Privacy Policy
Last updated: 2026-09-27
v1 template. This policy will be replaced by a fully reviewed one. Material changes will be announced on this page and emailed to active accounts.
1. Who we are
ViperSonar is a monitoring service operated by IOT LTD, a company registered in Cyprus (registration number HE343300; registered office Mnasiadou 9, Demokritos Building, 1065 Nicosia, Cyprus) ("ViperSonar", "we", "us"). IOT LTD is the controller of the personal data described here. For privacy questions or requests, email support@vipersonar.com.
2. Data we collect
We collect what we need to run the Service:
- Account information. Your name, email address, organisation and workspace names, your role in each, a hashed password when you use one, the identifier of a Google or Microsoft sign-in when you use one, and your two-factor settings.
- Device and network data. What you and your collectors tell us about the devices you monitor: names, tags, IP addresses, hostnames, MAC addresses, SNMP system names and descriptions, network interfaces and firmware versions — and the result of every check, such as up or down, response times and messages.
- Discovery scans. When you start a discovery scan, your collector reports the devices it finds in the address ranges you chose: their open ports, the version banner of an SSH service, and the identifying headers, title and a short extract of any web page they serve.
- Collector details. Each collector's version, operating system, counters and the public IP address it connects from.
- Signals. The heartbeats your jobs and devices send, with any message or data they carry. For a signal sent by email to a device's address, we keep the sender, subject, date and the receiving server's authentication results; we read the message's headers, not its body.
- Alert settings and deliveries. The email addresses, phone numbers, webhook addresses and connected services you set up for alerts, and a record of each alert we send.
- Incidents. Incident history, including any notes you or your colleagues add.
- Billing. Our payment processor, Stripe, collects your payment details. We keep the plan you are on and Stripe's references to your subscription.
- Operational logs. IP address, user agent, request times and error reports, used for security, debugging and rate limiting.
- Cookies. A session cookie (HttpOnly), a cookie that protects form submissions against forgery, and short-lived cookies that carry a Google or Microsoft sign-in through to its end. No advertising or analytics cookies.
3. How we use your data
- To run the monitoring you set up: check your devices, notice missed signals and failed checks, and open incidents.
- To send the alerts you configure, to the destinations you choose.
- To show the status pages you decide to publish.
- To sign you in, protect your account, and investigate abuse and operational incidents.
- To bill for paid plans.
- To send transactional email — sign-in, verification, billing and security notices. We do not send marketing email without your explicit opt-in.
- To answer the messages you send us.
For the data about your devices, and about the people you add as alert recipients, we act on your instructions: you decide what is monitored and who is alerted, and we process that data to provide the Service to you.
4. Public status pages
If you publish a status page, the device names, labels and statuses you choose to show can be seen by anyone with its address, or its password if you set one. Unpublish it, or delete its workspace, to take it down.
5. Sub-processors
We use these services to operate ViperSonar. Each processes data only to provide its service to us, under its data processing terms.
- Cloudflare — hosting and networking, the analytics store that holds check history, abuse protection, and the custom domains of status pages.
- Neon — the database holding account, workspace, device and incident data, hosted in the EU (Frankfurt).
- Resend — email delivery, including alert email.
- Twilio — SMS delivery: the recipient's phone number and the alert text.
- Stripe — payments and subscriptions.
- Sentry — error monitoring, including a recording of any session in the ViperSonar app in which an error occurs, with text, form inputs and media masked.
- Google — Gemini, only when you ask ViperSonar to identify discovered devices with AI (it receives those devices' discovery details); and Google sign-in, when you use it.
- Microsoft — sign-in, when you use it.
When you connect Slack, Microsoft Teams, Discord, PagerDuty or a webhook, alert content goes to that service because you asked us to send it there, and its own terms and privacy policy apply.
6. Retention and deletion
- Check results and signals are held in Cloudflare's analytics store, which deletes them automatically after about three months.
- Alert records, including the phone numbers an SMS was sent to, are deleted 30 days after the alert.
- Account, workspace, device, collector and incident records are kept for as long as the workspace or account exists.
The history window listed with each plan does not change these periods: on every plan, check history is kept for about three months and everything else for as long as its workspace exists.
Deleting a device, a collector or a workspace deletes its records from our database straight away; check history already in the analytics store expires on its own schedule. When you delete your account, we anonymise your account record and remove your memberships, and organisations you alone own are closed.
To have a closed organisation's records deleted, or to ask what we still hold, email support@vipersonar.com.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict its processing. To exercise any of them, email support@vipersonar.com; we reply within one month.
If you are in the European Union, you may also complain to a data protection authority — in Cyprus, the Commissioner for Personal Data Protection.
8. California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) gives you the rights below. They add to the rights in section 7 and apply even though our controller is a Cyprus company.
- Right to know. You can ask for the categories and specific pieces of personal information we hold about you, where we got it, why we collected it, and the categories of third parties we disclose it to.
- Right to delete. You can ask us to delete the personal information we hold about you, subject to the exceptions the law allows.
- Right to correct. You can ask us to correct inaccurate personal information.
- Right to opt out of sale or sharing. We do not sell or share your personal information for money or for cross-context behavioural advertising, and have not done so in the preceding 12 months. There is nothing to opt out of, but we honour opt-out preference signals, such as Global Privacy Control, that your browser sends.
- Right to non-discrimination. We will not deny you service, charge a different price or provide a different level of quality because you exercised any of these rights.
To exercise a California right, email support@vipersonar.com. We verify a request against the information associated with your account before acting on it, and you may have an authorised agent submit one for you.
9. Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Passwords, API keys and collector tokens are stored as hashes, never in readable form, and access to production data is limited to the people who operate the Service.
10. Children
ViperSonar is a service for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16.
11. International transfers
Our database is in the EU. Several of the services above — Twilio, Stripe, Sentry and Resend among them — are based in the United States, so your data may be processed there. Those transfers rely on the Standard Contractual Clauses in each provider's data processing terms.
12. Changes to this policy
We update the "Last updated" date above whenever this policy changes, and announce material changes in the Service and by email to active accounts.
13. Contact
Questions or complaints? Email support@vipersonar.com. The controller is IOT LTD, registered in Cyprus (registration number HE343300), at Mnasiadou 9, Demokritos Building, 1065 Nicosia, Cyprus.