, a Massachusetts limited liability company and operator of the OpsPing service ("Processor") and ______________________________ ("Controller"), each a "Party," and supplements the Terms of Service or other master agreement between the Parties governing the OpsPing on-call paging and alerting service (the "Service").
1. Roles and Scope
The Parties acknowledge and agree that, with respect to the processing of personal data submitted to the Service by or on behalf of the Controller ("Customer Personal Data"): the Controller is the data controller, and LTFI Tech, LLC is the data processor, as those terms are defined under the EU General Data Protection Regulation ("GDPR") and equivalent laws. The Processor processes Customer Personal Data only on the Controller's documented instructions, as represented by the Controller's use and configuration of the Service, unless required by law.
2. Subject Matter, Duration, Nature, and Purpose
- Subject matter: Provision of the on-call paging and alerting Service.
- Duration: The term of the underlying agreement, subject to the deletion provisions in Section 8.
- Nature and purpose: Storage and processing of account information, channel PII (on-call phone numbers and email addresses), push tokens, alert logs, and operational data, solely to deliver alerts and operate the Service.
- Categories of data subjects: The Controller's employees, contractors, and on-call personnel whose contact details are submitted to the Service.
3. Controller Obligations
The Controller warrants that it has a lawful basis for processing, has provided all required notices to and obtained all required consents from data subjects (including on-call team members whose phone numbers and email addresses are submitted), and will not submit special categories of personal data to the Service.
4. Subprocessors
The Controller authorizes the Processor to engage the following subprocessors:
| Subprocessor | Function |
|---|---|
| Amazon Web Services (AWS) | Hosting, compute, and database (DynamoDB); Amazon SES for email delivery |
| Expo | Push notification relay |
| Twilio | Optional SMS and voice delivery (only if enabled by Controller) |
The Processor will provide at least thirty (30) days' prior written notice before engaging a new or replacement subprocessor. The Controller may object on reasonable data-protection grounds within fourteen (14) days of such notice; if the objection cannot be resolved, the Controller may terminate the affected Service. See the full subprocessor list for details.
5. Security Measures
OpsPing implements the following technical and organizational measures:
- Hosting: All Service infrastructure is hosted on Amazon Web Services.
- Access control: IAM-based access control with least-privilege principles; access to production systems is restricted to authorized personnel.
- Encryption in transit: TLS 1.2 or higher for all connections to the Service.
- Encryption at rest: DynamoDB server-side encryption using AWS-managed keys.
Known limitation (disclosed): Channel PII (on-call phone numbers and email addresses) is not encrypted at the application layer; it is stored in plaintext in DynamoDB, protected at rest only by DynamoDB's server-side encryption with AWS-managed keys. OpsPing plans to add application-layer encryption for channel PII in a future release and will update this DPA's security annex when it does.
6. Data Breach Notification
OpsPing will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include, to the extent known: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed. OpsPing will provide reasonable cooperation in the Controller's breach investigation and any required notifications to authorities or data subjects.
7. Assistance and Data Subject Rights
OpsPing will provide reasonable assistance, taking into account the nature of the processing, to enable the Controller to respond to data subject requests (access, rectification, deletion, portability) and to demonstrate compliance with GDPR Articles 32–36. OpsPing will refer data subjects who contact OpsPing directly to the Controller. Deletion requests are honored within thirty (30) days of a verified request.
8. Return and Deletion on Termination
Upon termination or expiry of the underlying agreement, OpsPing will, at the Controller's election, return or delete Customer Personal Data within ninety (90) days of termination, unless retention is required by law. Note that alert logs and operational data are in any event automatically purged after ninety (90) days of retention during the subscription term.
9. International Transfers — Standard Contractual Clauses
To the extent Customer Personal Data subject to GDPR is transferred to a country without an adequacy decision (including the United States, where the Service is hosted), such transfers are governed by the EU Commission Standard Contractual Clauses (2021/914), Module Two (controller-to-processor), which are incorporated by reference and attached as a signed annex to this DPA.
Signed SCC attachment: ______________________________
The Parties agree to complete and execute the SCC annexes to reflect the processing described in this DPA.
10. Audits
Upon reasonable prior written notice, and not more than once annually unless required by a supervisory authority or following a breach, the Controller may audit OpsPing's compliance with this DPA through questionnaires and review of available third-party reports and documentation. On-site audits may be arranged where questionnaires and documentation are insufficient, at the Controller's reasonable cost.
11. Liability
Each Party's liability under this DPA is subject to the limitation-of-liability provisions of the underlying agreement, except where such limitation is prohibited by applicable data protection law.
12. Precedence and Changes
In the event of conflict between this DPA and the underlying agreement regarding data protection, this DPA prevails. OpsPing may update this DPA to reflect changes in law or subprocessors, with notice as required by Section 4.
13. Governing Law
This DPA is governed by the laws of the Commonwealth of Massachusetts, except that provisions implementing GDPR obligations are governed by the law specified in the applicable Standard Contractual Clauses where mandatory. Effective date: August 2026.
Signature Block
IN WITNESS WHEREOF, the Parties have executed this Data Processing Agreement as of the effective date above.
| Controller | Processor | |
|---|---|---|
| Party | ______________________________ | OpsPing |
| Name | ______________________________ | ______________________________ |
| Title | ______________________________ | ______________________________ |
| Signature | ______________________________ | ______________________________ |
| Date | ______________________________ | ______________________________ |
Questions about this DPA: legal@ops-ping.com.