Zondax Ping Privacy Policy
Effective Date: 15 July 2026
Version: 1.0
Controller: Zondax AG, Dammstrasse 16, 6300 Zug, Switzerland
This Privacy Policy explains how Zondax AG ("Zondax", "we", "us") handles personal data for the Zondax Ping mobile application ("App") and its backend service. Ping delivers infrastructure incident alerts (for example monitoring alarms) to your device as push notifications.
1. Summary
- We process the data needed to deliver push notifications to your device and to operate your account: your email address, sign-in identity, push token, and a few device details.
- Incident alerts shown in the App come from your team's monitoring sources; we process them to deliver the service.
- The App contains no advertising, no tracking SDKs, and no analytics or crash-reporting SDKs.
- We do not sell personal data.
2. Data We Process
Account data. Ping requires an account. When you sign in with an email link or with Google, we process your email address and a user identifier provided by the sign-in provider (Firebase Authentication, a Google service). We key your account to an internal identifier. The App sends a short-lived authentication token with each request to our backend to identify your session. Account data is necessary to use Ping; device registration is necessary to receive alerts on a device.
Device and notification data. To deliver push notifications, the App registers your device with our backend. This registration includes: a push notification token (Apple/Google push services), an installation identifier generated by the App, your device platform (iOS/Android), the App version, your device locale (language and region), and your notification permission status. The push token is stored on our backend, associated with your team.
Incident data. The alerts you receive (title, summary, affected service, severity, labels, timestamps) originate from your team's connected monitoring and alerting sources. We store and transmit this content to deliver it to your team's registered devices. Avoid routing sensitive personal data through alert content.
App integrity. In production, the App uses Firebase App Check (Play Integrity on Android; App Attest, with DeviceCheck as fallback, on iOS) to confirm requests come from a genuine App instance. The attestation exchange is processed by Google and, on iOS, by Apple; an attestation token then accompanies API requests to our backend.
Local data. Sign-in state, the installation identifier, the device registration, and your pending sign-in email are stored locally on your device.
3. What We Do NOT Collect
- No advertising identifiers and no tracking across apps or websites.
- No analytics SDKs and no crash or performance reporting.
- No contact lists, location, photos, or other device content.
4. Purposes and Legal Bases
Where the GDPR or the Swiss FADP applies:
- Delivering the service (account management, device registration, sending and syncing incident alerts): performance of a contract where you are our customer; where your account is provided through your employer or team, our legitimate interest in providing the service they engaged.
- Service integrity and abuse prevention (app attestation, authentication): legitimate interest in operating a secure service.
- Legal obligations (e.g. accounting where subscriptions apply): compliance with law.
For incident alert content submitted by your team's monitoring sources, your organization determines what is sent; we process it to deliver the service. Under the Swiss FADP, we observe its processing principles and, where a justification is required, rely on consent, an overriding private or public interest, or law, as applicable.
We do not use your personal data for advertising or profiling.
5. Recipients and Processors
We use service providers to operate Ping: Google (Firebase Authentication for sign-in, Firebase Cloud Messaging for push delivery, Firebase App Check for attestation, and Google Cloud Platform for backend hosting) and Apple (APNs push delivery and App Attest/DeviceCheck attestation on iOS). These providers process data under data protection agreements; for certain security and platform operations they may act under their own terms. We do not share personal data with third parties for their own marketing.
The current list of our providers, their processing locations, and retention periods is maintained at https://kunobi.com/legal/providers and is updated as our infrastructure evolves.
6. International Transfers
We are based in Switzerland; our service providers may process data outside Switzerland and the EEA, notably in the United States (Google and Apple services). Where they do, we rely on recognized standard contractual clauses or an applicable adequacy decision. You can request information about the safeguards applying to a specific transfer via the contact in Section 13.
7. Retention
Account data is kept while your account exists. Push tokens and device registrations are kept while the device is registered and are removed or invalidated when the device is unregistered or your account is deleted. Incident data is retained only as long as needed to provide the service. We delete or anonymize data when it is no longer needed.
8. Your Rights and Account Deletion
Depending on applicable law, you can request access, correction, deletion, or portability of your data, and object to or restrict processing, by contacting dataprotection@zondax.ch. Where your account or incident data is controlled by your organization, we may refer your request to them.
Account deletion: you can request deletion of your account and associated data (including device registrations and push tokens) at any time via dataprotection@zondax.ch; deletion is subject only to legally required retention. As in-app account deletion becomes available, this policy will be updated with the direct path.
If you are in the EU/EEA, you may lodge a complaint with your supervisory authority; in Switzerland, with the FDPIC.
9. Notifications Control
You control push notifications through your device's notification settings and the in-App preferences. Disabling notifications in your device settings stops them from being shown on that device; the underlying device registration is removed as part of account deletion (Section 8).
10. Children
Ping is a professional tool and not directed at children under 16. We do not knowingly collect data from children.
11. Security
We use appropriate technical and organizational measures, including transport encryption, authenticated APIs, and app attestation, to protect data against loss, misuse, and unauthorized access.
12. Changes to This Policy
The current version of this policy is always available at https://kunobi.com/privacy/ping, with its version and effective date; every published version also remains permanently available at its own versioned address. For material changes, and before any materially new data processing begins, we will notify you in the App or by email before the changes take effect.
13. Contact
Zondax AG Dammstrasse 16 6300 Zug Switzerland
Email: dataprotection@zondax.ch