Integration Notification Centre. Service levels.

What you can rely on from the platform that watches your integrations: how it behaves, how it is secured, and how we support you. Written to be read by your IT team as much as by you.

Version 1.0 · Effective 10 June 2026

What the Centre is, and what it is not.

The Integration Notification Centre is Kongo Industries’ monitoring and alerting platform for the integrations we build and operate for you. It receives operational events from those integrations, maintains a live health status for each one, gives your team a dashboard at integrations.hellokongo.com, and emails the people you nominate when something needs attention.

The Centre is a monitoring aid. It is not the system of record for your business data, and it does not process or store the business data flowing through your integrations; it stores operational telemetry only. The presence or absence of an event in the Centre is not evidence that underlying business processing did or did not occur. Service levels for the integrations themselves are agreed per engagement in your Statement of Work.

Continuously monitored, honestly described.

The Centre runs on serverless, multi-availability-zone managed services in the AWS Sydney region, with no single server to fail and capacity allocated on demand. It is itself monitored: automated alarms watch every Centre function and its queues, and page Kongo’s on-call rotation when they fire.

The Centre is provided on a best-efforts basis with continuous monitoring. No numeric availability target applies in this version of these service levels; we may introduce one in a future version once sufficient operating history exists. Events are accepted on an at-least-once-attempt basis: under retry exhaustion or abnormal load an individual event may be deduplicated or not recorded, and we do not warrant delivery of any individual event. Sustained inability of an integration to report surfaces as a missed-heartbeat alert.

How you hear about it before you log in.

TriggerBehaviour
Critical or error eventEmailed immediately, per event, to the recipients you nominate for that integration.
Warning eventsAggregated into one digest email per integration per hour.
Info eventsDashboard only; no email.
Missed heartbeatWhere an expected reporting interval is configured, the integration is marked down and your recipients notified when no event arrives within twice that interval.
RecoveryYour recipients are notified when a degraded or down integration returns to healthy.

You self-manage recipients and the minimum email severity per integration on the dashboard. Notification emails are sent via Amazon SES; delivery to your mailbox is subject to your own mail infrastructure.

The section your IT team will want to read.

Data storedOperational telemetry only: event type, severity, timestamp, message, error details, retry metadata, correlation identifiers, and integration configuration. The Centre is not intended to receive personal or sensitive information; you agree not to include personal information in event payloads beyond the operator contact emails used for alerting.
ResidencyAll data is stored and processed in the AWS Sydney region (ap-southeast-2). No cross-border storage.
EncryptionEncrypted in transit (TLS) and at rest (AWS-managed encryption on all data stores and archives).
Tenant isolationEach client is a separate tenant. Data is partitioned per tenant at the storage layer; API credentials are bound to a single tenant and integration; dashboard sessions carry an immutable tenant claim. Cross-tenant access paths are independently security-reviewed.
Access controlDashboard access is via passwordless email sign-in with 10-minute single-use links. Kongo administrative access is restricted to a named admin group, and every administrative action performed in your tenant context is audit-logged.
CredentialsAPI keys are stored only as cryptographic hashes; the cleartext is shown once at issue and cannot be recovered. Keys are revocable with effect within minutes.
BackupsPoint-in-time recovery is enabled on the primary data store, allowing restore to any point in the preceding 35 days.
RetentionEvents are held live for 90 days, then moved to an encrypted cold archive. Configuration and health data are retained while your integration is active.
Deletion on exitOn termination, API keys are revoked and users disabled immediately; live and archived data are deleted or retained per your engagement’s offboarding terms.
SubprocessorsAmazon Web Services (hosting, Sydney region); Stripe (billing, only where you are usage-billed). No other third party receives your data.
Breach notificationWe will notify you of a confirmed data breach involving your data without undue delay, and in any case within 72 hours of confirmation, consistent with the Australian Notifiable Data Breaches scheme.

Business continuity: the Centre’s architecture is multi-availability-zone within the Sydney region. This version carries no cross-region disaster-recovery commitment; a regional AWS outage would interrupt monitoring until the region recovers. Loss of the Centre does not affect the operation of your integrations themselves; it affects visibility and alerting only.

Where requests land, and how fast.

Email integrations@hellokongo.com. Monitored Monday to Friday, 9:00 to 17:00 AEST/AEDT, excluding national Australian public holidays. Response targets are to first qualified human response, not resolution; incident response for your integrations themselves is governed by your Statement of Work.

PriorityDefinitionResponse target
P1 CriticalCentre dashboard or alerting inaccessible, or a suspected security incident.1 business hour
P2 HighA Centre feature broken with a workaround; alerts not behaving as configured.4 business hours
P3 NormalConfiguration changes, new users, questions.1 business day
P4 LowCosmetic issues, documentation, requests.3 business days

The fine print, kept short.

Remedies. Where we miss a target in these service levels materially or repeatedly, we will review the failure with you and present a remediation plan. This is your sole remedy under these service levels, without limiting your master agreement with us.

Exclusions. Targets do not apply to the extent a failure results from: your systems, network, mail infrastructure, or configuration you control; failure or degradation of third-party platforms your integrations depend on (these are addressed per engagement in your Statement of Work); a regional failure of the underlying cloud provider; suspension for non-payment or misuse; or events beyond our reasonable control.

Maintenance and change. The platform deploys without scheduled downtime windows; releases are zero-downtime in the ordinary course. Where disruptive maintenance is unavoidable, we give at least 2 business days’ notice. Material changes to these service levels are notified 30 days in advance.

Your integration’s own service levels. Response and restoration targets for the integrations we operate for you, including incident priorities and upstream platform dependencies, are agreed per engagement in the Service Levels Schedule attached to your Statement of Work.

Fees. Centre fees are per the subscription tier set out in your Statement of Work, billed by calendar month with automatic tier adjustment in months where your event volume exceeds your tier’s allowance. No per-event surcharges. Annual prepayment is available.