General written authorisation — The customer gives general written authorisation for MONITOR AWARELY to appoint the subprocessors listed here and replacements or additions notified under this section.
Flow-down and responsibility — Before a subprocessor processes customer personal data, MONITOR AWARELY imposes by written contract data-protection obligations that provide at least the protection required of MONITOR AWARELY for the relevant processing. MONITOR AWARELY remains fully liable to the customer for the subprocessor’s performance of those obligations as required by GDPR Article 28(4).
Changes and objections — MONITOR AWARELY will provide at least 15 days’ prior notice of an intended material new or replacement subprocessor where reasonably practicable. Emergency, security, availability, or legal changes may take effect sooner, with notice as soon as reasonably practicable. The customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate only the affected Service portion without penalty, and the customer’s exclusive remedy for the subprocessor objection is a pro-rata refund of prepaid fees for that terminated portion, subject to mandatory law. The customer must keep its DPA contact current.
Amazon Web Services — Amazon Web Services EMEA SARL and/or the applicable AWS contracting entity — cloud hosting, storage, authentication through Amazon Cognito, transactional email through Amazon SES, logging, monitoring, backup, and related infrastructure; customer account, configuration, audit, usage, security, support, recipient, and message-delivery data; primary region Frankfurt, Germany (eu-central-1), subject to AWS’s documented processing locations and transfer safeguards.
Slack support workflow — Slack Technologies Limited and/or the applicable Slack/Salesforce contracting entity — MONITOR AWARELY’s private support workflow; support message, account contact details, source page, and limited request metadata. Slack states that its default hosting location is the United States unless eligible data-residency settings apply, and that relevant transfers rely on its DPA and applicable safeguards. This entry does not cover a customer’s own Slack alert destination.
Customer-configured destinations — Where the customer configures browser-push delivery, Slack, Microsoft Teams, Jira, Linear, or a generic webhook destination, the customer instructs MONITOR AWARELY to transmit the configured content to that destination. The customer is responsible for the destination, its users, and its privacy/security settings; the destination is not made a MONITOR AWARELY subprocessor solely because the customer enabled it.
Customer-configured identity providers — Where an eligible customer configures enterprise OIDC SSO through Microsoft Entra ID, Okta, Google Workspace, or another supported provider, the customer instructs MONITOR AWARELY to accept the identity and limited authentication/profile claims released by that provider. The customer controls user/group assignments, MFA policy and its contractual relationship with the provider. The provider is not made a MONITOR AWARELY subprocessor solely because the customer selected it; AWS Cognito remains covered by the AWS appointment above as the Service-side identity broker.
Independent-controller vendors — Stripe and Link process self-serve payment data under their own controller terms as merchant of record. Cookiebot, Google Analytics and optional Google OAuth sign-in are used for MONITOR AWARELY’s own controller-side site/app operations where relevant. They are not appointed under this DPA solely for those activities.
International transfers — Primary application processing is configured in the EU. Where processor-side customer data is transferred outside the EU/EEA, MONITOR AWARELY uses an applicable GDPR Chapter V mechanism, such as an adequacy decision or the European Commission Standard Contractual Clauses, and supplementary measures where required. The customer authorizes MONITOR AWARELY to enter those safeguards on its behalf where legally permitted. Customer-configured destinations operate under the customer’s chosen arrangements.