Privacy Policy

This policy explains what data HWKeeper collects, why, how long we keep it and who receives it. It covers the hwkeeper.com website, the HWKeeper dashboard and the HWKeeper agents for Windows, macOS, Linux and Android.

1. Who we are

HWKeeper (hwkeeper.com, “we”) provides a service that keeps an inventory of a company’s computers and reports when their hardware, software or connected devices change. For any question about this policy or your data, write to privacy@hwkeeper.com. The service is operated by Alex Semensky.

2. Our role

  • Data from the computers where the agent is installed. The organization that installs the agent (our customer) decides which devices to monitor and why. For this data the customer is the controller and we process it on the customer’s behalf and on its instructions.
  • Dashboard accounts, website visitors and requests sent through the website. For this data we are the controller.

If you work at a company that uses HWKeeper and have questions about data collected from your computer, please contact your employer first. If you write to us, we will pass your request to them.

3. What data we collect

3.1. Dashboard account

  • Email address, company name, name (if you enter it), role (viewer, manager or administrator).
  • Password, stored only as a bcrypt hash. Sign-in links and codes are stored only as hashes.
  • Interface language and settings, email confirmation time, last sign-in time, the page you came from when you registered.
  • Security events: successful and failed sign-ins, sending of sign-in codes, registrations, with the IP address they came from.

3.2. Data from computers with the agent

CategoryWhat exactly
SystemComputer name, operating system and version, domain, device identifier, uptime, name of the signed-in user account.
HardwareModels and serial numbers of the motherboard, chassis, processor, memory modules, drives, graphics card and monitors; BIOS version; drive health (SMART), battery health, temperatures and fan speed.
SoftwareInstalled programs (name, version, publisher, install date, size, folder), startup items with their command lines, services. On Android — the list of installed apps.
Security settingsDisk encryption, Secure Boot, TPM, firewall, antivirus, system updates, open network ports with the name of the program that opened them.
PerformanceEvery minute: processor and memory load, the busiest processes (name and ID), free disk space, connection checks to the local gateway and public DNS servers.
NetworkNetwork adapter names, MAC addresses and local IP addresses; the public IP address seen by our server, and the country, city and provider determined from it.
USB and peripheralsVendor and product ID, manufacturer, model, serial number and class of connected devices.
Other devices on the local networkNetwork discovery finds devices without the agent (printers, routers, cameras): their IP and MAC addresses, network names and announced services. The customer can turn discovery off.
LocationWindows: position from the Windows location service; if it is not available, the list of nearby Wi-Fi access points (BSSID, network name, signal strength). Linux and macOS: the list of nearby Wi-Fi access points; a separate macOS build can use macOS location services after the user allows it. Android: GPS or network position, can be turned off in the app. The accuracy is usually about a building. The customer can turn location off for its agents.
Android deviceManufacturer, model, system build and security patch level, mobile carrier name and SIM country, root and developer mode flags, battery state. The IMEI only where the system allows it (not on Android 10 and later).

The agent does not collect: screenshots, keystrokes, clipboard contents, file contents, documents, emails and messages, browser history, passwords, phone numbers, contacts or text messages.

3.3. Website

  • Requests sent through the forms “Plan for MSPs” and “More than 50 computers”: email address, number of computers, language and the IP address the request came from.
  • Website analytics (Google Analytics) — see section 10.

4. Why we use data

  • To provide the service (performance of the contract): show the inventory, detect changes, send alerts and reports, run tickets.
  • Security and abuse prevention (legitimate interests): sign-in logs, protection against password guessing and fake registrations.
  • Service emails (performance of the contract): email confirmation, sign-in codes, alerts you set up.
  • Replying to requests from the website forms (steps at your request before a contract / legitimate interests).
  • Website analytics — where required by law, only with your consent.
  • Legal obligations, when the law requires us to keep or disclose data.

We do not sell personal data, do not use it for advertising and do not share it with advertisers.

5. Who receives data

  • Hosting. The service runs on a virtual server rented from a hosting provider; the server is located in the European Union.
  • Email. We send emails from our own mail server, without third-party email services.
  • ip-api.com receives the public IP addresses of computers to determine the country, city and provider.
  • beaconDB (api.beacondb.net) receives the identifiers of nearby Wi-Fi access points and their signal strength to estimate location. Computer names and user names are not sent.
  • Telegram — only if the customer turns on Telegram alerts: the alert text (computer name, rule, description, time).
  • Webhooks — only if the customer sets them up: alert data is sent to the addresses the customer specifies.
  • Google — analytics on the public website (with consent where required).
  • OpenStreetMap, unpkg.com, flagcdn.com — the dashboard loads map tiles, map icons and country flags from these services, so your browser’s IP address becomes visible to them.
  • Authorities — only when the law requires it.

Some of these services may process data outside the European Union. In that case we rely on the safeguards they provide under applicable law.

6. How long we keep data

  • Computer snapshots: 365 days (the latest snapshot of each computer is kept while the computer is in the account).
  • Change history: 730 days.
  • Location records: 30 days.
  • Fleet statistics: 400 days.
  • Other account data (computers, tickets, online history, network discovery results, sign-in log): while the account exists.
  • Website requests: as long as needed to reply; on request we delete them earlier.
  • Backups: up to 14 days.

When a computer is deleted from the account, its data is deleted with it. When an account is deleted on request, we delete its data within 30 days; copies disappear from backups within the following 14 days.

7. How we protect data

  • Connections to the website, the dashboard and the agents are encrypted (HTTPS).
  • Each organization sees only its own data: isolation is enforced in the database itself.
  • Roles: a viewer only looks, a manager adds and changes, only an administrator deletes.
  • Each agent has its own key tied to one computer.
  • Passwords, sign-in codes and links are stored only as hashes. Daily backups.

8. Your rights

Depending on the law that applies to you, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, transfer it to another service, and withdraw consent you have given. Write to privacy@hwkeeper.com from the email address of your account; we will reply within 30 days. You also have the right to complain to the data protection authority of your country.

To delete your account and all its data, write to the same address from the account administrator’s email.

9. Customer responsibilities

A customer who installs the agent must have a legal basis for monitoring those devices and must inform the people who use them, especially about location. Location and network discovery can be turned off in the agent settings. More details are in the Terms of Service.

10. Cookies and browser storage

  • Dashboard: the hw_session cookie (a sign-in flag, 7 days); sign-in tokens and interface settings (language, theme, menu) are kept in the browser’s local storage.
  • Website: the chosen theme, language and analytics consent (hw_theme, hw_lang, hw_consent) are kept in local storage.
  • Google Analytics (website only) sets _ga cookies. In the EU, the UK and Switzerland they are set only after you click “Allow”; elsewhere analytics is on by default and can be turned off via “Cookie settings” at the bottom of the page. Advertising features and Google Signals are turned off.

11. Children

The service is meant for companies and is not intended for people under 16.

12. Changes to this policy

When we change this policy, we update it on this page together with the date at the top. We will notify account administrators of significant changes by email in advance.

13. Contact

privacy@hwkeeper.com