Legal

Privacy Policy

Clear information about the limited personal data processed when you use OCS Ping.

Privacy at a glance

OCS Ping has no user accounts, no advertising, no behavioral profiling and no analytics in this build. We process only the technical data needed to deliver and protect the network tools you request.

1. Controller and service operator

OCS Ping is operated by One Core Spark SRL, a company established in Romania, CUI/CIF 39824776, registered office at Bd. Constantin Brancoveanu nr. 116, Sector 4, Bucharest, Romania (the “Operator”, “we”, “us”). For privacy-rights requests, you may contact the Operator through its publicly available corporate channels or by written correspondence to its registered office.

2. Scope

This Privacy Policy applies to the OCS Ping website, installed Progressive Web App (PWA), and the diagnostic services available through ocsping.com. It is intended to provide transparent information under applicable privacy laws, including the EU General Data Protection Regulation (GDPR), Romanian implementing rules, and, where applicable, comparable rights under other privacy regimes.

3. Personal data and technical data we process

  • Connection data: public IP address, request date/time, requested URL, HTTP metadata, browser/user-agent information and security-related request data that may appear in normal web-server or security logs.
  • Diagnostic input: domain names, public IP addresses, ports or URLs that you intentionally submit to a tool.
  • Rate-limit data: a one-way SHA-256 hash derived from the visitor IP address together with a tool identifier, request counter and short rate-limit window.
  • Local device preferences: theme choice and acknowledgement of the browser-storage notice, stored locally in your browser.
  • Normal browser cache: your browser may temporarily cache static files such as CSS, JavaScript and images as part of normal web browsing.

4. Why we process data and legal bases

PurposeDataLegal basis / reason
Provide a diagnostic tool you requestConnection data and submitted targetNecessary to deliver the requested service and, where applicable, performance of a service requested by you; otherwise our legitimate interest in providing the requested functionality.
Security, abuse prevention and rate limitingIP-derived hash, request metadataLegitimate interests in protecting OCS Ping, its infrastructure and third parties from misuse.
Technical operation and troubleshootingServer logs and error dataLegitimate interests in operating a secure and reliable service.
Remember user-selected interface preferencesLocal browser storageStorage necessary to remember a preference or feature explicitly requested by you.

5. Diagnostic tools and network targets

When you submit a target, OCS Ping uses it only to perform the selected diagnostic operation. Server-side checks may establish a network connection to the public host you entered. OCS Ping is designed to block server-side probing of private and reserved address ranges where appropriate. Submitted targets are not intentionally added to a permanent user history.

6. Speed Test

The Speed Test transfers generated test data between your device and the OCS Ping server to estimate latency, jitter, download and upload throughput. The payload is synthetic test data, not user content, and the application does not intentionally retain it after the test.

7. Retention

OCS Ping keeps application-level data only as long as reasonably necessary for its stated purpose. Rate-limit counters currently operate on short windows (typically 60 seconds). Stale application rate-limit files are eligible for automated deletion after 24 hours and are removed during later housekeeping runs. Web-server, security, system and backup logs may be retained separately according to the infrastructure provider and server configuration. Browser preferences remain on your device until you clear site data or change the relevant setting.

8. Recipients and service providers

Technical data may be processed by hosting, network, security, DNS or infrastructure providers acting as service providers where needed to operate the site. The current OCS Ping build does not intentionally load third-party advertising, behavioral analytics, social tracking scripts or externally hosted fonts. A public host that you explicitly ask OCS Ping to test will receive a connection from OCS Ping infrastructure as part of that diagnostic request.

9. International data transfers

Internet traffic can transit multiple jurisdictions. Where a service provider processes personal data outside the European Economic Area and applicable law requires safeguards, the Operator will rely on an available lawful transfer mechanism. A diagnostic target selected by you may also be located in another country.

10. Your privacy rights

Depending on your location and applicable law, you may have rights to request access, correction, deletion, restriction or portability of personal data, and to object to certain processing. Where processing is based on consent, you may withdraw that consent at any time. Because OCS Ping intentionally stores very little application-level data and does not maintain user accounts, in some cases we may not be able to identify data as relating to a particular requester without additional information.

Residents of the EU/EEA may also lodge a complaint with their competent supervisory authority. In Romania, the supervisory authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP). UK residents may have corresponding rights under applicable UK data-protection law. Where the California Consumer Privacy Act (CCPA/CPRA) applies, eligible California residents may have rights including access/knowledge, correction, deletion and non-discrimination. OCS Ping does not sell personal information and does not share personal information for cross-context behavioral advertising in this build.

11. Automated decisions, profiling and children

OCS Ping does not use personal data to make decisions that produce legal or similarly significant effects, and it does not create advertising profiles. The service is a general technical utility and is not specifically directed to children.

12. Security

We use reasonable technical measures appropriate to the service, including HTTPS, input validation, private/reserved address protections for relevant server-side probes, Content Security Policy headers and rate limits. No internet service can guarantee absolute security.

13. Changes to this policy

We may update this policy when the service, law or data-processing practices change. Material changes will be reflected on this page with a revised effective date.

Effective date: September 16, 2026 · Version: 1.5