Privacy Policy
Last updated: 20 September 2026 · Deutsche Fassung (authoritative)
Diese Seite ist noch nicht konfiguriert.
Die Betreiberangaben fehlen. Setze OPERATOR_NAME,
OPERATOR_STREET,
OPERATOR_CITY und
OPERATOR_EMAIL in der Datei .env
und starte die Anwendung neu. Bis dahin ist diese Seite auf noindex gesetzt.
1. Controller
The controller for all processing described here is:
[OPERATOR_NAME fehlt]
[OPERATOR_STREET fehlt]
[OPERATOR_CITY fehlt]
Deutschland
E-Mail: [OPERATOR_EMAIL fehlt]
We have not appointed a data protection officer because the legal thresholds for doing so are not met. For any privacy question, write to the address above.
2. Principle
PingGuard monitors the availability of websites, APIs and background jobs. We process only what running that service requires. We do not sell data, run ad networks or set tracking cookies. The application and its database run exclusively on servers in Germany.
3. Hosting and server logs
The service runs at Hetzner Online GmbH in a data centre in Nuremberg, Germany. When a page is requested we process the IP address, timestamp, requested URL, HTTP status, bytes transferred, referrer and user agent. This is necessary for secure and stable operation, so the legal basis is Art. 6(1)(f) GDPR. Logs are deleted after 14 days at the latest unless needed to investigate a specific security incident. A data processing agreement under Art. 28 GDPR is in place with the host.
4. Cookies
We use strictly necessary cookies only. There is no behavioural analysis via cookies and no third-party cookies, so no consent banner is required.
| Name | Purpose | Lifetime |
|---|---|---|
| csrf_token | Cross-site request forgery protection on forms | 24 hours |
| access_token | Keeps you signed in | 30 days |
| oauth_state | Secures sign-in with Google | 10 minutes |
5. Account data
To use the service you need an account. We process your email address, organisation name, a bcrypt hash of your password (never the plaintext), the signup timestamp and your notification settings. Legal basis: Art. 6(1)(b) GDPR. To prevent abuse we limit signups and login attempts per IP address; those counters live only in memory (Art. 6(1)(f) GDPR).
6. Monitoring data
For each monitor we store the URL or heartbeat token, its configuration and the results of each check (timestamp, status code, response time, error message) plus any incidents derived from them. When we check your address, our server IP appears in your own logs. You may only monitor addresses you are authorised to monitor. Legal basis: Art. 6(1)(b) GDPR.
7. Notifications
We send outage and recovery notifications to your email address via Resend, Inc. Optionally you can add Slack, Discord, Telegram or your own webhook, in which case we deliver the notification to the endpoint you configured, on your instruction only. Legal basis: Art. 6(1)(b) GDPR.
8. Public status pages
Every account gets a publicly reachable status page showing the organisation name, the monitors you marked public, their uptime figures and incidents. Visitors may subscribe with their email address; we store and use it only after they confirm via a double opt-in link (Art. 6(1)(a) GDPR) and every message carries an unsubscribe link. For those subscriber records you are the controller towards your own users and we act as processor - see the data processing agreement.
9. Payments
Paid plans are handled by Stripe Payments Europe, Ltd., Dublin, Ireland. Card details are processed solely by Stripe and never reach our servers. We store only the Stripe customer and subscription identifier and the plan. Legal basis: Art. 6(1)(b) GDPR. Invoicing records are kept for up to ten years under German commercial and tax law (Art. 6(1)(c) GDPR).
10. Sign-in with Google
You may optionally sign in with a Google account. Google Ireland Limited then provides us your email address and name. This happens only if you actively choose it. Legal basis: Art. 6(1)(b) GDPR.
11. AI incident analysis
On paid plans we generate a short automatic summary once an incident resolves. For that we send the monitor name, the monitored URL, the error messages, status codes and timestamps to Anthropic PBC, USA. No account data, email addresses or payment data are sent, and the data is not used to train models. Legal basis: Art. 6(1)(b) GDPR. Tell us if you would rather not use this and we will disable it for your account.
12. Contact form
If you write to us we process your name, email address and message to answer the enquiry (Art. 6(1)(b) or (f) GDPR) and delete it once the matter is settled and no retention duty applies.
13. Processors and recipients
| Provider | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Nürnberg, Deutschland | Hosting von Anwendung und Datenbank, Server-Logfiles |
| Stripe Payments Europe, Ltd. | Dublin, Irland (Konzernmutter Stripe, Inc., USA) | Zahlungsabwicklung, Rechnungsstellung, Abonnementverwaltung |
| Resend, Inc. | USA (Versand über EU-Region) | Versand von Transaktions- und Alarm-E-Mails |
| Anthropic PBC | USA | KI-gestützte Störungsanalyse - nur in kostenpflichtigen Tarifen und nur mit Monitorname, URL, Fehlermeldung und Zeitstempel des Vorfalls |
| Google Ireland Limited | Dublin, Irland | Optionale Anmeldung per Google-Konto - nur bei aktiver Nutzung |
Transfers outside the EU/EEA rely on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR.
14. Retention
- Check results: 30 to 365 days depending on plan, then deleted automatically
- Account and monitor data: for the life of the contract
- After account deletion: removed immediately, within 30 days at the latest
- Server logs: 14 days maximum
- Invoicing records: statutory retention of up to ten years
15. Your rights
You have the right to:
- Access your data (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) - you can trigger this yourself in your account
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) - export at any time via the REST API
- Object to processing based on legitimate interests (Art. 21 GDPR)
- Withdraw consent at any time with future effect (Art. 7(3) GDPR)
Email to exercise any of these. You may also lodge a complaint with a supervisory authority, in particular in your country of residence or the one responsible for us.
16. No automated decision-making
There is no automated decision-making or profiling within the meaning of Art. 22 GDPR.
17. Changes
We update this policy when the service or the law changes. The current version is always on this page, and we email registered users about material changes.