BackupWatch respects your privacy and the sovereignty of your client data. This Privacy Policy explains our practices regarding data collection across our marketing website (backupwatch.app), licensing server (licence.backupwatch.app), and self-hosted software installations.
1. The Self-Hosted Application (Data Sovereignty Guarantee)
The BackupWatch software is engineered as a 100% self-hosted application running entirely within your private infrastructure.
- Local Data Processing:
- All email parsing, client matching, scheduling, and alerting occur locally on your server.
- Client names, internal server hostnames, IP addresses, backup storage paths, error logs, and notification email bodies never leave your server.
- We do not operate a multi-tenant cloud database or collect customer backup contents.
- Outbound Network Connections from Your Instance:
- Your configured mailbox provider (Microsoft Graph API, Google Workspace, or generic IMAP) to retrieve backup notification emails.
- Your configured outbound SMTP server to deliver alerts and daily digest summaries.
- Our licensing server (
licence.backupwatch.app) for daily status check-in.
- Daily License Check-In Telemetry:
- Free and commercial instances perform an automated daily check-in.
- Data transmitted: License key hash/token, BackupWatch application version, total number of active backup jobs, and basic operating system details (e.g. Linux version, Python runtime).
- Data explicitly NOT transmitted: No client names, no email contents, no hostnames, no IP addresses of your clients, and no event histories.
2. Website and Licensing Operations
When you visit backupwatch.app or purchase a subscription, we collect limited personal information necessary to process transactions and support you:
- Purchases and Billing (Stripe):
- When purchasing a license, Stripe collects your billing details, email address, and payment card details.
- We do not store or process raw credit card numbers. Stripe retains billing information under its own compliance frameworks (PCI-DSS).
- Transactional Communications (Klaviyo):
- We process your email address to deliver license keys, renewal reminders, and critical security notices.
- We do not sell, rent, or share your contact information with marketing third parties.
- Website Analytics (Litlyx):
- Our marketing website uses privacy-focused, cookie-free analytics (Litlyx) to track aggregate pageviews, documentation visits, and download clicks.
- We do not track individual visitor identities across external websites.
- Contact Form Submissions:
- If you submit inquiries through our contact form, we collect your name, email address, and message solely to respond to your request.
3. Legal Bases and Regulatory Compliance
- Australian Privacy Principles (APPs): We manage personal information in compliance with the Australian Privacy Act 1988.
- GDPR / UK GDPR:
- For website visitors and direct buyers, we act as a Data Controller for account and billing data.
- For your self-hosted instance, we do not act as a Data Processor because client backup data and notification emails remain on your private infrastructure and never enter our custody.
- Essential Eight and Data Custody: BackupWatch’s self-hosted architecture ensures compliance with data residency mandates by keeping client operational telemetry within your designated hosting perimeter.
4. Data Retention
- Account and billing transaction records are retained for the duration required by financial, taxation, and corporate reporting regulations.
- License check-in telemetry records are retained for up to twelve (12) months for fleet capacity and version tracking.
5. Your Rights and Contact Information
You have the right to request access to, correction of, or deletion of personal account information held in our billing systems.
For privacy inquiries or data requests, contact us at:
Email: privacy@backupwatch.app
Website: https://backupwatch.app