European operation
Itnetic is operated from the Czech Republic by a named individual, under EU law, with the DPA, the sub-processor list, the retention policy and the incident-response policy readable in full before you sign up. Including the parts that are inconvenient for us.
For a lot of European organisations the deciding factor is not a feature. It is a question from a compliance reviewer, a client’s vendor form, or an insurer: who is the controller, where is the data processed, who are the sub-processors, and can we read the DPA without opening a sales conversation?
Itnetic is operated by Petr Chlíbek, IČO 21210756, in the Czech Republic. The controller for your customer relationship and the processor for your visitors’ traffic are both an EU-established operator, under EU law, with a supervisory authority you can actually reach.
What follows is deliberately specific, because "GDPR compliant" as a phrase means nothing. Two of our three points of presence are outside the EU, and our own sign-in page uses a third-party bot check. Both facts are published, and both are on this page.
Jurisdiction and processing
Itnetic facts come from our published sub-processor list. The right column states publicly documented availability and jurisdiction only.
| Question a reviewer asks | Itnetic | Cloudflare |
|---|---|---|
| Operator and data controller | Czech Republic (EU) — Petr Chlíbek, IČO 21210756 | United States |
| Data Processing Addendum | Published in full, EN and CS, before signup | Published |
| Sub-processor list | Published, with role, location and transfer mechanism per entry | Published |
| Notice before a new sub-processor | 30 days, contractual | Per their DPA |
| Where request logs and analytics are stored | EU only (control-plane database) | Plan-dependent (Logpush destination is yours) |
| Where visitor traffic is processed | Frankfurt (EU), Beauharnois (Canada, adequacy) or Singapore (SCCs) | Global anycast network |
| EU point of presence | Frankfurt | Many |
| Retention periods | Published, and enforced by database TTL indexes | Published |
| Right-to-erasure path | Self-serve account deletion covering every customer-scoped record | Per their privacy policy |
| Incident-response policy | Published in full | Published |
| Security policy | Published in full | Published, plus formal certifications |
| ISO 27001 / SOC 2 certification | Not certified — policies published instead | Certified |
| Cross-tenant signal sharing | Disclosed: ML weights and JA4 fingerprint reputation | Per their documentation |
| Contract language and invoicing | English or Czech, EUR | Per their terms |
| Who answers a data-protection question | The operator, by email | Support tier depends on plan |
Compiled from Cloudflare’s own public documentation and plan pages on 10 September 2026, and describing feature availability by plan at that date. Plan contents change — check Cloudflare’s current pages before making a decision. Cloudflare is a trademark of Cloudflare, Inc.; Itnetic Technologies is not affiliated with, endorsed by or sponsored by Cloudflare, Inc. Prices named on this page are Itnetic’s own; this page makes no claim about any other provider’s pricing, performance, capacity or availability.
Three sub-processors touch end-user traffic and all three are named. Traffic served from Frankfurt is processed inside the EU by Datalix, in Germany. Traffic served from Beauharnois is processed in Canada under the European Commission’s adequacy decision. Traffic served from Singapore is processed there under Standard Contractual Clauses. The upstream volumetric layer in front of Frankfurt and Beauharnois is operated by a provider established in Australia, also under SCCs.
A vendor page that only lists the flattering half of the truth is worth nothing to someone doing real diligence. So: two of our three points of presence are outside the EU, which is a transfer you are accepting when your visitors are served from them. Our own sign-in and sign-up forms use Cloudflare Turnstile as a bot check — customer-account data only, never a protected site’s visitors, and disclosed on our sub-processor page. And we hold no ISO 27001 or SOC 2 certificate; what we offer instead is a published security policy and a published incident-response policy you can read line by line.
Any retention policy can state a number. The question is what happens if someone forgets to run the clean-up job. Every retention period Itnetic publishes is enforced by a TTL index in the database, which means expiry is a property of the record rather than a task on someone’s list. That is the specific thing that lets the retention policy claim expiry cannot be forgotten, and it is why the policy and the schema have to be changed together.
Account deletion is self-serve and is the GDPR Article 17 path. It is written to cover every collection keyed to a customer — domains, logs, rollups, tokens, credentials, sessions, billing references — and adding a new customer-scoped data store without adding it there is treated as a bug, because the alternative is personal data quietly surviving an erasure request. Requests by email are answered by the operator, not a ticket queue.
Two mechanisms learn from traffic across all tenants, and both are disclosed in the DPA and privacy policy rather than buried. The machine-learning scorer trains on weakly labelled request features from across the fleet and ships weights — not rows — to the edge. The JA4 reputation layer scores TLS fingerprints seen as automated on at least three distinct hostnames, and publishes a fingerprint-level score used across customers. A fingerprint describes a client population, not a person, and the enforcement is challenge-only: never a block, never a kernel drop. We narrowed our own earlier wording specifically because this layer genuinely does share a score across tenants.
Invoicing is in EUR with EU VAT handling; contracts and every legal document exist in English and Czech, and both versions are maintained together rather than one being a courtesy translation. Setup never touches your nameservers, so your zone stays with whichever EU DNS provider you already chose. And the person who answers a data-protection question is the person who operates the service.
FAQ
Yes — Itnetic is operated from the Czech Republic by an EU-established operator, with an EU data controller, request logs stored in the EU only, and a published sub-processor list naming every party that touches traffic, with its location and transfer mechanism.
No, and it would be dishonest to claim it. Request logs and analytics are stored in the EU only. Visitor traffic is processed at whichever point of presence serves them: Frankfurt (EU), Beauharnois (Canada, under the adequacy decision) or Singapore (under SCCs). If you need EU-only processing end to end, tell us and we will say plainly whether we can do it for your traffic.
Yes, published in full in English and Czech and readable before you sign up — not a document you request from a salesperson. It includes the sub-processor annex, the transfer mechanisms and the 30-day notice commitment.
No. We publish a security policy, an incident-response policy and a retention policy in full instead, and we say this plainly rather than implying otherwise. If a certificate is a hard procurement requirement, that is a real reason to buy elsewhere.
The exact periods are in the published retention policy, and every one of them is enforced by a database TTL index rather than a scheduled clean-up — the record expires by construction.
Two security layers learn across tenants and both are disclosed: machine-learning model weights trained on fleet-wide request features, and a JA4 TLS fingerprint reputation score. Neither shares one customer’s request rows with another, and fingerprint reputation is challenge-only — never a block.
Yes — EUR invoicing with EU VAT handling, and every legal document in English and Czech.
The operator directly, by email. There is no ticket queue in front of it and no plan tier that changes the answer.
Same provider, different question — each page compares what matters to one specific use case.
Same method, different provider — feature availability by plan, with the date it was checked.
Two DNS records, no nameserver change, free plan with no card.