Data Processing Addendum
Effective date: August 8, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Glasstack, LLC, doing business as Acked ("Processor", "Acked", "we", "our"), and the customer identified in the Agreement ("Controller", "Customer", "you").
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.
1. Definitions
Applicable Data Protection Law means all laws applicable to the processing of Personal Data, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar privacy laws.
Controller, Processor, Data Subject, Personal Data, Processing, and Subprocessor have the meanings assigned under Applicable Data Protection Law.
Customer Data means all data submitted to or processed by Acked on behalf of Customer through the Services.
2. Scope
This DPA applies whenever Acked processes Personal Data on behalf of Customer in connection with the Services.
Customer acts as the Controller.
Acked acts as the Processor.
3. Subject Matter and Duration
Acked processes Personal Data solely to provide the Services described in the Agreement.
Processing continues for the duration of the Agreement and for any applicable retention period required for backups, legal obligations, or security purposes.
4. Nature and Purpose of Processing
Acked processes Customer Data to:
- Operate the incident management platform.
- Authenticate users.
- Deliver notifications.
- Manage schedules and on-call rotations.
- Store incidents and acknowledgements.
- Provide APIs and integrations.
- Monitor service reliability and security.
- Prevent abuse and fraud.
- Provide customer support.
5. Categories of Personal Data
Depending on Customer's use of the Services, Personal Data may include:
- Names
- Email addresses
- User identifiers
- Device push notification tokens
- Organization membership
- Schedule assignments
- Incident acknowledgements
- IP addresses
- Authentication metadata
- Audit logs
- Any personal data Customer chooses to include in alert content
Acked does not require Customers to submit special categories of personal data.
6. Categories of Data Subjects
Data Subjects may include:
- Customer employees
- Contractors
- Administrators
- On-call responders
- Authorized users
7. Customer Responsibilities
Customer represents that:
- it has all necessary rights to provide Customer Data;
- it has provided all required notices;
- it has obtained all required consents where necessary; and
- its instructions comply with Applicable Data Protection Law.
Customer remains responsible for determining what Personal Data is submitted to the Services.
8. Processing Instructions
Acked shall process Personal Data only:
- to provide the Services;
- under Customer's documented instructions;
- as required by applicable law.
If Acked is legally required to process Personal Data beyond Customer's instructions, Acked will notify Customer unless prohibited by law.
9. Confidentiality
Acked shall ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
10. Security Measures
Acked maintains administrative, technical, and organizational safeguards designed to protect Personal Data, including as appropriate:
- encryption in transit;
- encryption at rest where applicable;
- authentication and authorization controls;
- audit logging;
- least-privilege access;
- vulnerability management;
- infrastructure monitoring;
- backup and disaster recovery procedures.
Acked may modify these measures provided the overall level of protection is not materially reduced.
11. Subprocessors
Customer provides general written authorization for Acked to engage Subprocessors to process Customer Personal Data.
Acked remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
A current list of Subprocessors is maintained at:
https://acked.dev/legal/subprocessors
11.1 Notice of new Subprocessors
Acked will notify Customer at least thirty (30) days before a new Subprocessor begins processing Customer Personal Data. Notice is given by email to Customer's account holders and by updating the list above.
11.2 Optional features
Some Subprocessors process Customer Personal Data only where Customer enables an optional feature that requires them. These are identified as conditional on the list above, and Acked does not engage them for Customers who have not enabled the feature.
Acked will identify a conditional Subprocessor on the list, and in the product, before Customer enables the feature it supports. Enabling that feature constitutes Customer's authorization for that Subprocessor, and the thirty (30) day period in section 11.1 does not apply to it — no Customer Personal Data reaches that Subprocessor unless and until Customer enables the feature, and declining is simply not enabling it.
11.3 Objection
Customer may object to a new Subprocessor on reasonable data protection grounds by writing to support@acked.dev within the notice period. The parties will work in good faith to identify an alternative arrangement. If no reasonable alternative is available, Customer may terminate the affected Service without penalty for the remainder of its then-current term.
11.4 Urgent engagement
Acked may engage a Subprocessor without the prior notice period in section 11.1 where doing so is necessary to maintain the security, availability, or integrity of the Services, or to comply with a legal obligation. This includes replacing a Subprocessor that has suffered a security incident, failed, or ceased to provide its service.
Acked will not rely on this section for commercial convenience, and it does not reduce Customer's rights. Acked will:
- engage only a Subprocessor performing substantially the same function, bound by data protection obligations no less protective than those in this DPA;
- notify Customer without undue delay and in any event within five (5) business days, identifying the Subprocessor and the circumstances that required urgent engagement; and
- update the Subprocessor list.
Customer's objection rights under section 11.3 apply in full, running from that notice rather than from a prior one.
The Services deliver alerts to on-call responders. Where the affected Subprocessor is part of that delivery path, the alternative to urgent replacement is that notifications do not reach the people waiting for them, which is a harm to Customer and to its Data Subjects rather than a protection.
12. International Transfers
Where Personal Data is transferred internationally, Acked will implement an appropriate lawful transfer mechanism required under Applicable Data Protection Law.
13. Security Incidents
Acked will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.
Notification will include information reasonably available regarding:
- the nature of the incident;
- affected data, if known;
- mitigation steps taken; and
- recommended actions where appropriate.
Notification does not constitute an admission of fault or liability.
14. Assistance
Taking into account the nature of processing, Acked will provide reasonable assistance to Customer in responding to:
- requests from Data Subjects;
- supervisory authority inquiries;
- data protection impact assessments;
- prior consultations where required.
Acked may charge reasonable fees for assistance beyond normal support obligations.
15. Audits
Upon reasonable written request and no more than once annually, Acked will provide information reasonably necessary to demonstrate compliance with this DPA.
Where additional audits are legally required, the parties will cooperate in good faith while protecting Acked's confidential information and the security of other customers.
16. Return or Deletion
Upon termination of the Agreement and Customer's request, Acked will delete or return Customer Personal Data unless retention is required by law or necessary for backup recovery, fraud prevention, security, or legitimate legal obligations.
Residual copies contained within backups may remain until overwritten in the normal course of operations.
17. Liability
This DPA is subject to the liability limitations contained in the Agreement.
Nothing in this DPA expands either party's liability beyond the limits established in the Agreement unless prohibited by Applicable Data Protection Law.
18. Governing Law
This DPA is governed by the governing law specified in the Agreement.
Appendix A — Processing Details
Subject Matter
Provision of the Acked incident management platform.
Duration
For the duration of the Agreement and any applicable retention period.
Purpose
Incident management, authentication, notification delivery, scheduling, audit logging, integrations, customer support, and security.
Categories of Data
- User profile information
- Authentication information
- Contact information
- Device identifiers
- Push notification tokens
- Schedule data
- Incident metadata
- Audit logs
- Integration configuration
- Operational telemetry
Data Subjects
- Customer users
- Customer administrators
- On-call personnel
- Authorized contractors
Frequency
Continuous as required to provide the Services.
Contact
Questions about this DPA:
Glasstack, LLC
support@acked.dev