OCS Ping has no user accounts, no advertising, no behavioral profiling and no analytics in this build. We process only the technical data needed to deliver and protect the network tools you request.
1. Controller and service operator
OCS Ping is operated by One Core Spark SRL, a company established in Romania, CUI/CIF 39824776, registered office at Bd. Constantin Brancoveanu nr. 116, Sector 4, Bucharest, Romania (the “Operator”, “we”, “us”). For privacy-rights requests, you may contact the Operator through its publicly available corporate channels or by written correspondence to its registered office.
2. Scope
This Privacy Policy applies to the OCS Ping website, installed Progressive Web App (PWA), and the diagnostic services available through ocsping.com. It is intended to provide transparent information under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), Romanian implementing rules, and, where applicable, comparable rights under other privacy regimes.
3. Personal data and technical data we process
- Connection data: public IP address, request date/time, requested URL, HTTP metadata, browser/user-agent information and security-related request data that may appear in normal web-server or security logs.
- Diagnostic input: domain names, public IP addresses, ports or URLs that you intentionally submit to a tool.
- Rate-limit data: a one-way SHA-256 hash derived from the visitor IP address together with a tool identifier, request counter and short rate-limit window.
- Local device preferences: theme choice and acknowledgement of the browser-storage notice, stored locally in your browser.
- Normal browser cache: your browser may temporarily cache static files such as CSS, JavaScript and images as part of normal web browsing.
4. Why we process data and legal bases
| Purpose | Data | Legal basis / reason |
|---|---|---|
| Provide a diagnostic tool you request | Connection data and submitted target | Necessary to deliver the requested service and, where applicable, performance of a service requested by you; otherwise our legitimate interest in providing the requested functionality. |
| Security, abuse prevention and rate limiting | IP-derived hash, request metadata | Legitimate interests in protecting OCS Ping, its infrastructure and third parties from misuse. |
| Technical operation and troubleshooting | Server logs and error data | Legitimate interests in operating a secure and reliable service. |
| Remember user-selected interface preferences | Local browser storage | Storage necessary to remember a preference or feature explicitly requested by you. |
5. Diagnostic tools and network targets
When you submit a target, OCS Ping uses it only to perform the selected diagnostic operation. Server-side checks may establish a network connection to the public host you entered. OCS Ping is designed to block server-side probing of private and reserved address ranges where appropriate. Submitted targets are not intentionally added to a permanent user history.
6. Speed Test
The Speed Test transfers generated test data between your device and the OCS Ping server to estimate latency, jitter, download and upload throughput. The payload is synthetic test data, not user content, and the application does not intentionally retain it after the test.
7. Retention
OCS Ping keeps application-level data only as long as reasonably necessary for its stated purpose. Rate-limit counters currently operate on short windows (typically 60 seconds). Stale application rate-limit files are eligible for automated deletion after 24 hours and are removed during later housekeeping runs. Web-server, security, system and backup logs may be retained separately according to the infrastructure provider and server configuration. Browser preferences remain on your device until you clear site data or change the relevant setting.
8. Recipients and service providers
Technical data may be processed by hosting, network, security, DNS or infrastructure providers acting as service providers where needed to operate the site. The current OCS Ping build does not intentionally load third-party advertising, behavioral analytics, social tracking scripts or externally hosted fonts. A public host that you explicitly ask OCS Ping to test will receive a connection from OCS Ping infrastructure as part of that diagnostic request.
9. International data transfers
Internet traffic can transit multiple jurisdictions. Where a service provider processes personal data outside the European Economic Area and applicable law requires safeguards, the Operator will rely on an available lawful transfer mechanism. A diagnostic target selected by you may also be located in another country.
10. Your privacy rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction or portability of personal data, and to object to certain processing. Where processing is based on consent, you may withdraw that consent at any time. Because OCS Ping intentionally stores very little application-level data and does not maintain user accounts, in some cases we may not be able to identify data as relating to a particular requester without additional information.
Residents of the EU/EEA may also lodge a complaint with their competent supervisory authority. In Romania, the supervisory authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP). UK residents may have corresponding rights under applicable UK data-protection law. Where the California Consumer Privacy Act (CCPA/CPRA) applies, eligible California residents may have rights including access/knowledge, correction, deletion and non-discrimination. OCS Ping does not sell personal information and does not share personal information for cross-context behavioral advertising in this build.
11. Automated decisions, profiling and children
OCS Ping does not use personal data to make decisions that produce legal or similarly significant effects, and it does not create advertising profiles. The service is a general technical utility and is not specifically directed to children.
12. Security
We use reasonable technical measures appropriate to the service, including HTTPS, input validation, private/reserved address protections for relevant server-side probes, Content Security Policy headers and rate limits. No internet service can guarantee absolute security.
13. Changes to this policy
We may update this policy when the service, law or data-processing practices change. Material changes will be reflected on this page with a revised effective date.
Effective date: September 16, 2026 · Version: 1.5
