Privacy Policy

Effective Date: Feb 24, 2026
Last Updated: Feb 24, 2026

This Privacy Policy describes how Alertica, a brand operated by www.pagewiz.com, a company registered in Israel www.alertica.io, collects, uses, stores, and protects information in connection with the Alertica platform (the "**Service**") and our website at (https://www.alertica.io/).
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. What Alertica Does

Alertica is a file integrity monitoring (FIM) and configuration change detection tool. It monitors files and IoT device configurations (such as security cameras) for unauthorized changes by comparing cryptographic hashes. Alertica operates as a Software-as-a-Service (SaaS) platform and is also available as an on-premises deployment. Alertica does not access or store the contents of monitored files or device configurations.

2. Scope

This Privacy Policy applies to:

- Visitors to the Website
- Users who register accounts on the Service
- Customers using the SaaS version of the Service
- Individuals whose data may appear in system audit logs

For on-premises deployments, the customer operates the Service locally. See Section 10 for details.

3. Information We Collect

3.1 Account Information

When you create an account, we collect:

- Email address — used for authentication, communication, and account management.
- Authentication credentials — account login passwords are securely hashed using industry-standard one-way hashing and cannot be reversed or viewed by anyone, including Alertica staff.We do not collect names, phone numbers, physical addresses, or other personal identifiers beyond your email address.

3.2 Device and Credential Information

To operate the Service, you may provide:

- Device connection details — IP addresses, usernames, and passwords for monitored devices.Device credentials are stored using reversible encryption so the Service can connect to your devices. Access to device credentials is restricted to authorized personnel under strict internal controls and only for the purpose of providing the Service.You may delete device credentials at any time through the Service.

3.3 Monitoring Data

- File hashes — cryptographic hashes of monitored files. We do not store file contents.
- Configuration hashes — cryptographic hashes of IoT device configurations. We do **not** store raw configuration data.

3.4 Audit Logs

For security and integrity purposes, we maintain audit logs that may include:

- IP addresses
- Email addresses
- User actions and events
- Timestamps
- Error traces (which may contain limited configuration-related metadata)**Legal basis (GDPR):** Legitimate interest in maintaining platform security and integrity.
Retention: Up to 360 days.

3.5 Debug Logs

In limited circumstances, and only after notifying the affected customer, we may enable enhanced debug logging. Debug logs may include certain file metadata or configuration values necessary to diagnose issues.
**Retention:** Up to 30 days.

3.6 Website and Marketing Data

When you visit our Website, we may collect:

- Browser type and version
- Operating system
- Pages visited and time spent
- Referral source
- IP address
- Device identifiers
This data is collected through cookies and similar technologies. See our [Cookie Policy](cookie-policy.md) for details.

3.7 Payment Information

Payments are processed by Tranzila. Alertica does not store credit card details.

4. How We Use Your Information

We use collected information for the following purposes:

Purpose
Providing and operating the Service
Authenticating users and managing accounts
Monitoring files and device configurations for changes
Maintaining audit logs for security and integrity
Debugging and troubleshooting (when enabled)
Sending transactional communications (alerts, notifications)
Processing payments
Providing support
Website analytics and marketing
Complying with legal obligations
Legal Basis (GDPR)
Performance of contract
Performance of contract
Performance of contract
Legitimate interest
Legitimate interest
Performance of contract
Performance of contract
Performance of contract
Consent / Legitimate interest
Legal obligation

We do not use customer monitoring data (file hashes, configuration hashes, or device credentials) for any purpose other than providing the Service.
We do not use anonymized or aggregated customer data for product improvement or any secondary purpose.

5. Data Storage and Security

5.1 Location

Data processed through the SaaS platform is currently hosted in Israel. Upon request and subject to contractual agreement, we may host customer data in the European Union or the United States.

5.2 Security Measures

We implement reasonable and appropriate technical and organizational measures to protect your data, including:

- Encryption of data in transit (TLS)
- Encryption of data at rest
- Device credentials stored using reversible encryption with access controls
- Account passwords hashed using one-way algorithms
- Administrative access logging
- Encrypted backups retained for a minimum of one (1) year
No system can guarantee absolute security. While we strive to protect your information, we cannot guarantee that unauthorized access will never occur.

5.3 Multi-Factor Authentication

We may offer multi-factor authentication as an additional security measure. Where available, we recommend that users enable it.

6. Data Retention

Data Type
File and configuration hashes
Audit logs
Debug logs (when enabled)
Account data after deletion
Encrypted backups
Retention Period
As defined in customer contract
Up to 360 days
Up to 360 days
Up to 1 year
Minimum 1 year

Data may remain in encrypted backups during retention periods. Upon expiration of the applicable retention period, data is deleted or anonymized in accordance with our internal procedures.

7. Data Sharing and Sub-processors

We do not sell your personal data.

We may share data with the following categories of service providers ("Sub-processors") to operate the Service:

Sub-processor
Kamatera
Microsoft Azure
SendGrid (Twilio Inc.)
Twilio Inc.
Google
Meta
LinkedIn
Tranzila
Purpose
Cloud hosting infrastructure
Cloud hosting infrastructure
Transactional email delivery
SMS notifications
Website analytics and advertising
Advertising
Advertising
Payment processing

We may engage additional sub-processors from time to time. An updated list of sub-processors is available upon request.
We may also disclose information where required by law, regulation, legal process, or governmental request.

8. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including Israel and countries where our sub-processors operate.
Where personal data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

- Access — request a copy of your personal data
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Restriction — request restriction of processing
- Data Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw Consent — where processing is based on consent, you may withdraw your consent at any time

To exercise any of these rights, contact us at info@pagewiz.com.
We will respond to requests within 30 days or the timeframe required by applicable law.

10. On-Premises Deployment

For customers using the on-premises version of Alertica:

- All monitored data is processed and stored locally on the customer's infrastructure.
- Alertica does **not** have remote access to on-premises installations.
- No telemetry, monitoring data, or device information is transmitted to Alertica.
- The on-premises software performs periodic license validation checks that verify entitlement only. No device data, monitoring data, or personal data is transmitted during these checks.
- The customer acts as the **data controller** for all data processed through the on-premises deployment.

11. Personal Data Breach

In the event of a personal data breach, we will notify affected customers without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law.

12. EU Representative

Where required under applicable law, Alertica will designate a representative in the European Union. Until such designation, inquiries from EU residents may be directed to info@pagewiz.com.

13. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete such information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be posted on the Website with an updated "Last Updated" date. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:
Alertica (operated by Pagewiz 515270841 LTD) Israel Email: info@pagewiz.com

Stop breaches before they start

Get a personalized tour of Alertica from one of our team members and learn how it can fit your infrastructure.

Request a Demo