Privacy Policy
1. Privacy at a glance
General information
The following notes provide a simple overview of what happens to your personal data when you visit this website or use the Clesk Uptime service. Personal data is any data with which you can be personally identified.
Data collection on this website and in the service
Who is responsible? Data processing is carried out by the website operator. Contact details can be found in the section “Controller”.
How do we collect your data? On the one hand, you provide data to us — e.g. during registration, in account settings or by email. Other data is collected automatically when you visit the website or use the monitoring service (e.g. technical log data).
What do we use your data for? To provide the monitoring service, bill paid features, communicate with you (e.g. outage alerts) and ensure technically error-free operation. We do not use advertising cookies or cross-site tracking; for reach measurement we use a cookieless, self-hosted method (see section 8).
What rights do you have? You have the right to free information, rectification, erasure, restriction of processing, data portability and objection at any time. You also have the right to lodge a complaint with a supervisory authority.
2. Hosting
We host the contents of our website and the Clesk Uptime service with the following provider:
Hetzner
The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Servers are located in Germany (EU). Details: hetzner.com/de/rechtliches/datenschutz.
Use is based on Art. 6 (1) lit. f GDPR. We have a legitimate interest in reliable provision of our online service. A data processing agreement pursuant to Art. 28 GDPR is in place with Hetzner.
3. General notes and mandatory information
Data protection
The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
Please note that data transmission over the Internet may have security gaps. Complete protection of data against access by third parties is not possible.
Controller
Clesk Digital GmbH
Am Biehl 5
57234 Wilnsdorf, Germany
Phone: +49 (0) 271 33885017
Email: hey@clesk.de
Storage period
Unless a more specific storage period is stated in this privacy policy, your personal data remains with us until the purpose for processing no longer applies. Invoice data is retained for up to 10 years pursuant to tax law (§ 147 German Tax Code). Monitoring data is stored in tiers: individual check results (raw data) are automatically deleted after 14 days, hourly aggregated values after 90 days; aggregated daily statistics remain for the duration of the contractual relationship.
Legal bases for processing
If you have consented to processing, we process your data on the basis of Art. 6 (1) lit. a GDPR. If data is required for contract performance, we process it on the basis of Art. 6 (1) lit. b GDPR. Where there is a legal obligation, processing is based on Art. 6 (1) lit. c GDPR. Processing may also be based on our legitimate interest pursuant to Art. 6 (1) lit. f GDPR.
Revocation of your consent
You may revoke consent already given at any time. The lawfulness of processing carried out until revocation remains unaffected.
Right to object (Art. 21 GDPR)
If processing is based on Art. 6 (1) lit. e or f GDPR, you have the right to object at any time for reasons arising from your particular situation. If you object, we will no longer process your affected personal data unless we can demonstrate compelling legitimate grounds.
Right to lodge a complaint
In the event of violations of the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged violation. The supervisory authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
SSL/TLS encryption
This site uses SSL/TLS encryption for security reasons. You can recognize an encrypted connection by the lock symbol in your browser and the fact that the address bar begins with “https://”.
4. Data collection on this website and in the service
Cookies and local storage
Clesk Uptime does not use cookies for analytics or advertising. We use technically necessary session cookies for authentication (login) as well as cookies or local storage entries for your language and display settings (e.g. selected language, time range in the dashboard). For password-protected status pages, an access cookie valid for 30 days is set after the password is entered successfully. This storage is required for operation of the service (§ 25 (2) TDDDG).
Referral cookie (partner program)
If you visit our website via a partner referral link (link parameter “ref”), we store a first-party cookie (“clesk_ref”) containing the referral code for 90 days. Its sole purpose is to attribute a later registration to the referring partner; there is no cross-site tracking and no data is shared with third parties.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in settling our partner program). You can delete the cookie in your browser at any time; use of the service does not depend on it.
Server log files
The provider automatically collects information in server log files that your browser transmits. Collection is based on Art. 6 (1) lit. f GDPR (legitimate interest in the technically error-free and secure provision of the service, including defence against attacks); this data is not merged with other data sources. The following is collected:
- Browser type and version
- Operating system used
- Referrer URL
- Hostname of the accessing computer
- Time of the server request
- IP address
Registration and user account
When you register, we collect your email address and a password chosen by you (stored as a cryptographic hash). You may optionally provide a display name. Legal basis: Art. 6 (1) lit. b GDPR (contract performance).
During use, we store the monitors you configure (URLs, intervals, notification settings), heartbeat configurations, status page settings and results of availability checks performed (timestamps, response times, status codes).
You can delete your account yourself at any time in the settings. All associated data (monitors, measurement history, status pages, notification settings) is then deleted immediately and irrevocably; invoice data that we are legally required to retain (§ 147 German Tax Code) is exempt from this.
Outage notifications
If you configure alerts via email, webhook or other channels, we process the destination addresses you provide solely to send the notifications you have triggered. Legal basis: Art. 6 (1) lit. b GDPR.
Enquiries by email
If you contact us by email, we store your enquiry including the resulting personal data to process your request. Legal basis: Art. 6 (1) lit. b or lit. f GDPR.
5. Payment processing (Mollie)
For paid services, we use payment provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. In the course of payment processing, name, email address and payment data are transmitted to Mollie. Mollie is a supervised payment service provider based in the EU and processes payment data as an independent controller to fulfil its own legal obligations (including payment services and anti-money-laundering law).
Legal basis for the transfer: Art. 6 (1) lit. b GDPR (contract performance). Further information: mollie.com/privacy.
6. Email delivery (Amazon SES)
For transactional emails (registration, password reset, outage alerts, invoices), we use Amazon Simple Email Service (SES) from Amazon Web Services EMEA SARL in the eu-central-1 region (Frankfurt, Germany). Email addresses and, where applicable, names are processed.
Legal basis: Art. 6 (1) lit. b GDPR or Art. 6 (1) lit. f GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place with AWS.
To keep delivery traceable, we maintain a log of sent emails. Only metadata is stored (time, recipient address, subject, message type, delivery status and any error message), explicitly not the content of the messages. The log is used to troubleshoot delivery problems (Art. 6 (1) lit. f GDPR) and is deleted automatically after 90 days.
7. Fonts
This website uses locally hosted fonts. When you load a page, fonts are served from our server — no connection to third-party servers (e.g. Google Fonts) is established.
8. Reach measurement (Umami)
To understand how our website is used (e.g. number of visits and pages viewed), we use Umami, a cookieless web analytics tool that we host ourselves on our server in Germany. No cookies are set and no cross-site tracking takes place.
Only aggregated information that cannot be traced back to a person is collected (e.g. page viewed, referrer, rough device type, country). IP addresses are not stored; no personal user profile is created and no data is shared with third parties. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in data-minimal reach measurement).
9. Error diagnostics (GlitchTip)
To detect and fix technical errors, we use GlitchTip, an error-logging tool that we host ourselves on our server in Germany. When an error occurs, technical diagnostic data is recorded (e.g. error message and technical trace, requested address, timestamp, browser and system details).
We process this data solely to maintain the stability and security of the service and avoid recording the content of your inputs. No transfer to third parties takes place. The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in a technically error-free and secure service).
10. What we deliberately do not do
Clesk Uptime deliberately does not use cross-site tracking, advertising cookies, newsletter tools or embedded social media services. No data is processed for advertising purposes and no personal user profile is created. The reach measurement used (section 8) is cookieless and runs on our own server.