Template Template — not legal advice. Have qualified counsel review and adapt this to your jurisdiction before relying on it. Placeholders in [BRACKETS] must be replaced with your real details.

This Privacy Policy explains how [COMPANY LEGAL NAME] (“we,” “us,” or “DeadWatch”) collects, uses, and shares information when you use the DeadWatch website monitoring service, the Kestrel module, our websites, and related applications (together, the “Service”). It applies to visitors, account holders, and the authorized users of an account.

If you do not agree with this policy, please do not use the Service. Contact us at [CONTACT EMAIL] with any questions.

1. Who we are

The Service is operated by [COMPANY LEGAL NAME], located at [COMPANY ADDRESS]. For the purposes of applicable data-protection law, we act as a data controller for the account and marketing data described below, and as a data processor for the monitoring data you configure us to collect on your behalf about the websites you choose to monitor.

2. Data we collect

We collect the following categories of information:

Account information

Information you provide when you register and manage an account: name, email address, password (stored hashed), organization or team name, role, and — where you subscribe to a paid plan — billing contact details. Payment card details are handled by our payment processor and are not stored on our servers (see §5).

Monitored-site metadata & check configuration

The URLs, domains, hostnames, and endpoints you add for monitoring, together with the check settings you configure (intervals, regions, notification rules, maintenance windows, teams and client assignments, and similar). This may include authentication material you choose to supply for checks (for example, headers or credentials for a protected endpoint), which we store to perform the checks you request.

Check results & collected content

Data produced by running the checks you configure against the sites you designate. Depending on the checks you enable, this can include: HTTP status codes, response times and TTFB, uptime and incident history, SSL/TLS and certificate details, DNS records, WHOIS/domain-expiry data, HTTP headers, Web Vitals and performance metrics, screenshots captured for visual-regression testing, page content hashes and excerpts for content-drift and SEO checks, link-check results, asset fingerprints, and security/hijacking signals. You are responsible for ensuring you are authorized to monitor the sites and endpoints you add, and for any personal data that may appear in captured pages or responses.

Kestrel module data

If you use the Kestrel lead-generation module, we process the business/prospect information you search for or import, audit results generated for those sites, and outreach content you create or export. This may include publicly available business contact information.

Usage & device data

Information generated as you use the Service: log data, IP address, browser and device type, pages viewed, actions taken, timestamps, and diagnostic/error data. We use this to operate, secure, and improve the Service.

Communications & support

Messages you send us, support tickets, and related correspondence.

3. How we use data

We use the information above to:

  • Provide, operate, and maintain the Service and run the checks you configure;
  • Authenticate users and secure accounts (including fraud and abuse prevention);
  • Send operational and transactional messages, including monitoring alerts, incident notifications, and account notices via the channels you configure (email, Slack, Discord, webhook);
  • Process subscriptions, billing, and support requests;
  • Analyze usage to diagnose problems and improve features and performance;
  • Comply with legal obligations and enforce our terms; and
  • Send product or marketing communications where permitted — you can opt out at any time.

Where the EU/UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you sign up for); legitimate interests (to secure, maintain, and improve the Service, and for direct marketing where permitted); consent (for certain cookies and marketing, which you may withdraw); and legal obligation (to comply with applicable law). Confirm the correct bases with counsel for your jurisdiction and offerings.

5. How we share data & third-party processors

We do not sell your personal information. We share data with service providers who process it on our behalf under contract, and only as needed to run the Service:

  • Payment processing[e.g., Stripe] processes subscription payments. Card data is handled directly by the processor; we receive limited billing metadata (such as the last four digits, plan, and status).
  • Email & notification delivery[EMAIL PROVIDER, e.g., Postmark] and any messaging endpoints you configure (Slack, Discord, or your own webhook receivers) deliver the alerts and messages you request.
  • Hosting & infrastructure[HOSTING PROVIDER] hosts the Service and stores data on our behalf.
  • Analytics & error monitoring[ANALYTICS/ERROR PROVIDERS, if any], where enabled.

We may also disclose information: to comply with law, legal process, or lawful requests; to protect the rights, safety, and security of users, the public, or us; and in connection with a merger, acquisition, or sale of assets, in which case we will notify you as required. Maintain an up-to-date list of subprocessors and reference it here or via a linked page.

6. Cookies & analytics

We use cookies and similar technologies for essential functions (such as keeping you signed in and securing sessions) and, where applicable, for analytics and preferences. You can control non-essential cookies through your browser settings and any cookie controls we provide. Describe your specific cookies, their purposes, and durations here, and align with local consent requirements.

7. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service, then for the period required to meet legal, accounting, or reporting obligations. Monitoring results are subject to rolling retention limits appropriate to each check type (for example, historical check results, screenshots, and snapshots are pruned over time), and you can delete sites and results from your account. Specify concrete retention periods with counsel: [RETENTION PERIODS].

8. Your rights

Depending on where you live, you may have the right to access, correct, export (data portability), delete, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. Account holders can access and update much of their information directly in the Service, and can request an export or deletion by contacting [CONTACT EMAIL]. We will respond within the timeframe required by applicable law. If we process data as a processor on behalf of an account (for example, content captured from a monitored site), we will refer certain requests to the responsible account.

EEA/UK users may lodge a complaint with their local supervisory authority.

9. California privacy rights (CCPA/CPRA)

If you are a California resident, you may have the right to know what personal information we collect, use, and disclose; to request deletion or correction; and to opt out of any “sale” or “sharing” of personal information as those terms are defined by California law. We do not sell personal information. We do not discriminate against you for exercising these rights. To make a request, contact [CONTACT EMAIL]. Confirm the required disclosures and any authorized-agent process with counsel.

10. Security

We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit, hashed credentials, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Describe your actual safeguards accurately — do not overstate them. We will notify affected users and authorities of a breach where required by law.

11. International data transfers

We may process and store data in countries other than the one in which you reside. Where we transfer personal data across borders, we use appropriate safeguards required by applicable law (for example, standard contractual clauses). Confirm your transfer mechanisms and hosting locations here.

12. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under [AGE]. If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, notify you. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.

14. Contact us

For privacy questions or to exercise your rights, contact:

[COMPANY LEGAL NAME]
[COMPANY ADDRESS]
[CONTACT EMAIL]
[DATA PROTECTION OFFICER / EU-UK REPRESENTATIVE, if applicable]


See also our Terms of Service and Liability & Warranty Disclaimer.