Privacy policy
What personal data we collect, why, the legal bases, and your rights under GDPR, UK-GDPR, CCPA/CPRA, and the UAE PDPL.
Privacy policy
This is a plain-language template. It is not legal advice; have it reviewed by a qualified lawyer for your jurisdiction before relying on it.
Last updated: 2026-07-05
NoDowntimeShield ("we", "our", "us") operates a self-service security monitoring platform. This policy explains what personal data we collect, why we process it, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have. It applies to our website, dashboard, apps, extension, CLI, and API.
We serve customers across the US, Canada, UK, and Western Europe (primary) and India, the UAE, and the wider Middle East (secondary). This policy is written to meet the EU GDPR, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and the UAE Personal Data Protection Law (PDPL). Where a specific law gives you extra rights, the region-specific sections below explain them.
1. Who we are (controller)
NoDowntimeShield is the controller for personal data we collect about visitors, account holders, and the people who use the Service. Where we process personal data contained in your scan targets and findings on your behalf, we act as your processor under our Data Processing Agreement. Contact us at [email protected], or write to NoDowntime Technologies FZCO, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates.
2. What we collect
- Account data — name, email, hashed password, organisation name, role, and billing address.
- Scan data — the domains, subdomains, and assets you submit for monitoring; the technical findings our scanners produce; and any files you upload for manifest scanning. This can include personal data if it appears in your assets.
- Integration data — tokens and configuration for services you connect (for example DNS, WhatsApp, Slack, or a cloud provider), which we encrypt.
- Usage data — pages viewed, actions taken, and device and browser metadata.
- Billing data — handled by Stripe; we store only the customer ID and the last four digits of the card for display.
- Support and communications — messages you send us and our replies.
3. Why we process it, and our legal basis
For each purpose we rely on a legal basis under the GDPR, UK GDPR, and UAE PDPL:
- Running scans, producing findings, and showing your dashboard — performance of our contract with you.
- Sending alerts by email and WhatsApp — performance of our contract with you.
- Billing and managing subscriptions — performance of our contract with you.
- Security, abuse prevention, and rate limiting — our legitimate interest in keeping the Service safe.
- Product analytics and improvement — your consent, where required; otherwise our legitimate interest.
- Meeting legal, tax, and accounting duties — compliance with a legal obligation.
Where we rely on consent (for example non-essential cookies), you can withdraw it at any time without affecting processing that already happened. Where we rely on legitimate interests, we have weighed them against your rights and you can object (see your rights below).
4. Who we share it with
We share personal data only with the sub-processors that help us run the Service — for example hosting, database, email, WhatsApp routing, payments, error monitoring, and the AI providers that rewrite findings into plain English. Each is bound by a data-processing agreement, and we do not permit AI providers to train their models on your content — our primary providers (OpenAI, Anthropic) do not train on API inputs by default. The current list, what each receives, and where it sits is published in our Sub-processor list.
We may also disclose data where the law requires it, to protect our rights or users' safety, or as part of a merger or acquisition (we would tell you first).
5. We do not sell your personal data
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We have not sold or shared personal data for these purposes in the past 12 months, and we do not run advertising trackers. Because of this there is nothing for you to opt out of under the CCPA/CPRA "Do Not Sell or Share My Personal Information" right — but if that ever changed, we would add a clear opt-out link here and on our homepage first.
6. International transfers
We are a global service, so your data may be processed outside your home country, including outside the EEA and the UK. When we transfer personal data across borders we rely on appropriate safeguards — principally the Standard Contractual Clauses (and the UK International Data Transfer Addendum) with each sub-processor, published as part of our DPA. For UAE residents, we transfer data only to countries with an adequate level of protection or under equivalent contractual safeguards. Regional data-residency pinning is on our roadmap and not yet available in production — see the Sub-processor list for current status.
7. How long we keep it
- Scan data — kept for the life of the subscription plus 90 days.
- Account data — kept until you delete your account, then purged within 30 days.
- Billing records — kept for 7 years to meet tax and accounting obligations.
- Support messages — kept for up to 2 years.
We keep data no longer than we need it for the purpose it was collected, unless the law requires longer.
8. Security
Data in transit is protected with TLS 1.2+. Data at rest is encrypted with AES-256. Account passwords are hashed. Third-party credentials for your integrations are encrypted at rest with AES-256-GCM under a versioned application encryption key. We enforce tenant isolation at both the application layer and the database (row-level security), keep audit logs, and follow the practices described in our Trust centre. No system is perfectly secure, and — as our Disclaimer explains — you remain responsible for your own security.
9. Cookies
We use a small set of cookies for sign-in, security, remembering your consent choice, and spotting bugs. We do not use advertising cookies. See our Cookie Policy for the full list and how to control them.
10. Your rights
You can exercise any right by emailing [email protected]. We respond within 30 days (or sooner where the law requires), and we will not charge you or treat you differently for exercising a right.
If GDPR or UK GDPR applies to you, you have the right to access your data, correct it, erase it, restrict or object to processing, receive it in a portable format, withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effects.
If you are a California resident (CCPA/CPRA), you have the right to know what we collect and why, to access and delete it, to correct it, to opt out of any "sale" or "sharing" (we do neither — see section 5), to limit the use of sensitive personal information, and to not be discriminated against for exercising these rights. You may use an authorised agent, and we honour opt-out preference signals where applicable.
If the UAE PDPL applies to you, you have the rights of access, correction, erasure, restriction, portability, and objection, and the right to object to processing for direct-marketing or survey purposes.
11. Automated processing
We use AI models to rewrite technical findings into plain-English explanations and to help triage and prioritise them. This supports you; it does not make automated decisions that produce legal or similarly significant effects about you, and a human is always in the loop for account and billing decisions. We do not permit our AI providers to train their models on findings we send them.
12. Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or the age set by local law). If you believe a child has given us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service and the law change. We will post the new version here with an updated date and, for material changes, tell account holders by email. We will not make material, retroactive changes without a lawful basis.
14. Complaints
If you have a concern, please contact us first at [email protected] — we would like to put it right. You also have the right to complain to your supervisory authority:
- UK — the Information Commissioner's Office (ICO).
- EU/EEA — your local data protection authority, or the lead authority for our EU operations.
- California — the California Privacy Protection Agency or the California Attorney General.
- UAE — the UAE Data Office.
15. Contact
[email protected] — or write to NoDowntime Technologies FZCO, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates.