Privacy policy
This policy explains which personal data (not provided yet) processes when you use Cardiac, why, and what rights you have.
Controller
(not provided yet) (not provided yet) Email: (not provided yet)
Data we process
Account data (name, email address, password hash, language, time zone, theme), organization and membership data, the websites you add and their settings, check results and incidents, notification settings (secrets are stored encrypted), API keys (only as hashes), audit log entries with IP address and user agent, and technical logs of our servers.
Purposes and legal bases
We process this data to provide the service you signed up for (Art. 6(1)(b) GDPR), to keep it secure and prevent abuse (Art. 6(1)(f) GDPR), and to meet legal obligations such as bookkeeping (Art. 6(1)(c) GDPR).
Monitoring of your websites
CardiacBot requests the addresses you configure, reads the response, and stores status codes, timings, headers, and certificate details. Configure monitors only for websites you are allowed to monitor.
Cookies
We use only technically necessary cookies: a session cookie to keep you signed in and a cookie that remembers your color theme. We use no tracking, advertising, or third-party analytics, and we load no fonts or scripts from third-party servers.
Service providers
We use service providers for hosting, object storage, and sending email, bound by data processing agreements. Our hosting: servers and object storage in the European Union. The current list is on the subprocessors page.
Retention
Raw check results are kept for up to 30 days, aggregated statistics for up to 5 years, task logs for 90 days, and the audit log for one year. Account data is deleted when your account or organization is deleted, unless the law requires us to keep it longer.
Security
Connections are encrypted with TLS. Secrets such as webhook URLs are encrypted at rest, passwords and API keys are stored only as hashes, and every change is recorded in the audit log.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with a supervisory authority.
Contact
For questions about privacy, write to (not provided yet).