Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Privacy Policy

Itnetic Technologies

Last updated: 1 August 2026 Effective: 21 June 2026


1. Introduction

This Privacy Policy explains how Petr Chlíbek, an entrepreneur (OSVČ) registered in the Czech Republic under Company ID (IČO) 21210756, trading as Itnetic Technologies ("Itnetic", "we", "us", "our"), collects, uses, shares and protects personal data.

We operate a content delivery network (CDN), Layer-7 (application-layer) DDoS mitigation, web application firewall (WAF), bot management and related security and performance services (together, the "Service"), available at itnetic.com, dashboard.itnetic.com and related subdomains.

We take privacy seriously. We comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), Czech Act No. 110/2019 Coll. on the processing of personal data, the EU ePrivacy rules as implemented in the Czech Republic, and — for residents of California — the California Consumer Privacy Act as amended by the CPRA ("CCPA").

If you have any questions, contact us at chlibekbusiness@gmail.com.


2. The two roles we play (please read this first)

Because of how the Service works, we handle personal data in two very different capacities. Understanding which one applies to you is the key to this policy.

CapacityWhen it appliesWho decides why/how data is used
ControllerWhen you visit our websites, create an account, are billed, contact support, or receive our communications.Itnetic decides — see Sections 4–13.
ProcessorWhen traffic from visitors to a customer's website passes through our network (because that customer routed their domain to us).Our customer (the website operator) decides. We act only on their instructions. See Section 3.

If you are an end user / visitor of a website protected by Itnetic and you have questions about your data, your first point of contact is the operator of that website (our customer), because they are the controller. We will support them in responding to you.


3. Data we process on behalf of customers (we act as Processor)

To deliver CDN caching, DDoS mitigation, WAF and bot management, our network sits in front of our customers' websites as a reverse proxy. To do this we terminate TLS and inspect traffic. In the course of this, we process personal data relating to the visitors of our customers' websites, including:

  • Network identifiers — IP address, approximate geolocation derived from IP, ASN/network, connection metadata.
  • Request metadata — timestamp, requested URL/host, HTTP method, status code, bytes transferred, referrer, request and response headers.
  • Device/client signals — user-agent, TLS/HTTP fingerprint, and other signals used to distinguish humans from automated traffic.
  • Security signals & challenge data — bot-detection scores, rate-limit counters, WAF match events, and short-lived cookies or tokens we set on a visitor's browser to remember that a challenge was passed (see Section 9).
  • Request content — because TLS is terminated, request and response bodies pass through our systems and may be inspected by automated security rules (e.g. to detect injection or exploit payloads). We do not store request or response bodies, and we do not mine this content for our own purposes.

Network-wide bot detection. Our bot-detection model is trained across the traffic of the network as a whole, because an attack pattern first seen on one customer's site is exactly what has to be recognised on the next. The training input is a fixed set of derived technical signals about the shape of a request — which headers are present, the shape of the user-agent string, whether our own challenge cookies were echoed back, TLS/HTTP version, the number of path segments and their byte entropy, the number of query parameters, the HTTP method. It contains no IP address, no URL, no header values, no cookie contents and no request body, and nothing in it identifies a visitor, a customer or a site. The resulting model is a set of numeric weights; it is used only to decide whether to show a visitor a security challenge. This is part of providing and securing the Service, and it is recorded as such in our DPA (Annex I).

Our commitments in this role:

  • We process this data solely to provide and secure the Service on the customer's behalf and on their documented instructions.
  • We do not sell it, and we do not use it to build profiles for our own marketing.
  • We do not use it to train general-purpose or third-party AI models, and we do not make it available to any AI vendor.
  • Each customer is responsible, as controller, for having a lawful basis to route their visitors' traffic through us and for informing their visitors.
  • Our obligations in this role are set out in our Data Processing Addendum (DPA), which forms part of our agreement with every customer.

The rest of this policy (Sections 4 onward) describes the data for which we are the controller.


4. Personal data we collect as Controller

4.1 Information you give us

  • Account & identity: name, email address, password (stored hashed), company name, and — for paid/enterprise plans — billing name and address, VAT/tax ID where applicable.
  • Payment information: processed by our payment provider; we receive limited billing details and the last four digits/card type, not full card numbers (see Section 8).
  • Domains & configuration: the domains you protect and your security/CDN settings.
  • Communications: the content of your support tickets, emails, sales enquiries, and survey or feedback responses.

4.2 Information we collect automatically

  • Dashboard usage: log-in events, IP address, browser/device data, pages and features used, and diagnostic logs.
  • Website analytics: pages viewed, referrer, approximate location derived from IP, and browser/device type. This runs on our own self-hosted Umami instance; no third-party analytics provider is involved, and we do not record or replay your sessions. It sets no cookies and stores nothing on your device, so it runs on every visit to our marketing site on the basis of our legitimate interests; you can object at any time (Section 12).
  • Cookies & similar technologies on our own websites — see Section 9.

4.3 Information from third parties

  • Our payment provider (payment status, fraud signals).
  • Anti-fraud and security sources used to protect sign-ups and our own infrastructure.
  • Publicly available business information for B2B/enterprise sales (where lawful).

We do not intentionally collect special-category data (e.g. health, political opinions) as a controller, and we ask you not to send it to us.


5. Why we use your data, and our legal basis

PurposeCategories usedLegal basis (GDPR Art. 6)
Create and administer your account; provide the ServiceAccount, domains, usageContract (Art. 6(1)(b))
Process payments, billing, invoicingAccount, paymentContract; Legal obligation (Art. 6(1)(c)) for tax/accounting
Secure our own platform; prevent fraud and abuse; ensure network & information securityUsage, identifiers, security signalsLegitimate interests (Art. 6(1)(f)) — see Recital 49 GDPR, which recognises network/information security as a legitimate interest
Provide customer supportAccount, communicationsContract; Legitimate interests
Send service/transactional messages (outages, security, billing)AccountContract; Legitimate interests
Send marketing emails and product updatesAccount, marketing preferencesConsent (Art. 6(1)(a)) where required; otherwise Legitimate interests with opt-out
Comply with legal obligations and respond to lawful requestsAny relevantLegal obligation
Maintain accounting recordsAccount, payment, invoicesLegal obligation (Czech Act No. 563/1991 Coll. on Accounting)
Improve and develop the Service (aggregated/analytics)Usage (aggregated)Legitimate interests
Website analytics on our marketing siteUsage, identifiersLegitimate interests (Art. 6(1)(f)) — cookieless, stores nothing on your device; you may object
Establish, exercise or defend legal claimsAny relevantLegitimate interests; Legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (Section 12). Where we rely on consent, you may withdraw it at any time without affecting prior processing.


6. Cookies and similar technologies

See Section 9 for the cookie list. We do not show a consent banner on our websites, because we place nothing on your device that would require consent: our analytics is cookieless and stores nothing, and strictly necessary cookies (including the security/anti-bot cookies described in Section 3) do not require consent because they are essential to deliver a service you requested or to keep it secure.


7. Who we share data with

We share personal data only as needed and under appropriate safeguards:

  • Sub-processors / service providers who host and run the Service on our behalf — see the current list in Annex A. They act on our instructions under written contracts.
  • Payment provider for billing and fraud prevention.
  • Professional advisers (accountants, lawyers, auditors) under confidentiality.
  • Authorities / third parties where required by law, to comply with legal process, to enforce our Terms, or to protect the rights, safety and property of Itnetic, our customers or the public — including responding to abuse, security incidents and lawful requests.
  • In a business transfer (merger, acquisition, reorganisation), subject to this policy.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.


8. Payments

Card payments are handled by our third-party payment provider Stripe Payments Europe, Ltd., a PCI-DSS-compliant processor. We do not store full card numbers on our systems. The provider processes your payment data as an independent/third-party controller under its own privacy policy: https://stripe.com/privacy.


9. Cookie list

NameSet byPurposeCategoryLifetime
__itnetic_clxItnetic (edge)Remember that a visitor passed a bot/DDoS challenge, so they are not challenged again on every pageStrictly necessary30 minutes
__itnetic_ta, __itnetic_tb, __itnetic_tcItnetic (edge)Tell real browsers from automated traffic by which of these a client echoes back. They carry no identifier we look up — only a signature bound to the site and an expiryStrictly necessary7 days
__itnetic_wqItnetic (edge)Waiting-room queue ticket; fixes your place in line. Only set if the site operator has enabled a waiting roomStrictly necessary1 hour
__itnetic_waItnetic (edge)Waiting-room admission pass; slides forward while you browse and releases your slot after the operator's idle timeoutStrictly necessarySliding, per the operator's idle timeout
Session cookie (authjs.session-token, __Secure--prefixed over HTTPS)Itnetic (dashboard)Keep you logged inStrictly necessary7 days
turnstile_verifiedItnetic (dashboard)Remember that you passed the Cloudflare Turnstile bot check when signing inStrictly necessary1 hour
itnetic-lang (browser local storage, not a cookie)Itnetic (website)Remember your EN/CS language choiceFunctionalUntil you clear site data
Umami analytics (script.js from a.itnetic.com)Itnetic (self-hosted)Measure website usage; loaded on every visit to our marketing siteStatisticsSets no cookie and stores nothing on your device

All edge cookies above are Secure and scoped to the site you are visiting. Rate-limit and abuse counters are held on our servers, not in a cookie on your device. Our marketing website sets no cookies at all — only the two local-storage keys listed.

We do not use Google Analytics, advertising cookies or cross-site tracking. Our analytics are self-hosted on our own infrastructure — no third-party analytics provider receives your data. See the Cookie Policy for the full list.


10. International data transfers

We are based in the EU and prefer EU/EEA-based infrastructure. Our primary network/scrubbing and hosting partner OVHcloud operates within the EU. Our application, dashboard, website and self-hosted analytics run on Railway in its EU region, so this data is stored inside the EEA. Railway Corp. is nevertheless a US-incorporated company, and some sub-processors (for example our payment provider and the Turnstile bot check on our sign-in forms) may process data outside the EEA. For those transfers, and for any US-parent access to EU-stored data, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses (SCCs), together with supplementary technical and organisational measures where needed. You can request a copy of the relevant safeguards via chlibekbusiness@gmail.com.


11. How long we keep data

DataRetention
Account dataFor the life of your account. Deleting your account in the dashboard removes it, your domains, your API tokens and their usage counters, your stored origin credentials, your passkeys and your session records immediately; anything remaining is deleted or anonymised within 90 days
Edge security/traffic logs containing IPs (mitigation)Rolling 30 days, then deleted
Attack/event logs and analytics shown in the dashboardRolling 30 days — the per-minute aggregates behind the dashboard charts expire on the same schedule as the raw logs they summarise
Dashboard session records (IP, user-agent)30 days after last activity
Billing & accounting documentsAs required by Czech law — generally 5 years (Act No. 563/1991 Coll.); tax documents up to 10 years where VAT applies
Website analytics (Umami page/event statistics)12 months, then deleted
Support communications24 months
Marketing consents / preferencesUntil you withdraw consent or object, plus a short record of the withdrawal
BackupsRolling, overwritten within 35 days

When acting as processor (Section 3), retention follows the customer's instructions and our DPA. The full schedule, including what each retention period is enforced by, is in our Data Retention Policy.


12. Your rights (GDPR)

If you are in the EEA/UK, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") in certain circumstances.
  • Restrict processing in certain circumstances.
  • Data portability — receive certain data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time, where processing is based on consent.
  • Not be subject to solely automated decisions producing legal or similarly significant effects (see Section 14).

To exercise any right, email chlibekbusiness@gmail.com. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity. Exercising your rights is free unless requests are manifestly unfounded or excessive.

Right to complain: You may lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic — www.uoou.cz — or with the authority in your country of residence.

If you are an end user of a customer's website, please direct rights requests to that website's operator (the controller); we will assist them as their processor.


13. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls and least-privilege, network segmentation, logging and monitoring, and regular review of our providers. The full measures are listed in our Security Policy and in Annex II of the DPA. No system is perfectly secure, but we work hard to protect your data and will notify you and/or the relevant authority of a personal data breach where the law requires — see our Incident Response Policy.

To report a vulnerability, see our Security Policy or https://itnetic.com/.well-known/security.txt.


14. Automated decisions and profiling

Our Service automatically scores and may challenge, rate-limit or block traffic to keep sites online and secure (bot management, DDoS mitigation, WAF). This is essential to the Service.

  • For visitors to customers' sites, this filtering is configured by the customer (controller). Edge decisions are generally about an individual request, not decisions producing legal effects about a person; where a visitor is persistently blocked, the website operator can review and adjust the configuration.
  • We do not use these signals to make decisions that produce legal or similarly significant effects about you under Article 22 GDPR. If you believe an automated decision has significantly affected you, contact us (or the relevant website operator) for human review.

15. California privacy rights (CCPA/CPRA)

This section applies to California residents whose data we handle as a business (controller).

Categories of personal information we have collected in the last 12 months: identifiers (name, email, IP); commercial information (plan, billing); internet/network activity (dashboard usage, security/traffic logs); geolocation (approximate, from IP); and inferences used for security/anti-fraud. Sources and purposes are described in Sections 4–5. We disclose data to the recipients in Section 7.

  • We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding 12 months.
  • We do not knowingly collect personal information from individuals under 16.

Your California rights: to know/access, to delete, to correct, to opt out of sale/sharing (not applicable, as we do neither), and to limit use of sensitive personal information (we do not use sensitive PI for purposes that trigger this right). You also have the right to non-discrimination for exercising these rights.

To exercise these rights, email chlibekbusiness@gmail.com. You may use an authorized agent; we may require verification. We will respond within the timeframes required by the CCPA.


16. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.


17. Changes to this policy

We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, give reasonable notice (e.g. by email or in-dashboard notice). Continued use after the effective date means you accept the updated policy.


18. Contact

  • Controller: Petr Chlíbek (trading as Itnetic Technologies), IČO 21210756, Czech Republic
  • Registered address: Výletní 5258, Chomutov, Czech Republic
  • Privacy enquiries / rights requests: chlibekbusiness@gmail.com
  • Abuse / security reports: chlibekbusiness@gmail.com
  • General / legal: chlibekbusiness@gmail.com

Annex A — Current sub-processors

Sub-processorRoleScopeLocationSafeguard if outside EEA
OVHcloud (OVH SAS)Network DDoS absorption, infrastructure/hosting for the edge and the control planeEnd-user traffic + account dataEU (France)N/A (EU)
Railway Corp.Application/dashboard & website hosting, self-hosted analytics instanceAccount data + website analyticsData stored in the EU region; provider is US-incorporatedSCCs
Stripe Payments Europe, Ltd.Payment processing, fraud preventionAccount & billing data onlyEU / USASCCs
Seznam.cz, a.s. (Seznam Profi e-mail)Sending account, support and alert emailAccount data onlyCzech Republic (EU)N/A (EU)
Cloudflare, Inc.Turnstile bot check on our sign-in and sign-up formsAccount data only (never end-user traffic)USASCCs

Website analytics (Umami) are self-hosted by Itnetic at a.itnetic.com — no analytics vendor is a sub-processor. That instance runs on Railway in its EU region, so analytics data stays within the EEA.

Not sub-processors. Where you switch on an optional integration and give us the destination — for example a Discord webhook for attack alerts, or an alert email address — sending to that destination is a transfer you direct, to a recipient you chose. We do not select those recipients and they are not our sub-processors. Attack alerts contain the hostname and aggregate traffic counts, never visitor IP addresses. IP geolocation uses the DB-IP "lite" databases, which we download and query on our own servers — no visitor data is ever sent to DB-IP.

We update this list as our providers change. The authoritative, current list is published at itnetic.com/legal/subprocessors; material changes are notified to customers under the DPA at least 30 days in advance.

Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Legal

  • Acceptable Use
  • SLA
  • Security
  • Abuse
  • Sub-processors
  • Data Retention
  • Incident Response

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPAIP geolocation by DB-IP (CC BY 4.0)Powered by Startup FastLiftOff launch badgeFeatured on IndieHunt