Skip to content

Legal

Data Processing Agreement (DPA)

Art. 28 GDPR · Last updated: 17 July 2026

Notice: This DPA applies automatically to all users of the fastmon platform and is concluded with binding effect upon acceptance of the Terms at registration. For individual Enterprise constellations with bilateral signature, an extended DPA version is available on request at privacy@fastmon.eu.

§ 1 Contracting parties, order of precedence

(1) Customer, Controller: The user of the "fastmon" platform (entrepreneur within the meaning of Section 14 BGB) whose individual details are recorded in the user profile at contract conclusion.

(2) Provider, Processor:

fastmon labs UG (haftungsbeschränkt)
Stresemannallee 4, 30173 Hannover, Germany
Hannover Local Court, HRB 230880
Managing Directors: Kamil Adrian Czujowski, Lucas Röhrs
Email: privacy@fastmon.eu

(3) This DPA specifies the data protection obligations of the parties arising from the use of the Software-as-a-Service offering fastmon (Real User Monitoring). In the event of conflicts between this DPA and other agreements (in particular the Terms), the provisions of this DPA prevail.

§ 2 Subject, nature and purpose of processing

(1) The Provider makes the SaaS service fastmon available to the Customer. The subject matter is the measurement of performance and availability of websites and web applications operated by the Customer from the perspective of actual end users (Real User Monitoring). Processed are Core Web Vitals (LCP, INP, CLS, TTFB, FCP), Navigation and Resource Timing, technical metadata on browser, operating system, device, viewport, country code (ISO-2) and error events.

(2) The purpose of processing is to provide the dashboard, alerting and performance analysis to the Customer.

(3) Processing of the data for the Provider's own purposes (advertising, profiling, transfer to third parties) does not take place.

(4) The Customer warrants not to transmit personal or personally identifiable data of any kind into fields capable of being recorded by the Provider. This includes in particular URL paths, query strings, anchors, UTM and campaign parameters, freely configurable brand values, tag values and error contexts. Special categories under Art. 9 GDPR and data under Art. 10 GDPR are not processed. Any transmission contrary to this warranty takes place outside the agreed processing purpose and falls within the Customer's area of responsibility.

§ 3 Duration

The duration of this DPA corresponds to the term of the main contract (fastmon usage agreement).

§ 4 Customer's right of instruction

(1) The Provider processes personal data exclusively within the scope of the agreements made and according to documented instructions of the Customer.

(2) Instructions are generally given through the use of the dashboard and API; instructions going beyond this are to be issued in text form to privacy@fastmon.eu.

(3) If the Provider considers an instruction to be in breach of data protection law, it must inform the Customer immediately.

§ 5 Edge server architecture and Stitch identifier

(1) The Provider operates an upstream edge server layer. The IP address and raw User-Agent of the end user are processed there exclusively transiently (less than 1 second in memory) to derive the country code (ISO 3166-1 alpha-2) and browser category, and are discarded immediately thereafter.

(2) The application layer, database and logs do not at any time process or store raw IP addresses or raw User-Agent strings. This property is permanently safeguarded by automated tests.

(3) The Stitch identifier is a server-side computed HMAC-SHA256 hash based on a rotating 24-hour salt, tenant-internal and per-site. Recognition beyond a session, across sites or across devices is technically impossible. The Stitch can be disabled per site (store_stitch=false).

§ 6 Provider's obligations

(1) The Provider ensures that persons authorised to process the data are committed to confidentiality.

(2) The Provider implements the technical and organisational measures described in § 8.

(3) The Provider supports the Customer in complying with the obligations under Art. 32 to 36 GDPR within the scope of the information available to it.

§ 7 Sub-processors

(1) The Customer approves the following sub-processors:

  • Hetzner Online GmbH, Gunzenhausen (DE), hosting, storage, backup (Falkenstein data center, DE)
  • sevdesk GmbH, Offenburg (DE), accounting and invoicing
  • Lettermint B.V., Zwolle (NL), transactional emails
  • Soverin B.V., Rotterdam (NL), business mail
  • BunnyWay d.o.o., Tržič (SI), authoritative DNS service
  • smoxy GmbH, Berlin (DE), ingress
  • Mistral AI SAS, Paris (FR), LLM inference (only when the AI chat function is opted in)
  • ScaleCommerce GmbH, Berlin (DE), hosting
  • All Quiet GmbH, Berlin (DE), on-call tool for fastmon Engineering

(2) With Mollie B.V., Amsterdam (NL), there is no processing on behalf within the meaning of Art. 28 GDPR. Mollie acts as a regulated payment service provider under PSD2 in its own data protection responsibility.

(3) A current list of sub-processors is available at fastmon.eu/en/subprocessors and on request from privacy@fastmon.eu.

(4) If the Provider intends to engage further sub-processors or replace existing ones, it informs the Customer 30 days in advance in text form. The Customer has a right of objection for important data protection reasons. In case of a legitimate objection, the new sub-processor may not be used for the processing of the data of the objecting Customer until an amicable solution has been reached. If no solution is reached within 30 days, the Customer has a right of extraordinary termination of the main contract.

§ 8 Technical and Organisational Measures (TOM)

The Provider implements in particular the following measures pursuant to Art. 32 GDPR:

  • EU-only infrastructure, no data transfer to US providers in the data path
  • TLS encryption of all external connections
  • Edge stripping of IP and User-Agent before the application layer
  • Data minimisation as architectural principle, no cookies and no persistent identifiers in the default mode
  • Tenant separation in the database via tenant IDs
  • Role-based access control, least-privilege principle
  • SSH access only via public key, 2FA for administrative consoles
  • Encrypted database backups, retention 7 days
  • External uptime monitoring and alerting

Detailed TOM documentation available on request from privacy@fastmon.eu.

§ 9 Data subject rights

(1) The Provider supports the Customer in responding to requests of data subjects under Art. 15 to 22 GDPR within the scope of the information available to it.

(2) Due to the data-minimised architecture (edge stripping of IP, no persistent identifiers, 24-hour limit of the Stitch), direct attribution of telemetry data to a natural person is regularly not possible. The Provider points this out in individual cases (Art. 11 GDPR).

(3) If a data subject contacts the Provider directly, the Provider forwards this request to the Customer without delay.

§ 10 Data breaches

The Provider notifies the Customer of any breach of the protection of personal data pursuant to Art. 4 No. 12 GDPR immediately, at the latest within 24 hours of becoming aware. The notification contains at least the nature of the breach, affected data categories, approximate number of data subjects, consequences and measures taken.

§ 11 Deletion and return after end of contract

(1) After termination of the main contract, the Provider deletes the personal data of the Customer within 30 days, including all backups within the regular backup retention.

(2) The Customer can secure its data prior to end of contract via the export interfaces provided in the product.

(3) Storage beyond the end of contract only takes place insofar as statutory retention obligations require it (in particular invoicing data, Section 257 HGB, Section 147 AO, 10 years).

§ 12 Audit rights

(1) The Customer has the right to verify compliance with this DPA. This is primarily done by submission of the current TOM documentation, self-assessments and, if applicable, certificates of sub-processors (Hetzner ISO 27001, All Quiet ISO 27001).

(2) On-site audits are possible with 30 days' prior notice, at most once per calendar year, during normal business hours. The costs are borne by the Customer, and by the Provider in case of a material violation found.

§ 13 Liability

Liability is governed by Art. 82 GDPR and the provisions of the Terms. Liability caps in the Terms do not apply to fines under Art. 83 GDPR, insofar as their cause falls within the Provider's area of responsibility, and to intent and gross negligence.

§ 14 Government and law enforcement requests

(1) If the Provider receives requests from authorities to disclose personal data of the Customer, it examines the lawfulness and discloses only the minimum legally required.

(2) The Provider informs the Customer without delay, insofar as legally permitted.

(3) Processing under the U.S. CLOUD Act, FISA 702 or comparable extraterritorial access regimes is currently not expected, as processing activities take place in the EU or EEA.

§ 15 Final provisions

(1) German law applies, excluding the UN Sales Convention.

(2) Place of jurisdiction is Hannover, unless mandatory statutory provisions provide otherwise.

(3) Amendments to this DPA require text form. In case of conflicts between this DPA and the main contract, the provisions of this DPA prevail with respect to data protection matters.

(4) Should individual provisions be invalid, the validity of the remaining provisions remains unaffected.

fastmon labs UG (haftungsbeschränkt) · Stresemannallee 4, 30173 Hannover · Hannover Local Court HRB 230880