Skip to content

Privacy Policy

As of: September 13, 2026 · Version 1.2

Note: This English translation is provided for convenience only and is non-binding. In case of any discrepancy between the German version and this translation, the German version shall prevail.

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

UptimeSheriff

Niels van Veen

c/o Postflex #8764, Emsdettener Str. 10

48268 Greven, Germany

Email: support@uptimesheriff.com

VAT ID: DE309665873

A Data Protection Officer is currently not appointed pursuant to Art. 37 GDPR in conjunction with § 38 BDSG (German Federal Data Protection Act), as the statutory requirements are not met. For all questions regarding data protection, you can reach us at the email address stated above.

2. Scope

2.1. This privacy policy informs about the nature, scope, and purpose of the processing of personal data in connection with the use of the website and the uptime monitoring service UptimeSheriff(hereinafter "Service").

2.2. Personal data means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR), in particular email addresses, IP addresses, and usage data.

3. Overview of legal bases

Insofar as this privacy policy refers to legal bases, the following apply:

  • Art. 6(1)(a) GDPR (Consent): you have given consent to the processing for one or more specific purposes;
  • Art. 6(1)(b) GDPR (Performance of a contract): the processing is necessary for the performance of the contract with you or for pre-contractual measures;
  • Art. 6(1)(c) GDPR (Legal obligation): the processing is necessary for compliance with a legal obligation to which we are subject;
  • Art. 6(1)(f) GDPR (Legitimate interest): the processing is necessary for the purposes of our legitimate interests, except where such interests are overridden by your interests or fundamental rights.

4. Hosting and server log files (Hetzner)

4.1. The Service is hosted with Hetzner. The server location is in Germany or the European Union.

4.2. Each time the Service is accessed, information transmitted by your browser is automatically collected (server log files). These include:

  • IP address of the accessing device;
  • time of access;
  • page accessed.

4.3. This data is processed to provide the Service, to ensure system security and stability, and for technical error analysis. The server log files are stored for a maximum of 7 days and subsequently deleted.

4.4. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the technically flawless provision and security of the Service.

5. Registration and user account

5.1. A user account is required to use the Service. During registration, we collect:

  • your email address;
  • your password (stored exclusively as a cryptographic hash; we have no access to the plaintext password).

5.2. The processing is necessary for the provision of the user account and the features of the Service. The legal basis is Art. 6(1)(b) GDPR.

5.3. We store the account data until your account is deleted. We retain contract data for 30 days after the end of the contract so that you can export your data; thereafter it is deleted (see § 12).

6. Monitoring data processed on your behalf

6.1. In the Service, you create monitors (URLs and endpoints) and store alert recipients (email addresses as well as Telegram, Slack, or webhook targets).

6.2. Insofar as this data contains personal data (for example, email addresses of your team members), we process it on your behalf pursuant to Art. 28 GDPR. You remain the controller for this data within the meaning of Art. 4(7) GDPR and ensure that an appropriate legal basis exists and that the data subjects have been informed in accordance with Art. 13/14 GDPR.

7.3. We provide a data processing agreement upon request.

7. Alert messages

7.1. If one of your monitors triggers an alert, we send a message to the recipients you have stored. The message contains the information about the affected monitor that is required for the alert.

7.2. Available channels are email, Telegram, Slack, and webhook. You choose the recipients and the channel yourself.

7.3. For third-party channels such as Telegram or Slack, the message is delivered via the infrastructure of the respective provider; these providers process the data in accordance with their own privacy policies. For webhooks, the message is sent to the target you specify.

7.4. The message is sent as processing on your behalf (see § 6). In relation to you, the legal basis is Art. 6(1)(b) GDPR (performance of a contract).

8. Email delivery (Resend)

8.1. We use the service Resend (Plus Five Five, Inc., 2261 Market Street No. 5039, San Francisco, CA 94114, USA) to send emails. This covers account emails (registration confirmation, password reset, confirmation of a new email address) and alert emails (see § 8).

8.2. Emails are sent via Resend's EU infrastructure in Ireland. In doing so, Resend processes the recipient address, the subject and content of the message, and delivery data, and acts as our processor under Art. 28 GDPR on the basis of Resend's Data Processing Agreement.

8.3. Resend is a company based in the USA. For transfers to the USA, we rely on Resend's certification under the EU-US Data Privacy Framework (Art. 45 GDPR) and on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).

8.4. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). We do not send newsletters or marketing emails.

9. Payment processing (Stripe)

9.1. Payment processing for paid subscriptions is carried out by the payment service provider Stripe. In this process, the data required for the payment is transmitted to Stripe.

9.2. Stripe acts partly as our data processor and partly as an independent controller, in particular for fraud prevention and for compliance with its own legal obligations. This is based on Stripe's Data Processing Agreement.

9.3. The legal basis for the transmission to Stripe is Art. 6(1)(b) GDPR (performance of a contract).

10. Invoicing (sevDesk)

10.1. For the creation and management of invoices, we use the service sevDesk. In this process, the data required for invoicing is transmitted to sevDesk.

10.2. We retain invoice data for 10 years (§ 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)).

10.3. The legal basis is Art. 6(1)(b) GDPR (performance of a contract) in conjunction with Art. 6(1)(c) GDPR (tax and commercial law retention obligations).

11. Cookies and local storage

11.1. We do not use any marketing or tracking cookies. There is no user-level tracking and no profiling.

11.2. Only what is technically necessary is stored in your browser: your theme setting in localStorage. This storage is required for the display you have chosen; consent is not required for this (§ 25(2)(2) TDDDG (German Telecommunications Digital Services Data Protection Act)).

11.3. In all other respects, the legal basis is Art. 6(1)(f) GDPR (legitimate interest in the technical provision of the Service).

12. Storage period and deletion

12.1. We store personal data only for as long as necessary for the respective purpose or as statutory retention obligations require. At a glance:

  • Server log files: a maximum of 7 days;
  • Account data: until your account is deleted;
  • Contract data: 30 days after the end of the contract (period for data export), then deletion;
  • Invoice data: 10 years (§ 147 AO (German Fiscal Code), § 257 HGB (German Commercial Code)).

12.2. Data subject to statutory retention periods is blocked for further use and deleted upon expiry of the retention period.

13. Your rights

13.1. Under the GDPR, you have the following rights vis-à-vis us:

  • Access (Art. 15 GDPR): you can request confirmation as to whether we process personal data concerning you, and obtain access to this data as well as information about the processing purposes, recipients, and storage period;
  • Rectification (Art. 16 GDPR): you can request the rectification of inaccurate data or the completion of incomplete data;
  • Erasure (Art. 17 GDPR): you can request the erasure of your data, provided no statutory retention obligations oppose this (see § 12);
  • Restriction of processing (Art. 18 GDPR): you can request the restriction of processing under certain conditions;
  • Data portability (Art. 20 GDPR): you can receive the data you have provided to us in a structured, commonly used, and machine-readable format;
  • Objection (Art. 21 GDPR): you can object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR;
  • Withdrawal of consent (Art. 7(3) GDPR): you can withdraw consent you have given at any time with effect for the future.

13.2. To exercise your rights, please contact support@uptimesheriff.com. We will process your request without undue delay, at the latest within one month of receipt (Art. 12(3) GDPR).

14. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR).

15. Changes to this privacy policy

15.1. We amend this privacy policy as necessary, for example in the event of changed legal requirements, technical changes, or new processing activities. The version published here at any given time applies.

15.2. We will inform you of material changes affecting your rights by email or within the Service.

As of: September 13, 2026 · Version 1.2