Metproof

Data processing agreement

Made under Article 28 of Regulation (EU) 2016/679 (GDPR) and Portuguese Law 58/2019 between the holder of the Metproof account who accepts it at registration or in the billing area (the Customer, controller) and José Mendonça, tax number (NIF) PT207822166, trading as Metproof, a StackCare product (the Provider, processor). It is accepted electronically when the account is created; the date and version accepted are recorded. It forms part of the Metproof terms of service.

1. Subject matter, nature and purpose

  1. The Provider processes personal data on the Customer's behalf only to provide the Metproof service: receiving and storing tickets imported or sent by the Customer's helpdesk, calculating service level agreement (SLA) compliance, showing dashboards, and generating and sending reports and alerts, by email and, on the Customer's instruction, to the Customer's own Slack or Teams channels.
  2. Processing consists of receiving, storing, calculating, displaying, emailing, copying and deleting data. The Provider looks at the Customer's data only when strictly necessary to diagnose and fix a problem, or when the Customer asks.
  3. The Provider does not use the data for other purposes, its own or third parties'.

2. Types of data and categories of data subjects

  1. Data subjects: the Customer's staff (service users and support agents) and, to the extent they appear in the uploaded data, people who opened or are mentioned in tickets and contacts of the Customer's own clients.
  2. Data: ticket identifier, priority, status and dates; the assigned agent's name; the name and report recipient email address of each end client; the Customer's user data (name, email, role). A ticket title is stored only if the Customer imports it, and appears in reports only if the Customer turns it on for that end client. The service does not store ticket bodies, requesters or attachments.
  3. Special categories: the service is not meant to process Article 9 GDPR data or criminal conviction data. The Customer agrees not to upload it, including in ticket titles.
  4. The Customer tells the Provider of any relevant change to the types of data processed.

3. Duration

This agreement lasts while the Customer has an active account and afterwards until all data is deleted under section 11.

4. Customer's instructions

  1. The Provider processes data only on the Customer's documented instructions: those in this agreement, those given through the service settings (for example the retention period) and those given in writing, including email.
  2. If the Provider believes an instruction breaches the GDPR, it informs the Customer immediately and may suspend carrying it out.
  3. If the law requires the Provider to process data otherwise, it informs the Customer beforehand unless the law forbids it.

5. Confidentiality

People authorised to process the data are bound by a confidentiality commitment or a legal duty of confidentiality. At this date the only person processing is the Provider.

6. Security of processing

  1. The Provider applies the measures in Appendix B, appropriate to the risk (GDPR Article 32), and may update them without lowering the level of security.
  2. The Customer is responsible for the security of its user accounts, in particular passwords, two-factor authentication and public report links it shares.

7. Sub-processors

  1. The Customer gives the Provider general authorisation to use sub-processors. Those in use are on the subprocessor list, which is Appendix A.
  2. The Provider emails the Customer at least 30 days before adding or replacing one.
  3. The Customer may object on reasonable grounds within that period. If no agreement is reached, it may close the account at no extra cost before the change takes effect.
  4. The Provider imposes equivalent data protection obligations on sub-processors and remains responsible to the Customer for their compliance.

8. International transfers

  1. Data is processed and stored in data centres in the European Economic Area (Germany).
  2. The Provider does not transfer personal data outside the European Economic Area without the Customer's written authorisation and the safeguards of GDPR Chapter V.

9. Assistance to the Customer

  1. The Provider helps the Customer respond to data subject requests (access, rectification, erasure, restriction, portability) and meet GDPR Articles 32 to 36. The service lets the Customer delete end clients (and with them their tickets and reports), replace agents' names on tickets with pseudonyms, set the retention period and delete the account; the Provider supplies a copy of the data on request.
  2. If the Provider receives a request directly from a data subject, it forwards it to the Customer without delay and does not reply without instructions.

10. Personal data breaches

  1. The Provider notifies the Customer without undue delay and at most 48 hours after becoming aware of a breach affecting the Customer's data.
  2. The notice includes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Missing information follows in stages.
  3. Notifying the Portuguese data protection authority (CNPD) and data subjects is the Customer's job. The Provider gives it the information it needs to do so within 72 hours.

11. End of processing: return and deletion

  1. While the account exists the Customer can export and delete its data, including deleting the account, which deletes all data immediately (backups expire as set out in Appendix B). For 30 days after closure the Provider gives the Customer a copy of the data on request.
  2. Thirty days after closure the Provider deletes the Customer's personal data unless the law requires keeping it. Data in backups is deleted when they expire, within the maximum period in Appendix B.
  3. The Provider confirms deletion in writing on the Customer's request.
  4. During the term the service automatically deletes resolved tickets and reports older than the retention period the Customer has set (24 months if it does not change it).

12. Audits and information

  1. The Provider makes available the information needed to show compliance with GDPR Article 28, in particular the current description of the Appendix B measures and of the sub-processors.
  2. The Customer, or an auditor it appoints who is bound by confidentiality, may audit compliance with this agreement on 15 working days' notice, at most once a year unless after a breach, without access to other customers' data. Costs are the Customer's.

13. Liability and precedence

  1. Liability for damage caused by processing is governed by GDPR Article 82 and, between the parties, by the service terms, as far as the law allows.
  2. If this agreement and the service terms conflict on data protection, this agreement prevails.

Appendix A: sub-processors

See the current subprocessor list.

EntityServiceLocation
Hetzner Online GmbHHosting server and backup storage (Storage Box)Germany
WebTugaSending email: reports, SLA alerts, account verificationPortugal

Appendix B: technical and organisational measures

Access

Backups

Systems

Monitoring and incidents

Minimisation

Version 2026-10-02.1