UptimePoint

Privacy Policy

1. Data Controller

The data controller is UptimePoint. For any questions regarding your data, contact us at contact@uptimepoint.com.

2. Data Collected

We collect the following data: name, email address, payment information (via PayPal or ZyndPay — we do not store banking details), URLs of monitored sites, and monitoring results (response time, HTTP status, etc.).

3. Purposes of Processing

Data is processed to: provide the monitoring service, send alerts and notifications, generate reports, provide customer support, and improve the platform.

4. Legal Basis

Processing is based on contract performance (Article 6.1.b GDPR) for service-necessary data, and consent (Article 6.1.a) for optional marketing communications.

5. Retention Period

Data is retained for the duration of the subscription and up to 12 months after cancellation for monitoring results. Payment data is retained in accordance with legal obligations (5 years).

6. Data Recipients

Data is processed by our hosting provider (Contabo, Germany), payment processors (PayPal, ZyndPay), and transactional email service. These sub-processors comply with GDPR.

7. User Rights

Under GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection. To exercise them, contact us at contact@uptimepoint.com.

8. Cookies

We only use strictly necessary cookies for the platform's operation (session cookie, theme cookie, language cookie). No advertising or third-party tracking cookies are used.

9. International Transfers

Data is hosted in Germany (Contabo). Payment data is processed via PayPal (Luxembourg) and ZyndPay. These transfers are governed by the European Commission's Standard Contractual Clauses.

10. Security

We implement appropriate technical and organizational measures to protect your data: TLS 1.3 encryption, role-based restricted access, strong authentication, regular security audits, encrypted daily backups, and continuous access monitoring.

11. Children

The Platform is not intended for individuals under the age of 16. We do not knowingly collect personal data from minors. If we learn that data from a minor has been collected without parental consent, we will delete it promptly.

12. Data Breach Notification

In the event of a data breach likely to result in a high risk to your rights and freedoms, we will notify you within 72 hours of becoming aware of the incident, in accordance with Article 34 GDPR. This notification will include the nature of the breach, categories of data concerned, measures taken, and recommendations to mitigate potential risks.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on users. Alerts and notifications are generated based on predefined rules (performance thresholds, certificate expiry, etc.) and do not constitute automated decision-making under Article 22 GDPR.

14. Changes to This Policy

We reserve the right to modify this Privacy Policy. Any material changes will be notified to you by email at least 30 days before they take effect. We encourage you to review this page periodically for any updates.

15. Contact and Complaints

For any questions regarding your personal data or to exercise your rights, contact us at contact@uptimepoint.com. You also have the right to lodge a complaint with the competent supervisory authority (CNIL or equivalent) if you believe that the processing of your data does not comply with applicable regulations.