Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Data Processing Addendum (DPA)

Itnetic Technologies

Last updated: 31 July 2026


1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Petr Chlíbek, trading as Itnetic Technologies (IČO 21210756) ("Itnetic"). It applies where Itnetic processes Personal Data relating to the Customer's End Users in the course of providing the Service.

For such Personal Data:

  • the Customer is the Controller (or a processor acting for its own customers), and
  • Itnetic is the Processor.

This DPA implements Article 28 GDPR. If there is a conflict between this DPA and the Terms regarding the processing of End-User Personal Data, this DPA prevails.

Terms not defined here have the meaning given in the GDPR or the Terms.


2. Subject matter, duration, nature and purpose

  • Subject matter & nature: Itnetic receives, proxies, caches, inspects (including after TLS termination) and filters the Customer's web traffic to provide CDN, DDoS mitigation, WAF, bot management, rate limiting and logging.
  • Purpose: to deliver and secure the Service for the Customer.
  • Duration: for as long as Itnetic provides the Service to the Customer, plus any deletion/return period in Section 11.
  • Details of the processing are in Annex I.

3. Customer instructions

  • Itnetic processes End-User Personal Data only on the Customer's documented instructions, including as set out in this DPA, the Terms, and the Customer's configuration of the Service (e.g. security rules, WAF rules, rate limits, caching, waiting room).
  • Request logging is a fixed part of the Service and is not currently configurable per Customer: every proxied request is logged with the fields in Annex I and deleted after 30 days. A Customer who needs a shorter period or no logging at all should contact us before routing traffic.
  • Itnetic will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law (without obligation to provide legal advice).
  • If law requires Itnetic to process otherwise, it will inform the Customer first unless that law prohibits it on important grounds of public interest.

4. Itnetic's obligations as Processor

Itnetic will:

  1. process Personal Data only as instructed (Section 3);
  2. ensure persons authorised to process Personal Data are bound by confidentiality;
  3. implement the technical and organisational security measures in Annex II (Article 32 GDPR);
  4. respect the conditions for engaging sub-processors (Section 6);
  5. assist the Customer, taking into account the nature of processing, by appropriate measures, in responding to Data Subject requests (Section 5);
  6. assist the Customer with security, breach notification, data protection impact assessments, and prior consultation under Articles 32–36 GDPR (Sections 7–8);
  7. at the Customer's choice, delete or return Personal Data after the end of the Service (Section 11);
  8. make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 10).

5. Data subject requests

If Itnetic receives a request from a Data Subject (e.g. access, erasure, objection), it will, where the request relates to Customer data, promptly forward it to the Customer and not respond directly except as legally required or as the Customer instructs. Itnetic will provide reasonable assistance to enable the Customer to fulfil its obligations.


6. Sub-processors

  • The Customer gives general authorisation for Itnetic to engage sub-processors to provide the Service. The current list is in Annex III (and at itnetic.com/legal/subprocessors).
  • Itnetic imposes on each sub-processor data-protection obligations equivalent to those in this DPA, and remains liable for its sub-processors' performance.
  • Itnetic will give the Customer at least 30 days prior notice of adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve it, and if they cannot, the Customer may terminate the affected Service.
  • Customer-directed recipients are not sub-processors. Where the Customer enables an optional integration and supplies the destination — for example a Discord webhook or an alert email address — Itnetic transmits to that destination on the Customer's instruction, to a recipient the Customer selected. Itnetic does not choose those recipients, does not contract with them on the Customer's behalf, and they do not appear in Annex III. Alert payloads contain the hostname and aggregate traffic counts; they contain no End-User IP addresses or request content. The Customer is responsible for the lawfulness of any onward transfer that its chosen destination entails.

7. Personal data breach

Itnetic will notify the Customer without undue delay and, where feasible, within 72 hours after becoming aware of a Personal Data Breach affecting Customer data, with the information reasonably available to help the Customer meet its own notification duties (Articles 33–34 GDPR). Itnetic will take reasonable steps to contain and remediate the breach.


8. Assistance with DPIAs

Taking into account the nature of processing and the information available to it, Itnetic will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35–36 GDPR.


9. International transfers

  • Itnetic will not transfer End-User Personal Data outside the EEA except where a valid transfer mechanism under Chapter V GDPR is in place.
  • Where transfers occur (e.g. to a non-EEA sub-processor in Annex III), the parties agree that the European Commission's Standard Contractual Clauses (SCCs) are incorporated by reference, with Itnetic as data importer/exporter as applicable, supplemented by appropriate measures.
  • Module and details for the SCCs are set out in Annex III.

10. Audits

Itnetic will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, by the Customer or an auditor it mandates. To minimise disruption, the Customer will give reasonable notice, conduct audits during business hours no more than once per year (unless required by an authority or following a breach), and treat findings as confidential. Itnetic may satisfy audit requests by providing existing reports/certifications where available.


11. Deletion or return

On termination of the Service, Itnetic will, at the Customer's choice, delete or return all End-User Personal Data and delete existing copies, unless EU or Member-State law requires storage. Edge logs are deleted on the rolling 30-day schedule in the Data Retention Policy — no separate request is needed for them to expire. Backups are deleted on their ordinary cycle.

Deleting the account in the dashboard is self-service and immediate: it removes the Customer record, every domain configuration, API tokens and their usage counters, stored origin credentials, passkeys and session records in a single operation.


12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where mandatory data-protection law provides otherwise.


Annex I — Details of processing

  • Controller: the Customer.
  • Processor: Itnetic Technologies (Petr Chlíbek, IČO 21210756, Czech Republic).
  • Categories of Data Subjects: the Customer's End Users and visitors of the Customer's protected websites/applications.
  • Categories of Personal Data: IP addresses; approximate geolocation; connection/request metadata (timestamps, URLs, headers, status, bytes); device/client signals (user-agent, TLS/HTTP fingerprints); security signals (bot scores, rate-limit and WAF events, challenge tokens); and request/response content traversing the proxy (which may incidentally contain personal data placed there by End Users).
  • Special categories: not intended; may incidentally appear in request content. Not used by Itnetic for any purpose beyond transit/security.
  • Nature & purpose: CDN delivery, DDoS mitigation, WAF, bot management, rate limiting, logging — to provide and secure the Service.
  • Retention: request logs and the per-minute aggregates derived from them are deleted 30 days after the request. Request and response bodies are never stored. Query strings are stripped from logged URLs.
  • Network-wide bot detection (instructed processing). The Customer instructs Itnetic to operate bot detection across the network as a whole. For that purpose Itnetic derives, from requests to all protected sites, a fixed 20-value vector of technical request-shape signals — header presence, user-agent shape, challenge-cookie echo class, TLS/HTTP version, path segment count and byte entropy, query-parameter count, HTTP method — and fits a statistical model over them. The vector contains no IP address, no URL, no header values, no cookie contents and no request body, identifies neither a visitor nor a Customer nor a site, and cannot be reversed into a request. The output is a set of numeric weights used solely to decide whether a visitor is shown a security challenge. No Personal Data leaves this purpose, and nothing derived from one Customer's traffic is disclosed to another. Itnetic does not use End-User Personal Data to train general-purpose or third-party AI models.
  • Duration: for the term of the Service plus the deletion/return period.

Annex II — Technical and organisational security measures (Article 32)

  • Encryption in transit: TLS between End Users and the edge, and between the edge and origin where the origin supports it. Requests to private object-storage origins are signed per request (AWS SigV4).
  • Encryption at rest: provider-level disk encryption at our managed hosting and database providers. Customer account passwords are stored hashed, never in plaintext. Stored object-storage credentials are additionally encrypted with AES-GCM under a key held outside the database.
  • Access control: Itnetic is operated by a single operator; there is no shared production credential and no standing third-party access. Provider and infrastructure accounts are protected with multi-factor authentication. Dashboard accounts support passkeys, and edge nodes authenticate to the control plane with short-lived (15-minute) tokens rather than long-lived secrets.
  • Network security: the edge is segmented from the control plane; abusive sources are dropped in the kernel firewall; connection admission limits protect against handshake floods; edge nodes are hardened and run as containers with a minimal image.
  • Logging & monitoring: security logging of requests and mitigation decisions, automated anomaly detection on traffic baselines, and alerting on attack events.
  • Confidentiality: the operator and all sub-processors are bound by confidentiality obligations.
  • Resilience: redundancy across multiple points of presence; volumetric attacks absorbed upstream by OVHcloud; deployments performed with an overlapping blue/green rollout so a release does not drop live connections.
  • Data minimisation & retention: request and response bodies are never stored; query strings are stripped from logged URLs. Edge logs holding IP addresses are kept on a short rolling window (30 days) enforced by a database TTL rather than by a manual clean-up job, so expiry cannot be forgotten. The per-minute aggregates derived from those logs expire on the same schedule. Analytics are self-hosted and consent-gated.
  • Vulnerability disclosure: a published reporting channel (/.well-known/security.txt and the Security Policy) with a safe-harbour commitment for good-faith researchers.
  • Vendor management: written contracts with every sub-processor, and review before adding one.
  • Incident response: we investigate suspected personal-data breaches without undue delay and, where the law requires, notify the competent supervisory authority within 72 hours of becoming aware, and affected individuals or the Customer where the breach is likely to result in a high risk. As Processor, we notify the Customer without undue delay after becoming aware of a breach affecting their data.

Annex III — Sub-processors

This annex is kept identical to Annex A of the Privacy Policy and to the published list at itnetic.com/legal/subprocessors.

Sub-processorRoleTouches End-User Personal Data?LocationTransfer mechanism
OVHcloud (OVH SAS)Network DDoS absorption, infrastructure for the edge and control planeYesEU (France)N/A (EU)
Railway Corp.Application/dashboard & website hostingNo — Customer-account data onlyData stored in the EU region; provider is US-incorporatedSCCs
Stripe Payments Europe, Ltd.BillingNo — Customer-account data onlyEU / USASCCs
Seznam.cz, a.s. (Seznam Profi e-mail)Account, support and alert emailNo — Customer-account data onlyCzech Republic (EU)N/A (EU)
Cloudflare, Inc.Turnstile bot check on Itnetic's own sign-in and sign-up formsNo — Customer-account data onlyUSASCCs

SCC details (Section 9). Where a sub-processor above is outside the EEA, the Commission Implementing Decision (EU) 2021/914 Standard Contractual Clauses apply as follows: Module Three (processor to sub-processor), with Itnetic as data exporter and the sub-processor as data importer; docking clause on; option 2 general written authorisation for onward sub-processors with 30 days' notice; governing law and forum: Czech Republic. Between the Customer and Itnetic, where the Customer is established outside the EEA, Module Two applies with the Customer as exporter and Itnetic as importer. Annexes I–III of the SCCs are populated by Annexes I–III of this DPA.

Only OVHcloud processes End-User Personal Data, and it does so inside the EU. IP geolocation uses the DB-IP "lite" databases, downloaded and queried on Itnetic's own servers — no End-User data is sent to DB-IP, which is therefore not a sub-processor.

Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Legal

  • Acceptable Use
  • SLA
  • Security
  • Abuse
  • Sub-processors
  • Data Retention
  • Incident Response

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPAIP geolocation by DB-IP (CC BY 4.0)Powered by Startup FastLiftOff launch badgeFeatured on IndieHunt