I get warning messages like "zone example.com/IN: refresh: failure trying primary 126.96.36.199#53: timed out".
Check that you can make UDP queries from the secondary to the primary:
dig +norec example.com soa @188.8.131.52
You could be generating queries faster than the secondary can cope with. One simple strategy would be to lower the serial query rate:
serial-query-rate 5; // default 20
DNS system administrators who would like to learn more about tuning their primary and secondary servers more effectively may be interested in reading: Tuning your BIND configuration effectively for zone transfers (particularly with many frequently-updated zones).