Privacy Policy
Last updated: 30 July 2026. Written under the GDPR and French data protection law.
Who is responsible
The controller is Cœur du Web (SASU, 58 rue de Monceau, 75008 Paris, France, RCS Paris 850 520 941). Data protection officer: Laurent Tulpan, reachable at support@uptimeez.com.
What we collect, why, and for how long
Every line below names a lawful basis and a retention period, because a privacy policy without those two is decoration.
| Data | Why | Lawful basis | Kept for |
|---|---|---|---|
| Name, email, company name or registration number | Opening and running your account | Performance of the contract | Until you close the account |
| Billing details and invoices | Charging you, and accounting | Contract, then legal obligation | Ten years, as French commercial law requires |
| Card details | Taking payment | Contract | Never held by us. Stripe processes them directly |
| The addresses you ask us to monitor, and your alert settings | Doing what you subscribed for | Performance of the contract | Until you delete the monitor or the instance |
| Measurements taken on those addresses | History, uptime and diagnosis | Performance of the contract | 60 days by default, a value you can change in your instance |
| The address you submit to either free public tool, the “is it down” checker or the SSL certificate checker, and your IP address | Being able to show who asked us to fetch or to connect to a third-party site, and to investigate abuse of either tool | Legitimate interest in not letting an open tool be used to hammer someone else | Twelve months |
| Connection logs and IP address | Security, abuse and debugging | Legitimate interest in keeping the service safe | Twelve months at most |
| Audience measurement (Google Analytics) | Understanding which pages are useful | Your consent, and nothing loads before you give it | Fourteen months |
Aggregated statistics we publish
Because UptimeEZ diagnoses rather than only pings, each instance knows things no uptime checker records: that a page returning 200 is showing a database error, that a stylesheet has stopped loading, that a noindex was left in production, that a certificate is about to expire. We count those across all customer instances and we publish the counts, because they are useful to people who run other people's sites.
What the count contains. Whole numbers, a date, and the diagnosis codes of the engine. Nothing else, and in particular: no URL, no domain name, no instance name, no customer or account identifier, and no per-event timestamp. A total with no identifier is not personal data, which is why it is not a row in the table above: there is nothing to erase, nothing to export, and nothing to hand over on request, because nothing in it points at anyone.
What we refuse to publish. A share computed over fewer than 10 customer instances, because on one or two customers a percentage is an audit of an identifiable customer rather than a statistic. The threshold is enforced in the code, not by intention: the command that reads the figures refuses to conclude below it and says what is missing. Your own monitoring data still never leaves your own database.
Where it is stored
On a dedicated server operated by OVH SAS (2 rue Kellermann, 59100 Roubaix, France), in France. Each customer has their own database on that server, not a shared table with a customer column: the separation is physical, not a filter in a query. Your monitoring data does not leave France.
Who else processes it
Three processors, and no others:
- OVH SAS (France): hosting. No transfer outside the EU.
- Stripe: payments and invoicing. Stripe processes card details directly and we never see them. This involves a transfer to the United States, framed by the European Commission adequacy decision and Stripe's contractual clauses.
- Google (Analytics): audience measurement, only after you consent. Refuse the banner and no request reaches Google at all: the tag is not loaded, not merely inactive.
We do not sell data, we do not share it for advertising, and we do not enrich it from third-party sources.
Data you send us about other people
If you configure alerts to colleagues, or a read-only link for one of your own clients, you decide whose address goes in and what they see. For that data you are the controller and we act as your processor: you need a lawful basis for it, and we process it only to deliver what you configured.
Your rights
You may ask for access, rectification, erasure, restriction and portability, and object to processing based on our legitimate interest. Write to support@uptimeez.com; we answer within one month. Deleting your instance is done on request and it is total: the directory and the database go, which is what “one instance per customer” makes possible in the first place. If our answer does not satisfy you, you may lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris.
Cookies
Three kinds, and we count the third one because a policy that undercounts its own cookies is not worth reading.
-
Strictly necessary, and there are two of them:
uptimeez_sessionkeeps you logged in, andXSRF-TOKENis the anti-forgery token that lets a form you submit be recognised as yours. Both expire after 3 days and neither needs consent. -
Your cookie choice itself:
cookie_consentrecords whether you accepted or refused, so the banner does not ask again on the next page. It is kept for 182 days, which is the ceiling the CNIL recommends, and it holds nothing but that answer. Exempt from consent, not from being described. - Audience measurement (Google Analytics), which is set only if you accept it in the banner. Refuse, and no Google cookie is ever written, because the tag is not loaded at all.
There is no advertising cookie and no tracker beyond those.
Changes
If this policy changes in a way that affects you, we say so by email before it applies. Company details are on the mentions légales page.