Privacy Policy

Last updated: 20 September 2026 · Deutsche Fassung (authoritative)

Diese Seite ist noch nicht konfiguriert.

Die Betreiberangaben fehlen. Setze OPERATOR_NAME, OPERATOR_STREET, OPERATOR_CITY und OPERATOR_EMAIL in der Datei .env und starte die Anwendung neu. Bis dahin ist diese Seite auf noindex gesetzt.

1. Controller

The controller for all processing described here is:

[OPERATOR_NAME fehlt]

[OPERATOR_STREET fehlt]

[OPERATOR_CITY fehlt]

Deutschland

E-Mail: [OPERATOR_EMAIL fehlt]

We have not appointed a data protection officer because the legal thresholds for doing so are not met. For any privacy question, write to the address above.

2. Principle

PingGuard monitors the availability of websites, APIs and background jobs. We process only what running that service requires. We do not sell data, run ad networks or set tracking cookies. The application and its database run exclusively on servers in Germany.

3. Hosting and server logs

The service runs at Hetzner Online GmbH in a data centre in Nuremberg, Germany. When a page is requested we process the IP address, timestamp, requested URL, HTTP status, bytes transferred, referrer and user agent. This is necessary for secure and stable operation, so the legal basis is Art. 6(1)(f) GDPR. Logs are deleted after 14 days at the latest unless needed to investigate a specific security incident. A data processing agreement under Art. 28 GDPR is in place with the host.

4. Cookies

We use strictly necessary cookies only. There is no behavioural analysis via cookies and no third-party cookies, so no consent banner is required.

Name Purpose Lifetime
csrf_tokenCross-site request forgery protection on forms24 hours
access_tokenKeeps you signed in30 days
oauth_stateSecures sign-in with Google10 minutes

5. Account data

To use the service you need an account. We process your email address, organisation name, a bcrypt hash of your password (never the plaintext), the signup timestamp and your notification settings. Legal basis: Art. 6(1)(b) GDPR. To prevent abuse we limit signups and login attempts per IP address; those counters live only in memory (Art. 6(1)(f) GDPR).

6. Monitoring data

For each monitor we store the URL or heartbeat token, its configuration and the results of each check (timestamp, status code, response time, error message) plus any incidents derived from them. When we check your address, our server IP appears in your own logs. You may only monitor addresses you are authorised to monitor. Legal basis: Art. 6(1)(b) GDPR.

7. Notifications

We send outage and recovery notifications to your email address via Resend, Inc. Optionally you can add Slack, Discord, Telegram or your own webhook, in which case we deliver the notification to the endpoint you configured, on your instruction only. Legal basis: Art. 6(1)(b) GDPR.

8. Public status pages

Every account gets a publicly reachable status page showing the organisation name, the monitors you marked public, their uptime figures and incidents. Visitors may subscribe with their email address; we store and use it only after they confirm via a double opt-in link (Art. 6(1)(a) GDPR) and every message carries an unsubscribe link. For those subscriber records you are the controller towards your own users and we act as processor - see the data processing agreement.

9. Payments

Paid plans are handled by Stripe Payments Europe, Ltd., Dublin, Ireland. Card details are processed solely by Stripe and never reach our servers. We store only the Stripe customer and subscription identifier and the plan. Legal basis: Art. 6(1)(b) GDPR. Invoicing records are kept for up to ten years under German commercial and tax law (Art. 6(1)(c) GDPR).

10. Sign-in with Google

You may optionally sign in with a Google account. Google Ireland Limited then provides us your email address and name. This happens only if you actively choose it. Legal basis: Art. 6(1)(b) GDPR.

11. AI incident analysis

On paid plans we generate a short automatic summary once an incident resolves. For that we send the monitor name, the monitored URL, the error messages, status codes and timestamps to Anthropic PBC, USA. No account data, email addresses or payment data are sent, and the data is not used to train models. Legal basis: Art. 6(1)(b) GDPR. Tell us if you would rather not use this and we will disable it for your account.

12. Contact form

If you write to us we process your name, email address and message to answer the enquiry (Art. 6(1)(b) or (f) GDPR) and delete it once the matter is settled and no retention duty applies.

13. Processors and recipients

Provider Location Purpose
Hetzner Online GmbH Nürnberg, Deutschland Hosting von Anwendung und Datenbank, Server-Logfiles
Stripe Payments Europe, Ltd. Dublin, Irland (Konzernmutter Stripe, Inc., USA) Zahlungsabwicklung, Rechnungsstellung, Abonnementverwaltung
Resend, Inc. USA (Versand über EU-Region) Versand von Transaktions- und Alarm-E-Mails
Anthropic PBC USA KI-gestützte Störungsanalyse - nur in kostenpflichtigen Tarifen und nur mit Monitorname, URL, Fehlermeldung und Zeitstempel des Vorfalls
Google Ireland Limited Dublin, Irland Optionale Anmeldung per Google-Konto - nur bei aktiver Nutzung

Transfers outside the EU/EEA rely on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR.

14. Retention

  • Check results: 30 to 365 days depending on plan, then deleted automatically
  • Account and monitor data: for the life of the contract
  • After account deletion: removed immediately, within 30 days at the latest
  • Server logs: 14 days maximum
  • Invoicing records: statutory retention of up to ten years

15. Your rights

You have the right to:

  • Access your data (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR) - you can trigger this yourself in your account
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) - export at any time via the REST API
  • Object to processing based on legitimate interests (Art. 21 GDPR)
  • Withdraw consent at any time with future effect (Art. 7(3) GDPR)

Email to exercise any of these. You may also lodge a complaint with a supervisory authority, in particular in your country of residence or the one responsible for us.

16. No automated decision-making

There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.

17. Changes

We update this policy when the service or the law changes. The current version is always on this page, and we email registered users about material changes.

© 2026 PingGuard