Privacy Policy
Version v1.0 · Last updated 11 July 2026
This policy is written to be reviewed as-is by an MSP’s auditor or data-protection officer. It covers where your data lives, who processes it, international transfers, and your rights — for both EU/UK and US data subjects. The complete third-party list is in our sub-processor register.
1. Who we are
Tidehawk (“we”, “us”) provides certificate and domain monitoring for UK/EU managed service providers (MSPs). This policy explains how we handle personal data when you use the Tidehawk platform or visit our website. For any question or request, contact hello@tidehawk.co.
2. Our roles (controller vs processor)
For an MSP’s own account data, we are the controller. For the end-client monitoring data an MSP loads into Tidehawk (client names, domains, certificates), the MSP is the controller and Tidehawk is the processor, acting only on the MSP’s documented instructions under our Data Processing Agreement.
3. Data we collect
Account data (controller):your name, work email address, password hash, optional two-factor secrets (stored encrypted), IP addresses, and billing details (processed by Stripe — we never store card numbers).
Service data (processor for your MSP): client names, monitored hostnames, certificate metadata discovered from public Certificate Transparency logs and live TLS scans, domain registration records, and PSA integration credentials (stored AES-256-GCM encrypted).
Usage data: sign-in events, audit-log entries (actor, action, timestamp, IP address), and error diagnostics.
Domain names and TLS certificates generally identify organisations and infrastructure rather than individuals; we treat them as personal data only in the edge cases where they identify a person (e.g. a sole trader’s personal domain or unredacted registry contact details).
4. Where your data lives (residency)
All customer data is stored and primarily processed in the United Kingdom / EU. Application compute and the primary database run on DigitalOcean in LON1 (London). Transactional email is sent via AWS SES in eu-west-2 (London). Files (reports, exports) are stored on Wasabi in eu-west-1 (London). Error monitoring runs on self-hostedGlitchTip within our own LON1 infrastructure. DNS is provided by Cloudflare in DNS-only mode — no application data is proxied through Cloudflare. No customer data is stored outside the UK/EU.
5. Why we process data (lawful bases)
Contract: operating your account, monitoring the assets you configure, sending expiry alerts, and creating the PSA tickets you request.
Legitimate interests: securing the platform (audit logs, rate limiting) and improving the service.
Legal obligation: tax and accounting records relating to billing.
6. International transfers
We store nothing outside the UK/EU. Certain look-up queries (a domain name, to discover public certificate/registration data) and billing data may transit providers that are US-based. GDPR treats such transmission as a transfer, so we rely on UK↔EU adequacy, the UK–US / EU–US Data Privacy Framework and/or Standard Contractual Clauses with the UK Addendum, and data minimisation (domain-name-only queries against public data). Full detail and the per-provider mechanism are in the sub-processor register.
7. What this means for you, by location
If you are in the EU or UK
Your data is stored and primarily processed in the United Kingdom (EU adequacy applies) and is not stored in the US. The only routine cross-border transmissions are public certificate/domain look-ups (domain name only) and billing, each covered above. You have full UK-GDPR / GDPR rights (§9) and may complain to the UK ICO or your national authority. Certificate look-ups carry the domain name only; see how discovery sources are configured and our roadmap commitment to a per-workspace EU-only option (not currently available).
If you are in the United States
Your data may be stored in the United Kingdom— a lawful, protective arrangement. For California residents (CCPA/CPRA), Tidehawk acts as a service provider and processes personal information only to provide the service: we do not “sell” or “share” personal information or use it for cross-context behavioural advertising. Comparable rights apply under other state laws (VCDPA, CPA, etc.). Rights are exercised via your MSP with our tooling (§9).
8. Sub-processors
We maintain a complete, versioned sub-processor register, each under a data processing agreement, and give at least 30 days’ notice before adding or replacing one. In summary: DigitalOcean (hosting/database, LON1), AWS SES (email, London), Wasabi (storage, London), Stripe (payments), Cloudflare (DNS-only), and the public certificate/domain look-up sources (Certspotter, Censys, crt.sh, RDAP/WHOIS). Error monitoring is self-hosted (not a sub-processor).
9. Certificate discovery sources
We discover certificates using a combination of in-region methods (a direct TLS scan that transmits data to no third party) and queries to one or more public Certificate Transparency sources (currently Certspotter, Censys, crt.sh), sent with the domain name only — never an MSP or end-client identity. Which CT sources are active is set at the platform level (see the sub-processor register). A per-workspace option to restrict discovery to in-region methods only is on our roadmap; it is not currently available and will be announced through the sub-processor change notice before it can be relied upon.
10. Retention
Account and service data is retained while your subscription is active. After cancellation, data is retained for 30 days (so you can reactivate or export) and then permanently deleted via a signed, verifiable erasure pipeline. Security and delivery logs are kept for fixed periods (network identifiers on staff access logs 90 days, email delivery log 90 days, look-up log 30 days) and then deleted automatically. Your workspace audit log is kept for the life of your account and pseudonymised on erasure. Billing records and records of rights requests are kept for 6 years where the law requires.
11. Your rights
Under UK GDPR / EU GDPR you have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing. Account owners can run a data export and erasure directly from the app (Settings → Account); where we act as processor, requests are directed to your MSP and we provide the tooling to fulfil them. Email hello@tidehawk.co for help. You may also complain to the Information Commissioner’s Office (ico.org.uk).
12. Security
Sensitive values (PSA credentials, two-factor secrets) are encrypted at rest with AES-256-GCM; all connections use TLS 1.2+. Tenant data is isolated with PostgreSQL Row-Level Security enforced at the database layer, access is least-privilege, administrative access to customer data is recorded in a tamper-evident audit chain, and we run a 72-hour breach notification watchdog. See our security overview.
13. Changes
We will notify account owners by email of material changes to this policy at least 14 days before they take effect.