PRIVACY AND GDPR
Privacy notice
How UpBot collects, uses, stores and protects personal data.
Effective from 2026-09-111. Controller
The controller is PET Digital s. r. o., Agátová ulica 464/8, 951 04 Malý Lapáš, Slovenská republika, company ID 53 324 412. Contact us about privacy at privacy@upbot.eu.
For personal data a customer adds for its contacts, team members, status-page subscribers or monitored services, UpBot may act as processor and the customer as controller.
2. Data we process
- Account and profile data: name, email, hashed password, language and time zone.
- Organisation and collaboration data: memberships, roles, invitations, contact groups and audit events.
- Monitoring data: targets, settings, check results, incidents, latency and technical logs.
- Communications: notification addresses and deliveries, webhooks and support requests.
- Billing: name or company, address, tax identifiers, plan and payment status. Stripe processes card details; they do not pass through UpBot servers.
- Technical data: IP address, user agent, session identifier and security logs required to operate the service.
3. Purposes and legal bases
- Contract: account creation, monitoring, alerts, collaboration, support and billing.
- Legal obligation: accounting and tax records and legally required requests.
- Legitimate interests: security, abuse prevention, auditing, troubleshooting and proportionate service improvement.
- Consent: only where explicitly requested for optional marketing or analytics technologies. Consent may be withdrawn at any time.
4. Recipients and providers
We share data only with personnel and providers that need it to deliver the service, are subject to appropriate safeguards and act on our instructions. Categories and planned subprocessors are listed in the DPA.
Where a transfer outside the EEA is necessary, we use a valid GDPR mechanism such as an adequacy decision or standard contractual clauses.
5. Retention
- Account and configuration data are kept for the contract term and a reasonable period afterwards for recovery or claims.
- Monitoring history follows the selected plan retention; aggregated or anonymised statistics may remain longer.
- Accounting records are kept for the statutory period.
- Security and audit logs are kept only as long as proportionate to their purpose and risk.
- Backups are deleted through rotation unless law or incident handling requires longer retention.
6. Your rights
- You may request access, correction, erasure, restriction and portability where GDPR provides these rights.
- You may object to processing based on legitimate interests and withdraw consent.
- Send requests to privacy@upbot.eu. We may reasonably verify your identity.
- You may complain to the Slovak Data Protection Authority at Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk, or to the authority in your country.
7. Required data
Data marked as required is needed to enter into or perform the contract or comply with law. Without it, an account, paid service or feature may not be available. Other data is optional.
8. Automated processing
UpBot automatically evaluates technical checks and opens incidents or sends alerts according to customer rules. This does not produce legal or similarly significant effects on individuals under GDPR Article 22.
9. Security and changes
We apply appropriate technical and organisational measures, including access controls, encrypted transmission, secure password storage, auditing and backups. We may update this notice when the service, providers or law changes and will publish the effective date.