Our role as controller
This policy covers our role as controller for account, billing, and site data. Where we process personal data on behalf of a Customer as part of running Tests, we act as a processor under our Data Processing Addendum, and the Customer is the controller.
for questions, reach out to [email protected].
Data we collect
You give us
- Account & workspace: name, work email address, organization/workspace name, role, time zone, and password (stored only as a salted hash).
- Authentication: two-factor (TOTP) configuration, stored encrypted; email-verification status.
- Test configuration: domains you add and verify, test plans, and health-check paths.
- Support: the content of support tickets and any files you attach.
- Billing: billing and tax details you provide. Card payments are processed by Stripe; we do not receive or store full card numbers.
We generate or collect automatically
- Test & health data: results and service-health samples (such as latency and HTTP response codes) produced while your Tests run.
- Audit & log data: logins, approvals, changes, and lifecycle events, together with IP address, timestamps, and technical metadata used for security and abuse prevention.
- Session data: a session identifier stored in a cookie and checked on each request.
- Network & edge-security data: connection metadata — including IP address, request headers, and TLS details — inspected at our network edge by Cloudflare to filter malicious traffic and absorb denial-of-service attacks before they reach our servers.
Purposes & legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create and operate your account and Workspace; provide the Service | Performance of a contract (6(1)(b)) |
| Run Tests, provision Workers, and show health data | Performance of a contract (6(1)(b)) |
| Take payment and issue invoices | Contract (6(1)(b)); legal obligation for tax/accounting (6(1)(c)) |
| Secure the Service, prevent abuse, verify authorization, keep audit logs | Legitimate interests (6(1)(f)) — protecting the Service and third parties |
| Provide support | Contract (6(1)(b)); legitimate interests (6(1)(f)) |
| Comply with legal requests and enforce our terms | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) |
| Optional product updates | Consent (6(1)(a)) or legitimate interests, with opt-out |
Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to that processing (see Your rights).
International transfers
We aim to keep personal data within the European Economic Area (EEA). Our hosting and test Workers run in the EU, all data at rest is stored in the EU, and we use email providers' EU regions where available. Traffic to our sites and portal passes through Cloudflare's global edge network before reaching those EU servers; requests from Europe are normally handled at a European point of presence, but Cloudflare's anycast routing means a request may be processed outside the EEA. Where a provider (such as Cloudflare or Stripe) processes or routes data outside the EEA, that transfer is protected by an adequacy decision or by Standard Contractual Clauses together with additional safeguards. You can ask us for details of the safeguards in place.
Retention
- Account data — for as long as your Workspace is active, then deleted or anonymized within 30 days after closure.
- Test and health data — retained as long as your Workspace is active to let you review results, unless you delete a Test earlier.
- Invoices and tax records — retained for 7 years, as required by Dutch tax law.
- Audit and security logs — retained for 12 months for security and abuse prevention.
- Support tickets and attachments — retained for 24 months after resolution.
Security
We apply technical and organizational measures appropriate to the risk, including: strict tenant isolation with every query scoped to your Workspace and sessions re-checked on each request; passwords stored only as salted hashes; two-factor secrets stored encrypted; support attachments validated by content and served only through authenticated, ownership-checked handlers; encryption in transit (HTTPS); loopback-only internal interfaces; DDoS protection and malicious-traffic filtering at our network edge through Cloudflare, which fronts our websites and the customer portal; and audit logging. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where required.
Your rights
Subject to conditions in the GDPR, you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To exercise these rights, contact [email protected]. We will respond within the time limits set by law. If your data is processed by us on a Customer's behalf (as a processor), we will refer your request to that Customer.
Changes
We may update this policy from time to time. We will post the updated version here and, for material changes, notify you through the portal or by email. The "last updated" date shows when it last changed.
Contact & complaints
For any privacy question or request, contact [email protected].
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority where you live or work.