Privacy
Last updated: 3 September 2026
Controller
Leon Matthies, Rathausstraße 33, 6900 Bregenz, Österreich. Email: contact@duskwatch.me.
What Duskwatch stores
Duskwatch monitors automation instances. Three kinds of data arise in doing so:
- Account: name, email address, password as a hash, time of creation. In addition, one session per sign-in with IP address, browser identifier and expiry time.
- Connected instances: name, instance URL, assigned client and the API key. The API key is stored encrypted (AES-256-GCM) and is never shown again after saving.
- Monitoring data: names and schedules of the workflows, time and status of the most recent executions, and for each incident the execution ID, the affected node and an error message truncated to 500 characters.
The payload data of executions is not stored. Duskwatch does not read execution contents. One exception is the error message: it comes from the monitored workflow and may in individual cases contain fragments of processed data, if the workflow writes them into its own error message. Anyone who must rule that out should shape their own workflows' error messages accordingly.
Purpose and legal basis
- Account and monitoring: performance of the usage contract, Art. 6(1)(b) GDPR.
- Session data and logs: legitimate interest in secure, traceable operation, Art. 6(1)(f) GDPR.
Who else sees the data
- Hosting: Oracle Corporation, Rechenzentrum Frankfurt. Servers and database are located in the EU.
- Email delivery: Brevo (Sendinblue GmbH), EU-Region — receives the recipient address and the content of alert emails.
- Alert channels you choose yourself: anyone who sets up Slack or Telegram sends the alert texts there. Those providers process the data outside the EU. Setting them up is voluntary; without it, nothing goes to them.
- The monitored instances themselves: Duskwatch calls them. The data flows from there to here, not the other way round.
No third-party analysis takes place: no tracking, no advertising or statistics services.
Cookies
Duskwatch sets exactly one cookie: the session cookie after sign-in. It is technically necessary, therefore requires no consent, and expires with the session. There are no other cookies.
How long
Account and instance data until the account is deleted. Incidents and workflow data are deleted along with the instance they belong to. Sessions expire automatically.
Your rights
Access, rectification, erasure, restriction of processing, data portability and objection — informally to contact@duskwatch.me. Complaints are handled by the Austrian data protection authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at).
Data processing
Anyone using Duskwatch for their own clients' data is the controller for it, and Duskwatch is the processor. The agreement for that is available under data processing.