This policy explains which personal data we process when you visit failover.cc, register an account and use the Service, and what rights you have.

1. Controller

Knut D. Möller – Software & SaaS
Blankeneser Chaussee 92
22869 Schenefeld, Germany

E-mail: [email protected]

We have not appointed a data protection officer; we are not required to do so.

2. What we process, why, and for how long

2.1 Visiting the website

When you open a page on failover.cc, the web server records the IP address of your device, date and time, the requested page, the referring page, browser type and operating system. This data is needed to deliver the pages and to detect and defend against attacks.

  • Legal basis: Art. 6 (1) (f) GDPR – our legitimate interest in operating a functional and secure website.
  • Retention: server logs are deleted after [LOG RETENTION, e.g. 14 days].

failover.cc is delivered through the content delivery network and web application firewall of Cloudflare, Inc. Cloudflare processes your IP address and request data on its edge servers, including in the EU, to filter malicious traffic and to deliver the pages. See section 3.

2.2 Account

To register, we need your e-mail address and a password (stored as a hash). We also store the IP address and time of registration, of confirmation and of logins to prevent misuse and to investigate security incidents. We send a confirmation e-mail to verify your address.

  • Legal basis: Art. 6 (1) (b) GDPR (contract); for the IP records Art. 6 (1) (f) GDPR (security).
  • Retention: until you delete your account or we terminate it (see Terms, section 8). Accounts without a confirmed e-mail address are deleted after [X] days.

2.3 Using the Service

To perform checks and failovers we store the data you enter: the e-mail address and API credentials of your Cloudflare account, the DNS zones and records you import, hostnames and IP addresses of your primary and backup servers, check settings, and – if you configure them – additional e-mail addresses for alerts and a Slack webhook URL.

Your Cloudflare credentials are stored on our servers in Germany and are used only for the API calls required by the checks you configure. Access is limited to the operator. You can revoke the credentials in your Cloudflare account at any time.

We also store the results of the checks (timestamp, hostname, server, result, state) and the DNS changes made, so that you can see the history and we can trace failovers.

  • Legal basis: Art. 6 (1) (b) GDPR (contract).
  • Retention: configuration data until your account is deleted; check results and change logs are deleted after [CHECK LOG RETENTION, e.g. 30 days].

If you add alert recipients other than yourself, you must make sure that these persons agree to receive notifications from failover.cc.

2.4 Health checks

Our check nodes send HTTP requests to the hostnames you configure at the interval you selected and process the response (status code, response time, page content for string matching). The check nodes only receive the hostname, IP address and check settings; they do not receive your Cloudflare credentials. The check nodes are located in Germany (Hetzner) and in the USA and Singapore (DigitalOcean) [CONFIRM]. Their IP addresses are published in the FAQ.

  • Legal basis: Art. 6 (1) (b) GDPR.

2.5 Notifications

We send alerts about check states, failovers and recoveries to the e-mail address of your account and to additional addresses you configure. If you configure a Slack webhook, we send the same information (hostname, server, state, time) to Slack Technologies, LLC. You control this recipient; Slack processes the data under its own terms and privacy policy.

Transactional e-mails (confirmation, password reset, alerts, notices about your account) are sent via [MAIL PROVIDER, e.g. SendGrid / own mail server]. We do not send newsletters and do not use tracking pixels.

  • Legal basis: Art. 6 (1) (b) GDPR.

2.6 API

If you use the failover.cc API, we process your account e-mail address, your failover.cc API key, the IP address of the calling system and the request data. API requests are logged for troubleshooting and abuse prevention.

  • Legal basis: Art. 6 (1) (b) and (f) GDPR.
  • Retention: logs as in 2.1.

2.7 Contact by e-mail

If you write to us, we process your e-mail address, the content of your message and the time it was sent in order to answer you.

  • Legal basis: Art. 6 (1) (b) GDPR if the enquiry concerns your account or the contract, otherwise Art. 6 (1) (f) GDPR (our interest in answering enquiries).
  • Retention: we delete correspondence [X] months after the matter has been resolved, unless statutory retention obligations apply.

2.8 Payments

We currently do not offer paid plans and do not process payment data.

3. Recipients

We use the following service providers, which process data on our behalf under data processing agreements pursuant to Art. 28 GDPR:

ProviderPurposeLocation
Hetzner Online GmbH, GunzenhausenHosting of the application, database and check nodesGermany
Cloudflare, Inc., San FranciscoCDN, DNS and web application firewall for failover.ccEU and USA
DigitalOcean, LLC, New York [CONFIRM]Check nodesUSA, Singapore
Sending of transactional e-mails

In addition, data is transferred to the following recipients at your instruction: Cloudflare, Inc. (API calls to your own Cloudflare account) and Slack Technologies, LLC (if you configure a Slack webhook). These companies process the data as controllers under their own privacy policies.

We disclose personal data to authorities only where we are legally obliged to do so.

4. Transfers to third countries

Cloudflare and DigitalOcean [CONFIRM] are based in the USA and are certified under the EU-U.S. Data Privacy Framework; in addition, we have concluded the EU standard contractual clauses (Art. 46 (2) (c) GDPR) with them. Transfers to Singapore (DigitalOcean check nodes) are covered by the same standard contractual clauses. Data sent to Slack is transferred at your instruction.

5. Cookies

We use only cookies that are technically necessary:

  • – session cookie of the application (login state, CSRF protection); deleted when you close the browser or log out.
  • __cf_bm, cf_clearance – set by Cloudflare to distinguish humans from bots and to protect the site against attacks; lifetime 30 minutes to [X].

Storing and reading these cookies is permitted without consent under § 25 (2) no. 2 TDDDG, because they are strictly necessary to provide the service you request. We do not use analytics, advertising or tracking cookies, and we do not embed third-party content that sets cookies. For this reason there is no cookie banner.

6. Your rights

You have the right to obtain information about the personal data we hold about you (Art. 15 GDPR), to have inaccurate data corrected (Art. 16), to have data erased (Art. 17), to restrict processing (Art. 18), to receive the data you provided in a machine-readable format (Art. 20), and to object to processing based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation (Art. 21).

Where processing is based on consent, you may withdraw it at any time with effect for the future.

To exercise your rights, e-mail us at [email protected]. You can also view and change most account data yourself in your profile settings and delete your account there.

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany, https://www.datenschutzzentrum.de. You may also contact the authority at your place of residence.

7. Obligation to provide data

You are not legally obliged to provide personal data. Without an e-mail address and Cloudflare credentials, however, we cannot provide the Service.

8. Automated decision-making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

9. Security

All connections to failover.cc are encrypted (TLS). The application and database are hosted in Germany, are accessible only through Cloudflare, and administrative access is restricted to the operator and protected by key-based authentication. Please note that the Service is currently in maintenance mode; see the Terms of Service, section 2.

10. Changes

We will update this policy when the Service or the legal requirements change. The current version is always available at this address. If a change affects the processing of your data, we will inform you by e-mail.