Data Processing Addendum
Back to dashboardEffective date: July 22, 2026
This Data Processing Addendum ("DPA") forms part of the Leoric Watch Terms of Service when Leoric Watch processes personal data on behalf of a customer. It describes how Leoric Watch processes customer personal data for uptime monitoring, alerting, reporting, billing support, mobile push notifications, account management, and optional AI Deep Diagnosis.
1. Roles
For customer monitor configuration, alert destinations, incident records, connected diagnosis sources, and similar service data, the customer is the controller and Leoric Watch is the processor. For Leoric Watch account administration, security, billing records, abuse prevention, product analytics, and legal compliance, Leoric Watch may act as an independent controller as described in the Privacy Policy.
2. Processing Instructions
Leoric Watch processes customer personal data only to provide, secure, maintain, support, and improve the service, to comply with applicable law, and as otherwise instructed through product configuration. Customer configuration of monitors, alert channels, integrations, diagnosis sources, billing actions, and account settings is an instruction to process the related data for those features.
3. Subject Matter and Duration
Processing continues for the duration of the customer's use of Leoric Watch and for any additional period required for deletion, backup expiry, billing, security, fraud prevention, dispute handling, tax, legal, or operational records.
4. Categories of Personal Data
- Account identifiers such as email address, display name, authentication state, and linked OAuth provider identifiers
- Monitor configuration such as endpoint URLs, group names, check settings, response metadata, incidents, and SSL certificate metadata
- Alert destination data such as email addresses, Telegram chat IDs, Discord webhook URLs, generic webhook URLs, optional webhook headers, signing-secret metadata, and delivery diagnostics
- Mobile app and push notification data such as Expo push tokens, device metadata, app version, push permission state, and last-seen metadata
- Monthly report preferences, report recipients, send status, and delivery errors
- Billing identifiers, plan state, subscription status, invoice references, transaction references, and payment-method summaries received from Paddle
- AI Deep Diagnosis configuration such as integration names, provider type, source scope, encrypted connector credentials, connection test status, diagnosis jobs, connector status metadata, redaction counts, token counts, model metadata, probable causes, supporting evidence, and suggested next steps
- Security and operational data such as IP addresses, audit events, abuse-prevention records, worker heartbeats, and service diagnostics
5. Categories of Data Subjects
- Customer account owners, administrators, and users
- People whose email addresses or delivery destinations are configured for alerts or reports
- People whose personal data appears in customer-configured monitored endpoints, incident metadata, webhook payloads, connected diagnosis sources, logs, repository metadata, or error tracking events
- Billing contacts and payer representatives handled through Paddle
6. AI Deep Diagnosis
AI Deep Diagnosis is optional and available only where the account is entitled to use it. When enabled on a monitor, Leoric Watch may collect bounded incident-time evidence from enabled customer-configured sources that apply to that monitor, such as Sentry, GitHub Actions, AWS CloudWatch Logs, or Grafana Loki.
The diagnosis pipeline decrypts connector credentials only when needed, collects evidence within configured time and item limits, sanitizes common secrets and personal data patterns, reduces evidence before model analysis, and stores the diagnosis result and metadata. Full raw connector payloads are not stored as separate evidence records after diagnosis processing.
The default local deployment uses an Ollama container for model analysis. If Leoric Watch is configured to use an external OpenAI-compatible model provider, reduced and sanitized incident evidence may be sent to that provider for the purpose of producing the diagnosis.
7. Security Measures
- Password storage with bcrypt hashing
- HTTPS/TLS encryption for data in transit
- JWT-based authentication
- OAuth provider access tokens are not stored after identity and verified email checks finish
- AES-GCM encryption for stored AI Deep Diagnosis connector credential payloads
- SSRF validation for monitor, webhook, and diagnosis source URLs where applicable
- Outbound network policy controls for AI Deep Diagnosis source URLs, including private URL blocking by default
- Masked owner-facing display for webhook URLs, Discord URLs, secret-like headers, and signing secrets
- Connector timeouts, diagnosis job timeouts, retry limits, evidence item limits, evidence byte limits, and token budgets
- Role-based admin areas and audit or operational records for security-sensitive activity
8. Subprocessors and Recipients
Leoric Watch uses third-party services and customer-configured recipients depending on the features enabled for an account:
- Email delivery through the SMTP provider configured for the deployment
- Telegram alert delivery when the customer configures a Telegram destination
- Discord alert delivery when the customer configures a Discord webhook
- Customer-configured generic webhooks for alert delivery
- Expo push notification services for mobile push notifications
- Cloudflare Turnstile for CAPTCHA verification when enabled
- Google and GitHub for OAuth authentication when the customer chooses those sign-in methods
- Paddle for payment processing, tax calculation, receipts, invoices, and subscription events
- Google Ads for advertising conversion measurement when enabled
- Customer-configured AI Deep Diagnosis sources such as Sentry, GitHub Actions, AWS CloudWatch Logs, and Grafana Loki
- An external OpenAI-compatible model provider only when Leoric Watch is configured to use one instead of the local Ollama provider
Customer-configured alert destinations and diagnosis sources are selected and controlled by the customer. The customer is responsible for ensuring that those recipients and sources are authorized for the intended processing.
9. International Transfers
Leoric Watch is based in Greece. Some subprocessors, customer-configured recipients, or connected systems may process data outside Greece or outside the European Economic Area. Where GDPR requires a transfer mechanism, the parties will rely on an applicable lawful transfer mechanism for that processing.
10. Data Subject Requests
If Leoric Watch receives a data subject request relating to customer personal data for which the customer is the controller, Leoric Watch will direct the requester to the customer where appropriate. Leoric Watch will provide reasonable assistance through product functionality or support channels, taking into account the nature of the processing.
11. Deletion and Return
Customers can delete monitors, alert channels, diagnosis integrations, and accounts through product functionality where available. Account deletion removes user-owned active application records, including monitors, groups, historical check results, SSL checks, incidents, alert channels, notification settings, authentication tokens, verification tokens, monthly report send-state, and profile data, subject to active subscription restrictions and retained records described in the Privacy Policy and Terms of Service.
Some billing, security, backup, tax, legal, fraud-prevention, dispute, and platform-level operational records may be retained where required or where Leoric Watch has a legitimate business need.
12. Security Incidents
Leoric Watch will notify affected customers without undue delay after becoming aware of a personal data breach affecting customer personal data, where required by applicable law. The notice will include information reasonably available to Leoric Watch to help the customer meet its own legal obligations.
13. Customer Responsibilities
Customers are responsible for the lawfulness of monitored endpoints, alert destinations, webhook recipients, diagnosis source configurations, connector credentials, source scopes, and any personal data made available to Leoric Watch through those configurations. Customers should use least-privilege credentials and avoid connecting sources that contain data unnecessary for incident diagnosis.
14. Contact
For questions about this DPA or Leoric Watch data processing, contact [email protected].
Last updated: July 22, 2026
Leoric Watch | Greece