Privacy Policy
Last updated: 24 August 2026 · Effective from: 24 August 2026
Beta notice: Uptime Agent is currently a free beta service. This policy describes how we handle personal data during the beta. If anything material changes, we will notify account holders before it does (see “Changes to this Privacy Policy”).
Thank you for choosing Uptime Agent. We are committed to protecting and respecting your privacy.
This Privacy Policy, and any other documents referred to in it, sets out the basis on which we collect and use your personal data when you use our website (uptimeagent.com) or our services. We urge you to read and understand this Privacy Policy carefully. If you do not agree with it, please refrain from using our website or our services. We also encourage you to revisit this document from time to time, as we may update it to remain compliant with the law and transparent about our privacy practices.
For the purposes of the UK GDPR and the EU GDPR (or any applicable Data Protection Laws, regulations, implementing laws or secondary legislation relating to the processing of personal data), the Data Controller is Mozilor Limited, 3 Warren Yard, Wolverton Mill, Milton Keynes, England, United Kingdom – MK12 5NW (Company No. 11946756), operating the Uptime Agent service.
The two roles we play
We act in two distinct capacities, and it matters which one applies to which data.
We are the data controller for data about you and your team: your account data, product usage analytics, support conversations, data from our marketing website, and the emails we send you. This Privacy Policy governs that data.
We are a data processor on your behalf for the data your monitoring generates: monitor configurations, check results, incident evidence, and — especially — Log Content ingested by the optional log collector. You are the controller of that data. We process it only on your instructions, to provide the service.
The point that matters most, in plain terms: if you install the log collector, your logs may contain personal data of your own users — for example email addresses in stack traces, IP addresses, or user identifiers. You are the controller of that personal data, and you are responsible for being able to lawfully send it to us.
A Data Processing Agreement is available on request from support@uptimeagent.com (a full self-serve DPA will follow). In the meantime, our Terms of Service include a data-processing clause covering the essentials.
Legal bases for processing
We only use your personal data when the law allows us to do so. We generally use your personal data in the following circumstances:
- To fulfil our contractual obligations with you, the user.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- To comply with a legal obligation.
In other cases where we may have to use your personal data, we will only do so after getting your freely given, specific, informed and unambiguous consent to do so.
Personal data that we may collect
Personal data is any information that can uniquely identify a natural person. It does not include information where the identification has been removed (anonymised data). We collect the following personal data:
| Purpose | Type of data | Lawful basis |
|---|---|---|
| Creating and administering your account; providing monitoring, incident and alerting services | Name, email address, password (held in our own self-hosted authentication system) | Performance of our contract with you |
| Sending service emails — incident alerts, account, security and change notices | Email address; incident data | Performance of our contract with you |
| Answering your support requests | Support conversations; account data | Performance of our contract with you |
| Product usage analytics | Usage events, feature interactions, device characteristics, IP address (see “Analytics”) | Consent, via our cookie consent banner |
| Keeping the service secure and preventing abuse | Server and access logs, IP addresses | Legitimate interests |
| Operating our marketing website and public status pages | Standard web server logs (such as IP address and browser information) | Legitimate interests |
How do we collect the data?
We collect data through the following methods:
- Through direct interactions: when you sign up to use our services, we require you to fill out a form detailing the information we need to provide you with our services; and when you contact us for support.
- Through your use of the services: the monitors you configure, the check results they produce, and the incidents they generate.
- Through the optional log collector: recent error/log output from the streams your developers choose to connect, sent to us on your instructions (see “Service data we process on your behalf”).
- Automatically: via cookies and analytics, subject to your consent choices (see “Cookies” and “Analytics”).
Service data we process on your behalf
As your processor, we handle: monitor configurations (the endpoints you ask us to check), check results from our six probe regions (Ireland, North Virginia (US), Canada, Frankfurt, Mumbai, Sydney), incident evidence (timings, error output), and Log Content from the optional log collector. Log Content may incidentally contain personal data of your end users.
If you connect an alert destination such as a Slack workspace or a webhook, incident data is sent to that destination on your instruction; what that provider does with it is governed by your agreement with them.
Public status pages are hosted separately from the main application; we keep standard server logs of visits to them.
Special categories of personal data
We do not knowingly collect, and our services do not require, special categories of personal data — details about race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health, or genetic and biometric data. If you use the log collector, you must not connect log streams containing such data (see our Terms of Service). We cannot inspect your logs for it in advance; Log Content is processed on your instructions as described above.
Cookies
We use essential cookies for login, sessions and security; these are required for the website and product to function and do not require consent. Analytics runs only with your consent (see below). We use no advertising cookies. You can change your choices at any time using the cookie-consent control on our website.
Analytics
We use Mixpanel to generate performance and product usage analytics across our website and products. Mixpanel supports our internal service-optimisation workflows by providing aggregated insights on user behaviour, including pages or screens viewed, feature interactions, device characteristics, session performance, and general usage patterns. These analytics enable continuous service improvement, incident diagnostics, and UX optimisation.
Mixpanel is activated only after you grant consent through our cookie consent banner. The lawful basis for this processing is consent under Article 6(1)(a) GDPR. You may withdraw your consent at any time by updating your cookie preferences, and withdrawal will immediately disable further analytics collection.
Mixpanel may process limited technical indicators such as your IP address or device-level identifiers to deliver its analytics functionality. Our Mixpanel project is configured to Mixpanel’s EU data-residency environment. Additional information on Mixpanel’s processing practices is available in its privacy policy.
AI investigation
When an incident opens, our AI investigation feature can analyse the evidence and produce a diagnosis and root-cause write-up. Here is exactly how that works with your data:
- Models: we use Google Gemini models, provided by Google Cloud EMEA Limited, on Google’s paid/enterprise terms. Under those terms, Google does not use our prompts or responses to train or improve its models or products.
- What we send: incident evidence only — check results, error output, and short log excerpts where the log collector is installed.
- Retention at Google: Google retains API data only for limited-period abuse monitoring.
- Accuracy: AI output may be inaccurate or incomplete. It is informational, always labelled as AI-generated, and must not be the sole basis for action on your production systems.
- Read-only: the AI investigates; it never changes your systems.
Automated decision-making: the AI investigates technical incidents in infrastructure. It makes no decisions about people that produce legal or similarly significant effects.
Third-party services and sub-processors
We may share your personal data with third parties for the purposes set out in this Privacy Policy. This may include the following:
- Any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries.
- Business partners, suppliers and subcontractors for the performance of any contract we enter into with them or you, to provide services such as hosting.
- Professional advisers acting as service providers to us — including lawyers, bankers, auditors and insurers.
- Tax authorities, regulators and other authorities who require reporting of processing activities in certain circumstances.
We use the following third parties to store and process the data described in this policy. You can read their legal documents at the given links.
| Provider | Legal entity | Purpose | Location | Legal terms |
|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services EMEA SARL (Luxembourg) | Hosting, database, backups (eu-west-1, Ireland); CloudFront CDN; Route 53 DNS; probe VMs in the six check regions | Data at rest: Ireland (EEA). Probes process check data transiently in-region | AWS GDPR DPA |
| Google Cloud EMEA Limited (Dublin, Ireland) | Gemini AI models for incident investigation | Processing may occur outside the UK/EEA depending on configuration; safeguarded by SCCs | Google Cloud DPA | |
| Resend | Plus Five Five, Inc. (San Francisco, US) | Transactional email (alerts, account emails) | US — account data, email metadata and logs are stored in the US | Resend DPA |
| Mixpanel | Mixpanel, Inc. (US) | Product usage analytics | EU data residency (our project is configured to Mixpanel’s EU environment) | Mixpanel DPA |
| Intercom | Intercom R&D Unlimited Company (Dublin, Ireland) | Customer support chat | Hosted in the US; transfer safeguarded by SCCs / EU-US Data Privacy Framework | Intercom DPA |
We will update this list as it changes and notify account holders of material changes.
International transfers
Our services are global, and personal data may be processed where we have operations, where our staff are located, or where our service providers are situated. We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this Privacy Policy. In particular, personal data is only transferred to a country that provides an adequate level of protection (for example, where the European Commission or the UK Information Commissioner’s Office (“ICO”) has determined that a country provides an adequate level of protection), or where the recipient is bound by standard contractual clauses in the form approved by the European Commission or the ICO.
Specifically:
- Home region: your data is stored at rest in AWS Ireland (EEA), including database and backups.
- Probe regions: monitoring probes run in six regions — Ireland, North Virginia (US), Canada, Frankfurt, Mumbai, Sydney — and process check data transiently in-region. Results are stored in Ireland.
- EEA ↔ UK: transfers from the EEA to the UK are covered by the European Commission’s adequacy decision for the UK (renewed 19 December 2025, valid to 27 December 2031). Transfers from the UK to the EEA are covered by UK adequacy regulations.
- US providers: transfers to Resend, Intercom, and Google (where applicable) are safeguarded by EU Standard Contractual Clauses and the UK Addendum/IDTA, and/or the EU-US Data Privacy Framework where the provider is certified.
- Staff access from India: some of our engineering and support staff, employed by Mozilor Limited, access our systems remotely from India. This is not a transfer of your data to another organisation: the data remains held in our EEA infrastructure and is accessed under our own security controls, including role-based access on a need-to-know basis.
Data security
We have taken appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. Data is encrypted in transit and at rest. We limit access to personal data to those employees, agents, contractors and other third parties on a need-to-know basis, enforced through role-based access controls. Authentication is self-hosted — we run our own authentication system rather than sending your credentials to a third-party identity provider. Internal monitoring runs on self-hosted Prometheus and Grafana on our own AWS infrastructure; these are internal tools, not third parties.
However, the transmission of data over the internet is not always foolproof. Although we will endeavour to protect your personal data, we cannot guarantee that transmission to our site or services is completely secure; any transmission is at your own risk. Once we have received your personal data, we use strict procedures and security features to try to prevent unauthorised access.
Data retention
We retain the data that we collect from you for as long as it is necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain personal data for a longer period in the event of a complaint, if we reasonably believe there is a prospect of litigation in respect of our relationship with you, to comply with law enforcement requests, maintain security, prevent fraud and abuse, resolve disputes, and enforce our legal agreements.
Our standard retention periods are:
| Data | Retention |
|---|---|
| Raw check results | 30 days, then aggregated |
| Aggregated uptime rollups (1-minute / 1-hour) | 13 months |
| Incident records and RCA write-ups | Life of the account |
| AI investigation inputs (including quoted log excerpts) | 30 days |
| AI investigation outputs (findings) | Life of the account, with quoted log excerpts removed or expired per the Log Content window |
| Log Content from the collector | 14 days by default; configurable down; 30 days maximum |
| History of a deleted monitor | 30 days |
| Account data after account deletion | Deleted within 30 days; backup copies expire within 35 days |
| Server and access logs | 30 days |
| Support conversations | Per Intercom’s terms; deleted 180 days after our agreement with Intercom ends |
Your rights
Depending on the privacy law of your country, you may have the following rights:
- Right to be informed: you have the right to be informed of the collection and use of your personal data.
- Right to access: you have the right to view and request copies of the personal data we hold about you.
- Right to rectification: you have the right to request that inaccurate or outdated information be corrected or updated.
- Right to be forgotten / right to erasure: you have the right to ask for your personal data to be deleted. Note that this right is not absolute and may be subject to exemptions under certain laws.
- Right to data portability: you have the right to ask for your data to be transferred to another controller, or provided to you, in a machine-readable electronic format.
- Right to restrict processing: you have the right to restrict the processing of your personal data.
- Right to withdraw consent: you have the right to withdraw consent to processing where consent is the basis. This may make us unable to serve you with some of our services.
- Right to object to processing: you have the right to object to processing of your personal data. Exercising this right may affect our ability to provide you with our services.
- Right to object to automated processing: you have the right to object to automated processing. See “AI investigation” above — we make no solely automated decisions about people with legal or similarly significant effects.
If you wish to exercise any of the above rights, please contact us as set out at the end of this Privacy Policy. We will respond to such requests within 30 days, in accordance with applicable Data Protection Law. Occasionally it could take longer if your request is particularly complex or you have made a number of requests; in that case, we will notify you and keep you updated.
You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee, or refuse to comply, if your request is clearly unfounded, repetitive or excessive. We may need to request specific information from you to help us confirm your identity before responding; this is a security measure to ensure personal data is not disclosed to a person who has no right to receive it.
Personal data inside Log Content or monitored-site data: the customer who sent us that data is its controller, not us. If you are an end user of one of our customers and your personal data appears in their logs, please contact that customer — we redirect data-subject requests to them and assist them in responding. To be plain: we cannot search log content by data subject — requests must go through the customer.
Complaints and queries
If you have any complaints about our use of your personal data, you have three routes:
- Directly to us, at support@uptimeagent.com. We will acknowledge your complaint within 30 days and explain the outcome. This direct route is a statutory duty on us under UK law — you do not need to go to a regulator first.
- The UK Information Commissioner’s Office (ico.org.uk).
- Your local EU data protection supervisory authority, if you are in the EU.
Changes to this Privacy Policy
Any changes we make to this Privacy Policy in the future will be posted on this page. If we make a material change, we will notify account holders by email at least 14 days before it takes effect, and update the dates at the top of this page.
Contact
If you have any questions, comments, requests or complaints regarding this Privacy Policy or our privacy practices, kindly reach out to us:
- By post: Mozilor Limited, 3 Warren Yard, Wolverton Mill, Milton Keynes, MK12 5NW, United Kingdom.
- By email: support@uptimeagent.com
- Complaints and grievances: the Product Manager, reachable at support@uptimeagent.com.
Last updated: 24 August 2026 · Uptime Agent is a product of Mozilor Limited.