Data Processing Agreement

Last updated: July 10, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (“Controller” / “Data Fiduciary”) and PagerCo India Ltd. (“Processor”) and applies where PagerCo processes personal data on the customer’s behalf. Enterprise customers who require a countersigned DPA may request one at legal@pagerco.ai.

1. Roles & scope

The customer is the Controller/Data Fiduciary of the personal data it submits (including its responders’ contact details and incident data). PagerCo is the Processor and processes such data only on documented instructions from the customer, being the provision of the Service under the Terms.

2. Subject matter of processing

  • Duration: the term of the customer’s subscription, plus deletion periods.
  • Nature & purpose: hosting, routing, notifying and analysing incident and on-call data.
  • Data subjects: the customer’s users, responders and stakeholders.
  • Categories: names, work emails, phone numbers, roles, on-call schedules, incident content and notification metadata.

3. Processor obligations

  • Process personal data only on the customer’s documented instructions, unless required by law.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Assist the customer, taking into account the nature of processing, with data-subject requests, security, breach notification and impact assessments.
  • On termination, delete or return personal data, save where retention is required by law.
  • Make available information reasonably necessary to demonstrate compliance.

4. Subprocessors

The customer authorises PagerCo to engage the subprocessors listed at /subprocessors. PagerCo imposes data-protection obligations on subprocessors substantially similar to those in this DPA and remains responsible for their performance. We will provide notice of new subprocessors as described on that page.

5. International transfers

Where personal data is transferred across borders, the parties will rely on lawful transfer mechanisms (such as standard contractual clauses) to the extent required by applicable law.

6. Security incidents

PagerCo will notify the customer without undue delay after becoming aware of a personal-data breach affecting the customer’s data, and will provide information reasonably available to help the customer meet its notification obligations.

7. Audits

On reasonable prior notice and subject to confidentiality, PagerCo will make available information necessary to demonstrate compliance and, where required by law, allow for audits, which may be satisfied by third-party certifications or reports where available.

8. Liability

Each party’s liability under this DPA is subject to the limitations of liability in the Terms of Service.

9. Contact

To request a signed DPA or raise a data-protection matter: privacy@pagerco.ai.

Questions about this document? Contact us at legal@pagerco.ai.

This document is being finalised and may be updated following legal review.