Certificate Checker

Privacy statement

Version 2026-08-01, in force since 1 August 2026

This is a translation

Only the Dutch text is legally binding. This translation is provided for convenience; where the two differ, the Dutch version applies. Read the Dutch version

Certificate Checker processes personal data in order to provide the service. This statement sets out which data that is, why we process it, how long we keep it and which rights you have.

1. Controller

Ekstra Software B.V., Chamber of Commerce number 94000948, established at Middenveld 13, 5126 DH Gilze, the Netherlands. For privacy questions and for the rights below you can reach us at support@certificate-checker.com.

We process this data for our own service and not on your instructions. We are therefore a controller and not a processor; a data processing agreement between us is not needed for that reason. What we have arranged with the parties that do process on our behalf is set out in section 4.

2. Which data we process

Account data — your name, email address and an encrypted representation of your password. We need them to create your account, let you sign in and send you notifications.

Data about the domains you monitor — the domain names you enter and the results of our checks: expiry date, issuer and validity of the certificate, and whether your site was reachable, with the associated response times. Domain names are usually not personal data, but they can be, for instance where a domain is registered in a person's name.

Billing data — on a paid plan: company name, Chamber of Commerce number, VAT identification number, address, invoice email address, IBAN and account holder. We use them to invoice and collect payment, and to determine whether we show prices including or excluding VAT.

Settings you enter yourself — language, time zone, notification thresholds, and optionally a Slack webhook or a webhook address of your own.

Technical data — log files and error reports from our servers, which may contain IP addresses, and data about the use of the website. How we measure visits is set out in our cookie statement: we use our own Matomo installation for that, without cookies and without sending data to third parties.

We do not process special categories of personal data and we do not carry out automated decision-making with legal effects.

3. Why we process it, and on which legal basis

We do not send commercial newsletters without your consent.

4. Who else processes your data

We engage service providers that act as processors for us. With each of them we have made arrangements about confidentiality and security:

If you send notifications to Slack or to a webhook of your own, the data in that notification goes to the party you designate for it. That happens on your initiative and under your responsibility.

We do not sell your data and do not provide it to third parties, except where the law obliges us to.

5. Transfers outside the EEA

Our servers and databases are in Germany, and our invoicing and payment providers are established in the Netherlands. That data therefore stays within the European Economic Area.

One exception: our email runs through Proton AG in Switzerland. Switzerland lies outside the EEA, but the European Commission has determined that the country offers an adequate level of protection. On the basis of that adequacy decision, the transfer is permitted without additional measures.

Our error tracking (Sentry) stores error reports in Frankfurt and therefore within the EEA. Its American parent company does replicate limited metadata — such as the login details of our own administrator account there — to the United States. That transfer is covered by the EU-US Data Privacy Framework, with the standard contractual clauses as a fallback; the error reports themselves stay in Frankfurt.

6. How long we keep it

7. Security

We send all traffic over TLS, store passwords encrypted and limit access to production data to those who need it. We treat webhook addresses and payment links as confidential and do not record them in log files.

To investigate a fault or a question, one of our administrators can look inside your account: they see your dashboard the way you see it. Only an administrator can do this, they cannot perform anything irreversible while doing so — they cannot delete your account, change your plan, change your password or email address, or create an API token — and we record every time who did it, on which account and for how long. We keep that record for the period stated in section 6.

8. Your rights

You have the right to access your data, to have it corrected or deleted, to have the processing restricted, to object to processing based on a legitimate interest, and to receive or transfer your data in a common format. Much of this you can do yourself: change your data in the dashboard, read out your domains through the API, and delete your account.

If you wish to invoke one of these rights, email support@certificate-checker.com. To prevent us from providing data to the wrong person, we may ask you to identify yourself; usually it is enough that you send the request from the email address of your account. We respond within one month. If you are not satisfied with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority.

9. Third-party websites

Our website and the dashboard contain links to other people's sites, for instance to our payment provider or to documentation. This statement does not apply there: those parties decide for themselves how they handle your data. Read their privacy statement if you want to know what they do.

10. Changes

We may amend this statement where the service or regulation calls for it. We announce a new version in advance in the dashboard and by email, with the date on which it takes effect. Earlier versions remain available on our website.