Abuse Policy
Itnetic Technologies
Last updated: 31 July 2026
1. Where to report
abuse@ — chlibekbusiness@gmail.com
One address for all report types. Put the type in the subject line so it routes correctly:
| Subject prefix | Use for |
|---|---|
[CSAM] | Child sexual abuse material — handled first, always |
[PHISHING] | Credential-harvesting or impersonation pages |
[MALWARE] | Malware, ransomware, exploit kits, C2 infrastructure |
[COPYRIGHT] | Claimed copyright or trademark infringement |
[SPAM] | Spam campaigns and their landing pages |
[ATTACK] | Traffic attacking you that appears to come from our network |
[DSA] | Notices under the EU Digital Services Act |
[LEA] | Law-enforcement and authority requests |
Communications may be in Czech or English.
2. What we are, technically
Itnetic is a reverse proxy: we transmit and cache traffic whose content is hosted on our customer's own origin server. Under the EU Digital Services Act we act as a mere conduit (Art. 4) and caching (Art. 5) provider, not a hosting provider, and correspondingly under Czech Act No. 480/2004 Coll.
That has two practical consequences for a reporter:
- We cannot edit or take down the content. Only the operator of the origin can. What we can do is stop proxying it, disable a path, or suspend the domain.
- The fastest fix is usually the host. Where the underlying host is identifiable, reporting to them as well will normally resolve the matter sooner.
We still act, including on our own initiative, where content is manifestly illegal or violates our Acceptable Use Policy.
3. What to include
A report we can act on contains:
- The exact URL(s) — not just the domain.
- What is wrong, in one or two sentences.
- Evidence — a screenshot, response headers, a sandbox report, a hash, the phishing target being impersonated.
- When you observed it (with time zone).
- Your contact details, so we can ask follow-up questions and tell you the outcome.
- For copyright claims, additionally:
- identification of the protected work,
- a statement that you are the rightsholder or authorised to act for them,
- a statement, made in good faith, that the use is not authorised by the rightsholder, the law or a licence,
- your name and an address for service.
Deliberately false or abusive notices are themselves an AUP violation, and we retain the right to pass them to the reported party.
4. Response times
We are a small operation and we say so plainly. These are targets, not contractual commitments:
| Report type | First response | Action target |
|---|---|---|
| CSAM | Immediately on sight | Immediate suspension + report to authorities |
| Active phishing / malware / C2 | 24 hours | 24–48 hours |
| Attack originating from our network | 24 hours | 24–48 hours |
| Copyright / trademark | 3 business days | Forwarded to the customer; escalated if unresolved |
| Spam, other AUP matters | 3 business days | Case by case |
| Authority requests | Without undue delay | Per the legal basis cited |
Acknowledgement does not imply that we agree with the report.
5. What happens after a report
- Triage. We verify the report reproduces and identify the affected domain and customer.
- Customer notice. Except for zero-tolerance categories and emergencies, we notify the customer and give them a chance to fix it.
- Measure. We apply the least disruptive effective measure — see Section 4 of the AUP.
- Statement of reasons. Where we restrict a service and the DSA requires it, the affected customer receives a clear statement of reasons, including the legal or contractual ground and the available redress.
- Outcome. We tell the reporter what we did, unless the law or an ongoing investigation prevents it.
- Appeal. The affected customer may contest any measure at chlibekbusiness@gmail.com. A human reviews every appeal; no restriction is decided by an automated system alone.
6. Law-enforcement and authority requests
- Send requests from an official address with the legal basis stated.
- We disclose data only where we are legally required to, and only what the request covers.
- We notify the affected customer unless the law forbids it or there is an immediate risk to life.
- Note the retention limits: request logs exist for 30 days and cannot be recovered afterwards. A preservation request must arrive inside that window. See the Data Retention Policy.
- Our single point of contact under Articles 11 and 12 DSA is chlibekbusiness@gmail.com.
7. Reporting a security vulnerability
Not this address — see the Security Policy and https://itnetic.com/.well-known/security.txt.