Last updated 4 August 2026
Hesklo ("Hesklo", "we", "us") is a monitoring and on-call service, operated by Sverige Analytics AB, that checks the availability of websites and servers and delivers alerts according to rules you configure. For the purposes of the EU General Data Protection Regulation (GDPR), Sverige Analytics AB is the data controller for the personal data described in this policy.
This policy explains what personal data we handle, why, and what control you have over it.
When you register we store your email address, an optional display name, and a hashed (bcrypt) form of your password. We never store passwords in plain text.
The monitors, flows, schedules and connections you create. Connection credentials such as webhook URLs, API tokens and SMS provider secrets are encrypted at rest. Recipient details you enter, such as alert email addresses and phone numbers, are stored so we can deliver alerts.
Check results, uptime history, incident events and the notifications we send on your behalf, retained for the window included in your plan.
If you invite team members, we store each member's email address and role. If you set up a weekly on-call rota, we store the schedule you configure, including the recipient addresses and shift times assigned to it.
If you create an API key, we store a name you give it and a hashed form of the key together with its scope. The key itself is shown only once when created and cannot be recovered afterwards.
Standard server logs including IP address, browser user-agent and timestamps, kept for security and abuse prevention. We keep a short-lived audit log of significant account actions for the same reasons. To tell humans from bots on our signed-out forms we use ALTCHA, a self-hosted proof-of-work challenge that runs in your browser; it does not send your data to a third party and does not track you.
If you subscribe to a paid plan, payments are handled by Mollie. We do not see or store your full card number. We retain your plan, subscription status and Mollie customer reference.
Under GDPR we rely on: performance of a contract to provide the service you signed up for; legitimate interests for security, abuse prevention and keeping the service working; consent where you actively confirm an alert recipient address; and legal obligation for records we are required to keep, such as billing records.
Hesklo is hosted within the European Union, in Denmark. We share data only with service providers ("processors") who help us run Hesklo, and only as needed. These currently include:
Account and configuration data are kept while your account is active. Check results and incident history are kept for the window included in your plan, then aged out. If you delete a monitor, its history and incident state are removed. If you close your account we delete or anonymise your personal data within a reasonable period, except records we must keep by law such as billing records.
Passwords are hashed with bcrypt. Integration secrets are encrypted at rest. Access to the service is over HTTPS, sign-in supports email-based two-factor authentication, and your monitors, connections and history are scoped to your account.
If a personal data breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority, and you where required, without undue delay and in line with our obligations under GDPR.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
Subject to GDPR, you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a portable copy. You can update your email, display name and password, and delete monitors, from inside the dashboard. For anything else, contact us using the details below. You also have the right to lodge a complaint with your local supervisory authority; in Sweden this is the Integritetsskyddsmyndigheten (IMY).
We use a single strictly necessary cookie to keep you signed in. Our bot protection (ALTCHA) runs as an in-browser proof-of-work challenge and does not set a cookie of its own. We do not use advertising or third-party tracking cookies. Because the session cookie is essential to the service, it is set without a consent banner; if you block it, sign-in will not work.
Some of our processors operate outside the European Economic Area. Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
We may update this policy from time to time. When we do, we will revise the "last updated" date above and, for material changes, notify you by email or in the dashboard.
For privacy questions or to exercise your rights, contact us at [email protected].