Legal·effective 2026-09-19 · updated 2026-09-19 · v1

Data Processing Addendum

Data Processing Addendum

Effective date: the publication date shown above

This Data Processing Addendum ("DPA") is incorporated into the Terms of Service between XODO Services SRL ("Processor", "Witch") and the customer ("Controller") and applies where Witch processes personal data on behalf of the Controller.

1. Roles

For monitoring activity the Controller configures, the Controller is the data controller and Witch is the processor. For Witch's own account and billing data, Witch is the controller.

2. Processing details

  • Subject matter: website monitoring of Controller-configured targets
  • Duration: the term of the customer's subscription
  • Nature and purpose: availability, content, and visual monitoring; incident recording; alerting
  • Categories of data subjects: visitors to Controller's monitored pages (as reflected in screenshots, page renders, and error data)
  • Categories of data: screenshots and rendered page evidence, DOM-derived signals, resource and network metadata, error messages, monitored URLs

Witch cannot guarantee that monitored Controller pages contain no personal data; the Controller is responsible for its lawful monitoring of its own pages.

3. Controller obligations

The Controller ensures it is entitled to direct the monitoring, including with respect to pages containing personal data.

4. Processor obligations

Witch processes data only to provide the service, on documented instructions (the monitoring configuration), applies appropriate technical and organizational measures, ensures personnel confidentiality, and assists where reasonably possible with data subject requests.

5. Subprocessors

Current subprocessors are listed at https://witch.pw/legal/subprocessors. We will give reasonable notice of new subprocessors.

6. Retention and deletion

Monitoring evidence is retained according to the plan's history window and deleted on workspace deletion. Account data is deleted or anonymized on account deletion.

7. Security incidents

We will notify the Controller of confirmed security incidents affecting Controller data without undue delay.

8. Audits

On reasonable request, we can provide information demonstrating compliance with this DPA.

Contact

DPA questions: [email protected]