Data Processing Addendum
For any further assistance, please email [email protected].
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (“Agreement”) between FatSync Software Private Limited, an Indian private limited company operating the Spike platform (“Spike”, “Processor”, “we”, “us”), and the customer entity using Spike’s services (“Controller”).
This DPA applies where Spike processes Personal Data on behalf of the Controller in connection with the provision of the Spike incident management and alerting platform.
This DPA is incorporated into the Agreement by reference. Where this DPA conflicts with the Agreement in relation to the Processing of Personal Data, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses or the UK Addendum, those clauses prevail.
Version 2.0. Effective 14 September 2026. A summary of changes from version 1.0 is available on our GDPR page.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on Personal Data, including collection, storage, use, transmission, or deletion.
“Applicable Data Protection Law” means all laws applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the UK General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018 (“UK GDPR”), the UK Data Protection Act 2018, and the Indian Digital Personal Data Protection Act 2023, in each case as applicable to the relevant Processing.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Spike or a Subprocessor.
“Subprocessor” means any third party engaged by Spike to Process Personal Data on behalf of the Controller.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under section 119A of the UK Data Protection Act 2018.
“Supervisory Authority” means an independent public authority established under Applicable Data Protection Law.
2. Roles of the Parties
The Controller determines the purposes and means of Processing Personal Data.
Spike acts as a Processor and Processes Personal Data only on documented instructions from the Controller, as described in the Agreement and this DPA, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by law to which Spike is subject. Where Spike is required by law to Process Personal Data other than on the Controller’s instructions, Spike will inform the Controller of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
Spike will inform the Controller without undue delay if, in Spike’s opinion, an instruction from the Controller infringes Applicable Data Protection Law. Spike may suspend performance of the affected instruction until the Controller confirms, amends, or withdraws it.
3. Subject Matter and Duration of Processing
Subject Matter: Provision of the Spike incident management, alerting, escalation, and on-call scheduling platform.
Duration: For the duration of the Agreement, and until deletion or return of Personal Data in accordance with Section 8.
4. Nature and Purpose of Processing
Spike Processes Personal Data to:
- Provide incident management and alerting services
- Manage user accounts and authentication
- Deliver notifications via email, SMS, phone calls, Slack, Microsoft Teams, and other integrations
- Maintain system logs and audit trails
- Provide customer support
5. Categories of Personal Data
Personal Data Processed may include:
- Names
- Email addresses
- Phone numbers
- Account credentials (hashed passwords where applicable)
- Incident-related content submitted by users
Spike does not intentionally collect special categories of personal data. The Controller is responsible for the content it and its users submit to the platform, and should not submit special categories of personal data through incident content or other free-text fields.
6. Categories of Data Subjects
- Customer employees
- Authorized users of the Spike platform
- Individuals whose contact information is configured for alerting
7. Technical and Organizational Measures
Spike maintains administrative, technical, and organizational safeguards appropriate to the nature of the data Processed, including:
- Encryption in transit (TLS)
- Encryption at rest via MongoDB Atlas
- Role-based access controls
- Authentication and access restrictions for production systems
- Logging and monitoring of system activity
- Cloud infrastructure hosted on AWS (United States)
- Managed database services via MongoDB Atlas (United States)
A more detailed description is provided in Annex II.
Spike reviews these measures periodically and may update them. Spike will not make changes that materially reduce the overall level of security provided.
8. Confidentiality of Personnel
Spike restricts access to Personal Data to personnel who need that access to perform the Agreement.
All Spike personnel authorised to Process Personal Data are bound by written confidentiality obligations covering Personal Data, whether under an employment contract, a contractor agreement, or a separate confidentiality agreement. These obligations survive the end of that person’s engagement with Spike.
Before personnel are granted access to production systems, Spike verifies their identity against government-issued identification and takes up references with their previous managers, in each case to the extent permitted by applicable law.
Spike provides its personnel with guidance appropriate to their role on the handling and security of Personal Data.
9. Personal Data Breach
Spike will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data.
Notification will be sent to the Controller’s designated security or administrative contact, or, where none is designated, to the account owner’s email address on record. The Controller is responsible for keeping this contact information current.
The notification will describe, to the extent known at the time and supplemented without undue delay as further information becomes available:
- The nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and records concerned
- The likely consequences of the Personal Data Breach
- The measures taken or proposed to address the Personal Data Breach and to mitigate its adverse effects
- A point of contact at Spike from whom further information can be obtained
Spike will assist the Controller, taking into account the nature of Processing and the information available to Spike, in meeting the Controller’s own obligations to notify a Supervisory Authority or affected data subjects under Applicable Data Protection Law.
Spike will document Personal Data Breaches, including the facts, effects, and remedial action taken, and will make that documentation available to the Controller on request.
Spike’s notification of a Personal Data Breach is not an acknowledgement of fault or liability.
10. Deletion and Return of Data
The Controller may request deletion of Personal Data at any time by contacting [email protected].
On termination or expiry of the Agreement, Spike will, at the Controller’s election, delete or return the Personal Data it Processes on the Controller’s behalf. The Controller must communicate its election within 30 days of termination or expiry. Where no election is communicated within that period, Spike will delete the Personal Data.
Spike will complete deletion or return within 60 days of the Controller’s election or, where no election is made, within 60 days of the end of the 30-day election period. Deletion covers existing copies, subject to the paragraph below.
Spike may retain Personal Data where required by law to which it is subject, and only for as long as that law requires. Personal Data retained on this basis remains subject to the protections of this DPA, and Spike will Process it only for the purpose that requires its retention. Encrypted backups follow their ordinary rotation cycle and are overwritten in the normal course, and remain subject to this DPA until overwritten.
Spike will confirm deletion in writing on the Controller’s request.
11. Subprocessors
The Controller gives Spike general written authorisation to engage Subprocessors to provide infrastructure and communication services necessary for platform operation.
The current list of Subprocessors is published and maintained on our GDPR page and is incorporated into this DPA by reference as Annex III. It identifies each Subprocessor, the purpose for which it is engaged, and its location.
Notice and objection. Spike will give the Controller at least 14 days’ notice before a new Subprocessor begins Processing Personal Data, or before an existing Subprocessor is engaged for a materially different purpose. Notice will be given by email to the Controller’s designated contact, or, where none is designated, to the account owner’s email address on record.
The Controller may object to a new Subprocessor on reasonable grounds relating to data protection by notifying Spike in writing within 14 days of the notice. The parties will work together in good faith to find a resolution, which may include Spike offering an alternative arrangement or a change to the affected functionality. If no resolution is reached within 30 days of the objection, the Controller may terminate the affected part of the services, or the Agreement where the affected functionality is essential to it, without penalty and with a pro-rata refund of prepaid fees for the terminated portion.
Terms and liability. Spike will impose on each Subprocessor, by written contract, data protection obligations that are materially equivalent to those in this DPA and that meet the requirements of Applicable Data Protection Law. Spike remains fully liable to the Controller for the performance of each Subprocessor’s obligations.
Where a Subprocessor is located outside the EEA, the UK, or another jurisdiction benefiting from an adequacy decision, Spike will put in place an appropriate transfer mechanism as described in Section 13.
Emergency engagement. Where a Subprocessor must be engaged at shorter notice to prevent or address a material service outage or security incident, Spike may do so and will notify the Controller as soon as reasonably practicable, with the objection rights above applying from the date of that notice.
12. Assistance to the Controller
Taking into account the nature of the Processing and the information available to Spike, Spike will provide reasonable assistance to the Controller in relation to:
- Security of Processing, including the measures described in Annex II
- Notification of Personal Data Breaches to a Supervisory Authority and communication to data subjects
- Data protection impact assessments
- Prior consultation with a Supervisory Authority
Spike will assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights under Applicable Data Protection Law. Where Spike receives such a request directly from a data subject in respect of the Controller’s Personal Data, Spike will not respond to it substantively, and will refer the data subject to the Controller and notify the Controller without undue delay.
Spike may charge a reasonable fee for assistance that is materially beyond the scope of the platform’s standard functionality, and will tell the Controller before any such fee is incurred.
13. International Data Transfers
FatSync Software Private Limited (“Spike”) is incorporated in India and operates the Spike platform using infrastructure hosted in the United States. Spike personnel access production systems from India. Processing therefore takes place in the United States and India, and in the locations of the Subprocessors listed in Annex III.
EEA transfers. Where Personal Data originating in the European Economic Area is transferred to Spike or further transferred to a Subprocessor outside the EEA, the transfer is governed by the Standard Contractual Clauses. For transfers between the Controller and Spike, Module Two (Controller to Processor) applies. Where the Controller acts as a processor on behalf of a third-party controller, Module Three (Processor to Processor) applies.
The Standard Contractual Clauses are incorporated into this DPA by reference and form part of it, completed as follows:
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 11 of this DPA.
- In Clause 11, the optional independent dispute resolution provision does not apply.
- In Clause 17, the governing law is the law of Ireland.
- In Clause 18(b), the forum is the courts of Ireland.
- Annex I, Annex II, and Annex III to the Standard Contractual Clauses are completed by Annex I, Annex II, and Annex III to this DPA respectively.
The full text of the Standard Contractual Clauses is available from the official EUR-Lex publication.
UK transfers. Where Personal Data originating in the United Kingdom is transferred to Spike or further transferred to a Subprocessor outside the UK, the transfer is governed by the Standard Contractual Clauses as amended and supplemented by the UK Addendum. The UK Addendum is incorporated into this DPA by reference and is completed as set out in Annex IV. Where the UK Addendum conflicts with the Standard Contractual Clauses, the UK Addendum prevails in respect of UK transfers.
Government access requests. If Spike receives a legally binding request from a government, law enforcement, or other public authority for disclosure of the Controller’s Personal Data, Spike will notify the Controller without undue delay so that the Controller may seek a protective order or other remedy, unless Spike is legally prohibited from giving that notice. Where notice is prohibited, Spike will use reasonable efforts to obtain a waiver of the prohibition and will provide as much information as it lawfully can, as soon as it lawfully can. Spike will review each request for lawfulness and will challenge any request it considers unlawful, overbroad, or inconsistent with Applicable Data Protection Law. Spike will disclose only the minimum amount of data necessary to respond to a request it is legally obliged to meet.
Spike does not grant any government or public authority direct or unrestricted access to Personal Data, and does not maintain any back door or similar means of access to its systems.
14. Audit Rights
Spike will make available to the Controller the information necessary to demonstrate compliance with the obligations in this DPA and with Article 28 of the EU GDPR and UK GDPR. This includes Spike’s security documentation, its responses to reasonable security questionnaires, and any third-party audit reports or certifications Spike holds.
Where the information above is not sufficient for the Controller to demonstrate compliance, Spike will allow for and contribute to an audit or inspection conducted by the Controller or an auditor mandated by the Controller, subject to the following:
- The Controller gives at least 30 days’ written notice, except where an audit is required by a Supervisory Authority or follows a Personal Data Breach affecting the Controller’s Personal Data, in which case a shorter reasonable notice period applies.
- Audits take place during business hours, are conducted so as to cause minimum disruption to Spike’s operations, and do not require Spike to disclose information relating to other customers or to compromise the security of its systems.
- Audits are limited to once in any twelve-month period, except where required by a Supervisory Authority or following a Personal Data Breach affecting the Controller’s Personal Data.
- The Controller and its auditors are bound by confidentiality obligations covering all information obtained. Spike may require an auditor that is a competitor of Spike to be replaced with an independent third party.
- The Controller bears the cost of any on-site or third-party audit, other than where the audit reveals material non-compliance by Spike with this DPA.
The Controller will share the findings of any audit with Spike.
15. Changes to this DPA
Spike may update this DPA to reflect changes in Applicable Data Protection Law, changes to the platform, or improvements to its commitments. Updates are published with a new version number and effective date, and a summary of changes is maintained on our GDPR page.
Where an update strengthens Spike’s obligations or leaves the protections in this DPA materially unchanged, it takes effect on the published effective date.
Where an update would materially reduce the protections in this DPA in respect of an existing Agreement, Spike will give the Controller at least 30 days’ notice by email to the account owner’s address on record before it takes effect, and will not apply the change to that Agreement without the Controller’s agreement.
Annex I — Description of Processing
Controller: The customer entity entering into the Agreement. Contact details are those provided in the customer’s account or in the Agreement.
Processor: FatSync Software Private Limited, operating as Spike. Data protection contact: [email protected].
Processing Description: Provision of the incident management and alerting platform, including user account management, notification delivery via email, SMS, phone, and chat integrations, logging and audit trails, and customer support.
Data Subjects: Customer employees, authorized users of the platform, and individuals whose contact information is configured for alerting.
Categories of Personal Data: Names, email addresses, phone numbers, account credentials (hashed where applicable), incident content submitted by users, and system metadata including access and activity logs.
Special Categories of Personal Data: None. Spike does not intentionally collect special categories of personal data.
Frequency of Transfer: Continuous for the duration of service use.
Nature of Processing: Collection, storage, retrieval, use, transmission, and deletion, as necessary to provide the platform.
Purpose of Processing: Provision of the Spike platform under the Agreement.
Retention Period: For the duration of the Agreement and thereafter as set out in Section 10 of this DPA.
Locations of Processing: United States (AWS and MongoDB Atlas hosting), India (Spike personnel access and support operations), and the locations of the Subprocessors identified in Annex III.
Subprocessor Transfers: The subject matter, nature, and duration of Processing by each Subprocessor are as set out in the Subprocessor List incorporated as Annex III.
Competent Supervisory Authority: For EEA transfers, the Supervisory Authority of the EEA member state in which the Controller is established or, where the Controller is not established in the EEA, the Supervisory Authority of the member state in which its Article 27 representative is appointed. For UK transfers, the Information Commissioner’s Office.
Annex II — Technical and Organizational Measures
Spike maintains the following technical and organizational safeguards:
Infrastructure and Hosting: Spike’s production infrastructure is hosted on Amazon Web Services (AWS) in the United States. Customer data is stored in MongoDB Atlas hosted in the United States.
Encryption: All data in transit is encrypted using TLS. All data at rest is encrypted using MongoDB Atlas encryption-at-rest mechanisms.
Access Control: Production system access is restricted to specifically authorized personnel. Access to AWS and MongoDB Atlas administrative accounts is limited to named individuals. Multi-factor authentication (MFA) is enforced for AWS root, IAM administrative users, and MongoDB Atlas administrative accounts.
Least Privilege: Access to production systems is granted based on role and operational necessity. Production data access is restricted to a small number of authorized individuals, and the access list is reviewed periodically and on any change in personnel or role.
Personnel: Before access to production systems is granted, Spike verifies the individual’s identity against government-issued identification and takes up references with their previous managers. Personnel with production access are bound by written confidentiality obligations as described in Section 8.
Logging and Monitoring: System activity and production access are logged. Operational logs are maintained to support troubleshooting and security monitoring.
Business Continuity: Customer data is backed up on a regular schedule. Backups are encrypted and are subject to the same access restrictions as production data.
Data Deletion: Customer data may be deleted upon request through documented internal procedures. On termination of service, customer data is deleted in accordance with Section 10 of this DPA.
Certifications: Spike is working towards SOC 2 compliance. Current status and any resulting reports are available from [email protected] on request.
Annex III — Subprocessors
The Controller authorises Spike to engage the Subprocessors published on Spike’s GDPR page at https://spike.sh/gdpr/ (the “Subprocessor List”). The Subprocessor List is incorporated into this DPA by reference and constitutes Annex III. It identifies each Subprocessor, the purpose for which it is engaged, and its location.
Spike maintains the Subprocessor List, and any changes to it are handled in accordance with Section 11.
Annex IV — UK International Data Transfer Addendum
This Annex completes the UK Addendum. It applies only to transfers of Personal Data subject to UK GDPR.
Table 1: Parties
| Exporter | Importer | |
|---|---|---|
| Role | Controller | Processor |
| Party details | The customer entity entering into the Agreement, as identified in the customer’s account or the Agreement | FatSync Software Private Limited, an Indian private limited company operating as Spike. CIN U72900PN2019PTC183459. Registered office: L3/404, Bramha Sun City, Vadgaon Sheri, Pune, Maharashtra 411014, India |
| Key contact | As provided in the customer’s account or the Agreement | [email protected] |
| Signature | Entering into the Agreement constitutes signature of this Addendum | Entering into the Agreement constitutes signature of this Addendum |
Table 2: Selected SCCs, Modules and Selected Clauses
The UK Addendum attaches to the Standard Contractual Clauses as incorporated in Section 13 of this DPA, with the Module, clause selections, and options set out in that Section.
Table 3: Appendix Information
- Annex 1A (List of Parties): as set out in Table 1 above and in Annex I to this DPA.
- Annex 1B (Description of Transfer): as set out in Annex I to this DPA.
- Annex II (Technical and Organisational Measures): as set out in Annex II to this DPA.
- Annex III (List of Subprocessors): as set out in Annex III to this DPA.
Table 4: Ending this Addendum when the Approved Addendum Changes
Neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.
The UK Addendum incorporates the Standard Contractual Clauses as amended by Part 2 of the UK Addendum, including the substitution of UK GDPR for EU GDPR, the Information Commissioner as the relevant Supervisory Authority, and the law and courts of England and Wales in place of the Clause 17 and Clause 18 selections in Section 13 of this DPA.
For any further assistance, please email [[email protected]](mailto:[email protected]). This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement (“Agreement”) between FatSync Software Private Limited, an Indian private limited company operating the Spike platform (“Spike”, “Processor”, “we”, “us”), and the customer entity using Spike’s services (“Controller”). This DPA applies where Spike processes Personal Data on behalf of the Controller in connection with the provision of the Spike incident management and alerting platform. This DPA is incorporated into the Agreement by reference. Where this DPA conflicts with the Agreement in relation to the Processing of Personal Data, this DPA prevails. Where this DPA conflicts with the Standard Contractual Clauses or the UK Addendum, those clauses prevail. **Version 2.0. Effective 14 September 2026.** A summary of changes from version 1.0 is available on our [GDPR page](/gdpr#dpa-version-history). ## 1. Definitions “Personal Data” means any information relating to an identified or identifiable natural person. “Processing” means any operation performed on Personal Data, including collection, storage, use, transmission, or deletion. “Applicable Data Protection Law” means all laws applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the UK General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018 (“UK GDPR”), the UK Data Protection Act 2018, and the Indian Digital Personal Data Protection Act 2023, in each case as applicable to the relevant Processing. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Spike or a Subprocessor. “Subprocessor” means any third party engaged by Spike to Process Personal Data on behalf of the Controller. “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner under section 119A of the UK Data Protection Act 2018. “Supervisory Authority” means an independent public authority established under Applicable Data Protection Law. ## 2. Roles of the Parties The Controller determines the purposes and means of Processing Personal Data. Spike acts as a Processor and Processes Personal Data only on documented instructions from the Controller, as described in the Agreement and this DPA, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by law to which Spike is subject. Where Spike is required by law to Process Personal Data other than on the Controller’s instructions, Spike will inform the Controller of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest. Spike will inform the Controller without undue delay if, in Spike’s opinion, an instruction from the Controller infringes Applicable Data Protection Law. Spike may suspend performance of the affected instruction until the Controller confirms, amends, or withdraws it. ## 3. Subject Matter and Duration of Processing **Subject Matter:** Provision of the Spike incident management, alerting, escalation, and on-call scheduling platform. **Duration:** For the duration of the Agreement, and until deletion or return of Personal Data in accordance with Section 8. ## 4. Nature and Purpose of Processing Spike Processes Personal Data to: - Provide incident management and alerting services - Manage user accounts and authentication - Deliver notifications via email, SMS, phone calls, Slack, Microsoft Teams, and other integrations - Maintain system logs and audit trails - Provide customer support ## 5. Categories of Personal Data Personal Data Processed may include: - Names - Email addresses - Phone numbers - Account credentials (hashed passwords where applicable) - Incident-related content submitted by users Spike does not intentionally collect special categories of personal data. The Controller is responsible for the content it and its users submit to the platform, and should not submit special categories of personal data through incident content or other free-text fields. ## 6. Categories of Data Subjects - Customer employees - Authorized users of the Spike platform - Individuals whose contact information is configured for alerting ## 7. Technical and Organizational Measures Spike maintains administrative, technical, and organizational safeguards appropriate to the nature of the data Processed, including: - Encryption in transit (TLS) - Encryption at rest via MongoDB Atlas - Role-based access controls - Authentication and access restrictions for production systems - Logging and monitoring of system activity - Cloud infrastructure hosted on AWS (United States) - Managed database services via MongoDB Atlas (United States) A more detailed description is provided in Annex II. Spike reviews these measures periodically and may update them. Spike will not make changes that materially reduce the overall level of security provided. ## 8. Confidentiality of Personnel Spike restricts access to Personal Data to personnel who need that access to perform the Agreement. All Spike personnel authorised to Process Personal Data are bound by written confidentiality obligations covering Personal Data, whether under an employment contract, a contractor agreement, or a separate confidentiality agreement. These obligations survive the end of that person’s engagement with Spike. Before personnel are granted access to production systems, Spike verifies their identity against government-issued identification and takes up references with their previous managers, in each case to the extent permitted by applicable law. Spike provides its personnel with guidance appropriate to their role on the handling and security of Personal Data. ## 9. Personal Data Breach Spike will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data. Notification will be sent to the Controller’s designated security or administrative contact, or, where none is designated, to the account owner’s email address on record. The Controller is responsible for keeping this contact information current. The notification will describe, to the extent known at the time and supplemented without undue delay as further information becomes available: - The nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and records concerned - The likely consequences of the Personal Data Breach - The measures taken or proposed to address the Personal Data Breach and to mitigate its adverse effects - A point of contact at Spike from whom further information can be obtained Spike will assist the Controller, taking into account the nature of Processing and the information available to Spike, in meeting the Controller’s own obligations to notify a Supervisory Authority or affected data subjects under Applicable Data Protection Law. Spike will document Personal Data Breaches, including the facts, effects, and remedial action taken, and will make that documentation available to the Controller on request. Spike’s notification of a Personal Data Breach is not an acknowledgement of fault or liability. ## 10. Deletion and Return of Data The Controller may request deletion of Personal Data at any time by contacting [[email protected]](mailto:[email protected]). On termination or expiry of the Agreement, Spike will, at the Controller’s election, delete or return the Personal Data it Processes on the Controller’s behalf. The Controller must communicate its election within 30 days of termination or expiry. Where no election is communicated within that period, Spike will delete the Personal Data. Spike will complete deletion or return within 60 days of the Controller’s election or, where no election is made, within 60 days of the end of the 30-day election period. Deletion covers existing copies, subject to the paragraph below. Spike may retain Personal Data where required by law to which it is subject, and only for as long as that law requires. Personal Data retained on this basis remains subject to the protections of this DPA, and Spike will Process it only for the purpose that requires its retention. Encrypted backups follow their ordinary rotation cycle and are overwritten in the normal course, and remain subject to this DPA until overwritten. Spike will confirm deletion in writing on the Controller’s request. ## 11. Subprocessors The Controller gives Spike general written authorisation to engage Subprocessors to provide infrastructure and communication services necessary for platform operation. The current list of Subprocessors is published and maintained on our [GDPR page](/gdpr) and is incorporated into this DPA by reference as Annex III. It identifies each Subprocessor, the purpose for which it is engaged, and its location. **Notice and objection.** Spike will give the Controller at least 14 days’ notice before a new Subprocessor begins Processing Personal Data, or before an existing Subprocessor is engaged for a materially different purpose. Notice will be given by email to the Controller’s designated contact, or, where none is designated, to the account owner’s email address on record. The Controller may object to a new Subprocessor on reasonable grounds relating to data protection by notifying Spike in writing within 14 days of the notice. The parties will work together in good faith to find a resolution, which may include Spike offering an alternative arrangement or a change to the affected functionality. If no resolution is reached within 30 days of the objection, the Controller may terminate the affected part of the services, or the Agreement where the affected functionality is essential to it, without penalty and with a pro-rata refund of prepaid fees for the terminated portion. **Terms and liability.** Spike will impose on each Subprocessor, by written contract, data protection obligations that are materially equivalent to those in this DPA and that meet the requirements of Applicable Data Protection Law. Spike remains fully liable to the Controller for the performance of each Subprocessor’s obligations. Where a Subprocessor is located outside the EEA, the UK, or another jurisdiction benefiting from an adequacy decision, Spike will put in place an appropriate transfer mechanism as described in Section 13. **Emergency engagement.** Where a Subprocessor must be engaged at shorter notice to prevent or address a material service outage or security incident, Spike may do so and will notify the Controller as soon as reasonably practicable, with the objection rights above applying from the date of that notice. ## 12. Assistance to the Controller Taking into account the nature of the Processing and the information available to Spike, Spike will provide reasonable assistance to the Controller in relation to: - Security of Processing, including the measures described in Annex II - Notification of Personal Data Breaches to a Supervisory Authority and communication to data subjects - Data protection impact assessments - Prior consultation with a Supervisory Authority Spike will assist the Controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects exercising their rights under Applicable Data Protection Law. Where Spike receives such a request directly from a data subject in respect of the Controller’s Personal Data, Spike will not respond to it substantively, and will refer the data subject to the Controller and notify the Controller without undue delay. Spike may charge a reasonable fee for assistance that is materially beyond the scope of the platform’s standard functionality, and will tell the Controller before any such fee is incurred. ## 13. International Data Transfers FatSync Software Private Limited (“Spike”) is incorporated in India and operates the Spike platform using infrastructure hosted in the United States. Spike personnel access production systems from India. Processing therefore takes place in the United States and India, and in the locations of the Subprocessors listed in Annex III. **EEA transfers.** Where Personal Data originating in the European Economic Area is transferred to Spike or further transferred to a Subprocessor outside the EEA, the transfer is governed by the Standard Contractual Clauses. For transfers between the Controller and Spike, Module Two (Controller to Processor) applies. Where the Controller acts as a processor on behalf of a third-party controller, Module Three (Processor to Processor) applies. The Standard Contractual Clauses are incorporated into this DPA by reference and form part of it, completed as follows: - The optional docking clause in Clause 7 does not apply. - In Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 11 of this DPA. - In Clause 11, the optional independent dispute resolution provision does not apply. - In Clause 17, the governing law is the law of Ireland. - In Clause 18(b), the forum is the courts of Ireland. - Annex I, Annex II, and Annex III to the Standard Contractual Clauses are completed by Annex I, Annex II, and Annex III to this DPA respectively. The full text of the Standard Contractual Clauses is available from the [official EUR-Lex publication](https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj). **UK transfers.** Where Personal Data originating in the United Kingdom is transferred to Spike or further transferred to a Subprocessor outside the UK, the transfer is governed by the Standard Contractual Clauses as amended and supplemented by the UK Addendum. The UK Addendum is incorporated into this DPA by reference and is completed as set out in Annex IV. Where the UK Addendum conflicts with the Standard Contractual Clauses, the UK Addendum prevails in respect of UK transfers. **Government access requests.** If Spike receives a legally binding request from a government, law enforcement, or other public authority for disclosure of the Controller’s Personal Data, Spike will notify the Controller without undue delay so that the Controller may seek a protective order or other remedy, unless Spike is legally prohibited from giving that notice. Where notice is prohibited, Spike will use reasonable efforts to obtain a waiver of the prohibition and will provide as much information as it lawfully can, as soon as it lawfully can. Spike will review each request for lawfulness and will challenge any request it considers unlawful, overbroad, or inconsistent with Applicable Data Protection Law. Spike will disclose only the minimum amount of data necessary to respond to a request it is legally obliged to meet. Spike does not grant any government or public authority direct or unrestricted access to Personal Data, and does not maintain any back door or similar means of access to its systems. ## 14. Audit Rights Spike will make available to the Controller the information necessary to demonstrate compliance with the obligations in this DPA and with Article 28 of the EU GDPR and UK GDPR. This includes Spike’s security documentation, its responses to reasonable security questionnaires, and any third-party audit reports or certifications Spike holds. Where the information above is not sufficient for the Controller to demonstrate compliance, Spike will allow for and contribute to an audit or inspection conducted by the Controller or an auditor mandated by the Controller, subject to the following: - The Controller gives at least 30 days’ written notice, except where an audit is required by a Supervisory Authority or follows a Personal Data Breach affecting the Controller’s Personal Data, in which case a shorter reasonable notice period applies. - Audits take place during business hours, are conducted so as to cause minimum disruption to Spike’s operations, and do not require Spike to disclose information relating to other customers or to compromise the security of its systems. - Audits are limited to once in any twelve-month period, except where required by a Supervisory Authority or following a Personal Data Breach affecting the Controller’s Personal Data. - The Controller and its auditors are bound by confidentiality obligations covering all information obtained. Spike may require an auditor that is a competitor of Spike to be replaced with an independent third party. - The Controller bears the cost of any on-site or third-party audit, other than where the audit reveals material non-compliance by Spike with this DPA. The Controller will share the findings of any audit with Spike. ## 15. Changes to this DPA Spike may update this DPA to reflect changes in Applicable Data Protection Law, changes to the platform, or improvements to its commitments. Updates are published with a new version number and effective date, and a summary of changes is maintained on our [GDPR page](/gdpr). Where an update strengthens Spike’s obligations or leaves the protections in this DPA materially unchanged, it takes effect on the published effective date. Where an update would materially reduce the protections in this DPA in respect of an existing Agreement, Spike will give the Controller at least 30 days’ notice by email to the account owner’s address on record before it takes effect, and will not apply the change to that Agreement without the Controller’s agreement. ## Annex I — Description of Processing **Controller:** The customer entity entering into the Agreement. Contact details are those provided in the customer’s account or in the Agreement. **Processor:** FatSync Software Private Limited, operating as Spike. Data protection contact: [[email protected]](mailto:[email protected]). **Processing Description:** Provision of the incident management and alerting platform, including user account management, notification delivery via email, SMS, phone, and chat integrations, logging and audit trails, and customer support. **Data Subjects:** Customer employees, authorized users of the platform, and individuals whose contact information is configured for alerting. **Categories of Personal Data:** Names, email addresses, phone numbers, account credentials (hashed where applicable), incident content submitted by users, and system metadata including access and activity logs. **Special Categories of Personal Data:** None. Spike does not intentionally collect special categories of personal data. **Frequency of Transfer:** Continuous for the duration of service use. **Nature of Processing:** Collection, storage, retrieval, use, transmission, and deletion, as necessary to provide the platform. **Purpose of Processing:** Provision of the Spike platform under the Agreement. **Retention Period:** For the duration of the Agreement and thereafter as set out in Section 10 of this DPA. **Locations of Processing:** United States (AWS and MongoDB Atlas hosting), India (Spike personnel access and support operations), and the locations of the Subprocessors identified in Annex III. **Subprocessor Transfers:** The subject matter, nature, and duration of Processing by each Subprocessor are as set out in the Subprocessor List incorporated as Annex III. **Competent Supervisory Authority:** For EEA transfers, the Supervisory Authority of the EEA member state in which the Controller is established or, where the Controller is not established in the EEA, the Supervisory Authority of the member state in which its Article 27 representative is appointed. For UK transfers, the Information Commissioner’s Office. ## Annex II — Technical and Organizational Measures Spike maintains the following technical and organizational safeguards: **Infrastructure and Hosting:** Spike’s production infrastructure is hosted on Amazon Web Services (AWS) in the United States. Customer data is stored in MongoDB Atlas hosted in the United States. **Encryption:** All data in transit is encrypted using TLS. All data at rest is encrypted using MongoDB Atlas encryption-at-rest mechanisms. **Access Control:** Production system access is restricted to specifically authorized personnel. Access to AWS and MongoDB Atlas administrative accounts is limited to named individuals. Multi-factor authentication (MFA) is enforced for AWS root, IAM administrative users, and MongoDB Atlas administrative accounts. **Least Privilege:** Access to production systems is granted based on role and operational necessity. Production data access is restricted to a small number of authorized individuals, and the access list is reviewed periodically and on any change in personnel or role. **Personnel:** Before access to production systems is granted, Spike verifies the individual's identity against government-issued identification and takes up references with their previous managers. Personnel with production access are bound by written confidentiality obligations as described in Section 8. **Logging and Monitoring:** System activity and production access are logged. Operational logs are maintained to support troubleshooting and security monitoring. **Business Continuity:** Customer data is backed up on a regular schedule. Backups are encrypted and are subject to the same access restrictions as production data. **Data Deletion:** Customer data may be deleted upon request through documented internal procedures. On termination of service, customer data is deleted in accordance with Section 10 of this DPA. **Certifications:** Spike is working towards SOC 2 compliance. Current status and any resulting reports are available from [[email protected]](mailto:[email protected]) on request. ## Annex III — Subprocessors The Controller authorises Spike to engage the Subprocessors published on Spike’s GDPR page at [https://spike.sh/gdpr/](https://spike.sh/gdpr/) (the “Subprocessor List”). The Subprocessor List is incorporated into this DPA by reference and constitutes Annex III. It identifies each Subprocessor, the purpose for which it is engaged, and its location. Spike maintains the Subprocessor List, and any changes to it are handled in accordance with Section 11. ## Annex IV — UK International Data Transfer Addendum This Annex completes the UK Addendum. It applies only to transfers of Personal Data subject to UK GDPR. **Table 1: Parties** | | Exporter | Importer | | --- | --- | --- | | Role | Controller | Processor | | Party details | The customer entity entering into the Agreement, as identified in the customer’s account or the Agreement | FatSync Software Private Limited, an Indian private limited company operating as Spike. CIN U72900PN2019PTC183459. Registered office: L3/404, Bramha Sun City, Vadgaon Sheri, Pune, Maharashtra 411014, India | | Key contact | As provided in the customer’s account or the Agreement | [email protected] | | Signature | Entering into the Agreement constitutes signature of this Addendum | Entering into the Agreement constitutes signature of this Addendum | **Table 2: Selected SCCs, Modules and Selected Clauses** The UK Addendum attaches to the Standard Contractual Clauses as incorporated in Section 13 of this DPA, with the Module, clause selections, and options set out in that Section. **Table 3: Appendix Information** - Annex 1A (List of Parties): as set out in Table 1 above and in Annex I to this DPA. - Annex 1B (Description of Transfer): as set out in Annex I to this DPA. - Annex II (Technical and Organisational Measures): as set out in Annex II to this DPA. - Annex III (List of Subprocessors): as set out in Annex III to this DPA. **Table 4: Ending this Addendum when the Approved Addendum Changes** Neither party may end the UK Addendum as set out in Section 19 of the UK Addendum. The UK Addendum incorporates the Standard Contractual Clauses as amended by Part 2 of the UK Addendum, including the substitution of UK GDPR for EU GDPR, the Information Commissioner as the relevant Supervisory Authority, and the law and courts of England and Wales in place of the Clause 17 and Clause 18 selections in Section 13 of this DPA.