GDPR at Spike
Spike, operated by FatSync Software Private Limited, provides an incident management and alerting platform used by organizations globally. This page outlines our data processing practices, subprocessors, and transfer safeguards in accordance with the General Data Protection Regulation (GDPR).
Data hosting & international transfers
Spike is incorporated in India. Our production infrastructure and databases are hosted in the United States.
Personal data may be transferred outside the European Economic Area (EEA) or United Kingdom. Where such transfers occur, they are governed by appropriate safeguards, including the European Commission’s Standard Contractual Clauses (2021).
You can review our full Data Processing Addendum, which incorporates the EU Standard Contractual Clauses by reference:
Subprocessors
Spike engages trusted third-party service providers to operate and deliver the platform. These subprocessors process personal data only as necessary to provide infrastructure and communication services.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure hosting | United States |
| MongoDB Atlas | Database hosting | United States |
| SendGrid (Twilio) | Transactional email notifications | United States |
| Twilio | SMS, voice, and WhatsApp notifications | United States |
| Plivo | SMS and voice notifications | United States |
| Slack | Notifications and customer support messaging | United States |
| Microsoft Teams | Notifications | United States |
| Telegram | Notifications | United States |
| Intercom | Customer support CRM | United States |
| Loops.so | Marketing and engagement email delivery | United States |
| Honeybadger.io | Error monitoring | United States |
| Sentry | Error monitoring | United States |
| Google Analytics | Consent-based website analytics | United States |
This is Spike’s maintained subprocessor list and is incorporated by reference as Annex III of the Data Processing Addendum. We will give customers at least 14 days’ notice by email before a new subprocessor begins processing personal data, and customers may object within 14 days of that notice as set out in the DPA. Customers may contact [email protected] with any questions regarding subprocessors.
DPA version history
Version 2.0 — effective 14 September 2026
Version 2.0 strengthens Spike’s commitments as a processor. No protections were reduced. Changes from version 1.0:
- Added written confidentiality obligations for personnel with access to personal data, and identity and reference checks before production access is granted
- Added a commitment to notify customers of a personal data breach within 72 hours of becoming aware, with defined content and follow-up
- Added 14 days’ advance notice before engaging a new subprocessor, a right to object, and a right to terminate the affected services if no resolution is reached
- Added an express commitment that subprocessors are bound by materially equivalent obligations, and that Spike remains liable for their performance
- Added the UK International Data Transfer Addendum for transfers of UK personal data, alongside the existing EU Standard Contractual Clauses
- Added commitments on government and law enforcement access requests, including notice to customers where lawful
- Added assistance obligations covering data protection impact assessments, prior consultation, and security of processing
- Clarified deletion and return: the customer elects, with defined timelines and a written confirmation on request
- Expanded audit rights to include audits and inspections, with defined scope and frequency
- Corrected the stated locations of processing to include India, where Spike personnel access production systems
- Widened the scope of applicable law to cover UK GDPR, the UK Data Protection Act 2018, and India’s Digital Personal Data Protection Act 2023
Data subject requests
If you are located in the EEA or UK and wish to exercise your rights under GDPR (access, correction, deletion, restriction, objection, or data portability), please contact [email protected].
We respond to valid requests within 30 days.
Spike, operated by FatSync Software Private Limited, provides an incident management and alerting platform used by organizations globally. This page outlines our data processing practices, subprocessors, and transfer safeguards in accordance with the General Data Protection Regulation (GDPR). ## Data hosting & international transfers Spike is incorporated in India. Our production infrastructure and databases are hosted in the United States. Personal data may be transferred outside the European Economic Area (EEA) or United Kingdom. Where such transfers occur, they are governed by appropriate safeguards, including the European Commission’s Standard Contractual Clauses (2021). You can review our full Data Processing Addendum, which incorporates the EU Standard Contractual Clauses by reference: - [View the Data Processing Addendum (DPA)](/gdpr/dpa) - [Read the EU Standard Contractual Clauses (2021)](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj) ## Subprocessors Spike engages trusted third-party service providers to operate and deliver the platform. These subprocessors process personal data only as necessary to provide infrastructure and communication services. | Subprocessor | Purpose | Location | | --- | --- | --- | | Amazon Web Services (AWS) | Cloud infrastructure hosting | United States | | MongoDB Atlas | Database hosting | United States | | SendGrid (Twilio) | Transactional email notifications | United States | | Twilio | SMS, voice, and WhatsApp notifications | United States | | Plivo | SMS and voice notifications | United States | | Slack | Notifications and customer support messaging | United States | | Microsoft Teams | Notifications | United States | | Telegram | Notifications | United States | | Intercom | Customer support CRM | United States | | Loops.so | Marketing and engagement email delivery | United States | | Honeybadger.io | Error monitoring | United States | | Sentry | Error monitoring | United States | | Google Analytics | Consent-based website analytics | United States | This is Spike's maintained subprocessor list and is incorporated by reference as Annex III of the [Data Processing Addendum](/gdpr/dpa). We will give customers at least 14 days’ notice by email before a new subprocessor begins processing personal data, and customers may object within 14 days of that notice as set out in the DPA. Customers may contact [[email protected]](mailto:[email protected]) with any questions regarding subprocessors. ## DPA version history **Version 2.0 — effective 14 September 2026** Version 2.0 strengthens Spike's commitments as a processor. No protections were reduced. Changes from version 1.0: - Added written confidentiality obligations for personnel with access to personal data, and identity and reference checks before production access is granted - Added a commitment to notify customers of a personal data breach within 72 hours of becoming aware, with defined content and follow-up - Added 14 days' advance notice before engaging a new subprocessor, a right to object, and a right to terminate the affected services if no resolution is reached - Added an express commitment that subprocessors are bound by materially equivalent obligations, and that Spike remains liable for their performance - Added the UK International Data Transfer Addendum for transfers of UK personal data, alongside the existing EU Standard Contractual Clauses - Added commitments on government and law enforcement access requests, including notice to customers where lawful - Added assistance obligations covering data protection impact assessments, prior consultation, and security of processing - Clarified deletion and return: the customer elects, with defined timelines and a written confirmation on request - Expanded audit rights to include audits and inspections, with defined scope and frequency - Corrected the stated locations of processing to include India, where Spike personnel access production systems - Widened the scope of applicable law to cover UK GDPR, the UK Data Protection Act 2018, and India's Digital Personal Data Protection Act 2023 ## Data subject requests If you are located in the EEA or UK and wish to exercise your rights under GDPR (access, correction, deletion, restriction, objection, or data portability), please contact [[email protected]](mailto:[email protected]). We respond to valid requests within 30 days.