WatchTower15
Features Pricing About
Contact Sales
Features Pricing About Contact Sales
Legal

Privacy Policy

Last updated: 21 July 2026 · Effective: 21 July 2026

This Privacy Policy explains how WatchTower15 Ltd ("WatchTower15", "we", "us" or "our") collects, uses, discloses and protects personal data when you visit our website, contact us, or use the WatchTower15 monitoring platform (the "Service"). It also describes the rights available to you under the UK GDPR, the EU General Data Protection Regulation (GDPR) and comparable data protection laws.

WatchTower15 offers data residency options by default — you choose the region in which your monitoring data is stored, at no extra cost. Where you are a business customer using the Service to monitor your own infrastructure, the relationship between us is also governed by our Data Processing Agreement.

Contents

  1. Who we are
  2. Controller vs processor
  3. Data we collect
  4. How we use data
  5. Legal bases
  6. Sharing & sub-processors
  7. Data residency & transfers
  8. Retention
  9. Security
  10. Cookies
  11. Your rights
  12. Changes
  13. Contact us

1. Who we are

The Service is operated by WatchTower15 Ltd, registered in Delaware, United States. For the purposes of the UK and EU GDPR, WatchTower15 Ltd is the data controller of the personal data described in this policy that relates to your use of our website and your account. Where we process monitoring data on your behalf, we act as a data processor — see section 2.

If you have any questions about this policy or how we handle your data, contact us at privacy@watchtower15.com.

2. Controller vs processor

We wear two hats depending on the data:

  • As a data controller — for account, billing and contact information, and for data collected through our marketing website. We decide why and how this data is processed.
  • As a data processor — for the monitoring data your servers, domains and services generate and send to the Service. You (our customer) remain the controller of that data; we process it only on your documented instructions under the Data Processing Agreement.

3. Data we collect

Account & contact data

Name, work email address, company name, and the credentials you use to authenticate. If you contact sales, we retain the correspondence and any details you volunteer about your infrastructure.

Billing data

Billing contact details and the resource counts (servers, domains, services) used to calculate your usage-metered invoice. Card processing is handled by our payment provider; we do not store full card numbers.

Monitoring data

Telemetry and metadata collected by the wt15-server-agent and by external checks — for example CPU, memory, disk and network metrics, container metrics, log lines you choose to forward, DNS records, SSL/TLS certificate details and service reachability. This data may incidentally contain personal data (for example in log lines). We process it as your processor.

Website & technical data

Limited technical information such as IP address, browser type and pages visited, used to keep the site secure and functional. See section 10 on cookies.

4. How we use data

  • To provide, operate, secure and improve the Service.
  • To authenticate users and administer accounts, including SSO and audit logging.
  • To calculate usage-metered billing and issue invoices.
  • To respond to sales enquiries and provide customer support.
  • To send service and security notifications relevant to your account.
  • To meet legal, tax and regulatory obligations.

We do not sell personal data, and we do not use your monitoring data to train models or for advertising.

5. Legal bases for processing

Where GDPR applies, we rely on the following legal bases:

  • Contract — to deliver the Service you have signed up for and to bill you.
  • Legitimate interests — to secure our systems, prevent abuse, and communicate with business customers, balanced against your rights.
  • Legal obligation — to comply with accounting, tax and other statutory requirements.
  • Consent — where required, for example non-essential cookies; you may withdraw consent at any time.

6. Sharing & sub-processors

We share personal data only where necessary:

  • With infrastructure and sub-processors that host the Service in the region you select. A current list of sub-processors is available on request and is referenced in the Data Processing Agreement.
  • With our payment provider to process invoices.
  • Where required by law, regulation, or valid legal process.
  • In connection with a merger, acquisition or asset sale, subject to the protections in this policy.

All sub-processors are bound by contractual obligations that are no less protective than those in this policy.

7. Data residency & international transfers

Data residency is a default option, not a premium add-on. You choose the region in which your monitoring data is stored — we currently offer UK, EU, USA, Latam and SE-Asia regions.

Personal data of EU and UK data subjects is not transferred outside the EEA or the UK, or to a country without an adequacy decision, without your explicit instruction and an appropriate transfer mechanism (such as the UK International Data Transfer Agreement or EU Standard Contractual Clauses) in place.

8. Data retention

We retain account and billing data for as long as your account is active and thereafter only as required to meet legal and accounting obligations. Monitoring data is retained according to the retention settings you configure, and is deleted or returned at the end of the engagement in line with the Data Processing Agreement.

9. Security

Security is built into the product. The wt15-server-agent installs as an unprivileged service user with NoNewPrivileges=yes, ProtectSystem=strict and zero Linux capabilities. We apply encryption in transit and at rest, role-based access control, and audit logging across the platform.

In the event of a personal data breach affecting your data, we will notify you without undue delay and, where feasible, within 72 hours of becoming aware — so you can meet your own notification timelines.

10. Cookies

Our marketing website uses only strictly necessary cookies required for the site to function and stay secure. We do not use advertising or third-party tracking cookies. Where any non-essential cookie is introduced, we will request your consent first, and you can manage cookies through your browser settings at any time.

11. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent. To exercise any of these rights, email privacy@watchtower15.com.

Where WatchTower15 acts as a processor, requests from data subjects should be directed to the relevant customer (the controller); we will assist that customer in responding. You also have the right to lodge a complaint with your local supervisory authority.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of the Service after an update constitutes acceptance of the revised policy.

13. Contact us

Questions about this policy or your personal data? Contact us at privacy@watchtower15.com, or reach our sales team at sales@watchtower15.com. See also our Data Processing Agreement and the GDPR & compliance section of our About page.

WatchTower15

Server, domain and security monitoring for efficient engineering teams. Usage-metered. Zero privilege. No surprises.

Product

Features Pricing About

Solutions

Server monitoring Domain monitoring Security scanning Fleet management

Company

About us GDPR & DPA Contact sales

© 2026 WatchTower15 Ltd. Registered in Delaware - US

Privacy Policy Data Processing Agreement Cookie Policy