← all legal documents

Privacy Notice

version 2026-08-09·sha256 de7c3ba706b9be7a637b6ff5293688bec39c98079c0411dcced41fd90d1a0223
WHAT WE COLLECT. Account data (email address, password hash, MFA enrolment state, sessions, IP address and user agent at sign-in). Telemetry your agents send (hostnames, OS and kernel version, system and network metrics, active connections and their remote addresses, process names and paths, DNS queries, and — only where you enable per-host capture — redacted packet metadata). Security records (audit log, consent records). WHY. To operate the service, to show you your own fleet, to send the alerts you configure, to secure accounts against abuse, and to meet legal obligations. CONTROLLER / PROCESSOR. For your account data we are the controller. For the telemetry your agents send about your hosts and their users, you are the controller and we are your processor: you decide what to monitor and on what basis. SUB-PROCESSORS. Railway (hosting and managed Postgres, EU/US), Resend (transactional email). Telemetry is stored in the managed Postgres instance backing the service. RETENTION. Telemetry follows your account's retention setting. Audit and consent records are retained for up to seven years for security and legal-defence reasons. Sessions expire and are pruned. YOUR RIGHTS. You can export your data and delete your account from Settings. Where the GDPR or a comparable law applies you also have rights of access, rectification, erasure, restriction, portability and objection. Contact admin@netwatchlabs.com. SECURITY. Passwords are hashed with bcrypt. API keys are stored hashed and shown once. Refresh tokens are stored hashed and are individually revocable. TOTP MFA is available. Transport is TLS. Audit and consent tables are append-only at the database level. NO SALE. We do not sell personal data and do not use your telemetry to train models.

Questions about this document? Email admin@netwatchlabs.com.