Awarely Monitor
AwarelyMonitor
Legal center

Data Processing Agreement

This standard Data Processing Agreement ("DPA") applies where MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as MONITOR AWARELY ("MONITOR AWARELY"), processes personal data on behalf of an organization customer under Regulation (EU) 2016/679 ("GDPR"). This web version is a standard template, not a click-through agreement. It becomes binding only when incorporated into a signed customer agreement or separately accepted by authorized representatives in writing, including by confirmed email. The executed version controls the relevant processor relationship.

Last Updated: August 3, 2026Effective Date: July 26, 2026

1. Parties, Scope, and Precedence

Customer as controllerThe organization customer acts as controller for customer personal data submitted to or generated through its use of the Service, to the extent GDPR allocates that role to the customer.
MONITOR AWARELY as processorMUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as MONITOR AWARELY, acts as processor for the customer personal data described in this DPA when providing the Service to the customer.
Separate controller activitiesMONITOR AWARELY remains an independent controller for its own account administration, authentication, security logging, fraud prevention, direct billing/accounting records, legal compliance, and website/app operations that are outside processor instructions.
PrecedenceIf there is a conflict between this DPA and the general Terms or commercial documents regarding processor-side data protection obligations, this signed DPA prevails for that customer relationship.
Customer obligationsThe customer is responsible for the lawfulness, fairness, transparency, accuracy, and proportionality of its processing and instructions; for providing required notices and establishing a lawful basis; for obtaining necessary rights and authorizations; for responding to data subjects and regulators as controller; and for ensuring authorized users do not submit data that is excessive or incompatible with the Service. The customer warrants that its instructions comply with applicable law.
No unauthorized sensitive dataUnless the parties expressly agree otherwise in writing, the customer must not use the Service to process special-category data, criminal-offence data, payment-card numbers, passwords, private keys, or other authentication secrets. Any agreed sensitive-data processing may require additional safeguards, scope, and fees.

2. Subject Matter, Duration, and Processing Details

Subject matterProvision of the Awarely Monitor vulnerability monitoring service, including account administration, customer-configured enterprise OIDC SSO, alert configuration, team management, audit history, export features, support, and related service operations.
DurationProcessing continues for the duration of the customer contract and for any limited post-termination period required for secure deletion, return, legal retention, or backup lifecycle management.
Nature and purposeCollection, recording, hosting, storage, organization, retrieval, consultation, transmission to configured recipients, alert and report delivery, support handling, security monitoring, export, restriction, and deletion necessary to provide and secure the Service on the customer's behalf.
Data subjectsCustomer users, organization owners and administrators, invited team members, alert recipients, integration contacts, and support contacts whose data the customer causes the Service to process.
Personal-data categoriesAccount and external identity-provider identifiers, names where supplied, email addresses, limited OIDC authentication/profile claims, organization membership and roles, SSO provisioning metadata, alert settings and recipients, invite/contact details, browser-push endpoints, configured integration metadata, audit and usage records, IP/request metadata, report metadata, and support messages. Direct billing, accounting, and MONITOR AWARELY security/fraud records are processed in MONITOR AWARELY’s separate controller role to the applicable extent.

3. Instructions, Confidentiality, and Assistance

Documented instructionsMONITOR AWARELY processes customer personal data only on documented instructions from the customer, including the executed contract and DPA, applicable order documents, in-product configuration by authorized users, and lawful support requests. The instruction covers transfers to the subprocessors and customer-configured destinations identified in this DPA. Additional instructions outside the Service scope require prior written agreement and may incur reasonable fees.
Processing required by lawIf EU or Member State law requires MONITOR AWARELY to process customer personal data outside the customer’s instructions, MONITOR AWARELY will inform the customer of that legal requirement before processing unless the law prohibits notice on important grounds of public interest.
Unlawful instructionsMONITOR AWARELY will inform the customer if, in its opinion, an instruction infringes applicable data-protection law, unless applicable law prohibits that notice.
ConfidentialityMONITOR AWARELY ensures that persons authorized to process customer data are bound by confidentiality obligations.
Data subject requestsTaking into account the nature of processing, MONITOR AWARELY will assist the customer through appropriate technical and organizational measures, insofar as possible, to fulfil requests for access, rectification, erasure, restriction, portability, objection, and other applicable rights. Unless legally prohibited, MONITOR AWARELY will refer a request received directly about processor-side data to the customer and will not independently respond except on the customer’s documented instruction.
Articles 32–36 assistanceTaking into account the nature of processing and information available, MONITOR AWARELY will reasonably assist the customer with security obligations, breach assessment and notification, data-protection impact assessments, and prior consultation required by GDPR Articles 32–36. Assistance beyond standard Service functionality may be charged at reasonable rates unless caused by MONITOR AWARELY’s breach of this DPA.
Personal-data breachesWhere MONITOR AWARELY becomes aware of a personal-data breach affecting customer personal data processed under this DPA, MONITOR AWARELY will notify the customer without undue delay and provide information available to MONITOR AWARELY so that the customer can assess and meet its GDPR obligations. This statutory assistance is not a commercial support SLA.

4. Security Measures and Audit Information

Article 32 standardMONITOR AWARELY implements and maintains technical and organizational measures appropriate to the risk, taking account of the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. Measures are reviewed and may evolve without materially reducing the overall protection of customer personal data.
Technical and organizational measuresMeasures include TLS-protected transport; AWS-managed encryption at rest for core storage, with customer-managed keys for designated sensitive tables; role-based and least-privilege access; AWS Cognito authentication; separation of production roles; protection of integration secrets; logging, monitoring, and audit records; backup/recovery capabilities; retention controls; incident-response procedures; and controlled vendor access. No system is guaranteed to be completely secure.
Infrastructure and emailThe Service uses AWS-hosted infrastructure, including Cognito, Amazon SES, and related AWS storage and processing services, with primary application processing in Frankfurt (eu-central-1). Amazon SES delivers transactional email and processes sender and recipient addresses, subject, required text/HTML content, delivery events, and account-level bounce/complaint suppression records. Open and click tracking are not enabled.
Payment processingFor self-serve card subscriptions, payments are processed by Stripe, Inc. with Link (Sold through Link, LLC) acting as merchant of record under Stripe Managed Payments. Stripe/Link process the buyer's payment, billing and tax-ID data under their own controller terms and privacy policy (stripe.com/privacy); MONITOR AWARELY receives only the subscription status, billing period and customer/subscription identifiers needed to activate the plan. Card details never reach MONITOR AWARELY systems. Institutions billed by direct invoice do not go through Stripe.
Information and auditsMONITOR AWARELY will make available all information reasonably necessary to demonstrate compliance with GDPR Article 28 and will allow for and contribute to audits, including inspections, conducted by the customer or an independent auditor mandated by the customer.
Audit safeguards and costsUnless a regulator or credible incident requires urgency, the customer must give reasonable advance notice, first use available documentation and remote review, keep findings confidential, avoid disrupting operations, and ensure the audit does not expose another customer’s data, security vulnerabilities, or legally protected information. On-site access is limited to what is necessary after remote evidence is insufficient. Audits are normally limited to once per year. The customer bears its and MONITOR AWARELY’s reasonable audit costs unless the audit establishes MONITOR AWARELY’s material breach of this DPA. These safeguards do not restrict a competent supervisory authority.

5. Subprocessors and International Transfers

General written authorisationThe customer gives general written authorisation for MONITOR AWARELY to appoint the subprocessors listed here and replacements or additions notified under this section.
Flow-down and responsibilityBefore a subprocessor processes customer personal data, MONITOR AWARELY imposes by written contract data-protection obligations that provide at least the protection required of MONITOR AWARELY for the relevant processing. MONITOR AWARELY remains fully liable to the customer for the subprocessor’s performance of those obligations as required by GDPR Article 28(4).
Changes and objectionsMONITOR AWARELY will provide at least 15 days’ prior notice of an intended material new or replacement subprocessor where reasonably practicable. Emergency, security, availability, or legal changes may take effect sooner, with notice as soon as reasonably practicable. The customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may terminate only the affected Service portion without penalty, and the customer’s exclusive remedy for the subprocessor objection is a pro-rata refund of prepaid fees for that terminated portion, subject to mandatory law. The customer must keep its DPA contact current.
Amazon Web ServicesAmazon Web Services EMEA SARL and/or the applicable AWS contracting entity — cloud hosting, storage, authentication through Amazon Cognito, transactional email through Amazon SES, logging, monitoring, backup, and related infrastructure; customer account, configuration, audit, usage, security, support, recipient, and message-delivery data; primary region Frankfurt, Germany (eu-central-1), subject to AWS’s documented processing locations and transfer safeguards.
Slack support workflowSlack Technologies Limited and/or the applicable Slack/Salesforce contracting entity — MONITOR AWARELY’s private support workflow; support message, account contact details, source page, and limited request metadata. Slack states that its default hosting location is the United States unless eligible data-residency settings apply, and that relevant transfers rely on its DPA and applicable safeguards. This entry does not cover a customer’s own Slack alert destination.
Customer-configured destinationsWhere the customer configures browser-push delivery, Slack, Microsoft Teams, Jira, Linear, or a generic webhook destination, the customer instructs MONITOR AWARELY to transmit the configured content to that destination. The customer is responsible for the destination, its users, and its privacy/security settings; the destination is not made a MONITOR AWARELY subprocessor solely because the customer enabled it.
Customer-configured identity providersWhere an eligible customer configures enterprise OIDC SSO through Microsoft Entra ID, Okta, Google Workspace, or another supported provider, the customer instructs MONITOR AWARELY to accept the identity and limited authentication/profile claims released by that provider. The customer controls user/group assignments, MFA policy and its contractual relationship with the provider. The provider is not made a MONITOR AWARELY subprocessor solely because the customer selected it; AWS Cognito remains covered by the AWS appointment above as the Service-side identity broker.
Independent-controller vendorsStripe and Link process self-serve payment data under their own controller terms as merchant of record. Cookiebot, Google Analytics and optional Google OAuth sign-in are used for MONITOR AWARELY’s own controller-side site/app operations where relevant. They are not appointed under this DPA solely for those activities.
International transfersPrimary application processing is configured in the EU. Where processor-side customer data is transferred outside the EU/EEA, MONITOR AWARELY uses an applicable GDPR Chapter V mechanism, such as an adequacy decision or the European Commission Standard Contractual Clauses, and supplementary measures where required. The customer authorizes MONITOR AWARELY to enter those safeguards on its behalf where legally permitted. Customer-configured destinations operate under the customer’s chosen arrangements.

6. Return, Deletion, Liability, and General Terms

Deletion or returnAt termination and at the customer’s documented choice, MONITOR AWARELY will delete or return customer data under its processor role, unless applicable law requires retention or secure operational copies persist temporarily in backups or logs. The customer should request any needed export before ending access; the currently available self-service export has documented security exclusions and record limits.
Retention carve-outsController-side records that MONITOR AWARELY must keep for tax, accounting, fraud prevention, legal defense, or security purposes are outside the processor deletion obligation to that extent.
Certification of deletionOn reasonable written request after completion of deletion, MONITOR AWARELY will confirm completion, subject to remaining lawful controller records and backup copies that are isolated from ordinary use and deleted through their lifecycle.
LiabilityTo the maximum extent permitted by law, the exclusions and aggregate liability cap in the applicable Terms or signed customer agreement apply collectively to this DPA and the Service. Nothing limits liability or data-subject rights that cannot lawfully be limited, or either party’s responsibility to a supervisory authority under GDPR.
Term and survivalThis DPA starts when validly executed or incorporated and remains in effect while MONITOR AWARELY processes customer personal data. Confidentiality, return/deletion, audit records, liability, and provisions that by nature should survive remain effective after termination.
Governing law and jurisdictionThe governing law and jurisdiction in the applicable Terms or signed customer agreement apply to this DPA, without restricting mandatory GDPR rights or the powers of competent supervisory authorities.
Complete processing annexesSection 2 is Annex A (processing details); Section 4 is Annex B (technical and organizational measures); and Section 5 is Annex C (authorized subprocessors and transfers). They form part of this DPA.

7. Execution and Contact

This standard DPA is available for organization customers and is executed by separate signature or email confirmation, not through in-app click acceptance.

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ

Trading as: MONITOR AWARELY

ONRC: F2026008193001 · CUI: 53962936 · EU VAT (VIES): RO54197611

București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România

monitor@awarely.ro

https://monitor.awarely.ro

For DPA requests or execution, contact monitor@awarely.ro and identify your organization, contracting model, and billing path.

For the general contract terms, see our Terms and Conditions.

For controller-side privacy details, see our Privacy Policy.