Data Processing Addendum

Effective date: August 8, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Glasstack, LLC, doing business as Acked ("Processor", "Acked", "we", "our"), and the customer identified in the Agreement ("Controller", "Customer", "you").

If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

Applicable Data Protection Law means all laws applicable to the processing of Personal Data, including, where applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar privacy laws.

Controller, Processor, Data Subject, Personal Data, Processing, and Subprocessor have the meanings assigned under Applicable Data Protection Law.

Customer Data means all data submitted to or processed by Acked on behalf of Customer through the Services.

2. Scope

This DPA applies whenever Acked processes Personal Data on behalf of Customer in connection with the Services.

Customer acts as the Controller.

Acked acts as the Processor.

3. Subject Matter and Duration

Acked processes Personal Data solely to provide the Services described in the Agreement.

Processing continues for the duration of the Agreement and for any applicable retention period required for backups, legal obligations, or security purposes.

4. Nature and Purpose of Processing

Acked processes Customer Data to:

5. Categories of Personal Data

Depending on Customer's use of the Services, Personal Data may include:

Acked does not require Customers to submit special categories of personal data.

6. Categories of Data Subjects

Data Subjects may include:

7. Customer Responsibilities

Customer represents that:

Customer remains responsible for determining what Personal Data is submitted to the Services.

8. Processing Instructions

Acked shall process Personal Data only:

If Acked is legally required to process Personal Data beyond Customer's instructions, Acked will notify Customer unless prohibited by law.

9. Confidentiality

Acked shall ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

10. Security Measures

Acked maintains administrative, technical, and organizational safeguards designed to protect Personal Data, including as appropriate:

Acked may modify these measures provided the overall level of protection is not materially reduced.

11. Subprocessors

Customer provides general written authorization for Acked to engage Subprocessors to process Customer Personal Data.

Acked remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

A current list of Subprocessors is maintained at:

https://acked.dev/legal/subprocessors

11.1 Notice of new Subprocessors

Acked will notify Customer at least thirty (30) days before a new Subprocessor begins processing Customer Personal Data. Notice is given by email to Customer's account holders and by updating the list above.

11.2 Optional features

Some Subprocessors process Customer Personal Data only where Customer enables an optional feature that requires them. These are identified as conditional on the list above, and Acked does not engage them for Customers who have not enabled the feature.

Acked will identify a conditional Subprocessor on the list, and in the product, before Customer enables the feature it supports. Enabling that feature constitutes Customer's authorization for that Subprocessor, and the thirty (30) day period in section 11.1 does not apply to it — no Customer Personal Data reaches that Subprocessor unless and until Customer enables the feature, and declining is simply not enabling it.

11.3 Objection

Customer may object to a new Subprocessor on reasonable data protection grounds by writing to support@acked.dev within the notice period. The parties will work in good faith to identify an alternative arrangement. If no reasonable alternative is available, Customer may terminate the affected Service without penalty for the remainder of its then-current term.

11.4 Urgent engagement

Acked may engage a Subprocessor without the prior notice period in section 11.1 where doing so is necessary to maintain the security, availability, or integrity of the Services, or to comply with a legal obligation. This includes replacing a Subprocessor that has suffered a security incident, failed, or ceased to provide its service.

Acked will not rely on this section for commercial convenience, and it does not reduce Customer's rights. Acked will:

Customer's objection rights under section 11.3 apply in full, running from that notice rather than from a prior one.

The Services deliver alerts to on-call responders. Where the affected Subprocessor is part of that delivery path, the alternative to urgent replacement is that notifications do not reach the people waiting for them, which is a harm to Customer and to its Data Subjects rather than a protection.

12. International Transfers

Where Personal Data is transferred internationally, Acked will implement an appropriate lawful transfer mechanism required under Applicable Data Protection Law.

13. Security Incidents

Acked will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.

Notification will include information reasonably available regarding:

Notification does not constitute an admission of fault or liability.

14. Assistance

Taking into account the nature of processing, Acked will provide reasonable assistance to Customer in responding to:

Acked may charge reasonable fees for assistance beyond normal support obligations.

15. Audits

Upon reasonable written request and no more than once annually, Acked will provide information reasonably necessary to demonstrate compliance with this DPA.

Where additional audits are legally required, the parties will cooperate in good faith while protecting Acked's confidential information and the security of other customers.

16. Return or Deletion

Upon termination of the Agreement and Customer's request, Acked will delete or return Customer Personal Data unless retention is required by law or necessary for backup recovery, fraud prevention, security, or legitimate legal obligations.

Residual copies contained within backups may remain until overwritten in the normal course of operations.

17. Liability

This DPA is subject to the liability limitations contained in the Agreement.

Nothing in this DPA expands either party's liability beyond the limits established in the Agreement unless prohibited by Applicable Data Protection Law.

18. Governing Law

This DPA is governed by the governing law specified in the Agreement.

Appendix A — Processing Details

Subject Matter

Provision of the Acked incident management platform.

Duration

For the duration of the Agreement and any applicable retention period.

Purpose

Incident management, authentication, notification delivery, scheduling, audit logging, integrations, customer support, and security.

Categories of Data

Data Subjects

Frequency

Continuous as required to provide the Services.

Contact

Questions about this DPA:

Glasstack, LLC
support@acked.dev