European operation

A European Cloudflare alternative, with the paperwork published

Itnetic is operated from the Czech Republic by a named individual, under EU law, with the DPA, the sub-processor list, the retention policy and the incident-response policy readable in full before you sign up. Including the parts that are inconvenient for us.

For a lot of European organisations the deciding factor is not a feature. It is a question from a compliance reviewer, a client’s vendor form, or an insurer: who is the controller, where is the data processed, who are the sub-processors, and can we read the DPA without opening a sales conversation?

Itnetic is operated by Petr Chlíbek, IČO 21210756, in the Czech Republic. The controller for your customer relationship and the processor for your visitors’ traffic are both an EU-established operator, under EU law, with a supervisory authority you can actually reach.

What follows is deliberately specific, because "GDPR compliant" as a phrase means nothing. Two of our three points of presence are outside the EU, and our own sign-in page uses a third-party bot check. Both facts are published, and both are on this page.

Jurisdiction and processing

Where things actually are

Itnetic facts come from our published sub-processor list. The right column states publicly documented availability and jurisdiction only.

Question a reviewer asksItneticCloudflare
Operator and data controllerCzech Republic (EU) — Petr Chlíbek, IČO 21210756United States
Data Processing AddendumPublished in full, EN and CS, before signupPublished
Sub-processor listPublished, with role, location and transfer mechanism per entryPublished
Notice before a new sub-processor30 days, contractualPer their DPA
Where request logs and analytics are storedEU only (control-plane database)Plan-dependent (Logpush destination is yours)
Where visitor traffic is processedFrankfurt (EU), Beauharnois (Canada, adequacy) or Singapore (SCCs)Global anycast network
EU point of presenceFrankfurtMany
Retention periodsPublished, and enforced by database TTL indexesPublished
Right-to-erasure pathSelf-serve account deletion covering every customer-scoped recordPer their privacy policy
Incident-response policyPublished in fullPublished
Security policyPublished in fullPublished, plus formal certifications
ISO 27001 / SOC 2 certificationNot certified — policies published insteadCertified
Cross-tenant signal sharingDisclosed: ML weights and JA4 fingerprint reputationPer their documentation
Contract language and invoicingEnglish or Czech, EURPer their terms
Who answers a data-protection questionThe operator, by emailSupport tier depends on plan

About this comparison

Compiled from Cloudflare’s own public documentation and plan pages on 10 September 2026, and describing feature availability by plan at that date. Plan contents change — check Cloudflare’s current pages before making a decision. Cloudflare is a trademark of Cloudflare, Inc.; Itnetic Technologies is not affiliated with, endorsed by or sponsored by Cloudflare, Inc. Prices named on this page are Itnetic’s own; this page makes no claim about any other provider’s pricing, performance, capacity or availability.

Where your visitors’ data is actually processed

Three sub-processors touch end-user traffic and all three are named. Traffic served from Frankfurt is processed inside the EU by Datalix, in Germany. Traffic served from Beauharnois is processed in Canada under the European Commission’s adequacy decision. Traffic served from Singapore is processed there under Standard Contractual Clauses. The upstream volumetric layer in front of Frankfurt and Beauharnois is operated by a provider established in Australia, also under SCCs.

  • Request logs and analytics rollups are stored in the EU only, in the control-plane database.
  • Customer account, domain and configuration data is stored in an EU region.
  • IP geolocation runs on our own servers from a database we download — no visitor data is ever sent to a geolocation vendor.

The inconvenient facts, stated on our own page

A vendor page that only lists the flattering half of the truth is worth nothing to someone doing real diligence. So: two of our three points of presence are outside the EU, which is a transfer you are accepting when your visitors are served from them. Our own sign-in and sign-up forms use Cloudflare Turnstile as a bot check — customer-account data only, never a protected site’s visitors, and disclosed on our sub-processor page. And we hold no ISO 27001 or SOC 2 certificate; what we offer instead is a published security policy and a published incident-response policy you can read line by line.

Retention enforced by the database, not by a promise

Any retention policy can state a number. The question is what happens if someone forgets to run the clean-up job. Every retention period Itnetic publishes is enforced by a TTL index in the database, which means expiry is a property of the record rather than a task on someone’s list. That is the specific thing that lets the retention policy claim expiry cannot be forgotten, and it is why the policy and the schema have to be changed together.

Erasure that actually reaches everything

Account deletion is self-serve and is the GDPR Article 17 path. It is written to cover every collection keyed to a customer — domains, logs, rollups, tokens, credentials, sessions, billing references — and adding a new customer-scoped data store without adding it there is treated as a bug, because the alternative is personal data quietly surviving an erasure request. Requests by email are answered by the operator, not a ticket queue.

What we share across customers, and why we say so

Two mechanisms learn from traffic across all tenants, and both are disclosed in the DPA and privacy policy rather than buried. The machine-learning scorer trains on weakly labelled request features from across the fleet and ships weights — not rows — to the edge. The JA4 reputation layer scores TLS fingerprints seen as automated on at least three distinct hostnames, and publishes a fingerprint-level score used across customers. A fingerprint describes a client population, not a person, and the enforcement is challenge-only: never a block, never a kernel drop. We narrowed our own earlier wording specifically because this layer genuinely does share a score across tenants.

Practical things for an EU buyer

Invoicing is in EUR with EU VAT handling; contracts and every legal document exist in English and Czech, and both versions are maintained together rather than one being a courtesy translation. Setup never touches your nameservers, so your zone stays with whichever EU DNS provider you already chose. And the person who answers a data-protection question is the person who operates the service.

  • Operator: Petr Chlíbek, IČO 21210756, Czech Republic.
  • Eleven legal documents published in full, in both languages, before signup.
  • Terms acceptance is versioned and recorded, so you can prove what you agreed to and when.

FAQ

Cloudflare alternatives: common questions

Is there a European alternative to Cloudflare?

Yes — Itnetic is operated from the Czech Republic by an EU-established operator, with an EU data controller, request logs stored in the EU only, and a published sub-processor list naming every party that touches traffic, with its location and transfer mechanism.

Is all my data processed inside the EU?

No, and it would be dishonest to claim it. Request logs and analytics are stored in the EU only. Visitor traffic is processed at whichever point of presence serves them: Frankfurt (EU), Beauharnois (Canada, under the adequacy decision) or Singapore (under SCCs). If you need EU-only processing end to end, tell us and we will say plainly whether we can do it for your traffic.

Do you offer a DPA?

Yes, published in full in English and Czech and readable before you sign up — not a document you request from a salesperson. It includes the sub-processor annex, the transfer mechanisms and the 30-day notice commitment.

Are you ISO 27001 or SOC 2 certified?

No. We publish a security policy, an incident-response policy and a retention policy in full instead, and we say this plainly rather than implying otherwise. If a certificate is a hard procurement requirement, that is a real reason to buy elsewhere.

How long do you keep visitor request logs?

The exact periods are in the published retention policy, and every one of them is enforced by a database TTL index rather than a scheduled clean-up — the record expires by construction.

Do you share data between customers?

Two security layers learn across tenants and both are disclosed: machine-learning model weights trained on fleet-wide request features, and a JA4 TLS fingerprint reputation score. Neither shares one customer’s request rows with another, and fingerprint reputation is challenge-only — never a block.

Can I get an invoice for my accounting in the EU?

Yes — EUR invoicing with EU VAT handling, and every legal document in English and Czech.

Who do I contact about a data-protection question?

The operator directly, by email. There is no ticket queue in front of it and no plan tier that changes the answer.

Other comparisons

Same method, different provider — feature availability by plan, with the date it was checked.

Try it on one domain.

Two DNS records, no nameserver change, free plan with no card.