Articles 13 & 14 GDPR
Privacy notice
Last updated 8 September 2026
This notice explains how personal data is processed when Failsafe is used during its closed beta at failsafe.asta.cx. It covers the landing site, account area, monitoring workspace, notifications and public status pages. It is written as a layered notice: this page is the complete version.
1. Controller and contact
The controller is Nick Stahl, Hauptstraße 65, 35625 Hüttenberg, Germany. You can reach us about privacy at [email protected] or by post at that address. The service's legal details are in the Imprint.
No Data Protection Officer has been appointed for the closed beta. If that changes, this notice will name the DPO and provide their contact details.
For account and service-operation data, the operator acts as controller. Where an organization places personal data about its own customers, users or staff in a Failsafe workspace, that organization will normally be the controller and Failsafe will act only on its instructions. Do not use that customer-data scenario in the beta before agreeing the required data-processing terms with us.
2. What data Failsafe processes
- Account and organization data: email address, optional name, organization name, slug and logo, role, membership and invitation details.
- Authentication and security data: password hashes (never plaintext passwords), session and device/user-agent data, optional TOTP two-factor authentication data, passkey metadata and public keys, security challenges, password-reset token hashes and API-key hashes.
- Monitoring data: monitor names and configuration, including URLs, hosts, ports, DNS records, SSL settings, headers, request bodies and heartbeat tokens; check timestamps, latency, status codes and error messages; uptime aggregates; dependencies; and alert state.
- Operational content: incidents, incident updates, maintenance windows, public status-page settings, links, custom CSS and uploaded raster images. This content can be public where your workspace publishes it.
- Integration data: Discord webhook URLs, channel IDs, bot tokens, escalation webhook URLs and SSO configuration. Treat these as confidential credentials and only provide data you are authorized to use.
- Technical service data: technical request and security information that is necessary to operate, protect and diagnose the service.
3. Sources of data and whether it is required
Most data comes directly from you or someone in your organization. Organization owners can also provide invitation details about members. When SSO is configured, Failsafe receives the identity data that the organization's identity provider returns to it. Monitoring data is generated from the systems and endpoints your workspace instructs Failsafe to check.
An email address, password and organization name are required to create and secure an account; without them, the beta cannot be provided. Passkeys, TOTP, uploads, SSO and integrations are optional. Do not place personal or confidential data in monitor headers, bodies, incident text or public status pages unless you have a lawful basis to do so.
4. Why we use data and the legal basis
- Provide the beta: create accounts and workspaces, authenticate users, run checks, show results, manage incidents and publish the status pages you configure. Legal basis: performance of the beta agreement or steps requested before it, Art. 6(1)(b) GDPR.
- Keep Failsafe secure and reliable: prevent misuse, investigate failures, protect accounts and credentials, and maintain service integrity. Legal basis: legitimate interests in security, abuse prevention and reliable operation, Art. 6(1)(f) GDPR.
- Meet legal obligations and defend claims: where applicable, comply with binding legal requirements or establish, exercise or defend legal claims. Legal basis: Art. 6(1)(c) and Art. 6(1)(f) GDPR.
- Send an alert you configure: route the relevant monitor or incident information to the endpoint your workspace selected. Legal basis: performance of the beta agreement, Art. 6(1)(b) GDPR.
5. Who receives data
Authorized members of your organization can see the workspace data their role permits. If you configure Discord or another webhook destination, Failsafe sends the alert data needed for that notification—such as monitor name, status, timing and incident text—to that destination.
Service providers that operate the hosting, database, storage, backup, email or delivery layers may process data only to operate Failsafe on our instructions. The public deployment stack is still being finalized for this closed beta. Before a beta organization's data is activated, it will receive the current processor and transfer information applicable to that environment. We do not sell personal data or use it for advertising.
6. International transfers
Failsafe does not intentionally send workspace data to a third-country provider except where your workspace configures an external endpoint, such as Discord or another webhook. Those destinations are selected by your organization and are governed by their own data-handling and transfer terms. If Failsafe introduces a processor that transfers personal data outside the EEA, we will identify that processor and the relevant safeguard before activating that processing for a beta organization.
7. Retention
- The fs_token authentication cookie is HTTP-only, site-limited and valid for up to seven days.
- WebAuthn and two-factor challenges expire after five minutes. Password-reset tokens expire after 30 minutes and are stored as hashes.
- Raw monitoring check results are normally pruned after 35 days. Daily uptime aggregates remain with the associated monitor until that monitor is removed.
- Account, workspace, monitor, incident, status-page and security records are kept while the beta account or workspace is active, then only as long as necessary for security, support, legal obligations or legal claims.
- Uploaded images and integration settings are kept with the content or workspace that uses them until removed or the relevant account-deletion process is completed.
8. Your rights
Subject to the GDPR's conditions, you can request access, rectification, erasure, restriction, portability or object to processing based on legitimate interests. You can withdraw consent at any time where a processing operation relies on it; this does not affect processing already carried out. Send a request to [email protected]. We may request information needed to verify that the request comes from the relevant person.
You also have the right to complain to the Hessian Commissioner for Data Protection and Freedom of Information, or to your local supervisory authority.
9. Automated processing
Failsafe automatically evaluates monitoring signals to change a monitor's service status and can open or update an incident workflow. It does not make automated decisions about a person that produce legal effects or similarly significant effects within the meaning of Art. 22 GDPR.
10. Organizations using Failsafe
If you use Failsafe for an organization, you are responsible for the data you place in it and for selecting external alert destinations. Before using Failsafe to process personal data belonging to third parties, contact us at [email protected] so we can assess the data-processing documentation needed for the beta.
11. Changes to this notice
We will update this notice before using data for a new purpose or making a material change to the beta's processing. The current version is always published at this address.