Overview
These Data Processing Terms (the "DPA") form part of, and are incorporated into, the Terms of Service between you ("Customer," "you") and PageLantern LLC, a Texas limited liability company, doing business as PageLantern ("PageLantern," "we," "us"). Capitalized terms not defined here have the meaning given in the Terms of Service.
This DPA is self-executing. It applies automatically to every customer, on acceptance of the Terms of Service, without a signature ceremony. If your procurement process requires a countersigned copy, email privacy@pagelantern.com and we will provide one on these terms; we do not negotiate variations for self-serve plans.
"Data Protection Laws" means all laws applicable to the processing of Customer Personal Data, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended by the CPRA ("CCPA"). "Customer Personal Data" means personal data contained in Customer Content that PageLantern processes on your behalf.
1. Roles of the Parties
For Customer Personal Data, you are the controller (or, where you process on behalf of another controller, a processor) and PageLantern is the processor (or sub-processor). Under US state privacy laws, you are the business or controller and PageLantern is a service provider, contractor or processor.
This DPA applies only to the data for which PageLantern acts as a processor: the monitoring content you configure and the material generated from it — monitor configurations, authentication profiles and secrets used to run probes, probe results and operational telemetry, browser-check artifacts (screenshots, HAR captures, console logs), alert and webhook destinations, public status pages and their subscriber lists, and the incident and report content you create.
PageLantern acts as an independent controller for the data described in our Privacy Notice as controller data — account and identity data, authentication and session data, API key metadata, organization and membership data, billing records, audit logs, website data, in-app feedback and aggregate operational data. That processing is governed by the Privacy Notice, not by this DPA.
Where the same information falls into both categories, the role that applies is determined by who decides the purposes and means of the processing in question, not by where the data is stored.
2. Subject Matter, Duration, Nature and Purpose (Article 28(3) particulars)
Subject matter. The provision of the PageLantern monitoring service as described in the Terms of Service and our documentation.
Duration. For the term of your account, plus the export and deletion periods described in Section 12.
Nature and purpose. Hosting, storing, transmitting, structuring, retrieving, displaying, analysing and deleting Customer Personal Data in order to configure and execute monitoring checks against the targets you specify; to generate, store and display probe results, incidents, dashboards, reports and audit records; to deliver notifications to the destinations you configure; to publish your status pages and send status updates to your subscribers; to secure the Service and investigate abuse; and to provide support.
The types of personal data and categories of data subjects are set out in Annex I. Annex II describes the technical and organizational measures.
3. Processing on Documented Instructions
PageLantern will process Customer Personal Data only on your documented instructions, including for international transfers, unless required to do otherwise by law applicable to us — in which case we will inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.
Your documented instructions consist of: the Terms of Service; this DPA; the configuration you create in the Service and through the API; and any further written instruction you give that we accept.
You instruct and authorize us to create and use aggregated and de-identified data derived from operation of the Service, as described in Section 14 of the Terms of Service and Section 13 below.
You are responsible for the lawfulness of your instructions, for having a legal basis for the Customer Personal Data you configure into the Service or cause it to capture, and for giving individuals any notice or obtaining any consent required — including for status-page subscribers, alert recipients and the subjects of monitored targets.
If we consider that an instruction infringes Data Protection Laws, we will inform you without undue delay and may suspend performance of that instruction until it is withdrawn, amended or confirmed.
PageLantern will not sell or share Customer Personal Data, will not retain, use or disclose it for any purpose other than performing the Service and the purposes permitted by this DPA, will not use it outside the direct business relationship between us, and will not combine it with personal data received from another source except as permitted by the CCPA. PageLantern certifies that it understands and will comply with these restrictions.
4. Confidentiality of Personnel
PageLantern ensures that every person authorized to process Customer Personal Data — whether personnel, contractor or agent — is subject to an appropriate statutory or contractual duty of confidentiality that survives the end of their engagement, and is granted access only to the extent required to perform their role.
Access to production systems containing Customer Personal Data is limited to those who need it to operate, secure and support the Service, and is logged.
5. Security of Processing (Article 32)
PageLantern implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are described in Annex II.
We may update our measures over time. We will not make a change that materially reduces the overall level of security we provide.
Annex II states, accurately, which data is protected by which mechanism — including that heartbeat tokens are the one credential-bearing monitor field stored without field-level encryption (because an inbound ping is authenticated by matching the token value), while the other credential-bearing fields you complete are encrypted at rest. You should take that into account when deciding what to place in them.
6. Sub-Processors
You give PageLantern general authorization to engage sub-processors to process Customer Personal Data. The current list, with each provider's purpose, the data involved and its region where known, is published at pagelantern.com/subprocessors.
Before a new sub-processor begins processing Customer Personal Data, we will update that page and give account owners at least 30 days' advance notice by email — except where a change must be made on shorter notice for security or legal reasons, in which case we will give notice as soon as reasonably practicable.
You may object to a new sub-processor on reasonable data-protection grounds by emailing privacy@pagelantern.com within 30 days of notice. We will work with you in good faith to find an alternative. If we cannot, your sole and exclusive remedy is to terminate the affected part of the Service, without penalty, and without refund of fees already paid.
We impose on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and we remain fully liable to you for a sub-processor's performance of its obligations.
7. Assistance with Data Subject Rights
The Service gives you controls to access, correct, export and delete Customer Personal Data directly, which is normally the fastest way to respond to a request.
Taking into account the nature of the processing, PageLantern will assist you by appropriate technical and organizational measures, so far as possible, to fulfil your obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making.
If we receive a request directly from an individual relating to Customer Personal Data, we will not respond to it substantively other than to confirm that the request relates to a PageLantern customer, and we will forward it to you without undue delay where we can identify the relevant account. Because the same personal data may appear in more than one customer's configuration, we may be unable to attribute a request without further information.
8. Assistance with Security, Breaches, and Impact Assessments (Articles 32–36)
Taking into account the nature of the processing and the information available to us, PageLantern will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR and UK GDPR — security of processing, personal data breach notification to the supervisory authority and to individuals, data protection impact assessments, and prior consultation.
That assistance consists of providing the information in this DPA and its annexes, our published security documentation, completed security questionnaires, and reasonable answers to specific questions. Where assistance requires materially more than that, we may charge our reasonable costs, on notice to you before the work is done.
9. Personal Data Breach Notification
PageLantern will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We deliberately do not commit to a fixed number of hours: an accurate notification is more useful to you than a fast one, and the obligation to notify your supervisory authority within 72 hours is yours as controller and runs from when you become aware.
Our notification will describe, so far as we can at the time, the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information in phases as the investigation progresses.
Where PageLantern acts as processor, you as controller are responsible for any notification to a supervisory authority and to affected individuals. Our obligation is to notify you and to provide reasonable assistance. Notifying you is not an acknowledgement of fault or liability.
Report a suspected security issue to security@pagelantern.com.
10. Audits and Information Rights
PageLantern will make available to you the information necessary to demonstrate compliance with Article 28 and will allow for and contribute to audits, including inspections, conducted by you or another auditor you mandate.
In the first instance, that obligation is satisfied by our published security documentation, this DPA and its annexes, any third-party certification or report we hold, and completed security questionnaires, which we will provide on request.
Where that information is genuinely insufficient and a Data Protection Law requires more, you may conduct an audit subject to the following: no more than once in any 12-month period; at least 30 days' written advance notice; during business hours; without unreasonably disrupting the Service; under an obligation of confidentiality; with no access to another customer's data, to information confidential to another customer, or to information whose disclosure would compromise the security of the Service; and at your cost, including reimbursement of our reasonable costs at our then-standard rates.
An additional audit may be conducted where a supervisory authority requires it, or following a confirmed personal data breach materially affecting your Customer Personal Data.
11. International Transfers
PageLantern is established in the United States, and our sub-processors may process Customer Personal Data in the United States and elsewhere.
Where Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an applicable adequacy decision, the transfer is governed by the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference and completed as follows: Module Two (controller to processor) applies where you are a controller; Module Three (processor to sub-processor) applies where you are a processor; Clause 7 (docking) applies; under Clause 9 the general written authorization option applies with the 30-day notice period in Section 6; the Clause 11 optional independent-dispute-resolution language does not apply; under Clause 17 the Clauses are governed by the law of Ireland; under Clause 18(b) disputes are resolved before the courts of Ireland; Annex I and Annex II of this DPA populate Annexes I and II of the Clauses; and Annex III is the sub-processor list at pagelantern.com/subprocessors.
For transfers from the United Kingdom, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies, with the Clauses above as the Approved EU SCCs, Tables 1 to 3 completed by reference to this DPA and its annexes, and neither party able to terminate under Table 4.
For transfers from Switzerland, the Standard Contractual Clauses apply with the amendments recognized by the Swiss Federal Data Protection and Information Commissioner: the FDPIC is the competent supervisory authority, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the term "member state" does not prevent a data subject in Switzerland from bringing proceedings in Switzerland.
Transfer impact. We have no reason to believe that the laws and practices of the United States applicable to us prevent us from meeting our obligations under the Clauses, taking into account the nature of the data, the limited categories of Customer Personal Data involved, and the measures in Annex II. We will notify you if we become aware of a change.
Government access. PageLantern has not received a government request for access to Customer Personal Data of the kind described in Clause 15 of the Standard Contractual Clauses. If we receive one, we will challenge it where there is a reasonable basis to do so, will disclose only the minimum necessary, and will notify you unless legally prohibited — in which case we will use reasonable efforts to obtain a waiver of the prohibition.
Representatives. Where Article 27 of the GDPR or UK GDPR requires us to designate a representative in the European Union or the United Kingdom, the details of that representative are published in our Privacy Notice.
12. Return and Deletion
On termination or expiry of your account you may, at your choice, export Customer Personal Data or have it deleted. The default is deletion.
Access to the Service ends immediately on termination and public status pages are unpublished. For 30 days afterwards you may sign in to export your monitoring data, incident history and configuration through the interface and the API. After that period we delete Customer Personal Data from active systems within 30 days and from backups within 90 days.
Retention periods continue to apply during the export window, so some data will already have been deleted in the ordinary course — browser-check artifacts are retained for approximately 14 days from capture, probe results for approximately 90 days by default, and monitoring history is limited by your plan.
We may retain Customer Personal Data where a law applicable to us requires it, and we may suspend deletion of data we reasonably believe is subject to a legal hold or preservation obligation. Data retained on that basis remains subject to this DPA.
On request we will confirm in writing that deletion has been completed.
13. Aggregated and De-Identified Data
You instruct and authorize PageLantern to create aggregated and de-identified data from Customer Personal Data, and to use it to operate, secure, troubleshoot and improve the Service, and to produce statistical research and industry benchmarks, in each case as permitted by Section 14 of the Terms of Service.
PageLantern will de-identify by methods reasonably designed to make re-identification technically infeasible; will not attempt to re-identify the data; will contractually require any recipient not to attempt re-identification; and will not disclose it in a form that identifies you, your users or your targets. Under the CCPA, PageLantern may use Customer Personal Data to build or improve its own service quality only as that law permits, and never to provide services to another person.
We do not use Customer Content to train, fine-tune or develop machine-learning models. Where the standard for anonymisation under the GDPR is not met for particular data, we treat that data as personal data and it remains subject to this DPA.
14. Records and Cooperation
PageLantern maintains a record of processing activities carried out on behalf of controllers, as required by Article 30(2) of the GDPR and UK GDPR, and will make it available to a supervisory authority on request.
PageLantern will cooperate, on request, with a supervisory authority in the performance of its tasks.
15. Liability
Claims between you and PageLantern under this DPA are subject to the exclusions and limitations of liability in Section 20 of the Terms of Service, which allocates risk between us. This DPA does not change that allocation.
Nothing in this Section limits or affects an individual's rights under Article 82 of the GDPR or UK GDPR, the rights of data subjects as third-party beneficiaries under the Standard Contractual Clauses, or either party's liability to a supervisory authority.
Where the Standard Contractual Clauses conflict with this DPA or the Terms of Service, the Standard Contractual Clauses prevail.
Annex I — Details of Processing
Data exporter: the Customer, acting as controller (or as processor on behalf of its own controller), whose identity and contact details are those on its PageLantern account. Activities relevant to the transfer: receipt of monitoring, alerting and status-page services. Role: controller or processor as applicable.
Data importer: PageLantern LLC, a Texas limited liability company, doing business as PageLantern, PO Box 340351, Lakeway, TX 78734, contact privacy@pagelantern.com. Activities relevant to the transfer: provision of the PageLantern monitoring service. Role: processor.
Categories of data subjects whose personal data is processed:
- The Customer's personnel and users who configure or are named in monitors, incidents, reports and status pages.
- Individuals the Customer designates as alert or notification recipients, including email addresses, chat destinations and telephone numbers for SMS.
- Individuals who subscribe to the Customer's public status pages.
- Individuals whose personal data appears incidentally in probe artifacts generated from targets the Customer specifies, including in response-body excerpts, screenshots, HAR captures and console logs.
Categories of personal data: identifiers and contact details (names, email addresses, telephone numbers, chat and webhook destinations); monitor configuration supplied by the Customer (URLs, hosts, request methods, headers, request bodies, environment variables, assertions, browser scripts, heartbeat tokens); authentication material the Customer supplies so probes can authenticate to its targets; operational telemetry tied to the Customer's monitors (timestamps, status codes, response times, error messages, TLS certificate details, DNS and domain data, response-body excerpts); browser-check artifacts (screenshots, HAR network captures, console logs); notification delivery metadata with masked destinations; incident, report and status-page content; and status-page subscriber email addresses.
Sensitive data: the Service is not designed for special-category data and the Customer is prohibited from configuring it, as set out in Section 5 of the Terms of Service. Where such data is nevertheless captured incidentally in a probe artifact, the restrictions applied are those in Annex II together with the Customer's own obligation to avoid capturing it and our right to delete it on discovery.
Frequency of transfer: continuous, for the duration of the Customer's account.
Nature and purpose of processing: as stated in Section 2 above.
Retention: as stated in Section 12 above and in the retention section of our Privacy Notice.
Sub-processors: as listed at pagelantern.com/subprocessors, for the purposes and durations stated there.
Competent supervisory authority: determined under Clause 13 of the Standard Contractual Clauses by reference to the Customer's establishment or its Article 27 representative; for UK transfers, the Information Commissioner's Office; for Swiss transfers, the FDPIC.
Annex II — Technical and Organizational Measures
The measures below describe the Service as configured for production operation. They are stated accurately rather than aspirationally, including where a protection does not apply.
- Pseudonymisation and encryption: passwords are stored only as salted, iterated cryptographic hashes; session tokens, API keys, verification and reset tokens, WebAuthn credential identifiers and multi-factor recovery codes are stored only as hashes; multi-factor secrets and destinations and API authentication-profile secrets are encrypted at rest; transport is protected by TLS. The credential-bearing monitor-configuration fields the Customer completes — request header values, request bodies, environment variables, API step definitions, browser scripts and alert webhook URLs — are encrypted at rest with AES-256-GCM. Heartbeat tokens are the one exception and are stored unencrypted, because an inbound heartbeat ping is authenticated by matching the token value; they are masked in interfaces and logs. The Company does not provide transparent, database-wide encryption at rest.
- Access control: role-based access within a customer workspace; multi-factor authentication and passkeys available on all accounts; server-side sessions storing only a hash of the session token; an httpOnly, SameSite session cookie marked Secure in production; API keys scoped, expirable and revocable, displayed once at creation.
- Confidentiality and integrity of processing: secrets masked in interfaces and logs; a production hardening check that prevents startup with development secrets or an insecure database connection; separation of customer workspaces at the application layer.
- Network protection for probes: by default probes refuse requests resolving to private, loopback, link-local, carrier-grade-NAT, multicast or IPv4-mapped IPv6 addresses, block known cloud-metadata endpoints, permit only HTTP and HTTPS, and re-validate each redirect hop. These are security measures, not guarantees.
- Logging and accountability: an audit trail recording the acting user, client IP address, user-agent and event details, with safe client-IP resolution; application logs with masked request paths; notification delivery records storing only masked destinations.
- Availability and resilience: backups of application data, and configurable data-retention jobs that delete data on the schedules described in Section 12.
- Testing and evaluation: automated test coverage including security-tagged tests, dependency review, and a published vulnerability disclosure policy with a coordinated-disclosure process and safe harbour.
- Sub-processor governance: written terms with each sub-processor imposing obligations no less protective than this DPA, a published named list, and 30 days' advance notice of change.
- Measures for the transfer: the Standard Contractual Clauses and UK Addendum described in Section 11, together with the technical measures above and the government-access commitments in that Section.
Contact and Related Documents
Contact us about these Data Processing Terms, a sub-processor objection, an audit request, or a countersigned copy using the details below.
- Data protection and privacy
- privacy@pagelantern.com
- Security reports
- security@pagelantern.com
- Terms of Service
- pagelantern.com/terms
- Privacy Notice
- pagelantern.com/privacy
- Sub-processors
- pagelantern.com/subprocessors
Postal address: PO Box 340351, Lakeway, TX 78734.
