UpNTop

Privacy Policy

Last updated: 13 September 2026

This policy explains what personal data UpNTop processes when you use the website and the service, on what legal basis, and how long we keep it. It is written under the EU General Data Protection Regulation.

1. Who is responsible

The controller is Denis Malov s.p., Mlinska ulica 22, 2000 Maribor, Slovenia (tax number 14795914, registration number 7306024000).

For any question or request about your data, write to support@upntop.com.

2. What we process

Account data: your email address, your name and your password kept as a bcrypt hash. The password itself is never stored and cannot be recovered by us — only reset.

Project data: the addresses of the sites you monitor, their settings, and the drafts and reports produced for them.

Search metrics: clicks, impressions and positions read from Google Search Console and Bing Webmaster Tools using the read-only access you grant yourself. We can read statistics and nothing else — we cannot change anything in your search accounts.

The Google data we read serves one purpose only: showing you the statistics of your own site inside your account. We do not pass it to anyone, do not use it to train models, do not build advertising or profiles from it, and do not merge it with the data of other customers. The access is read-only and you can revoke it at any time in your Google account.

Speed and availability: to measure a page we send its address to Google PageSpeed Insights and to the Chrome UX Report, and we request the page itself every few minutes to see whether it answers. Only the address is sent. No data about your visitors is involved.

Mailing data, if you use the mail product: the contacts you add — email address, the fields you choose to store, subscription state, the date and proof of consent — and the delivery record of every message, including whether it was accepted, bounced, opened or clicked.

Technical data: server logs needed to run and secure the service, the cookies described in the Cookie Policy, and — on the public pages and only with your permission — website analytics.

3. IP addresses, precisely

For a list without double opt-in, the proof of consent contains the IP address the subscription came from. That is the only place where a full IP address is written down, and it exists because the GDPR puts the burden of proving consent on the sender.

The public AI visibility checker stores a salted SHA-256 fingerprint of the requester’s address, not the address itself, so that repeat checks can be counted without identifying anyone.

Rate limiting holds addresses in memory for minutes and writes nothing to disk.

4. Purposes and legal bases

To run your account and provide the service you asked for — performance of a contract, Art. 6(1)(b) GDPR.

To keep the service secure, prevent abuse, and understand in aggregate what works — our legitimate interests, Art. 6(1)(f) GDPR.

To keep a suppression list of people who unsubscribed, complained or whose address rejected our mail — our legitimate interest and theirs, Art. 6(1)(f) GDPR: it exists so that they are not written to again.

To meet obligations that apply to us by law — Art. 6(1)(c) GDPR.

To count how the public pages are read — your consent, Art. 6(1)(a) GDPR. Nothing is loaded until you give it, and you can withdraw it at any time at the bottom of the Cookie Policy page.

5. Where we are the controller and where the processor

For your account and your projects we are the controller: we decide what is stored and why.

For the contacts and campaigns you bring, you are the controller and we are your processor. You decide whom to write to and on what basis. We process those addresses only to deliver what you send and to record what happened to it, and we never use them for our own purposes.

If you need a written data processing agreement, ask at support@upntop.com and we will provide one.

6. Cookies

We set five cookies and all of them are strictly necessary: staying signed in, remembering which account and which site you are looking at, protecting the Search Console connection, and your interface language.

On the public pages we also use Google Analytics, but only if you allow it: until you do, the tag is not on the page and nothing is stored. It is never loaded in the cabinet. There is no advertising anywhere on the site. Cookie names, and the buttons for changing your answer, are in the Cookie Policy.

7. Who else touches the data

Hosting: our own server in a data centre in Germany, in the European Union. Everything you see in the cabinet is stored there.

Backups: encrypted on our server before they leave it and kept with Backblaze B2 in the European Union. The keys stay with us, so the storage provider holds ciphertext it cannot read. Copies older than 90 days are deleted.

Text generation: Anthropic. Drafting sends the topic, the brief and the profile of the site. Contact lists and subscriber data are never sent to a generation model.

Search, speed and index data: Google (Search Console API, PageSpeed Insights, Chrome UX Report) and Microsoft (Bing Webmaster Tools API).

Email delivery: our own mail server. No third-party sending provider is involved unless you configure one yourself.

Website analytics: Google (Google Analytics 4), on the public pages and only for visitors who allowed it. It receives the public addresses opened and the technical data of the request. It is not loaded in the cabinet, so nothing about your projects, your contacts or what you do inside the service reaches it.

We do not sell personal data, and we do not share it for advertising or profiling by anyone.

8. Transfers outside the EEA

Your data is stored in the European Union. Anthropic, Google and Microsoft are companies in the United States, and processing on their side is covered by the EU Standard Contractual Clauses and, where the provider is certified, by the EU–US Data Privacy Framework.

9. How long we keep things

Account and project data: while the account exists. When you delete it, we erase or anonymise personal data within 30 days.

Availability checks: 30 days, then deleted automatically. A year of downtime history is a different product and we do not promise it.

Contacts, campaigns and delivery events: as long as you keep them. Deleting a contact deletes its events with it; closing the account deletes all of it.

Suppression list: an address that unsubscribed or complained stays on it even after the contact itself is deleted. Dropping it would mean writing again to someone who asked us to stop — the opposite of what they asked for.

Backups: up to 90 days, after which the copy is deleted from offsite storage.

Records we must keep by law are kept for as long as the law requires and for nothing else.

10. Security

Traffic is encrypted in transit, passwords are stored as bcrypt hashes, offsite backups are encrypted before they leave the server, and access to production is limited to the operator.

Outgoing mail is signed with DKIM and covered by SPF and DMARC, so that mail claiming to come from a customer domain can be verified rather than trusted.

No method of transmission or storage is completely secure, and we do not claim otherwise.

11. Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, and to receive it in a portable form. Where processing rests on consent, you can withdraw it at any time.

You can export your data and delete your account from the cabinet. To exercise any other right, write to support@upntop.com.

If you are a subscriber on someone’s list rather than our customer, the fastest route is the unsubscribe link in the message; requests addressed to us are passed to the sender, who is the controller of that list.

12. Complaints

If you believe your data is processed unlawfully, you may complain to the Slovenian Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si) or to the supervisory authority where you live.

13. Children

The service is not intended for children under 16, and we do not knowingly collect their data.

14. Changes and contact

We may update this policy and will publish the new version with a new date; for material changes we notify account holders.

Controller: Denis Malov s.p., Mlinska ulica 22, 2000 Maribor, Slovenia. Email: support@upntop.com.