What we hold, and for how long.
Short version: enquiry details until we finish talking, client contact details for the length of the contract, and monitoring data for thirteen months. Nothing is sold, nothing goes to advertisers, and this site sets no cookies at all.
Who is responsible
Nightshift sp. z o.o., ul. Zabłocie 43, 30-701 Kraków, Poland. NIP 676 999 41 20. Data protection questions go to privacy@nightshift.ops and are answered by a person.
If you send an enquiry
We keep your name, company, email, phone if you gave one, and whatever you wrote about your systems. Legal basis: our legitimate interest in answering a business enquiry you started. We keep it for 12 months after the last message, then delete it. If you ask us to delete it sooner, we do, same day.
What you write about your last incident is commercially sensitive and we treat it that way. It is not used as a case study, an example on a call, or anything else without written permission.
If you become a client
Contact details of the people we are allowed to wake — name, role, phone, email, escalation order. Kept for the length of the contract and 30 days after. These are the most sensitive records we hold, because they are a list of phone numbers that ring at three in the morning.
Monitoring data — metrics, check results and alert history for 13 months; logs for 30 days. Stored in the EU, encrypted at rest, and deleted on request within 14 days of the contract ending.
What we go out of our way not to collect: we do not ingest your customers' personal data. Where a log line would contain it, our collectors strip it at source rather than storing and filtering later. If your logs are full of email addresses, we will tell you during onboarding and help you fix it, because that is your exposure, not just ours.
Access to your systems — every action taken by our engineers on your infrastructure is logged with a name and a timestamp, and that record is yours on request at any time, including after you leave.
Cookies and this website
This site sets no cookies and runs no analytics. There is no tracking pixel, no session recording and no fingerprinting. Fonts are served from this domain rather than from a font CDN, so loading this page tells nobody but our host that you were here.
Who else sees it
- Hosting and forms — Netlify, EU region
- Metrics and log storage — TODO(client), EU region
- Paging and telephony — TODO(client)
- Email — TODO(client)
Each receives only what it needs, each is bound by a processing agreement, and none may use it for their own purposes. The current list with sub-processors is sent to every client and updated 30 days before it changes.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to the processing. Write to privacy@nightshift.ops and we answer within 30 days, usually within two. If something has to be kept — an invoice, or an access log that is part of a client's audit trail — we tell you exactly what and why.
Unhappy with how we handled it? You can complain to the Polish data protection authority, the Urząd Ochrony Danych Osobowych.
Changes
Last updated . Anything affecting existing clients is announced by email 30 days ahead rather than quietly edited into this page.
Demo note: this is a portfolio demonstration, not a live business. No enquiries are processed and no personal data is collected. A real deployment would need the TODO(client) rows filled in and a lawyer's read-through.