Privacy

This notice covers zerolog Monitoring at zerolog.ch/monitoring, the landing page zerolog.ch/monitors and the API under /monitoring/api. It supplements the zerolog.ch privacy policy. Where the two differ, this notice governs the monitoring service. The German version is the authoritative one; this English text is a translation.

Version 1.0 · 23 September 2026

Controller

Gian-Luca Luongo, Dorfstrasse 77, 5430 Wettingen, Switzerland

Email: info@zerolog.ch

The controller is a natural person, not a company. There is no data protection officer; the controller answers requests personally. Further details are in the zerolog.ch legal notice.

In short

Principles

We process personal data only for the purposes stated here, only as much as needed and only for as long as needed. What we do not need, we do not collect: no name, no phone number, no account, no audience measurement, no advertising.

When you open a page

When you open a page or call the API, Cloudflare, as the platform operator, necessarily processes your IP address, the requested address, date and time, browser and operating system details and connection data. No page can be delivered without them.

Our application reads your IP address in memory only. It does not reach our database or our own log lines.

Cloudflare writes a log entry for every request containing the requested address, the response and technical metadata. These logs serve troubleshooting and protection of the service. Cloudflare deletes them after 7 days.

Cookies and browser storage

We set no cookies and use neither local storage nor session storage. Pages load fonts, scripts and map data only from our own server. You choose the language through the address or your browser setting.

The forms are the one exception (see Turnstile): there, a Cloudflare script reads signals from your browser for bot detection.

Abuse protection with a daily pseudonym

To stop anyone from flooding the service with automated entries, we limit the forms, for example to at most 5 new monitors per day and sender. For this we derive a pseudonym from your IP address: a keyed hash (HMAC-SHA-256) using a secret key and the current calendar day.

Where the pseudonym is stored and for how long is set out under Retention.

Turnstile (form protection)

The forms "Add a website", "Report a region", "Request a country", "Report abuse" and voting on the request board are protected by Cloudflare Turnstile. Only on these pages does your browser load a script from challenges.cloudflare.com. Turnstile processes your IP address, a technical fingerprint of the encrypted connection, your browser identifier (user agent) and the page address. When you submit, our server checks the result with Cloudflare and passes on your IP address.

For bot detection on our pages Cloudflare acts as our processor. According to Cloudflare, it additionally uses these signals under its own responsibility to improve bot detection. The Cloudflare Turnstile privacy addendum applies to that.

Without Turnstile you cannot submit the forms. All read-only pages work without it.

Website monitoring

When you add a website we store:

Purpose: check the website every 5 minutes, show a status page and notify you when its state changes.

Your management link is the only access to your monitor. Anyone who has it can change and delete the monitor. Keep it like a password and do not share it. We cannot recover lost management links.

Status page. Every monitor gets a status page with availability, response time and history. Only websites with a confirmed domain and public services pre-listed by us are listed publicly (search, sitemap). Unconfirmed status pages are reachable only through their link, blocked for search engines, and show the domain as plain text without a link. Alert channels, the daily pseudonym and the management key never appear on the status page.

Alerts. On a state change we send a message with the website's name, address and state to the channels you entered. Discord, Slack, ntfy or your own webhook receiver get this message on your instruction; their own terms apply to processing there. Each monitor also has a public Atom feed that contains state changes only.

Email alerts are currently not available, and the form does not ask for an email address. If we introduce them: sign-up only with a confirmation link (double opt-in), an unsubscribe link in every email, and we delete the address after you unsubscribe. We will update this notice beforehand.

Third-party websites. You do not have to own a website to add it. Our check requests the page like a browser and reads at most 256 KB. We keep only reachability, HTTP code, response time, certificate expiry and whether the keyword appears, no page content. Operators of a listed website can have the entry blocked through "Report abuse" or by email.

Requests and board

With "Report a region" and "Request a country" you report missing sources, false alarms or missed outages. We store:

The public board and the API show region or country, type, topic, your note, status, vote count and date, and whether a source was given. So please do not put details about yourself or other people in the note. Source address, email address and pseudonym stay internal. The operator reviews suggested sources by hand; nothing is adopted automatically.

The email address is optional. We use it only to reply about that one request, for example when it is done or rejected or when we have a question. No newsletter, no advertising, no disclosure.

For votes ("+1") we store the daily pseudonym per request so the same connection counts only once per day.

Reporting abuse

Every status page lets you report a monitor. We store the monitor ID, the reason, optionally your note, the daily pseudonym and the time. The operator reviews the report and blocks the monitor if needed. Please do not put details about yourself in the note that the review does not need.

Data from other sources

Outage indicators are based on public sources: grid and network operator notices, news metadata (from publisher feeds and GDELT), network measurements from IODA, and place data from GeoNames and Natural Earth. From news we take only title, publisher, link and time, no article text and no images. Personal data is not what we are after. If a title names a person, the name appears only as part of that title with a link to the source. We delete such entries after 90 days. All sources are listed on the methodology page.

The daily blocklist of harmful websites contains host names only, no personal data.

Recipients

Transfers abroad

USA. Cloudflare, Inc. is based in the USA. Under Annex 1 of the Swiss Data Protection Ordinance, the USA counts as providing adequate protection only for organisations certified under the Swiss-U.S. Data Privacy Framework. Cloudflare, Inc. is listed there (record 5666, Swiss-US certification, checked on 23 September 2026: active, re-certification under review). The transfer therefore rests on Art. 16 para. 1 of the Swiss Federal Act on Data Protection (FADP). We have not concluded separate standard contractual clauses. If the certification lapses, we will update this notice.

Locations. Your connection is handled by the Cloudflare location nearest to you; from Switzerland normally Zurich or Geneva, otherwise a location in the country or region you connect from. The database runs with the location hint Western Europe. Cloudflare states that the hint does not guarantee the location, so we cannot name a single country for it. Cached overview data without personal reference is distributed worldwide by Cloudflare.

Alert channels. Where an alert goes is determined by the address you enter. The message contains only details about the monitored website.

Retention and deletion

When you delete a monitor, we remove it and its alert channels immediately. The website's check history goes with it unless someone else monitors the same address.

A daily maintenance run applies these periods. Where it does not yet do so automatically, the operator deletes by hand.

Security

Your rights

You can ask what personal data we process about you (Art. 25 FADP). Access is free of charge, and we answer within 30 days. You can also ask us to correct inaccurate data or delete your data, object to processing, and ask for your data in a common electronic format (Art. 28 FADP).

Do it yourself. With your management link you can view, change and delete your monitor at any time.

By email. Write to info@zerolog.ch. Because there are no accounts, we can only match you through something you show us: a monitor's management link, a request number together with the email address given there, or the ID of a reported monitor. We can recompute a daily pseudonym only from the IP address and calendar day you give us. Without such proof we do not hand out data, because otherwise whoever asks first would get it.

Complaints

You can contact the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. The FDPIC can open an investigation (Art. 49 FADP).

For people in the EU and EEA

The service is also aimed at people in Europe outside Switzerland. Where the General Data Protection Regulation (GDPR) applies, the following also holds:

Disclaimer

zerolog Monitoring is not an official warning service. Its indicators are based on automatically evaluated public sources and fixed rules. They can be incomplete, late or wrong. We give no warranty for accuracy, completeness or availability, neither for the outage indicators nor for website monitoring and its alerts.

Do not rely on this site in an emergency. In an emergency, contact the official authorities: 112 across Europe; in Switzerland also police 117, fire 118, ambulance 144; 911 in North America. For power or network outages, your grid operator or provider and the authorities give binding information.

Operators of linked third-party sites are responsible for their content.

Changes

We update this notice when the service or the law changes. The version published here applies. Version 1.0 of 23 September 2026.