UPnatorUPTIME. VISIBILITY. CONFIDENCE.
ProductPricingIntegrationsDocumentationSecurityNetwork
Log inTalk to usFree access
/
ProductPricingIntegrationsDocumentationNetwork and IPsSecurityCompanyContact
/
Log inCreate account

UPnator Privacy Policy

Version: 2026-08-11.1 Effective date: 11 August 2026

1. Controller and contact

  1. The controller of personal data relating to UPnator accounts, access, security and billing is Jarosław Staroń, carrying on business as 9ne.pl Jarosław Staroń, Polish tax identification number (NIP) 8942787122, ul. Starobielawska 32a, 54-061 Wrocław, Poland, operator of the UPnator brand (the “Operator”).
  2. Privacy contact: privacy@upnator.com; security contact: security@upnator.com.
  3. The Operator has not appointed a data protection officer. Questions and requests may be sent directly to the address above.

2. Categories of data

UPnator may process:

  • account and organization data: name, email address, organization name, roles, language preferences and consents;
  • authentication and security data: password and token hashes, session identifiers, MFA/passkey data, IP address, user agent, login events and audit logs;
  • service configuration: monitors, targets, alert policies, recipients, integrations, maintenance windows and retention settings;
  • technical data: measurement results, response times, error codes, incident events, SIP/RTP metadata and quality diagnostics;
  • communications data: recipient addresses, delivery status and history, support requests and feedback;
  • billing and usage data: plan, limits, counters, billing periods, billing-profile data, customer, subscription and transaction identifiers; UPnator does not store full payment-card details;
  • website usage data: visit identifier, campaign source and basic conversion events, where enabled.

The platform does not store RTP content or call recordings. Full one-time tokens are not retained, and secrets are hashed or encrypted as appropriate.

3. Purposes and legal bases

The Operator processes data to:

  • create an account, provide the service, manage the plan and perform the contract—Article 6(1)(b) GDPR;
  • process payments, sales documents and billing—Article 6(1)(b) and (c) GDPR;
  • maintain security, prevent abuse, keep audit logs, diagnose issues and defend claims—legitimate interests under Article 6(1)(f) GDPR;
  • meet accounting, tax, telecommunications and other legal obligations—Article 6(1)(c) GDPR;
  • send product information following a voluntary request—consent under Article 6(1)(a) GDPR, which may be withdrawn at any time;
  • analyze aggregated usage and improve the product—legitimate interests, subject to minimization and, where possible, aggregation.

Where an organization configures data relating to its employees, customers or recipients, the organization is generally the controller and the Operator acts as processor under the DPA.

4. Sources and required data

  1. Data comes from the user, the organization administrator, the user’s device or browser, configured integrations, monitored systems and, for payments, Stripe.
  2. Required data is needed to create and secure an account or perform a paid contract. Failure to provide it may prevent the service from being supplied. Other data is optional.

5. Recipients

  1. Data may be disclosed to authorized UPnator personnel, infrastructure and email providers, professional advisers bound by confidentiality, and public authorities where required by law.
  2. OVHcloud is the principal infrastructure and transactional-email provider. The database and application components operate on dedicated infrastructure in the European Union.
  3. Stripe Payments Europe, Limited and Stripe group entities process payment data and customer and transaction identifiers for Checkout, subscriptions, refunds and the customer portal. Stripe may act as an independent controller where required by financial regulation and its own legal obligations.
  4. The current subprocessor list for entrusted data is set out in the DPA. The Operator does not sell personal data.

6. Transfers outside the EEA

  1. The core UPnator deployment and transactional email are maintained within the European Economic Area.
  2. Stripe and customer-configured integrations may involve entities outside the EEA. GDPR transfer mechanisms apply, in particular an adequacy decision or Standard Contractual Clauses, together with a transfer risk assessment where required.

7. Retention

  1. Account data is retained while the account is active and is then deleted or anonymized after closure, subject to backup cycles and legal obligations.
  2. Default operational retention is: raw attempts 90 days, check runs 365 days, incident events and audit logs 730 days, notification deliveries 180 days, agent events 90 days, guardrails 365 days, usage ledger 1,095 days and outbox 30 days. The administrator may select permitted values shown in the application.
  3. Email-provider events and deleted suppression entries are retained by default for 365 days. An active suppression entry may be kept longer solely to respect an objection or unsubscribe request.
  4. Database backups rotate after 14 days. Data may remain in an encrypted backup until the end of that cycle.
  5. Billing, accounting, tax and evidentiary records are retained for the period required by law or the applicable limitation period. Stripe applies its own retention periods described in its privacy policy.

8. Individual rights

Depending on the legal basis and circumstances, an individual may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to the President of the Polish Personal Data Protection Office. Requests may be sent to privacy@upnator.com. The Operator may request information needed to verify identity.

9. Automated decisions

UPnator automatically classifies monitoring results and may open incidents or trigger alerts according to the organization’s configuration. This concerns system state, produces no legal effects for individuals and is not profiling within Article 22 GDPR.

10. Security

Measures include organization isolation, encrypted connections, password and token hashing, secret encryption, mTLS between selected services, least privilege, SSRF protection, MFA/passkeys, audit logging, backups and restore tests, secret rotation, monitoring and incident-response procedures. No system can guarantee complete absence of risk.

11. Cookies and browser storage

UPnator uses technically necessary cookies or storage to maintain sessions, protect against CSRF, set language and remember basic visit attribution. Stripe may set its own technically necessary cookies during Checkout and customer-portal use. UPnator does not use these mechanisms for third-party behavioral advertising.

12. Policy changes

The Operator may update this Policy because of changes in law, features or providers. Material changes are communicated in the application or by email. The version and effective date appear at the beginning.

Questions about this document: legal@upnator.com

UPnatorUPTIME. VISIBILITY. CONFIDENCE.

A platform for uptime monitoring, alerts and incident management.

ProductFeaturesPricingIntegrations
ResourcesDocumentationNetwork and IPsAPISLA reports
CompanyAboutContactSecurity
Start with a real use case

Tell us what you need to monitor. We will help you choose a safe first scenario.

Create accountsupport@upnator.com
© 2026 UPnator · 9ne.pl Jarosław StarońTerms · Privacy · DPA
/