Skip to content
In development

Tenvey is not running yet. Every number on this site comes from one example website, not from a live service. What that means

Tenvey

Legal

Privacy policy

Tenvey watches websites from the outside. That shapes everything below: almost all of the data here describes servers and pages, not the people who visit them.

Last updated 12 August 2026

Tenvey is a demo product and this document is a template, not legal advice. No live service is processing anyone's data behind it — read it as an example of how a website monitoring product would describe its obligations, and have a lawyer write the version you publish.

What Tenvey monitors, and what it does not

When you add a website, Tenvey requests its public pages the way a browser or a search engine crawler would, records what came back, and turns the difference between one check and the next into issues.

Tenvey runs no code on your website and sets no cookie in your visitors' browsers. There is no tag to install and no script to embed. Tenvey therefore never learns who visits your site, what they click or where they came from. What appears in your dashboard describes your server's responses, not your audience.

Data you give us

  • Account — your name, work email address and a hashed password, or the subject identifier from your identity provider if you sign in with Google.
  • Workspace — the organisation name, the sites you add, the people you invite and the role each of them has.
  • Billing — company name, address, VAT number and the last four digits of the card. Payments run through our payment processor; full card numbers never reach Tenvey.
  • Support — whatever you write to us, and what we write back.

Tenvey is a tool for people who run websites. We do not knowingly create accounts for anyone under 16.

Data Tenvey records about the sites you monitor

  • The hostname, and the URLs found through links and the sitemap.
  • Status code, response time and transfer size for every check, kept as a time series.
  • Response headers, including cache directives, security headers and certificate metadata — issuer, common name, expiry.
  • An HTML snapshot and a screenshot of each checked page, so a change can be shown as a difference rather than asserted.
  • Issue records: what was wrong, the evidence for it, when it first appeared and when it was resolved.
  • Deployment markers, if you connect a deployment webhook — version and timestamp, nothing else from your build.

If your public pages contain personal data, the snapshot contains it too. A team page with names and photographs, a comment thread, a public staff directory: Tenvey stores those because it stores the page, not because it is looking for them. You can exclude paths in the site's settings, and excluded paths are never fetched.

Data collected while you use Tenvey

  • Server logs — IP address, user agent, request path and timestamp, for security and debugging.
  • Product analytics — which screens and features are used, recorded first-party. No advertising network, no cross-site tracking, no session replay.
  • Cookies — one to keep you signed in, one to remember your selected site and interface preferences. Both are strictly necessary for the dashboard to work. Tenvey sets no advertising cookie.

Why we are allowed to process it

  • To perform our contract with you — running the checks you asked for, keeping the results, sending alerts, issuing invoices.
  • Legitimate interests — keeping the service secure, preventing abuse, and understanding which features are used so we can improve them. We do not profile you and we do not advertise.
  • Legal obligation — invoices and the tax records behind them.
  • Consent — product announcements you opt into. Every one of those emails carries an unsubscribe link, and withdrawing consent has no effect on your account.

How long we keep it

  • Check results — 13 months at full resolution, then reduced to daily averages so year-on-year comparisons survive.
  • HTML snapshots and screenshots — 30 days.
  • Issue records — as long as the site is in your workspace, plus 90 days after you remove it.
  • Server logs — 30 days.
  • Account and workspace data — until you delete the workspace. Deletion removes it from production within 24 hours and from encrypted backups within 35 days.
  • Invoices — seven years, because tax law requires it.

Who else sees it

Tenvey uses a small number of processors: cloud hosting and databases, the regional runners that perform the checks, transactional email, payment processing and error tracking. Each one is bound by a written agreement, processes data only on our instructions, and receives only what its job needs. The current named list, with locations, is in the data processing agreement.

We do not sell personal data and we do not share it with advertisers. Nothing about your sites is shown to another customer. We disclose data to authorities only where the law obliges us to, and we tell you when we are allowed to.

Where it is stored

Accounts, results and snapshots are stored in the European Union, in Frankfurt. Checks run from Frankfurt, Washington and Singapore: a runner outside the EU sends a request to your site and returns the timing, the headers and the response body to EU storage. Those transfers rely on the European Commission's standard contractual clauses, with a transfer assessment on file for each provider.

Your rights

If the GDPR or a comparable law applies to you, you can ask for a copy of your data, correct it, have it deleted, export it in a machine-readable form, restrict how we use it, or object to processing based on legitimate interests.

Most of it needs no request at all: the dashboard exports your account data and your full check history as JSON, and deleting a workspace deletes what belongs to it. For anything else, write to privacy@tenvey.com or use the contact page. We answer within 30 days, and we ask for nothing beyond proof that you control the account's email address. If our answer does not satisfy you, you can complain to the data protection authority where you live.

How we protect it

Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Staff accounts require multi-factor authentication, access follows least privilege, and every touch of production is tied to a named ticket and logged. Backups are encrypted and restores are tested quarterly. No system is perfect; if a breach affects you, we tell you rather than wait to be asked.

Changes

The date at the top of this page changes whenever this policy does. For material changes we email account owners at least 30 days before they take effect, so cancelling remains a real option.

Contact

Privacy questions and rights requests: privacy@tenvey.com. Anything else: the contact page. See also the terms of service and the data processing agreement.