Data processing agreement
The Article 28 terms under which we process data on your behalf. Published so you can read it before you sign up rather than asking for it afterwards.
Scope and roles
You are the controller of the data your applications send. We are the processor. This agreement applies from the moment an organisation is created and for as long as we hold anything on your behalf.
Subject matter: monitoring of software errors, logs, traces and metrics. Duration: the term of the service agreement. Nature and purpose: receiving, storing, grouping and displaying the data you send. Types of data: technical telemetry which may contain identifiers, request context and free text written by your application. Categories of data subject: the users of your applications and your own staff.
Instructions
We process only on your documented instructions, which are these terms, the configuration you set in the product, and anything you ask us in writing. If we believe an instruction breaks data protection law, we will say so rather than carry it out quietly.
We do not use your data to train models, to build a product, or for any purpose of our own.
Confidentiality and access
Everyone with access is bound to confidentiality. Access to a customer bucket or database is limited to the accounts that operate the platform, and is used for support only at your request or where necessary to restore the service.
Security measures
Separation by database and by storage bucket per organisation, rather than by a filter in application code. Encryption in transit on every endpoint. Payloads compressed and stored in object storage with access restricted to the platform. Customer-supplied bucket credentials stored encrypted. A fixed scrubbing list applied to every payload before it is written. Scoped API tokens with abilities checked per tool rather than per HTTP method. Sessions scoped per organisation host.
Sub-processors
The current list is published on this site. You agree to those. We will announce a new one at least thirty days before it starts processing, and you may object; if we cannot resolve the objection you may terminate the affected service without penalty.
Transfers
Requests reach us through Cloudflare, Inc., in the United States, which terminates the encrypted connection at its network edge before passing it on. That transfer is covered by its certification under the EU-US Data Privacy Framework and by the standard contractual clauses in its data processing terms. No other processing takes place outside the European Economic Area, except where you configure alert delivery to a service outside it. In that case the transfer is on your instruction and covered by the standard contractual clauses that service relies on.
Breach notification
We notify you without undue delay and in any event within seventy-two hours of becoming aware of a personal data breach affecting your data, with what we know at the time. Your own clock starts when ours does, so we do not wait for the investigation to finish before telling you.
Assistance, deletion and audit
We help you answer data subject requests and complete impact assessments, as far as the nature of the processing allows. The management API is how most of this is done directly.
On termination, and on request at any time, we delete: the bucket is removed and the organisation database is dropped. Backups roll off within thirty days.
We provide the information needed to demonstrate compliance and allow audits, including inspections, on reasonable notice and at reasonable intervals, in a way that does not compromise other customers.
Fourteen days of Team, without a card.
Sign up with your work address, prove your domain with one DNS record, and paste a DSN. The first stack trace usually arrives before the coffee does.
No card. The trial ends by itself and drops to Free; nothing is charged unless you choose a plan.