Privacy Policy
Last updated: June 24, 2026
This Privacy Policy explains how Gestión Desarrollo e Innovación SAS ("MonitorKit", "we", "us", "our") collects, uses, and protects information when you use our Service at monitorkit.co.
1. Data Controller
The data controller responsible for your personal data is:
Gestión Desarrollo e Innovación SAS
Manzana 24 Casa 40, Samaria I, Pereira, Colombia
Email: [email protected]
2. Information We Collect
Account data: When you register, we collect your email address, username, and organization name.
Server metrics: CPU usage, memory, disk, network throughput, process lists, and system load — sent automatically by the MonitorKit agent installed on your servers.
Log data: Log lines from services you configure (nginx, PHP-FPM, MySQL, Redis, etc.). Log data may contain IP addresses, user agents, and other information from your application traffic. You control which services are monitored, and you can drop log lines matching patterns you define (for example lines containing tokens or sensitive request paths) using the agent's exclude-patterns setting. Log content is otherwise stored as received and is not automatically scrubbed, so you are responsible for configuring exclusions appropriate to your data.
APM traces: HTTP request traces, database query timings, and error information from your PHP applications. SQL parameters are scrubbed before transmission to prevent PII leakage.
Connection metadata: IP addresses of servers running the MonitorKit agent, and IP addresses of users accessing the MonitorKit dashboard.
Billing data: Payment processing is handled entirely by Paddle (our Merchant of Record). We do not store credit card numbers or payment details. We receive only a Paddle customer ID and subscription status.
Usage data: Browser type, pages visited within the dashboard, and feature usage — used to improve the Service.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases as defined in Article 6 of the GDPR:
- Performance of a contract (Art. 6(1)(b)): Processing your account data, server metrics, logs, and traces is necessary to provide the monitoring Service you have subscribed to.
- Legitimate interests (Art. 6(1)(f)): We process connection metadata and usage data to ensure security, detect abuse, and improve the Service. Our legitimate interests do not override your fundamental rights.
- Legal obligation (Art. 6(1)(c)): We may process data where required to comply with applicable law.
- Consent (Art. 6(1)(a)): Where we rely on consent (e.g., marketing emails), you may withdraw it at any time.
4. How We Use Your Data
- To provide the monitoring, alerting, and APM features of the Service.
- To send alert notifications and daily digest emails you configure.
- To manage your subscription and billing status.
- To detect security threats and prevent abuse.
- To improve the reliability and performance of the Service.
We do not sell your data to third parties. We do not use your server metrics, logs, or traces for advertising.
5. Data Retention
Telemetry data (metrics, logs, APM traces) is retained according to your plan limits and automatically deleted when it exceeds the retention window. Account data is retained for the duration of your subscription plus 30 days after account deletion, to allow for any billing disputes. Backups may retain data for up to 60 days after deletion.
6. Data Security
All data is transmitted over HTTPS/TLS. API keys are stored hashed (bcrypt). We apply security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options), rate limiting, and SSRF protection on all endpoints. Access to production infrastructure is restricted to authorized personnel only. We conduct periodic security audits.
7. International Data Transfers
Our primary infrastructure is hosted in the United States (Chicago, Illinois) by the hosting sub-processor identified in Section 8. MonitorKit itself is established in Colombia. If you access the Service from the European Economic Area, the United Kingdom, or Colombia, your personal data is transferred to the United States and to the other sub-processor locations listed in Section 8. For these transfers, and for any sub-processor located outside your jurisdiction, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) or an equivalent mechanism, as described in our DPA.
8. Third-Party Sub-processors
We engage the following sub-processors to help provide the Service. Those marked "on enable" are only engaged if you activate that integration. This list is current as of 2026-08-28; we notify account administrators before adding or replacing a sub-processor. The full description of each, together with the transfer safeguards that apply, is in Annex III of our DPA.
| Sub-processor | Purpose | Location | Engagement |
|---|---|---|---|
| Paddle.com Market Ltd | Payment processing and Merchant of Record (checkout, billing, VAT/tax remittance) | United Kingdom | Always |
| The Constant Company, LLC (Vultr) | Cloud infrastructure hosting (all application servers and databases) | United States (Chicago, IL) | Always |
| Twilio Inc. (SendGrid) | Transactional and notification email delivery (alerts, digests, verification) | United States | Always |
| Slack Technologies, LLC | Delivery of alert notifications to a customer-configured Slack incoming webhook | United States | On enable |
| PagerDuty, Inc. | Delivery of alert events to a customer-configured PagerDuty integration | United States | On enable |
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Request your data in a machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are in the EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local data protection supervisory authority.
10. Data Processing Agreement (DPA)
If you use MonitorKit as a business, our Data Processing Agreement applies to the personal data we process on your behalf. It is incorporated into our Terms of Service at no additional cost. For a countersigned copy, email [email protected].
11. Cookies
We use a single httpOnly, Secure session cookie for authentication. This cookie is strictly necessary for the Service to function and does not require consent. We do not use tracking, advertising, or third-party analytics cookies.
12. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact us at [email protected] and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy. We will notify you by email and/or a dashboard notice at least 15 days before material changes take effect. Continued use of the Service constitutes acceptance of the updated policy.
Contact
Privacy questions or data requests? Email [email protected]
Gestión Desarrollo e Innovación SAS — Manzana 24 Casa 40, Samaria I, Pereira, Colombia