Data Processing Agreement
Last updated: 2026-03-01
1. Introduction
This DPA applies when Notivio processes personal data on behalf of the Customer in connection with the provision of the Notivio service.
2. Roles of the Parties
- The Customer acts as the Data Controller
- Notivio acts as the Data Processor
The Customer determines the purposes and means of processing personal data. Notivio processes personal data solely on behalf of the Customer to provide the service.
3. Processing Instructions
The Customer instructs Notivio to process personal data as necessary to:
- operate the Notivio platform
- process Slack integration events
- store notification configuration
- deliver SMS notifications
- maintain system logs and service reliability
- provide customer support and security monitoring
Configuration settings and notification rules defined by the Customer within the platform constitute documented processing instructions.
4. Scope of Processing
- receiving notification events from Slack integrations
- storing configuration settings
- processing phone numbers
- delivering SMS notifications
- maintaining logs and delivery metadata
- providing technical support and system monitoring
Personal data processed through the service is not used for advertising or marketing purposes.
5. Categories of Personal Data
- phone numbers
- Slack workspace identifiers
- Slack channel identifiers
- user identifiers
- email addresses
- notification configuration
- delivery logs and metadata
- IP addresses and technical logs
6. Categories of Data Subjects
- Customer employees
- Customer contractors
- Customer team members
- individuals designated to receive system notifications
7. Customer Responsibilities
- it has a lawful basis for processing personal data
- it has the right to provide phone numbers and other personal data to Notivio
- recipients of SMS notifications have been informed where required by law
The Customer is responsible for the content of notifications and compliance with applicable telecommunications and data protection laws.
8. Sub-processors
- Twilio – SMS delivery
- Stripe – payment processing
- Slack – workspace integration
- cloud hosting providers
All sub-processors are contractually required to maintain appropriate security and data protection standards. Notivio remains responsible for processing performed by its sub-processors.
9. Security Measures
- encrypted communication (HTTPS / TLS)
- secure infrastructure and hosting
- access controls and authentication
- system monitoring and logging
- internal access restrictions
10. Data Subject Rights
- access to personal data
- correction or deletion
- restriction of processing
- data portability
11. Messaging Compliance
Notivio acts solely as a technical service provider delivering notifications configured by the Customer and does not determine the recipients or content of messages.
The Customer agrees not to use the service to send unsolicited marketing, spam, harassment, or unlawful communications.