Privacy Notice — Statuo

Rev. 4 — Last updated: 7 September 2026

Substantive revision: for Customers already registered it takes effect on 7 October 2026, the date stated in the e-mail notice (a full 30 days from 7 September 2026, as required by art. 3.2 of the Terms); until then Rev. 3.1 remains binding.

Courtesy translation. In case of any discrepancy, the Italian version prevails (statuo.io/termini, statuo.io/privacy).

1. Data controller

Apdsoftware of Carlo Zuffetti (apdsoftware.it), Via C. Colombo 15, 24047 Treviglio (BG), Italy, VAT IT03835250162, e-mail: privacy@statuo.io (the "Controller").

This notice covers data processed by the Controller in relation to the statuo.io website and the Statuo service (the "Service"). For data the Controller processes on behalf of its agency customers (e.g. end users' contact details added as notification channels), the Controller acts as processor: the DPA applies, not this notice.

2. Data processed, purposes and legal bases

Data Purpose Legal basis Retention
Account data: agency name, e-mail, password (hash) and, where the user enables two-factor authentication, the related data (encrypted TOTP secret and recovery codes stored as hashes) Provision of the Service, authentication Contract (art. 6.1.b GDPR) Contract duration + 30 days
Record of acceptance of the Terms, Privacy Notice and DPA and of the clauses under arts. 1341-1342 of the Italian Civil Code: version accepted, date and time, IP address and user agent Proving that the contractual conditions were accepted Contract (6.1.b); for the IP address and user agent, legitimate interest in being able to evidence acceptance (6.1.f) Contract duration + 30 days
Billing and payment data Subscription management Contract; legal obligations (6.1.c) Payment data is collected and processed by Paddle as merchant of record, not by the Controller, who receives an aggregated payout from Paddle. Tax documents issued by the Controller are addressed to Paddle and contain no Customer data: the ten-year statutory retention therefore does not entail retaining the Customer's personal data. Subscription identifiers held in the Controller's systems follow the retention of account data
Panel usage data and technical logs (IP, user agent, timestamps) Security, abuse prevention, diagnostics Legitimate interest (6.1.f) Max 12 months
Monitoring configurations (URLs, the agency's notification channels) Provision of the Service Contract Contract duration + 30 days
E-mail for service communications (alerts, expirations, changes to the Terms) Performance of the contract Contract Contract duration
E-mail for product updates/marketing Informing about Service news Consent (6.1.a) or soft-spam for existing customers, with opt-out offered at collection and at every message, for similar services Until withdrawal/objection
Messages sent through the contact/support form on the statuo.io website: e-mail, message text, page it was sent from, IP address Replying to the request and handling the contact; the IP address is used to limit automated submissions Pre-contractual measures (6.1.b) and legitimate interest in replying and preventing abuse of the form (6.1.f) For as long as needed to handle the request and any follow-up contacts; earlier erasure on request at privacy@statuo.io
Waitlist sign-up on the statuo.io website: e-mail, page of origin, IP address Informing about the launch of the Service and the terms reserved to subscribers; the IP address is used to limit automated sign-ups Consent (6.1.a); for the IP address only, legitimate interest in preventing abuse (6.1.f) Until the launch of the Service or withdrawal of consent, whichever is earlier; erasure on request at privacy@statuo.io

Provision of contractual data is necessary: without it, the Service cannot be supplied. Data is collected directly from the data subject.

Termination of the contract and deletion of data. Upon termination — which coincides with the end of the last paid period — monitoring stops and public status pages are switched off on the same day. For 30 days the panel remains accessible solely to export data and to subscribe to a new plan. After the 30 days, an automated process deletes from the live systems the account data, the monitoring configurations, the monitoring data and the record of acceptance, including IP address and user agent. What remains is: a record containing no identifying data, kept in order to demonstrate that deletion took place and when (art. 5.2 GDPR); and the technical log of payment events received from Paddle, stripped of its personal content and retained to prevent a retransmitted event from being processed twice. Tax documents relating to the Customer's purchases are issued and retained by Paddle (see §4), not by the Controller. As regards persistence in backup copies, §7 applies.

Data Protection Officer (DPO): not appointed, as the conditions of art. 37 GDPR are not met (no large-scale processing of special categories, no systematic monitoring of data subjects).

Automated decision-making: the Controller does not carry out processing under art. 22 GDPR (decisions based solely on automated processing producing legal or similarly significant effects).

3. Cookies and similar tools

The panel uses only technical storage (session token, language preference) necessary for its operation: it does not require consent. Public status pages use no cookies. The statuo.io website uses Umami, a self-hosted analytics tool running on the Controller's servers, which sets no cookies and does not track visitors across sites: data is aggregated and cannot be traced to individual visitors (legitimate interest, art. 6.1.f).

4. Recipients and sub-processors

Data may be processed, on the Controller's behalf, by providers appointed as processors under art. 28 GDPR:

Provider Service Location/data region
Hetzner Online GmbH Core/database infrastructure hosting EU (Falkenstein, Germany)
Google Cloud Continuous backup and disaster-recovery standby of the database; monitoring check (probe) infrastructure hosting EU (Belgium, Milan) + USA (Iowa; check execution in memory only, no data storage)
Paddle.com Market Ltd Payments (merchant of record — also acting as independent controller for the payment process) UK/EU
Resend Transactional e-mail delivery Ireland (EU)
Telegram FZ-LLC (only if the customer enables the channel; only the chat identifier is transferred) Notification delivery Non-EU

The parties below are not processors appointed by the Controller: they are recipients chosen by the customer and public sources the Controller queries.

Party Role Location/data region
Slack Technologies, Salesforce group (only if the customer enables the Slack channel; the webhook URL configured by the customer and the content of the alert are transferred) Recipient chosen by the customer, who towards Slack acts as an independent controller Non-EU (USA)
Microsoft (only if the customer enables the Microsoft Teams channel; the webhook URL configured by the customer and the content of the alert are transferred) Recipient chosen by the customer, who towards Microsoft acts as an independent controller Non-EU (USA)
IANA/ICANN and the domain name registries (only if the domain expiry check is enabled on the site; the domain name of the monitored site alone is transferred, and to IANA the TLD name alone) Public sources queried by the Controller for the domain expiry date; independent controllers Depends on the TLD: EU for European country-code domains (for .it, Registro.it — IIT-CNR, Pisa); usually non-EU (USA) for generic domains and for IANA/ICANN

For TLDs whose registry does not publish an RDAP service — including .it — this lookup uses the classic WHOIS protocol on port 43, which is not encrypted: the domain name of the monitored site alone travels in clear text, and nothing else. This is the single exception to the encryption in transit described in §7. Anyone who prefers to avoid it may switch off the domain expiry check on the individual site.

For the Slack and Teams channels the recipient is the workspace the customer chooses and whose webhook it pastes into the panel: towards that provider it is the customer that acts as an independent controller, and the relationship — including any data processing agreement — is governed by the contract between the customer and the provider, not by safeguards given by the Controller. It follows, for the customer, that it is for them to list that provider among the recipients in their own privacy notices, and that once the alert has been delivered, retention and deletion of the copy left in the workspace are not within the Controller's control: to stop delivery, the channel must be deleted from the panel and the webhook revoked at that provider. The full list of these obligations is in the DPA, arts. 5.3 and 5.4.

IANA/ICANN and the domain name registries, by contrast, operate public registers that the Controller queries and from which it receives an answer: they answer under their own policies and not on the Controller's instructions, and likewise act as independent controllers. The Controller cannot obtain from them the deletion of whatever they record of the query; anyone who prefers to avoid it may switch off the domain expiry check on the individual site.

The up-to-date list is available on request at privacy@statuo.io. The Controller does not sell personal data nor share it for advertising purposes.

5. Transfers outside the EU

Where a provider entails transfers outside the European Economic Area (e.g. Telegram; execution of monitoring checks from Google Cloud's US location, without data storage), the transfer takes place on the basis of adequacy decisions (including the EU-US Data Privacy Framework, where applicable) or the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where necessary.

The domain expiry check also entails a non-EU transfer where the TLD of the monitored site is managed by a registry outside the EEA (typically generic domains) and where IANA/ICANN is queried: in both cases what leaves is the domain name alone — or, towards IANA, the TLD name alone — to the operator of a public register, which acts as an independent controller. For these queries the Controller does not provide the guarantees set out above. Anyone who prefers to avoid them may switch off the domain expiry check on the individual site.

The Slack and Microsoft Teams channels likewise entail a transfer to the United States, but only if the customer enables them and only to the workspace the customer itself provides. The relationship with that provider rests with the customer: the terms agreed between the customer and the provider therefore apply, and not the guarantees set out above, which the Controller does not provide for this delivery. A customer who prefers not to make the transfer may refrain from enabling those channels and use e-mail, delivered within the EU.

6. Data subject rights

Under arts. 15-22 GDPR you may exercise the rights of access, rectification, erasure, restriction, portability and objection — including objection to processing based on legitimate interest — by writing to privacy@statuo.io. The Controller responds within 30 days, extendable by two months in particularly complex cases with a reasoned notice. You may also lodge a complaint with the Italian supervisory authority, the Garante per la Protezione dei Dati Personali (www.garanteprivacy.it).

7. Security

The Controller adopts appropriate technical and organizational measures, including: encryption in transit (TLS) on all communications — with the single exception, declared in §4, of the WHOIS query on port 43 used for the domain expiry check on TLDs without RDAP —, passwords stored with robust hashing, per-customer data segregation (multi-tenancy), encrypted backups with restore testing, key-based and restricted infrastructure access. Following deletion, data may persist in backup copies until overwritten according to the rotation cycle, for a maximum of 30 days.

8. Minors

The Service is intended exclusively for professionals and businesses; it is not directed at persons under 18.

9. Changes

Any material changes to this notice will be communicated by e-mail and published on this page with the new update date.