Privacy Policy

Last updated: February 12, 2026

1. Introduction

Watcher2 ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our file monitoring service. We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines and its Implementing Rules and Regulations, and with the National Privacy Commission (NPC). Where applicable, we also comply with the General Data Protection Regulation (GDPR) for users in the European Union.

2. Information We Collect

2.1 Account Information

  • Email address
  • Name (optional)
  • Password (hashed and encrypted)
  • Payment information (processed by Stripe, we don't store full card details)

2.2 Monitored Files Data

  • URLs of files you choose to monitor
  • File content snapshots (only when changes are detected)
  • File metadata (size, hash, timestamps)
  • HTTP response headers from monitored files
  • Server IP addresses serving your files

2.3 Usage Information

  • Check logs (timestamps, results, duration)
  • Notification history
  • Login activity and session data
  • Browser type and IP address (for security)

3. How We Use Your Information (Purpose and Legitimate Basis)

We process your personal data for specified, legitimate purposes and only to the extent necessary. We use your information to:

  • Provide and maintain the file monitoring service
  • Send you notifications about file changes
  • Process your payments and manage your subscription
  • Send you important service updates and security alerts
  • Respond to your support requests
  • Improve our service and develop new features
  • Prevent fraud and abuse
  • Comply with legal obligations

Processing is done fairly and lawfully. We do not process your data for purposes incompatible with those disclosed here without your consent or as permitted by law.

4. Data Storage and Security

We take data security seriously:

  • Location: All data is stored on Hetzner Cloud servers in Helsinki, Finland (EU)
  • Encryption: Data is encrypted at rest and in transit using industry-standard encryption (TLS 1.3, AES-256)
  • Access Control: Strict access controls and authentication mechanisms
  • Backups: Regular automated backups with encryption
  • Retention: We retain your data for as long as your account is active. File history is kept according to your plan

5. Data Sharing and Disclosure

We do NOT sell your personal data. We may share data with:

  • Service Providers: Hetzner (hosting), Stripe (payments), AWS SES (email delivery)
  • Legal Requirements: When required by Philippine or other applicable law, court order, or to protect our rights
  • Business Transfers: In the event of a merger, acquisition, or sale

All third-party service providers are contractually obligated to protect your data and use it only for specified purposes, in line with the Data Privacy Act.

5.1 Data Breach Notification

In the event of a personal data breach that is likely to pose a real and serious harm to you, we will notify affected data subjects and the National Privacy Commission in accordance with the Data Privacy Act and its Implementing Rules and Regulations. We will take steps to contain the breach and mitigate harm.

6. Your Data Subject Rights

Under the Data Privacy Act of 2012 (RA 10173), you have the right to:

  • Be informed: Know what personal data we collect and how we process it
  • Access: Request a copy of your personal data we hold
  • Correct: Request correction of inaccurate or incomplete data
  • Rectification, erasure, or blocking: Request that we rectify, erase, or block your data where processing is unlawful or no longer necessary
  • Data portability: Receive your data in a structured, commonly used format where feasible
  • Object: Object to the processing of your personal data in certain circumstances
  • Withdraw consent: Withdraw consent at any time where processing is based on consent

To exercise these rights, contact us at privacy@watcher2.com. We will respond within the period required by applicable law. If you are in the European Union, you also have the rights under the GDPR (including restriction of processing and the right to lodge a complaint with a supervisory authority).

Right to file a complaint: You have the right to file a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated. Complaints may be submitted to complaints@privacy.gov.ph. For more information, visit privacy.gov.ph.

7. Cookies and Tracking

We use the following cookies:

  • Essential Cookies: Required for authentication and security (session cookies)
  • Analytics Cookies: To understand how you use our service (anonymized)

You can control cookies through your browser settings. Disabling essential cookies may affect service functionality.

8. Data Retention

  • Account Data: Retained while your account is active and for 30 days after deletion
  • File Snapshots: Retained according to your plan (30 days for Free, unlimited for Pro/Enterprise)
  • Logs: Check logs retained for 90 days
  • Backups: Backup data deleted within 90 days of account deletion

9. International Data Transfers

Your data is primarily stored in the EU (Finland). If data is transferred outside the EU, we ensure adequate protection through Standard Contractual Clauses or other approved mechanisms.

10. Children's Privacy

Our service is not intended for minors. We do not knowingly collect personal data from children or minors without appropriate parental or guardian consent where required by law. If you believe we have collected data from a minor without proper consent, please contact us immediately so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through the service. Continued use after changes constitutes acceptance.

12. Contact Us

For questions about this Privacy Policy or to exercise your data subject rights:

Email: privacy@watcher2.com
Data Protection Officer: dpo@watcher2.com
Address: [Your Company Address, Philippines]

You may also lodge a complaint with the National Privacy Commission (NPC): complaints@privacy.gov.ph, or visit privacy.gov.ph. If you are in the EU, you may lodge a complaint with your local data protection supervisory authority.