Legal
Privacy Policy
This Privacy Policy explains how Uptime Beacon ("we" or "us") handles your personal data when you use the Uptime Beacon Platform and Services, visit our Web Site, or visit a status page published with Uptime Beacon.
What is personal data?
Personal data refers to any information that can identify you as an individual. This includes information that directly identifies you (like your name or contact details) or data that can be used in combination with other information to identify you. Our understanding of personal data aligns with the definitions in relevant laws.
Who does this policy apply to?
If you're using, have used, or plan to use the Uptime Beacon Platform and Services, this policy applies to you. It also applies if you are a member of a Client's Team, if a Client has added you as a recipient of alerts, or if you visit our Web Site or a Customer Status Page.
The definitions and terms defined below keep their meaning through this Privacy Policy, regardless of whether they are capitalised in the sentence.
Definitions
- Business Relationship: the period during which a Client has a Contract with us, as set out in the Terms of Service. A move to a free plan does not end it.
- Client: anyone who has agreed to use our services through a contract.
- Contract: the agreement you enter into with us to use our Platform and Services.
- Customer Status Page: a status page a Client publishes through the Platform.
- External Identity Provider: a third-party service you choose to sign up or sign in with instead of a password.
- Platform: our Software-as-a-Service offering, Uptime Beacon. For more details, please refer to our Terms of Service.
- Services: the various features and functionalities offered through our Platform.
- Team: a workspace in the Platform to which a plan, billing and a Client's content belong.
- Terms of Service: the rules and guidelines governing the use of our Platform.
- Uptime Beacon/ we/ us: Wealth Beacon OÜ, registry code 16889317, located at Teaduse 17-10, Saku 75501 Harjumaa, Estonia (email legal@uptimebeacon.eu), the operator of Uptime Beacon.
- Web Site: includes all domains under the Uptime Beacon brand (like uptimebeacon.eu) and their subdomains. This encompasses web pages, images, videos, code files, and other content owned by us.
Our role
We are the controller of the personal data we use to run the Platform, our business and the Web Site. For Client content, such as the email address of an alert recipient, the Client is the controller and we process it on the Client's behalf under the Data Processing Agreement in Appendix 1 of the Terms of Service. If this concerns you, you can also contact that Client directly.
General information
- We do not request special categories of personal data, and Clients should not include it in their content.
- Our Platform and Services are intended for users aged 18 or over, as stated in our Terms of Service. Therefore, we do not knowingly collect or process data of individuals under 18 years old.
- The Platform may automatically restrict a Team based on its payment status or security signals, which can interrupt access, monitoring and alerts. We do this where necessary to perform the Contract. You may request human review, explain your position and contest the decision by emailing us.
Personal data we collect and how we get it
- Identification Data (such as your name, sign-in credentials and, if you use an External Identity Provider, your account identifier, username and profile picture there): when you sign up for our Platform or join a Team, or from an External Identity Provider when you sign up or sign in with it. We may also receive account and transaction references from our payment processor.
- Contact Data (like your email address): when you sign up, when a Client invites you to a Team or adds you as an alert recipient, or when you contact us.
- Billing Data (such as company name, billing address and VAT number): when you subscribe to a paid plan. Payment credentials are handled by our payment processor.
- Communication Data (including emails and messages you send to us): directly from your interactions with us, such as when you reach out for support or inquiries.
- Content Data (such as monitors and the addresses they check, alert channels, status page texts, incident history, and data returned by the addresses you monitor): when you or your Team add them to the Platform, or when the Platform checks the addresses you monitor.
- Data Related to the Use of the Platform and Services ("usage data", such as cookie identifiers, IP addresses, browser and device details, and server, error and performance logs, which include the address of the page requested, including any parameters in it): automatically when you visit and use our Web Site, the Platform and Customer Status Pages.
Your name and email address, and for a paid plan the Billing Data, are needed to enter into and perform the Contract. Without them we cannot provide the Platform.
Cookies and similar technologies
- Strictly necessary: the Web Site and the Platform use cookies and browser storage needed to sign you in, keep your session secure and remember your cookie choice. These do not need your consent.
- Analytics: with your consent, Google Analytics measures how our Web Site is used. Before you choose, or if you refuse, it receives only basic visit information without cookies.
- Marketing: if you allow marketing cookies, we and our advertising partners (Reddit, OpenAI and Google) use cookies and pixels to measure, improve and personalise our advertising. If you came from a Reddit or OpenAI advertisement, we also report your sign-up and first purchase to that partner. Withdrawing consent through "Cookie settings" stops these reports from your next visit to the Platform in that browser; stopping advertising reports in your account settings stops them at once.
You choose separately whether to allow analytics and marketing, and can change your choice at any time through "Cookie settings" at the bottom of every page. Details, including cookie lifetimes, are shown there. The cookie choice is provided by Kukie.io, which records your choice on our behalf.
Recipients of personal data
- Within Uptime Beacon: your personal data may be shared internally within our company.
- Within your Team: other members of a Team you belong to can see your name, your email address and your actions in the Team, such as acknowledging an incident.
- Third-Party Service Providers: to assist in providing, delivering, analysing, administering and improving our Services, such as hosting, monitoring infrastructure, email delivery, payment processing, error monitoring, content delivery and security, web analytics and consent management. Their names are available on request.
- Services and applications you connect: when a Client connects an external service, alerts are sent there under the Client's control. If you connect a third-party application, such as an AI assistant, to your account, we send it the data it requests within the access you allow, which can include data about other members of your Team. It may process the data outside the EEA, under its own terms, and its provider is responsible for how it handles the data. You can disconnect it at any time in your account settings. This stops further access, but data already sent stays with its provider.
- Advertising partners: with your consent, as described under Cookies and similar technologies. We are responsible for collecting this data and sending it to them; each partner is responsible for its own use of it under its own privacy policy. The essence of this arrangement is available on request, and you can exercise your rights with us or with the partner.
- In Case of Merger or Acquisition: if there's a change in the control of our company (like a merger, sale, or acquisition), your personal data, along with this Privacy Policy, may be transferred to the new entity.
- Legal and Safety Reasons: we may disclose your personal data to third parties when it's necessary to comply with the law or a legal process, to enforce our Terms of Service, to detect or prevent fraud or security issues, or to protect the rights, property, or safety of Uptime Beacon, our users, or the public.
Transferring your personal data outside the EEA
- Where it is kept: the Platform's application and database are hosted in the EU. Our Web Site is hosted by Webflow, which may process usage data outside the EEA. Some providers, including monitoring locations, may process data outside the EEA, as may services and applications you connect (see Recipients of personal data).
- Transfer and Storage Outside the EEA: there may be times when your personal data is transferred to, and stored in, countries outside the EEA, such as the United States.
- Legal Basis for Transfer: we ensure that any transfer we make is lawful. We transfer personal data to countries or recipients that the European Commission recognises as providing an adequate level of protection, including under the EU-U.S. Data Privacy Framework, or where appropriate safeguards are in place, such as the European Commission's standard contractual clauses. This does not cover services and applications you connect, which receive data at your request and under their own terms.
- Request for More Information: you may contact us for details of these transfers or a copy of the applicable safeguards.
How we protect your personal data
- Comprehensive Approach: we implement technical and organisational security measures considering the latest technology, costs of implementation, and the nature and scope of data processing, while assessing risks to your privacy.
- Robust Security Practices: our measures include hashing or encryption of passwords and stored credentials, encryption of data in transit over public networks, and access controls to ensure only authorised personnel have access.
Data retention
- General Retention Policy: your personal data is kept only as long as necessary for the purposes it was collected, to protect our rights, or as required by applicable law. If the same data serves multiple purposes, we retain it for the longest applicable period.
- Account data: deleted within 90 days after your account is closed, unless needed for a purpose below. Content of a continuing Team is handled under that Client's instructions. API tokens you created for a continuing Team stay with that Team, no longer linked to your account, until the Team revokes them.
- Check results: for the period in the Team's plan, or until an open incident is resolved, and in every case deleted within 90 days of the end of the Business Relationship. Incident and alert history is shown for the period in the plan and kept no longer than the Team exists.
- Communication Data and Contract records: for 3 years after the Contract ends, or until a claim is resolved.
- Logs and backups: for as long as needed for operation and security; backups are overwritten on a regular cycle.
- Inactive free accounts: may be deleted after 24 months without a sign-in, after a warning email.
- Analytics and consent: Google Analytics data for up to 14 months, records of cookie choices no longer than 36 months, then deleted within 90 days, and advertising click identifiers only as long as needed to report them, and no longer than 90 days after sign-up.
- Billing Information: in compliance with Estonian accounting and taxation laws, we retain billing information for 7 years from the end of the relevant financial year.
Your rights regarding your personal data
- Right of Access: understand if your personal data is being processed, why it's processed, the categories of data, to whom it's disclosed, retention duration, and your rights concerning data correction, erasure, and processing restriction.
- Right of Rectification: request correction of inaccurate or incomplete personal data about you.
- Right of Erasure: in certain cases, like withdrawing consent without other legal processing grounds, request deletion of your personal data.
- Right to Restrict Processing: temporarily restrict processing of your personal data in specific situations (e.g., if you've objected to data processing).
- Right to Data Portability: receive your data in a structured, commonly used format and transfer it to another service provider, if processing is consent-based or contract-based and automated.
- Right to Withdraw Consent: where we rely on consent, withdraw it at any time, through "Cookie settings" for cookies, your account settings for advertising reports (as described under Cookies and similar technologies), or the unsubscribe link for marketing emails. This does not affect processing before the withdrawal.
- Complaints and Contact: if you feel your rights are violated, you can submit a complaint to the Data Protection Inspectorate (Andmekaitse Inspektsioon), another EEA supervisory authority, or a court. To exercise your rights, please contact us using the details provided.
Right to Object. You may object at any time to processing of your personal data based on legitimate interest, including profiling. We will cease processing unless there are overriding legitimate grounds. You can object to direct marketing at any time, and we will then stop it. Email legal@uptimebeacon.eu.
Some rights can be exercised directly in the Platform. We normally respond within one month.
Updates to our Privacy Policy
- When Changes Occur: we may update this Privacy Policy if there are changes in our personal data processing practices, or as required by data protection laws, other legal acts, case-law, or guidelines from competent authorities.
- Your Notification: if we make material changes, we'll notify you by email or in the Platform reasonably before these changes take effect.
Contact
- In case you have any questions regarding the processing of your personal data by us or you would like to exercise your rights as a data subject, please contact us by email at legal@uptimebeacon.eu.
- In case you would like to file a complaint with the Data Protection Inspectorate, the contact details are available at www.aki.ee.
Appendix 1: Lawful bases for processing
These bases apply where we act as controller. Client content is processed under the Client's instructions and the Data Processing Agreement.
| Lawful basis | Purpose of processing | Categories of personal data |
|---|---|---|
| Performance of contract | Concluding and performing the Contract, including providing the Services, billing for them, and contacting you about the Platform and the Services. | Identification, contact, billing, communication and usage data. |
| Legitimate interest | Safeguarding our rights, including retention of Contracts after they end; general business administration and support; keeping the Web Site and the Platform secure and working, including strictly necessary cookies, recording cookie choices and measuring Web Site visits without cookies before or without analytics consent; and direct marketing to business contacts, where permitted by law. | Identification, contact, billing, communication and usage data. |
| Consent | Web Site analytics; measuring, improving and personalising our advertising with our advertising partners, as described under Cookies and similar technologies; and marketing emails to Clients who are natural persons. | Usage data, contact data, and sign-up and subscription events. |
| Legal obligation | Bookkeeping, and responding to information requests from public authorities. | Identification, contact, billing, communication and usage data. |