Syschecks/Privacy Policy

Privacy Policy

Last updated: May 25, 2026

This Privacy Policy describes how Syschecks ("the Service"), operated by SysTeam ("we", "us", "our"), collects, uses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable Polish and EU law.

1. Data We Collect

Account Data

  • Email address (used for login and notifications)
  • Password (stored as a salted hash — we never store plaintext passwords)
  • Organization name and membership information

Monitoring Data

  • Check configurations (URLs, hostnames, ports, intervals)
  • Check results (response times, status codes, error messages)
  • Incident history and acknowledgment records
  • Notification channel configurations (webhook URLs, API keys)

Usage & Technical Data

  • IP address and browser user agent (for security and rate limiting)
  • Session tokens and authentication cookies
  • Audit logs (account actions, configuration changes)

Mobile Application — Additional Data

  • Push Notification Token — a device-specific identifier issued by the Expo Push Service, used solely to deliver incident and on-call notifications you subscribed to. Deleted on logout or when reported invalid by the push service.
  • Biometric authentication state — a local flag indicating Face ID / Touch ID / Fingerprint login is enabled. Biometric data NEVER leaves your device; iOS Secure Enclave / Android Keystore handle verification locally.
  • Camera — used only when you explicitly scan a QR code to sign in. No images or video are stored or transmitted.
  • Device type and OS version — collected by Expo runtime to ship the correct binary; not used for tracking or profiling.

Data We Do NOT Collect (Mobile)

  • No advertising identifiers (IDFA on iOS, GAID on Android)
  • No location data
  • No contacts, calendar, photos, or microphone access
  • No third-party analytics SDKs (no Google Analytics, no Facebook SDK)
  • No data sold to anyone, ever

2. How We Use Your Data

We use your data exclusively to:

  • Provide and operate the monitoring service
  • Send alerts and notifications when checks fail or recover
  • Authenticate your identity and secure your account
  • Generate reports and display dashboards
  • Improve the Service (aggregated, anonymized usage patterns)
  • Comply with legal obligations

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

3. Data Storage & Security

  • Data is stored on servers located in the European Union
  • All connections use TLS encryption (HTTPS)
  • Passwords are hashed using industry-standard algorithms
  • API tokens are stored as SHA-256 hashes
  • Access to production systems is restricted and audited

4. Data Retention

  • Check logs are retained according to your organization's plan (Free plan: 7 days; higher on paid plans), up to a 90-day platform maximum
  • Incident history is retained for the lifetime of your account
  • Audit logs are retained for 1 year
  • Account data is deleted within 30 days of account deletion

5. Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate personal data
  • Erasure — request deletion of your account and data
  • Data Portability — export your data via the API or report generation features
  • Restriction — request limitation of data processing
  • Objection — object to certain data processing activities

To exercise any of these rights, contact us at kontakt@systeam.pl. We will respond within 30 days.

6. Cookies

We use the following cookies:

  • Authentication cookies (essential) — JWT access and refresh tokens for session management
  • CSRF cookie (essential) — cross-site request forgery protection

We do not use analytics cookies, tracking pixels, or third-party advertising cookies.

7. Third-Party Services (Sub-processors)

We use a small number of carefully chosen sub-processors. All are bound by data processing agreements compliant with GDPR Article 28.

  • Expo Push Service (mobile app only) — delivers push notifications to your device. Receives: push token, notification payload (incident summary). Operated by Expo / 650 Industries, Inc.
  • Email delivery (SMTP) — sends transactional emails (account, alerts). Receives: your email address, the email body.
  • Cloudflare — DNS, TLS termination, DDoS protection at the edge. Receives: standard HTTP request metadata.

Notification channels you configure (Slack, Discord, email providers, etc.) may involve transmitting alert data to those third-party services. You control which channels are active and what data they receive.

If you use SSO (Google, GitHub, SAML, OIDC), the authentication provider shares limited profile information (email, name) as part of the login flow.

8. Changes to This Policy

We may update this Privacy Policy as the Service evolves. Significant changes will be communicated via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

9. Contact

For privacy-related questions or to exercise your GDPR rights, contact us at kontakt@systeam.pl.


See also: Terms of Service