1. Parties and scope
This DPA applies between ESSORIX LTD, trading as GreenSlope ("Processor"), and the GreenSlope customer ("Controller") when GreenSlope processes Personal Data on the customer's behalf.
2. Processing instructions
GreenSlope processes Personal Data only to provide, secure, support, and improve the GreenSlope service, and only on documented customer instructions expressed through product configuration, this DPA, and the Terms of Service.
3. Categories of data
Processed data may include:
- account owner and user contact details;
- billing and subscription metadata;
- OpenTelemetry trace attributes sent by the customer;
- release, deploy, alert, and incident metadata; and
- support communications.
GreenSlope is not intended for special-category data, protected health information, payment-card data, secrets, or unnecessary personal data in telemetry.
4. Security measures
GreenSlope applies technical and organisational measures appropriate for launch use, including TLS for data in transit, managed encryption at rest, role-scoped internal access, short retention, audit logging for administrative activity, and a public sub-processor list.
5. Sub-processors
Customer authorises GreenSlope to engage the sub-processors listed at https://greenslope.io/legal/subprocessors. We commit not to add sub-processors silently. Material additions are communicated to affected customers before they take effect.
6. Data subject requests
Taking into account the nature of processing, GreenSlope helps customers respond to data subject requests where customer-controlled data is held in GreenSlope. Contact privacy [at] greenslope [dot] io for privacy requests.
7. Personal data breaches
If GreenSlope becomes aware of a personal data breach affecting customer Personal Data, we will notify affected customers without undue delay and provide the information reasonably available to support customer obligations.
8. Deletion and return
Customer telemetry is retained for the periods described in the Privacy Policy and security docs. After retention, data is deleted. At account closure, remaining customer data is deleted after the applicable grace and retention periods.
9. International transfers
GreenSlope uses an EU processing region for launch. Where a sub-processor involves transfer outside the EEA or UK, GreenSlope relies on adequacy decisions, Standard Contractual Clauses, the UK IDTA, or an equivalent lawful transfer mechanism.
10. Audits and evidence
GreenSlope supports customer audit obligations through published Legal Documents, security documentation, sub-processor disclosures, and written answers to reasonable security questions. SOC 2 and ISO 27001 attestations have not yet been pursued.
11. Contact
For DPA questions, email legal [at] greenslope [dot] io.