Subprocessor FAQs – Stripe
LogicMonitor Legal
- Terms of Service
- Compliance
- Privacy
- ESG
Current as of April 2024
1. What is a subprocessor?
A subprocessor is a third-party engaged by LogicMonitor to process data on LogicMonitor’s behalf for the purpose of fulfilling LogicMonitor’s obligations as a data processor under GDPR. Subprocessors operate according to LogicMonitor’s instructions and are bound by specific data protection terms. LogicMonitor enters into a contract with each subprocessor that contains the same data protection obligations as those set out in the DPA between LogicMonitor (as processor) and Customer (as controller) and, of course, LogicMonitor is fully liable for each such subprocessor’s compliance with its data protection obligations.
2. Where can I find a list of LogicMonitor’s then current subprocessors?
LogicMonitor’s subprocessors are listed in LogicMonitor’s Data Handling Supplement, available at https://www.logicmonitor.com/data-handling-supplement. These subprocessors provide certain ancillary services that support LogicMonitor’s service, including data center hosting, live support chat and SMS notification. The residency of the data stored and processed by each of LogicMonitor’s subprocessors is indicated on our Data Handling Supplement.
3. Why did I get an email about updates to LogicMonitor’s subprocessor list?
LogicMonitor is generally required by applicable law (notably, the EU’s General Data Protection Regulation (“GDPR”)) to provide updates to Customers when there are changes to our subprocessors. While some Customers may not be subject to applicable regulations that necessitate such a communication, LogicMonitor has chosen to err on the side of transparency and communicate this proposed change to its entire Customer-base, given the paramount importance we place on trust.
4. What impact will this update to LogicMonitor’s list of subprocessors have on my organization as a LogicMonitor Customer?
No impact. LogicMonitor’s services will continue to be provided as is, without change.
5. Do I need to take any action when I receive subprocessor notification?
No. The subprocessor notification is provided for your information as required by law and does not require any action on the part of your organization.
6. Do LogicMonitor subprocessors have access to the data stored in our account?
LogicMonitor relies on each subprocessor for different purposes, some of which may include the storage and processing of certain types of Customer Data. Subprocessors operate only according to LogicMonitor’s explicit instructions and are bound by specific data protection terms.
7. As a general matter, what personal data of its Customers does LogicMonitor process (including via its subprocessors)?
The focus of LogicMonitor’s service is to provide observability for our Customers’ technology environments via the collection, aggregation, and analysis of metric and log data. Any personal data processed by LogicMonitor in connection with the service is incidental. This incidental personal data is limited to the end-user of the service (i.e., to log in to the portal). These personal data elements may include name, email address, mobile device number (optionally), and workstation IP address. None of the incidental personal data processed by LogicMonitor is deemed sensitive under GDPR.
8. Can you provide any further background on the reasons that LogicMonitor has chosen to engage Stripe as a subprocessor?
In order to increase our technical capabilities regarding processing of payments, LogicMonitor has replaced our PCI Level 1 Merchant Zuora with our new PCI Level 1 Merchant Stripe, for payment processing.
A “PCI Level 1 Merchant” must adhere to the most stringent Payment Card Industry Data Security Standards (PCI DSS) and mandates. These include:
-
- Comprehensive security management, policies, procedures, network architecture, and software designed to protect cardholder data; and
- An annual on-site audit by a Qualified Security Assessor (QSA); and
- Complete network vulnerability scans by an Approved Scan Vendor (ASV) to verify the implementation and effectiveness of these security measures.
For more information regarding PCI DSS compliance and certifications, you can visit: https://usa.visa.com/splisting/splistinglearnmore.html
To access the Stripe Privacy Center, click on this link.
*NOTE: For your security, LogicMonitor does not collect or store cardholder data. This is why we use only PCI DSS Level 1 Merchants for payment processing.
9. When does the Stripe change go into effect?
LogicMonitor’s ongoing change of its current PCI Level 1 Merchant is already in effect, but will not interrupt or impact the delivery of your services.
10. Where can I go for further information?
Please review the Privacy resources posted at https://www.logicmonitor.com/legal.