Privacy statement
Version 2026-08-01, in force since 1 August 2026
This is a translation
Only the Dutch text is legally binding. This translation is provided for convenience; where the two differ, the Dutch version applies. Read the Dutch version
Certificate Checker processes personal data in order to provide the service. This statement sets out which data that is, why we process it, how long we keep it and which rights you have.
1. Controller
Ekstra Software B.V., Chamber of Commerce number 94000948, established at Middenveld 13, 5126 DH Gilze, the Netherlands. For privacy questions and for the rights below you can reach us at support@certificate-checker.com.
We process this data for our own service and not on your instructions. We are therefore a controller and not a processor; a data processing agreement between us is not needed for that reason. What we have arranged with the parties that do process on our behalf is set out in section 4.
2. Which data we process
Account data — your name, email address and an encrypted representation of your password. We need them to create your account, let you sign in and send you notifications.
Data about the domains you monitor — the domain names you enter and the results of our checks: expiry date, issuer and validity of the certificate, and whether your site was reachable, with the associated response times. Domain names are usually not personal data, but they can be, for instance where a domain is registered in a person's name.
Billing data — on a paid plan: company name, Chamber of Commerce number, VAT identification number, address, invoice email address, IBAN and account holder. We use them to invoice and collect payment, and to determine whether we show prices including or excluding VAT.
Settings you enter yourself — language, time zone, notification thresholds, and optionally a Slack webhook or a webhook address of your own.
Technical data — log files and error reports from our servers, which may contain IP addresses, and data about the use of the website. How we measure visits is set out in our cookie statement: we use our own Matomo installation for that, without cookies and without sending data to third parties.
We do not process special categories of personal data and we do not carry out automated decision-making with legal effects.
3. Why we process it, and on which legal basis
- Providing the service, managing your account and sending notifications — performance of the contract.
- Invoicing, collection and keeping our records — performance of the contract and legal obligation.
- Security, troubleshooting and abuse prevention — legitimate interest in a secure, working service.
- Measuring website visits in aggregated form — legitimate interest; we measure without cookies and with shortened IP addresses, which keeps the intrusion on your privacy minimal.
- Sending messages about the service itself, such as changed terms — performance of the contract.
We do not send commercial newsletters without your consent.
4. Who else processes your data
We engage service providers that act as processors for us. With each of them we have made arrangements about confidentiality and security:
- Hosting — Hetzner Online GmbH, with servers in Germany, where our servers and databases run.
- Email — Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva (Switzerland), for sending notifications about your domains and messages about your account.
- Invoicing — WeFact, for drawing up and sending invoices and the related records.
- Payments — Mollie, for paying outstanding invoices online. Payment details you enter there do not reach us.
- Error tracking — Functional Software, Inc. (Sentry), with data storage in Frankfurt, for collecting error reports from our application. Such a report contains technical details about the error: the error message itself, the place in the code and, where needed, the name of the domain the check was running on. Your name, email address, cookies and anything you typed are never included; at most the internal identifier of your account is.
- Statistics — no third party: our Matomo installation runs on our own infrastructure.
If you send notifications to Slack or to a webhook of your own, the data in that notification goes to the party you designate for it. That happens on your initiative and under your responsibility.
We do not sell your data and do not provide it to third parties, except where the law obliges us to.
5. Transfers outside the EEA
Our servers and databases are in Germany, and our invoicing and payment providers are established in the Netherlands. That data therefore stays within the European Economic Area.
One exception: our email runs through Proton AG in Switzerland. Switzerland lies outside the EEA, but the European Commission has determined that the country offers an adequate level of protection. On the basis of that adequacy decision, the transfer is permitted without additional measures.
Our error tracking (Sentry) stores error reports in Frankfurt and therefore within the EEA. Its American parent company does replicate limited metadata — such as the login details of our own administrator account there — to the United States. That transfer is covered by the EU-US Data Privacy Framework, with the standard contractual clauses as a fallback; the error reports themselves stay in Frankfurt.
6. How long we keep it
- Account and settings data — for as long as your account exists. If you delete your account, we delete them, except for what we have to keep as set out below.
- Check history — the retention period depends on your plan and is stated on the pricing page; we delete older results automatically.
- Domains and check history after termination — another 30 days, so that a terminated account can still be restored. After that we delete them for good. If you delete your account yourself, that happens immediately.
- Invoices and financial records — seven years, under the statutory tax retention obligation.
- Evidence of acceptance of our terms — for as long as your account exists and afterwards for as long as is needed to show which agreements applied.
- Log files — 30 days.
- Error reports in our error tracking — 30 days; after that Sentry deletes them automatically.
- Administrative actions in our admin panel — twelve months. We record who performed which far-reaching action and when, for example changing a plan or ending an account.
- An administrator signing in as a customer — twelve months: who did it, on which account, when, and for how long.
- Backups — we back up our database every night and keep it for seven days. Data you have deleted therefore also disappears from the backups within seven days at the latest.
7. Security
We send all traffic over TLS, store passwords encrypted and limit access to production data to those who need it. We treat webhook addresses and payment links as confidential and do not record them in log files.
To investigate a fault or a question, one of our administrators can look inside your account: they see your dashboard the way you see it. Only an administrator can do this, they cannot perform anything irreversible while doing so — they cannot delete your account, change your plan, change your password or email address, or create an API token — and we record every time who did it, on which account and for how long. We keep that record for the period stated in section 6.
8. Your rights
You have the right to access your data, to have it corrected or deleted, to have the processing restricted, to object to processing based on a legitimate interest, and to receive or transfer your data in a common format. Much of this you can do yourself: change your data in the dashboard, read out your domains through the API, and delete your account.
If you wish to invoke one of these rights, email support@certificate-checker.com. To prevent us from providing data to the wrong person, we may ask you to identify yourself; usually it is enough that you send the request from the email address of your account. We respond within one month. If you are not satisfied with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority.
9. Third-party websites
Our website and the dashboard contain links to other people's sites, for instance to our payment provider or to documentation. This statement does not apply there: those parties decide for themselves how they handle your data. Read their privacy statement if you want to know what they do.
10. Changes
We may amend this statement where the service or regulation calls for it. We announce a new version in advance in the dashboard and by email, with the date on which it takes effect. Earlier versions remain available on our website.