Privacy Policy
The short version
- We collect what we need to run a monitoring service: who you are, how to reach you, what you set up, and a record of sign-ins and changes.
- No analytics, no tracking, no advertising. Our website sets no cookies at all.
- Your card details go to Stripe and never reach us.
- Our servers and backups are in the European Union.
- When an account ends, we delete its data 30 days later.
- You can ask us what we hold about you, and have it corrected or deleted, at [email protected].
This summary is here to help. The full policy below is what applies.
1. Who is responsible for your data
Lunolyte, established in the Netherlands, is the controller of the personal data described in this policy. Lunolyte is being registered with the Dutch Chamber of Commerce (KvK). Its legal name, registration number and business address will be stated here before any paid subscription is offered.
"We", "us" and "our" in this policy mean that party. For everything about privacy you can reach us at [email protected].
We have not appointed a data protection officer, because the law does not require us to.
2. What this policy covers
This policy explains what personal data we handle, why, on which legal basis, for how long, and who else is involved, when you:
- visit our website, lunolyte.com;
- join our waitlist;
- have an account in the Lunolyte portal, as the owner of an Account or as a User invited to one;
- pay us for a subscription;
- contact us;
- view a Status Page that we host.
It uses the same terms as our Terms of Service, such as Account, User and Status Page.
3. When we act for our customers instead
For most of what this policy describes we decide why and how personal data is used. That makes us the controller, and this policy is our account of it.
For some personal data our customer decides, and we only carry out what the customer asks. This is the case when a customer invites colleagues or clients to its Account or to a private Status Page, and for whatever a customer writes on a Status Page or in an Incident. There the customer is the controller and we are its processor, under our Data Processing Agreement.
In practice this means: if you were given access to Lunolyte by your employer or by a company you work with, and you have a question about why they added you or what they do with your data, they are the ones to ask. For how Lunolyte itself keeps your sign-in secure, this policy applies.
4. When you visit our website
You can read our website without telling us who you are. It sets no cookies and loads nothing from other parties: no analytics, no advertising, no fonts or scripts from elsewhere.
- What: the technical data every web request carries: your IP address, the page requested, the time, and your browser type.
- Why: to deliver the page to you, to keep the website secure, and to find the cause when something goes wrong.
- Legal basis: our legitimate interest in running a secure, working website.
- Kept for: the short period for which our hosting and network providers keep such logs. We do not copy them into systems of our own or combine them with other data about you.
5. When you join the waitlist
If you leave your email address on our waitlist:
- What: your email address and the date you signed up.
- Why: to send you a confirmation, and to tell you once when sign-ups open.
- Legal basis: your consent. You can withdraw it at any time by emailing us, and we will remove your address.
- Kept for: until we have told you that sign-ups are open, and for no longer than 12 months after you signed up.
6. When you have an account
If you have an account in the portal, as the person who signed a company up or as a User who was invited:
- What: your name and email address, the Account you belong to and your role in it, and whether you want to receive alerts by email.
- Why: to give you access, to show the right data to the right person, and to reach you about the Service.
- Legal basis: performance of our contract with you. If you are a User invited by your employer or another organisation, our legitimate interest in providing the Service to that organisation.
- Kept for: as long as the Account exists. When a User is removed from an Account, their access ends at once and their details are deleted 30 days later, unless they still belong to another Account. When the Agreement ends, the whole Account is deleted 30 days later.
Signing in works through a link we send to your email address. There are no passwords.
- What: a record of each sign-in link and each session: when it was created and used, your IP address and your browser type. Links and session keys are stored only in a scrambled form that cannot be turned back into the original.
- Why: to sign you in, to keep you signed in, and to detect and stop misuse of an account.
- Legal basis: performance of the contract, and our legitimate interest in the security of the Platform.
- Kept for: a sign-in link works once and for 10 minutes. A session lasts at most 12 hours. Both records are deleted one day after they expire.
7. When you use the portal
While you use the portal:
- What: what you set up, such as the addresses you have monitored, your Status Pages, alert settings and Incidents, and an audit log of actions taken in your Account: who did what, when, and from which IP address.
- Why: to provide the Service, and so that you and we can see afterwards who changed something.
- Legal basis: performance of the contract, and our legitimate interest in the security and accountability of the Platform.
- Kept for: your configuration as long as the Account exists. Monitoring history for the retention period of your plan. Audit log entries for 12 months.
The addresses you monitor and the results of our Checks usually say something about a system, not about a person. Where they do contain personal data, for example a name in a web address, we handle it as described here.
8. When you pay us
Payments are handled by Stripe, on a payment page that is Stripe's and not ours. Your card details go from your browser to Stripe. They never pass through our servers and we never have them.
- What: your company name, email address, billing address, country and VAT number where you give one, the plan you chose, what you were charged and whether the payment succeeded, and Stripe's reference numbers for you and your subscription. If a payment fails, the reason your bank gave. In Stripe's own dashboard we can see the type of card and its last four digits.
- Why: to charge you, to send invoices, to tell you when a payment fails, and to keep the records the tax authorities require.
- Legal basis: performance of the contract, and for invoices and financial records our legal obligation to keep them.
- Kept for: invoices and the financial records behind them for seven years, as Dutch tax law requires. The technical log of messages Stripe sends us about your payments for 90 days. Everything else as long as the Account exists.
Stripe also uses some of this data for purposes of its own, such as preventing fraud and meeting its own legal obligations. For that it is a controller itself, and Stripe's privacy policy applies.
9. When we send you messages
We send you email in connection with the Service: sign-in links, alerts about the services you monitor, a monthly report for each Status Page where your plan or an add-on includes reports, notices about your subscription and payments, and announcements you need to know about, such as a change to our terms.
- What: your email address and the content of the message.
- Why: because the Service cannot work without them, or because you need the information.
- Legal basis: performance of the contract. For Users invited by an organisation, our legitimate interest in providing the Service to it.
- Kept for: we do not keep a copy of the messages we send, other than what the audit log and the monitoring history record anyway.
You can switch alert emails and the monthly reports off in your profile. Messages about sign-in, billing and legal changes cannot be switched off while you have an account.
If you connect Slack, Microsoft Teams or a webhook, alerts go to the address you configured. What happens to them there is governed by that service and by you.
10. When you contact us
If you email us:
- What: your name and email address, what you write, and anything you attach.
- Why: to answer you and to solve the problem.
- Legal basis: performance of the contract if you are a customer, and otherwise our legitimate interest in answering people who write to us.
- Kept for: for as long as you are a customer, so that we can refer back to earlier questions. If you are not a customer, or once you no longer are, until you ask us to delete it. You can ask at any time, and we will.
Please do not send us more personal data than the question needs. In particular, never send passwords, or a full card or bank account number.
If you ask us by email to do something with an Account, we may need to check that you are entitled to. We do that by asking you to confirm details we already have: an email address on the Account, the name of the company and of a user, and the last four digits of the card or bank account the subscription is paid with. We compare your answer with our own records and with what Stripe shows us. We do not store it anywhere other than in the email itself, and we never ask for a full number.
11. When you view a status page
A public Status Page can be viewed by anyone, without an account and without cookies.
- What: the technical data of the request, as described in section 4. If you choose light or dark mode, or expand the history, that choice is stored in your own browser and is not sent to us.
- Why: to show you the page and to keep it secure.
- Legal basis: our legitimate interest in providing a secure, working Status Page.
- Kept for: as described in section 4.
A private Status Page can only be viewed by people the customer has invited. If you are one of them, you sign in with a link sent to your email address, and section 6.2 applies to you. A session for a Status Page lasts at most 8 hours. The customer who invited you is the controller of your details, see section 3.
12. What we do not collect
We want this to be as clear as what we do collect. We do not:
- receive or store your payment card number, expiry date or security code;
- store the content of the websites and services you have monitored. A Check records whether the service answered, with which status, how fast, until when its certificate is valid and by whom it was issued, what its domain name points to, and until when that name is registered according to its public register. A content check reads the page to see whether a text you chose is on it, and keeps only the answer to that question;
- use analytics, tracking pixels or advertising cookies, on our website, in the portal or on Status Pages;
- build profiles of you, or buy data about you from others;
- sell your personal data, or share it with anyone for advertising;
- ask for, or want to receive, special categories of personal data, such as data about health.
13. Where your data comes from
Most of the personal data we hold, we get from you directly: when you sign up, set up your Account, or write to us.
Some of it comes from someone else:
- from the owner or an administrator of an Account, when they invite you as a User or as a viewer of a private Status Page. They give us your email address and, if they choose, your name;
- from Stripe, which tells us whether a payment succeeded and passes on the billing details you entered on its payment page;
- from your browser, automatically, in the form of the technical data described above.
We do not collect personal data about you from public sources.
14. Our legitimate interests
Where this policy names our legitimate interest as the legal basis, these are the interests we mean:
- Security. Keeping the Platform, the accounts on it and the data in it safe, which includes logging sign-ins and actions, and recognising misuse;
- Providing the Service to organisations. A company that buys Lunolyte needs its staff and clients to be able to use it. We process their details to make that possible, without having a contract with each of them personally;
- Keeping things working. Finding and fixing faults, and understanding in general terms how the Service is used so that we can improve it. We use data that does not identify you for this wherever that is enough;
- Our legal position. Being able to show what was agreed and what happened if there is a dispute.
We have weighed these interests against yours and limited what we process to what they need. You can object, see section 21.
15. Who we share data with
We do not sell personal data. We share it only with the providers we need to run Lunolyte, each of which may use it only to provide its service to us:
| Provider | What it does for us | Where |
|---|---|---|
| Hetzner Online GmbH | Hosts the servers and databases of the Platform | Nuremberg, Germany |
| Cloudflare, Inc. | Delivers and protects the Platform, and stores our encrypted backups | Backups in the European Union. Network traffic is handled at the Cloudflare location nearest to you, which can be outside the EEA. |
| Zoho Corporation B.V. | Delivers the emails we send and hosts our own mailbox | European Union |
| Stripe Payments Europe, Limited | Processes payments and issues invoices | Ireland, with processing by Stripe group companies in the United States |
| Hostinger | Hosts this website | The Netherlands, with backups in Lithuania |
If you are an invited User or viewer, the owner and the administrators of the Account you belong to can see your name, email address and role, and the audit log of that Account.
We disclose personal data to authorities only when the law obliges us to, and then only what is required. If the business were ever taken over, the personal data needed to continue the Service would pass to the new owner, who would be bound by this policy.
16. Transfers outside the European Economic Area
Our own servers, databases and backups are in the European Union.
Two of our providers, Cloudflare and Stripe, are part of groups based in the United States, and personal data can be processed there. For those transfers we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Commission's standard contractual clauses.
You can ask us for more information about these safeguards at [email protected].
17. How long we keep data
The sections above state a period for each kind of data. In short:
| Data | Kept for |
|---|---|
| Account and User details | As long as the Account exists, then 30 days |
| Sign-in links and sessions | One day after they expire |
| Audit log | 12 months |
| Monitoring history | The retention period of your plan |
| Invoices and financial records | Seven years |
| Log of payment messages from Stripe | 90 days |
| Waitlist | Until sign-ups open, at most 12 months |
| Email you sent us | While you are a customer, and afterwards until you ask us to delete it |
Where no fixed period is possible, we keep data only for as long as the purpose it was collected for requires, and delete it when that purpose has ended.
We make a backup of our databases every night. Data that has been deleted can therefore still be present in a backup for a while. Backups are overwritten on a rolling schedule and are gone within about 90 days. In that time we do not use a backup for anything other than restoring the Platform after a failure.
18. How we protect data
We protect personal data with technical and organisational measures that fit the risk. Among other things: all traffic is encrypted in transit, sign-in works without passwords, each part of the Platform has access only to the data it needs, actions are logged, and backups are encrypted and stored at a second location in the European Union. Our Data Processing Agreement describes the measures in more detail.
No system is completely secure. If a breach of personal data occurs that is likely to put you at risk, we report it to the Dutch Data Protection Authority within the period the law sets, and we tell you where the law requires that.
19. Cookies and similar techniques
Our website sets no cookies. The portal sets one cookie, and only after you sign in, to keep you signed in. Our Cookie Policy lists exactly what is stored on your device and why.
20. Marketing
We do not send newsletters or promotional email. The only message we send to someone who is not a customer is the one announcement to people on the waitlist, described in section 5.
Messages we send to customers about their own account are part of the Service and are not marketing. See section 9.
If we ever start sending marketing email, we will ask for your permission first where the law requires it, and every such message will let you unsubscribe.
21. Your rights
Under the General Data Protection Regulation you have the right to:
- access the personal data we hold about you, and receive a copy;
- have data corrected that is wrong or incomplete;
- have your data deleted, where we have no reason left to keep it;
- have us restrict what we do with your data in certain cases, for example while a dispute about its accuracy is being settled;
- object to processing that is based on our legitimate interest;
- receive the data you gave us in a common format so that you can take it elsewhere (portability);
- withdraw consent you gave us, such as for the waitlist. This does not affect what was done before you withdrew it.
Some of this you can do yourself in the portal: you can change your name and your alert settings in your profile, and the owner of an Account can remove Users and viewers.
22. How to use your rights
To use one of these rights, email us at [email protected]. Tell us which right you want to use and which data it concerns.
We may ask you to show that you are who you say you are, for example by writing to us from the email address your account is registered with. We do this so that we do not hand your data to someone else. We will not ask for more than we need for that.
We answer within one month. If a request is complicated, or we receive many, the law allows us to take up to two more months. We will tell you within the first month if that is the case.
Using your rights is free. Only if a request is clearly unfounded or excessive may we charge a reasonable fee or decline it.
If you were added to Lunolyte by a customer of ours, we may pass your request on to that customer, because it is the controller of your details. See section 3.
You have the right to lodge a complaint with a supervisory authority. For us that is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. You can also turn to the authority of the EU country where you live or work. We would appreciate the chance to resolve your concern first.
23. Automated decisions and profiling
We do not take decisions about you by purely automated means that have legal or similarly significant effects for you, and we do not profile you. An alert about a monitored service is an automated message about a system, not a decision about a person.
24. Children
Lunolyte is a service for businesses and is not aimed at children. You must be at least 18 years old to have an account. We do not knowingly collect personal data of children. If you believe a child has given us personal data, tell us and we will delete it.
25. If you are outside the European Union
We are established in the Netherlands and apply the General Data Protection Regulation to everyone whose personal data we handle, wherever they live.
If you are in the United Kingdom, the UK GDPR gives you rights that are in substance the same as those described in section 21, and you can also complain to the Information Commissioner's Office.
We do not currently meet the thresholds at which the privacy laws of individual US states, such as California's, apply to a business. Whatever those laws would require, we do not sell personal data and do not share it for advertising.
26. Changes to this policy
We may change this policy, for example when the Service changes or the law does. The date at the top shows when this version took effect.
If a change is significant, for instance because we start using data for a new purpose or involve a new kind of provider, we will tell customers by email or in the portal before it takes effect.
27. Contact
Questions about this policy or about your personal data can be sent to [email protected].