Privacy Policy
Datenschutzerklärung under the EU General Data Protection Regulation (GDPR/DSGVO).
1. Controller
Daniel Alexander Bersenkowitsch, Haidbachstraße 31, 4061 Pasching, Austria — office@mcpvitals.com. See our Imprint.
2. What we collect & why
- Account data (email, hashed password) — to create and secure your account. Legal basis: performance of a contract (Art. 6(1)(b)).
- Monitor configuration (the MCP server URLs and settings you add, plus resulting check history) — to provide the monitoring service. Legal basis: Art. 6(1)(b).
- Server logs — standard request logs for security and abuse prevention. Legal basis: legitimate interest (Art. 6(1)(f)).
- Status-page subscriptions — if you subscribe to a public status page, we store your email address and a confirmation token so we can send incident notifications. Subscribing is double opt-in and every email carries an unsubscribe link. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.
- "Email me the setup link" — if you ask us to send the setup link, we store your email address, a confirmation token, and the campaign name of the ad or link you arrived from (never the anonymous visitor hash from §8, and never a click id). This is double opt-in: nothing is sent until you confirm, and after confirming you receive one setup email. Unsubscribing deletes the address — we keep no suppression list. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.
- Billing data — if you buy a paid plan, Stripe processes your payment and we store only your Stripe customer/subscription reference and plan status. We never see or store your card details.
- We do not collect special-category or health data.
3. Processors & international transfers
- Cloudflare, Inc. (hosting, edge network, and the D1 database that stores your account + monitors) — USA/global edge.
- Stripe, Inc. (payment processing and subscription billing, for paid plans only) — USA/EU.
- Sendinblue/Brevo SAS (transactional email: address verification, password resets, and status-page incident notifications) — EU (France).
- Transfers to US-based processors rely on the EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
4. Retention
Account data is kept while your account exists. Check history is pruned to your plan's retention window. Analytics events (see §8) are deleted after 90 days. Status-page subscriptions and setup-link addresses are kept until you unsubscribe, then deleted. You can delete monitors and your account at any time.
5. Your rights (GDPR)
You may request access, rectification, erasure, restriction and portability, and object to processing — contact office@mcpvitals.com. You may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde).
6. California residents (CCPA/CPRA)
We collect only the account and monitoring data described above, to provide the service. We do not sell or share personal information. California residents may request to know, delete, or opt out — contact us at the address above.
7. Cookies
We use a single essential session cookie to keep you logged in. No non-essential tracking cookies are used.
8. Analytics
We run our own first-party, cookieless analytics — no third-party service (no Google Analytics, etc.) and no tracking across sites. Nothing is stored on your device, so no consent banner is required. For each page or badge request we record only: the page template visited (query strings stripped), a coarse device/browser category (never your full user-agent), the referring domain, and your country (from Cloudflare's edge — never city, region, or precise location). We do not store your IP address. To estimate unique visitors we compute a short, daily-rotating salted hash that is unlinkable across days and is never combined with your account. Analytics events, including that hash, are deleted after 90 days. Within a single day, the site owner can see a reconstructed session view — the sequence of pages one (pseudonymous) visitor viewed, with timestamps, country, and device/browser category. We use this to understand how the site is used and to detect abuse; we do not attempt to identify you and the hash cannot be linked back to you or across days. Legal basis: legitimate interest (GDPR Art. 6(1)(f)). Analytics are visible only to the site owner. You may object to this processing at any time — see §5.