Anchor Uptime
TR EN
Sign in Start for Free
Sign in Start for Free →
Anchor Uptime
TR EN
Features Prices Documentation Changelog About Us
© 2026 Anchor Uptime · Digital Kernel Software
Digital Kernel
Privacy Terms of Use KVKK Return Policy Cookies Data Rights
// privacy

Privacy Policy

Last update
Last updated: March 2026
Scope
In line with the principles of GDPR and KVKK
Reading time
~10 min reading

Table of Contents

  1. Data Controller
  2. Data Collected
  3. Intended Use of Data
  4. Legal Basis
  5. Third Party Services and Paddle
  6. Data Retention Periods
  7. Data Security
  8. Cookies
  9. International Data Transfer
  10. Your rights
  11. Changes
  12. Contact

01Data Controller

This Privacy Policy governs the processing of personal data relating to the uptime monitoring service provided by Anchor Uptime (the "Service").

Data Controller Information
Trade NameAnchor Uptime
Contact[email protected]
Websiteanchoruptime.com
KVKK RoleData Controller
Payment processing is managed by Paddle.
Paddle.com Market Limited acts as Merchant of Record for payment and billing processes. Your payment card details are never processed or stored by Anchor Uptime.

02Data Collected

The following personal and technical data is collected during your use of the Service:

2.1 Account Data

  • Email address (for registration, login and notifications)
  • Encrypted password (hashed with bcrypt, not stored in plain text) - only when registration by email is preferred
  • Google account email and profile name - only when Google OAuth login is preferred; password is not stored
  • Account creation date and last login time

2.2 Monitoring Data

  • Site URLs and descriptive names you add
  • HTTP response times, status codes and probe results
  • SSL certificate expiration dates and domain WHOIS records
  • WordPress plugin heartbeat signals and timestamps
  • WordPress and PHP version information (for compatibility and error detection purposes)
  • Plugin activation status
  • Fatal error type and line number (file path or full stack trace is not stored)
  • Incident records: start/end time, duration, type

2.3 Technical and Log Data

  • IP address (for session security and abuse prevention purposes)
  • Browser type and operating system (User-Agent)
  • Account actions and in-platform transaction logs (adding/deleting sites, opening/closing maintenance, etc.)
  • Error logs and system events

2.4 Payment Data

Payment processing is handled directly by Paddle.com Market Limited. Anchor Uptime does not receive credit card number, CVV or full card information. Only subscription status, plan type and billing ID are received from Paddle.

03Intended Use of Data

Data Processing Purposes and Legal Basis
ObjectiveData UsedBasis
Service deliveryAccount, monitoring dataContract performance
Email notifications (alarm)Email addressContract performance
Subscription managementEmail, Paddle subscription IDContract performance
Security and fraud preventionIP, User-Agent, logsLegitimate interest
Service optimization and debuggingTechnical logsLegitimate interest
Fulfillment of legal obligationsInvoice, account informationLegal obligation

Your personal data will not be used for marketing, profiling or sales to third parties, except for the purposes mentioned above.

04Legal Basis

Your personal data is processed within the scope of the following legal bases:

  • Contract performance (Art.5/2-c of KVKK; Art.6/1-b of GDPR): Provision of services, sending notifications and subscription management.
  • Motivated interest (KVKK art.5/2-f; GDPR art.6/1-f): Protection of security, system stability and service quality.
  • Legal obligation (KVKK art.5/2-ç; GDPR art.6/1-c): Tax, invoice and legal retention obligations.
  • Explicit consent (when necessary): You will be explicitly informed and your consent will be obtained prior to procedures requiring consent.

05Third Party Services and Paddle

Certain third party providers are used for the provision of the Service. These providers process only the minimum necessary data and are subject to their own privacy policies.

Third Party Service Providers
ProviderObjectiveTransferred DataLocation
Paddle.com Market Ltd.Payment transaction, Merchant of RecordEmail, billing informationUK / EU
Google LLC (OAuth)Social login - only when preferredEmail address, profile nameUSA (assurance with SCCs)
Hetzner GmbH (Server)Application and data hosting, email deliveryAll application dataGermany (intra-EU)

Paddle's Merchant of Record Role

Paddle.com Market Limited acts as a Merchant of Record for payment transactions. Within this framework, Paddle;

  • Stores and processes payment card information in its PCI-DSS compliant infrastructure,
  • Fulfills VAT and other tax obligations,
  • It manages returns and payment disputes under its own policy.

For Paddle's privacy policy: paddle.com/legal/privacy

All transactions are carried out in USD ($). Paddle calculates local tax (VAT, etc.) based on your location and reflects it on the invoice.

06Data Retention Periods

Data Retention Periods
Data TypeStorage TimeRationale
Account details+ 30 days until account is deletedAccess redundancy, error compensation
Ham probe records (checks)1 day after summary calculation; up to 90 days in summary-free modeService functionality
Signal change events (check_events)180 daysLive panel, event timeline
Hourly/daily summary metrics (rollup)90 daysHistorical reporting and graphs
Incident recordsAccording to operational retention policy (approximately 90 days)Service history
Invoice and payment record10 yearsTax legislation obligation
Security logs (IP etc.)90 daysSecurity and abuse prevention
Unverified accounts30 daysAutomatic cleaning

07Data Security

The following technical and administrative measures are implemented to protect your personal data:

  • All data transmission is encrypted with TLS 1.2+ (HTTPS mandatory).
  • Passwords are hashed and stored with bcrypt; plaintext passwords are not stored anywhere.
  • Access to the API is protected with a Bearer token; each token site is managed comprehensively and separately.
  • SsrfSafeHttpClient is used for SSRF (Server-Side Request Forgery) protection.
  • Security headers (SecurityHeaders middleware) are attached to all responses.
  • Database access is only possible through the application layer.
  • Regular backup and disaster recovery procedures are in place.
Security breach notification
If a security breach affecting your personal data is detected, we will inform you and the relevant authorities in a timely manner within the framework of legal regulations.

08Cookies

Anchor Uptime uses only essential cookies for session management and service functionality. No third party cookies are used for analytics or marketing purposes.

Cookies Used
CookieTypeObjectiveDuration
sessionMandatoryUser sessionEnd of session
remember_tokenMandatory"Remember me" session30 days
XSRF-TOKENMandatoryCSRF protectionEnd of session

09International Data Transfer

Your personal data may be transferred to the following locations outside Turkey:

  • Germany - Hetzner GmbH: The application servers and database are hosted in Germany (EU). Within the scope of Article 9 of the LPPD, Germany is considered to have an adequate level of protection as it is an EU member state.
  • UK/EU - Paddle.com Market Ltd.: Payment data is processed in the Paddle infrastructure. The transfer is based on EU Standard Contractual Clauses (SCCs) and Paddle's GDPR/UK GDPR compliant data processing agreement.
  • US - Google LLC (OAuth): Valid only when Google login is preferred. Google manages EU-US data transfer under SCCs. For Google's privacy policy: policies.google.com/privacy

Data is not transferred to countries that do not have an adequate level of protection other than those mentioned above.

10Your rights

You have the following rights under KVKK and GDPR:

  • Access: You can request access to the personal data processed about you.
  • Correction: You can request correction of incorrect or missing data.
  • Deletion: You can request deletion of your data in certain circumstances.
  • Restriction of processing: You can request to stop processing in certain circumstances.
  • Portability: You can request your data in machine-readable format.
  • Objection: You can object to actions based on legitimate interest.
  • Revocation of consent: You can always revoke your consent in consensual transactions.
  • Complaint: You can file a complaint with the Turkish Personal Data Protection Authority (KVKK).

You can send your requests to [email protected]. Applications are responded within 30 days.

11Changes

You will be notified of any material changes to this policy at least 30 days prior to the effective date at your registered email address. Your continued use of the Service following the change constitutes your acceptance of the updated policy.

12Contact

For privacy related questions, requests or complaints:

Submit a Privacy Request

You can submit data access, deletion, correction or portability requests through the channels below. Response time: 30 days.

[email protected]
Contact Form
Anchor Uptime

We monitor your site 24/7 and notify you first when there is a problem.

Made by Digital Kernel Software

Product

  • Features
  • Prices
  • Changelog
  • Start for Free

Sources

  • Documentation
  • Start Guide
  • API Reference
  • WordPress Plugin

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
© 2026 Anchor Uptime · Digital Kernel Software
Privacy Terms Contact
All systems are working