Privacy Policy
1. Who we are
Calmping ("we", "us") provides uptime and incident monitoring. For the personal data described here, the data controller is Linoa Technologie. For the content you monitor and the credentials you store, you act as controller and Calmping acts as your processor.
2. Data we collect
- Account: email address, password (stored only as a bcrypt hash), email-verification status, and - if enabled - an encrypted TOTP secret and recovery codes.
- Monitoring configuration: app names, target URLs/hosts, check settings, alert email overrides, maintenance windows.
- Monitoring results: check results, response evidence snippets, latency, incidents, incident timelines, and postmortems you write.
- Integrations: encrypted API keys and webhook URLs you choose to connect (AI providers, Slack/Discord/webhooks), stored using AES-256-GCM.
- Notifications: your alert preferences and Web Push subscription endpoints.
- Security/operations: sessions, API tokens (stored hashed), and an audit log including IP addresses of sensitive actions.
- Billing (Pro): Stripe customer and subscription identifiers. Card details are handled entirely by Stripe; we never receive your card number.
3. How we use it
To run the monitoring you configure, send the alerts you enable, provide security (authentication, rate limiting, abuse prevention), process subscriptions, and meet legal obligations. Legal bases under the GDPR are performance of our contract with you, our legitimate interest in securing the service, and your consent where you connect optional integrations.
4. No tracking
We use no analytics, advertising, or third-party tracking scripts. Cookies are strictly necessary for login and security only - see the Cookie Policy.
5. Sharing and subprocessors
We share personal data only with the processors needed to run the service (hosting, email, billing, browser push) and with any integration you explicitly connect. When you request an AI diagnosis or connect Slack/Discord/a webhook, the relevant incident data or alert is sent to that provider at your instruction. See the Subprocessors list.
6. International transfers
Some processors or integrations you choose may process data outside your country/the EEA. Where required, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses. Integrations you connect are governed by that provider's own terms and privacy policy.
7. Retention
- Raw check results roll up into daily statistics after 90 days.
- Incidents and postmortems are kept as your operational history until you delete them or your account.
- Rate-limit records expire after 24 hours; processed billing-event records after 30 days; the notification queue after 30 days.
- Everything tied to your account is permanently erased when you delete your account, within 30 days at the latest.
- Accounting and invoice records are kept for 10 years as required by Article L123-22 of the French Commercial Code. Proof of your consent and acceptance of our terms is kept for the duration of the contract and for 3 years afterwards.
8. Security
Passwords are hashed with bcrypt. Integration keys, webhook URLs, and TOTP secrets are encrypted at rest with AES-256-GCM. Session and CSRF cookies are HttpOnly and use the __Host- prefix in production. Outbound monitoring is constrained by an anti-abuse guard.
9. Your rights
Subject to applicable law, you may access, correct, export, or erase your data, and object to or restrict certain processing. You can export all your data as JSON and permanently delete your account at any time from Settings. To exercise other rights, use the contact page. You may also lodge a complaint with your supervisory authority (in France, the CNIL).
10. Changes
We will update this page when our practices change and revise the "last updated" date.
11. Contact
Linoa Technologie, operated by Faiza Ammari (SIREN 530 002 815; SIRET 530 002 815 00047), 149 avenue du Maine, 75014 Paris, France. Privacy requests: use the contact page.