Subprocessors

A transparent overview of the third-party subprocessors and service providers we use to deliver our services.

Last updated: September 17, 2026

Uptimeify (Zaskoku & Haupt GbR) uses certain third-party subprocessors to assist in providing our services. A subprocessor is a third-party data processor who may have access to personal data of our customers or their end-users in order to provide services to Uptimeify.

This page provides information about the identity, location, and role of each subprocessor we use. We will update this page from time to time to reflect changes in our subprocessors.

Where we watch them

Most of the providers on this page publish their own availability, and we read it: they appear on our dependency status page alongside the other services we track. Four do not appear there, and the reason is the same in each case: there is nothing machine-readable to read. easybell publishes a plain web page and nothing else; LOX24's status address does not resolve at all. fastmon and Tuta publish data, but through undocumented, single-purpose endpoints that could change without notice. Tuta's even carries a report ID in its path, and the page shows no incident history at all. We would rather show nothing than show something we cannot stand behind.

Service Subprocessors

These providers are involved in operating the Uptimeify platform itself. Monitoring Data indicates whether customer account data or monitoring data (e.g. monitored URLs, check results, alert contents, notification recipients) is processed by this subprocessor to deliver our services.

  • Hetzner Online GmbH

    Cloud provider

    Hosting of our application, databases, object storage, error tracking (self-hosted), and monitoring infrastructure.

    Monitoring Data Germany
  • OVH SAS

    Cloud provider

    Server infrastructure for monitoring check locations and backups.

    Monitoring Data France / EEA
  • netcup GmbH

    Cloud provider

    Hosting for monitoring check nodes, Redis queues (job queues) and databases.

    Monitoring Data Germany
  • UpCloud Ltd

    Cloud provider

    Hosting for monitoring check nodes, Redis queues (job queues) and databases.

    Monitoring Data Finland (EU)
  • IONOS SE (IONOS Cloud)

    Cloud provider

    Server infrastructure for monitoring check nodes.

    Monitoring Data Germany (EU)
  • BunnyWay d.o.o. (bunny.net)

    CDN

    Delivery of static website assets via an EU-based content delivery network.

    No Monitoring Data Slovenia (EU)
  • Lettermint B.V.

    Email delivery & inbound processing

    Transactional email delivery (alert notifications, reports, account emails, and public status page subscription confirmations and updates when the organization has not configured its own SMTP server) and inbound processing of alert-forwarding emails for the email alert-source integration (e.g. a customer forwarding a monitoring tool's alert email to their Uptimeify ingest address).

    Monitoring Data Netherlands (EU)
  • seven communications GmbH & Co. KG (seven.io)

    SMS & voice delivery

    Primary provider for SMS and voice alert notifications. Receives the recipient's phone number and the notification content.

    Monitoring Data Germany
  • LOX24 GmbH

    SMS & voice delivery (failover)

    Secondary provider for SMS and voice alert notifications, used only when our primary provider (seven.io) cannot deliver. Receives the recipient's phone number and the notification content.

    Monitoring Data Germany
  • Mollie B.V.

    Payments

    Payment processing for subscriptions. Processes billing data only, no monitoring data.

    No Monitoring Data Netherlands (EU)
  • Google (Analytics)

    Website analytics

    Consent-based analytics on our public website. Only active after explicit cookie consent, never inside the monitoring application.

    No Monitoring Data United States / EEA (DPF)
  • fastmon labs UG (haftungsbeschränkt)

    Real user monitoring

    Real user monitoring (RUM): collects performance and page-load telemetry from visitors of the Uptimeify web application to measure and improve front-end performance.

    No Monitoring Data Germany
  • Dealfront Group GmbH (Leadfeeder)

    Website visitor analytics

    B2B company identification on our public website. The IP address is matched against a company database to reveal which companies visit the site, for sales and marketing, and is then truncated or discarded. Identifying individual people is not a purpose of this processing. Without your consent Leadfeeder is not loaded; consent can be withdrawn at any time. Never inside the monitoring application.

    No Monitoring Data Germany

Business Operations

These providers support our internal business operations. They do not process monitoring data.

  • GitHub, Inc.

    Version control

    Source code hosting, version control, and CI/CD pipelines.

    No Monitoring Data United States (DPF)
  • Ubicloud B.V.

    CI/CD compute

    "Managed GitHub Actions runners for our CI/CD pipelines. Processes source code and build secrets, no monitoring data. We contract with Ubicloud B.V. (NL); parent Ubicloud, Inc. is US-based: covered by SCCs."

    No Monitoring Data Netherlands (EU), US parent
  • Haufe-Lexware GmbH & Co. KG (Lexware)

    Accounting & administration

    Financial administration, accounting, and invoicing.

    No Monitoring Data Germany
  • Tutao GmbH (Tuta)

    Mailbox provider

    Email hosting for employee and shared mailboxes. Support inquiries sent to us by email are processed here. Mailboxes are end to end encrypted and the servers are located in Germany.

    No Monitoring Data Germany
  • easybell GmbH

    Telephony / VoIP

    Business telephony (SIP trunk and cloud PBX) for our company phone line. Processes call metadata and voice content of inbound and outbound calls; no monitoring data.

    No Monitoring Data Germany

Mobile Apps (optional)

Our iOS and Android incident management apps are optional. You do not need them to use Uptimeify: alerts still reach you by email, SMS, voice call, webhook and through the integrations you configure.

If you install an app and enable push notifications, delivery necessarily runs through your operating system vendor's push service. There is no other route to an iOS or Android lock screen. For that case, these providers act as subprocessors of Uptimeify.

What we transmit: the push carries a wake signal, an alert identifier, the severity, a signed acknowledgement token and the alert text in encrypted form. Your device generates a key pair when it registers and tells us only the public half; the private half never leaves the device. Apple and Google therefore carry a block they cannot open, and receive no monitoring data from us. Decryption happens on the device before the notification appears; with no key registered, the lock screen shows a generic line.

This section takes effect on 30 September 2026, together with the release of the apps. Until then Uptimeify sends no push notifications and no data reaches either provider.

  • A

    Apple Distribution International Ltd. (APNs)

    Push delivery, iOS

    Delivery of push notifications to iOS devices. Receives push token, device identifier, IP address and delivery timestamp.

    No Monitoring Data Ireland, infrastructure partly United States
  • Google Ireland Limited (Firebase Cloud Messaging)

    Push delivery, Android

    Delivery of push notifications to Android devices. Receives push token, device identifier, IP address and delivery timestamp.

    No Monitoring Data Ireland, infrastructure partly United States

If you do not install an app, or if you disable push notifications, no data is transmitted to these providers.

Downloads from the App Store or Google Play happen outside our reach. Apple and Google process the resulting data such as store account, downloads and device model under their own responsibility. For that they are not subprocessors of ours but controllers in their own right. See our privacy policy for details.

Optional Integrations

Uptimeify lets you connect third-party services to receive alert notifications. These integrations are optional and only become active when you configure them yourself. When you connect an integration, alert data (e.g. monitor name, status, error details) is transmitted to the provider you chose, under your own agreement with that provider. They are therefore not subprocessors of Uptimeify.

Slack
Discord
Telegram
PagerDuty
Pushover
Opsgenie
All Quiet
Matrix
Jira
Google Chat
Mattermost
Rocket.Chat
ntfy
Gotify
ilert
Grafana OnCall
incident.io
Squadcast
GitHub
GitLab
Linear
ServiceNow
Lark
DingTalk
WeCom
Custom Webhooks

International Data Transfers

Our core infrastructure is hosted exclusively in the European Union. For any transfers of personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place through:

  • Adequacy decisions (where the European Commission has determined that a third country ensures an adequate level of protection)
  • The EU-US Data Privacy Framework (DPF) for certified US providers
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical and organizational measures to protect personal data

Updates to Subprocessors

We may update our list of subprocessors from time to time. We will notify customers of any new subprocessors in accordance with the terms of our Data Processing Agreement.

All changes to our infrastructure and subprocessors are also published in our infrastructure changelog. Subscribe to its RSS feed to be notified automatically.

Objecting to Subprocessors

If you are a customer of Uptimeify and wish to object to a new subprocessor, please contact us promptly at hello@uptimeify.io. If we determine that your objection is reasonable, we will work with you to find a mutually acceptable resolution. If we cannot reach a resolution, you may terminate your agreement with us in accordance with the terms of your contract.

If you have questions or concerns about any of our subprocessors, please contact us at hello@uptimeify.io.