Template awaiting legal review — not yet binding.

Privacy Policy

Last updated 10 October 2026

Who we are

[Company legal name], [Registered address]. Contact: [privacy@your-domain].

What we collect

Account data: usernames, email addresses, roles, sign-in times and IP addresses, two-factor settings (never your authenticator codes).

Service data from your estate: inventory and configuration of your AWS resources, metrics, logs you search, uptime results, findings, incidents and the audit trail of actions in your workspace.

Credentials you store (AWS keys, tokens): encrypted with your workspace's own key; never shown again after you save them.

Billing data: plan, usage counts and invoices (card payments are handled by our payment provider; we don't store card numbers).

How we use it

To provide and secure the service, bill for it, support you when you ask, and improve its reliability. We don't sell personal data or use your service data for advertising.

Where it's kept

In managed database and storage services of our cloud providers (Amazon Web Services and MongoDB Atlas), encrypted in transit and at rest, plus nightly encrypted backups kept for about 35 days.

Sub-processors

Amazon Web Services (hosting, encryption keys, email delivery, backups), MongoDB Atlas (database), Stripe (payments), and the alerting services you choose to connect (e.g. Slack, Telegram).

Retention

Service data has fixed retention (for example 14 days of raw uptime results, up to 400 days of history); account data is kept while your workspace exists. When a workspace is deleted, its data and its encryption key are deleted.

Your rights

You can access, correct, export or delete your data — most of it directly in your workspace — or ask us at [privacy@your-domain]. You may complain to your data protection authority (in Malaysia, the Personal Data Protection Commissioner).

Changes

We'll tell workspace administrators about material changes before they apply.