Privacy Policy
Read our Privacy Policy to understand how we collect, use, and protect your data.
Zaskoku & Haupt GbR (Uptimeify) Version 2.1 · In force from 30 September 2026 · Until then version 1.2 of 2 September 2026 applies
This policy tells you what data we process, why we process it and what rights you have. It covers our website uptimeify.io, our documentation at docs.uptimeify.io and your use of the monitoring application.
This is a translation. The German version of this policy is the authoritative one and prevails in the event of any discrepancy. References to German statutes keep their original citation because German law applies. TDDDG is the German Digital Services Data Protection Act, BDSG the German Federal Data Protection Act.
1. Controller
Zaskoku & Haupt GbR Lange Str. 54 - 56 48683 Ahaus Germany
Represented by Florian Zaskoku and Pascal Haupt Phone: +49 2568 900 9000 Email: hello@uptimeify.io
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
We will appoint a data protection officer as soon as we are legally required to do so. Until then, address data protection enquiries to hello@uptimeify.io.
2. Two roles, one note up front
We process data in two distinct roles, and understanding the difference matters for reading this policy.
As controller we process data for our own purposes: operating the website, pre-contractual steps, your account, billing, support and security. That is what this policy is about.
As processor we handle the data our customers bring into Uptimeify, such as monitored addresses, check results and notification recipients. In that case the customer determines the purposes and means, not us. The basis for this is our data processing agreement. If you encounter Uptimeify through an account set up by your service provider, or through a status page, that provider is your point of contact for the data concerned. Section 9 explains this in more detail.
3. Your rights
You have the right at any time to:
- Access the data we hold about you, its origin, recipients and purpose of processing (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a commonly used, machine readable format (Art. 20 GDPR)
- Withdraw consent with effect for the future, without affecting the lawfulness of processing carried out up to that point (Art. 7 (3) GDPR)
- Lodge a complaint with a supervisory authority, in particular in the member state of your residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
Right to object under Art. 21 GDPR
Where we process data on the basis of a legitimate interest under Art. 6 (1) lit. f GDPR, you may object to that processing on grounds relating to your particular situation. This also applies to profiling based on those provisions. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
Where your data is processed for direct marketing purposes, you may object at any time and without giving reasons. After your objection we will no longer use it for direct marketing. If you withdraw a consent you have given, the processing concerned ends with effect for the future.
Send objections informally to hello@uptimeify.io.
4. Legal bases at a glance
We process personal data on one of the following bases:
- Consent (Art. 6 (1) lit. a GDPR, and additionally Sec. 25 (1) TDDDG where information on your device is accessed)
- Contract or pre-contractual steps (Art. 6 (1) lit. b GDPR)
- Legal obligation (Art. 6 (1) lit. c GDPR), for example tax retention and verification duties
- Legitimate interest (Art. 6 (1) lit. f GDPR)
The applicable basis is stated for each processing activity below.
5. Website
5.1 Hosting and delivery
We operate our website and the monitoring application with Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Further infrastructure is provided by OVH SAS, 2 rue Kellermann, 59100 Roubaix, France, netcup GmbH, UpCloud Ltd and IONOS SE. All locations are within the European Union.
Static content such as images, fonts and scripts is delivered through the content delivery network of BunnyWay d.o.o. (bunny.net), Cesta Komandanta Staneta 4a, 1215 Medvode, Slovenia. In doing so, bunny.net processes technical connection data such as IP address, time, resource requested and browser information. We have restricted delivery to European locations.
The legal basis is Art. 6 (1) lit. f GDPR. We have a legitimate interest in reliable and fast delivery. We have concluded data processing agreements with all of the providers named.
A complete overview of the service providers we use is available at https://uptimeify.io/subprocessors.
5.2 Server log files
When you access our pages, the server automatically records information transmitted by your browser:
- browser type and version
- operating system used
- referrer URL
- hostname of the accessing device
- time of the server request
- IP address
We do not combine this data with other sources. The legal basis is Art. 6 (1) lit. f GDPR; we have a legitimate interest in technically correct delivery, in optimising our website and in defending against attacks. We delete log files after 30 days at the latest, unless a specific security incident makes longer retention necessary for investigation.
5.3 Cookies and consent management
Cookies are small data files stored on your device. They do no harm there. Some are deleted at the end of your visit (session cookies), others remain until you delete them or your browser removes them.
Necessary cookies are set without consent because the website does not work without them, for example for login, session management and security. The legal basis is Sec. 25 (2) TDDDG in conjunction with Art. 6 (1) lit. f GDPR.
All other cookies and comparable technologies are set only after you have consented. The legal basis is Art. 6 (1) lit. a GDPR and Sec. 25 (1) TDDDG. You can change or withdraw your choice at any time through the cookie settings on our website.
In addition to cookies we sometimes use your browser's local storage. Entries stored there remain on your device and are not automatically transmitted to us with every page view. In legal terms we treat them like cookies: for anything that is not technically necessary we obtain your consent first. If you withdraw your consent, we delete the entries concerned.
To obtain and document your consent we use a consent management solution. It stores your choice, the time and technical details about your browser so that we can demonstrate the consent. The legal basis for this is Art. 6 (1) lit. c GDPR.
5.4 Google Analytics
On our public website we use Google Analytics provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We do not use Google Analytics within the monitoring application. Once you are signed in and working in the dashboard or the administration area, no measurement script is loaded. The only exception is the publicly accessible registration path.
Google Analytics analyses how our website is used: pages viewed, time spent, origin, device and individual interactions, for example running one of our free tools, clicking certain buttons or selecting a pricing tier. Recognition technologies such as cookies are used for this. Google partly supplements the collected data through modelling.
What we deliberately do not transmit:
- No query parameters. The address of the page you viewed is truncated at the question mark before transmission. Domains and other details you enter into our free tools therefore never reach Google.
- No personal details. Names, email addresses, company names, domains you monitor and free text entries are not transmitted. This restriction is enforced centrally in our code.
- No cross device linking. Google signals are switched off in our property, so there is no linking with signed in Google accounts.
- No advertising. We do not embed any advertising tags. Advertising storage stays disabled regardless of your choice.
The legal basis is your consent under Art. 6 (1) lit. a GDPR and Sec. 25 (1) TDDDG. Without your consent nothing is loaded and nothing is stored. Consent can be withdrawn at any time.
Data may be transferred to the USA in this context. Google LLC is certified under the EU-US Data Privacy Framework; in addition we base the transfer on standard contractual clauses. We have concluded a data processing agreement with Google.
Further information: https://policies.google.com/privacy
5.5 fastmon (real user monitoring)
We use real user monitoring provided by fastmon labs UG (haftungsbeschränkt), Germany. It lets us measure how quickly our interfaces load for real visitors so that we can improve performance. Technical telemetry is collected, such as load times, page views, browser, device type and approximate origin.
The legal basis is your consent under Art. 6 (1) lit. a GDPR and Sec. 25 (1) TDDDG, because information on your device is accessed for this purpose. Consent can be withdrawn at any time. Processing takes place in Germany. We have concluded a data processing agreement.
5.6 Dealfront (Leadfeeder), identifying visiting companies
On our public website we use Leadfeeder provided by Dealfront Group GmbH, Germany, to identify which companies visit our website. The aim is to identify and approach potential business customers.
We process your IP address and details of the page visit. The IP address is matched against a database in order to determine the company behind it, and is then truncated or discarded. Identifying individual people is not a purpose of this processing. Information on your device is accessed in the process.
The legal basis is your consent under Art. 6 (1) lit. a GDPR and Sec. 25 (1) TDDDG. Without your consent Leadfeeder is not loaded. Consent can be withdrawn at any time. Processing takes place in Germany and we have concluded a data processing agreement.
Further information: https://www.dealfront.com/privacy/
5.7 Origin marker and origin recorded at the account
If you consent to analytics, we store an entry in your browser's local storage that records which page you first arrived on. It holds the page category, the path with the query string removed, the language and the time. It is read for 90 days and then no longer evaluated, it is never transmitted to a third party, and it never contains anything you typed into our free tools.
If you go on to create an account, we save that page category and that path, together with the category of the page on which the registering session began, at your organisation. The purpose is to understand which of our content wins paying customers, an evaluation that runs entirely on our own systems.
The legal basis is your consent under Art. 6 (1) lit. a GDPR and Sec. 25 (1) TDDDG, because information on your device is stored and accessed for this purpose. You give it as a separate item in our cookie settings, next to Google Analytics and real user monitoring, and you can grant or refuse it independently of those.
If you withdraw your consent, we delete the entry in your browser. The origin already recorded at your organisation remains, because at that point it documents how the contract came about, and it is deleted together with the account.
6. Contact and support
6.1 Contact form, email and support enquiries
When you write to us through the contact form or by email, we process your details in order to handle your request and in case of follow up questions. Our mailboxes run on Tuta (Tutao GmbH, Hanover, Germany). The mailboxes are end to end encrypted and sit on servers in Germany.
The legal basis is Art. 6 (1) lit. b GDPR where your enquiry relates to a contract or its preparation, otherwise Art. 6 (1) lit. f GDPR based on our legitimate interest in handling enquiries.
We delete this data once your request has been dealt with and no retention obligations apply, and at the latest three years after the end of the year in which the contact ended.
6.2 Telephone
For our business telephony we use easybell GmbH, Germany. Connection data such as phone numbers, time and duration is generated in the process. If you call us, we process your request as described in section 6.1. We do not record calls.
The legal basis is Art. 6 (1) lit. b or lit. f GDPR.
7. Registration, customer account and billing
Uptimeify is offered exclusively to business customers (Section 1.2 of our Terms).
7.1 Account data
On registration we process company name, address, legal form, name and contact details of the person acting, email address, credentials in encrypted form and the VAT identification number. The legal basis is Art. 6 (1) lit. b GDPR.
7.2 Verification of the VAT identification number
We verify the VAT identification number you provide through the European Commission's VIES system. The number is transmitted to the Commission's system and forwarded from there to the tax administration of the relevant member state. We store the result of the query with a timestamp as evidence.
The legal basis is Art. 6 (1) lit. c GDPR. The check is necessary so that we can invoice correctly for VAT purposes, in particular under the reverse charge procedure. For sole traders and freelancers the VAT identification number can be personal data; for corporations it generally is not.
7.3 Trial and prevention of abuse
After a trial account has expired and been deleted, we retain a minimal technical marker showing that a trial has already been used for your organisation. Its sole purpose is to prevent repeated use of the free trial (Section 3.4.4 of our Terms). It does not allow any conclusions about individual people or about the content of the deleted account.
The legal basis is Art. 6 (1) lit. f GDPR. Our legitimate interest lies in preventing abuse.
7.4 Payment processing
We process payments through Mollie B.V., Netherlands. Your payment data is processed by Mollie; we do not store complete card details. Invoicing and accounting data is processed using Lexware (Haufe-Lexware GmbH & Co. KG, Germany).
The legal basis is Art. 6 (1) lit. b GDPR for processing the payment and Art. 6 (1) lit. c GDPR for retention under tax and commercial law.
7.5 Notifications to you
Account, system and billing emails are sent through Lettermint B.V., Netherlands. The legal basis is Art. 6 (1) lit. b GDPR.
8. Security and logging within your account
We log security relevant events in your account, such as sign ins, changes to access and administrative actions. The purpose is to detect and investigate unauthorised access. The legal basis is Art. 6 (1) lit. f GDPR together with Art. 32 GDPR.
The connection to our website and to the application is encrypted with TLS throughout. Details of our technical and organisational measures are set out in Annex 1 of our data processing agreement.
9. Use of the monitoring application
9.1 Our customers' data
Whatever a customer brings into Uptimeify is processed solely on that customer's behalf and on their instructions: monitored addresses, check results, incident histories, notification recipients, configurations and the diagnostic data generated in the process. The controller is the customer concerned, not us.
The basis for this is our data processing agreement, which forms part of the contract for the use of Uptimeify. It also sets out which sub-processors are involved, where processing takes place and when data is deleted.
To deliver alerts we use Lettermint (email), seven.io and LOX24 (SMS and voice calls). If a customer connects optional services such as Slack, Microsoft Teams, PagerDuty or their own webhooks, we transmit alert data to the provider they have chosen; the customer is responsible for that.
9.2 If you are a user of one of our customers
If you use Uptimeify through an account set up by your service provider or your employer, that organisation is the controller for the data processed there. Please exercise your rights of access, rectification and erasure with them. If such a request reaches us directly, we forward it to the controller and do not answer it ourselves.
9.3 Public status pages
If you visit a status page operated with Uptimeify, the same principle applies to the content shown there: the operator of the status page is the controller. Server log data as described in section 5.2 is generated on our side for technical delivery.
9.4 Mobile apps and push notifications
Our iOS and Android incident management apps are optional. Without them, alerts still reach you by email, SMS, voice call, webhook and through your integrations.
Getting the apps. The apps are distributed through the Apple App Store and Google Play. The download produces data such as the store account's user name, email address and customer number, the time of the download, payment information and a device identifier. We have no influence over that processing. Apple and Google are solely responsible for it as the operators of their respective platforms. All we receive from there is aggregated, non personal statistics.
Push notifications. We send push notifications only if you allow them in your device's system dialog. The legal basis is your consent under Art. 6 (1) lit. a GDPR. You can withdraw it at any time in your device's system settings or in the app settings, without alerts failing to reach you through other channels.
To deliver one, we transmit a wake signal, an alert identifier, the severity and a signed acknowledgement token to your operating system's push service, that is the Apple Push Notification service on iOS and Firebase Cloud Messaging on Android. The alert text travels with it, but sealed: your device generates a key pair when it registers for notifications, we only ever learn the public half, and we encrypt the text with it. Apple and Google carry a block of bytes they cannot open, and the app decrypts it on your device before the notification appears. Until then, and on a device that has registered no key, the lock screen shows a generic line instead.
Device registration. So that we can reach you at all, we store per device the push token, the platform, the app version and the language setting, along with the link to your user account. When you sign out on a device or uninstall the app, we remove the entry; a token reported as invalid by Apple or Google is deleted automatically.
10. Job applications
If you apply to us, we process your application documents, contact details and interview notes to the extent necessary to decide on an employment relationship. The legal bases are Sec. 26 (1) BDSG, Art. 6 (1) lit. b GDPR and, where you have consented, Art. 6 (1) lit. a GDPR.
If no appointment is made, we retain the documents for up to six months after the end of the process in order to defend against possible claims (Art. 6 (1) lit. f GDPR), and delete them afterwards. Inclusion in a talent pool takes place only with your express consent; data held there is deleted no later than two years after consent was given.
11. Retention periods
Where no specific period is stated above, we store data until the purpose no longer applies. We then delete it unless a statutory retention obligation applies.
| Data | Retention |
|---|---|
| Server log files | 30 days, longer only to investigate a security incident |
| Contact enquiries | until resolved, at the latest three years after the end of the year |
| Customer account during the term of the contract | for the duration of the contract |
| Customer content after the contract ends | available for retrieval for 30 days, then deleted, in backups no later than a further 90 days (Section 12.4 of the Terms) |
| Cancelled trial account | deleted 30 days after deactivation (Section 3.4.3 of the Terms) |
| Marker for the prevention of abuse | retained in minimal form until the purpose no longer applies |
| Invoicing and accounting data | statutory retention periods, generally ten years |
| Analytics data in Google Analytics | event data 2 months, user data 14 months |
| Application documents where no appointment is made | six months |
| Consent records | for the duration of the obligation to demonstrate consent |
12. Recipients and transfers to third countries
We pass on personal data only where this is necessary to perform a contract, where we are legally required to do so, where a legitimate interest exists or where you have consented. Where processors are used, a contract under Art. 28 GDPR is in place in each case.
The complete and continuously updated overview of the service providers we use, including role and location, is available at https://uptimeify.io/subprocessors.
All service providers that process monitoring data are established and process within the European Union or the EEA. We operate our databases exclusively at German locations.
Transfers to the USA take place only for individual services supporting general business operations and for the consent based analytics service described in section 5.4. We base these transfers on the EU-US Data Privacy Framework, on standard contractual clauses of the European Commission and on supplementary measures. Despite these safeguards, a level of protection fully comparable to that in the EU cannot be guaranteed in third countries; in particular, access by public authorities cannot be ruled out in every case.
13. Advertising emails
We hereby object to the use of the contact details published in our legal notice for sending advertising that has not been expressly requested. We reserve the right to take legal action.
14. Changes to this policy
We update this policy when the law, our services or our processing activities change. The current version is always available on this page, and every previous version is listed with its validity period in our legal archive. For your use of Uptimeify, the change procedure in Section 20 of our Terms applies in addition.
Version 2.1 · In force from 30 September 2026 · Until then version 1.2 of 2 September 2026 applies