Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Data Processing Addendum (DPA)

Itnetic Technologies

Last updated: 21 June 2026


1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer and Petr Chlíbek, trading as Itnetic Technologies (IČO 21210756) ("Itnetic"). It applies where Itnetic processes Personal Data relating to the Customer's End Users in the course of providing the Service.

For such Personal Data:

  • the Customer is the Controller (or a processor acting for its own customers), and
  • Itnetic is the Processor.

This DPA implements Article 28 GDPR. If there is a conflict between this DPA and the Terms regarding the processing of End-User Personal Data, this DPA prevails.

Terms not defined here have the meaning given in the GDPR or the Terms.


2. Subject matter, duration, nature and purpose

  • Subject matter & nature: Itnetic receives, proxies, caches, inspects (including after TLS termination) and filters the Customer's web traffic to provide CDN, DDoS mitigation, WAF, bot management, rate limiting and logging.
  • Purpose: to deliver and secure the Service for the Customer.
  • Duration: for as long as Itnetic provides the Service to the Customer, plus any deletion/return period in Section 11.
  • Details of the processing are in Annex I.

3. Customer instructions

  • Itnetic processes End-User Personal Data only on the Customer's documented instructions, including as set out in this DPA, the Terms, and the Customer's configuration of the Service (e.g. security rules, caching, logging settings).
  • Itnetic will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law (without obligation to provide legal advice).
  • If law requires Itnetic to process otherwise, it will inform the Customer first unless that law prohibits it on important grounds of public interest.

4. Itnetic's obligations as Processor

Itnetic will:

  1. process Personal Data only as instructed (Section 3);
  2. ensure persons authorised to process Personal Data are bound by confidentiality;
  3. implement the technical and organisational security measures in Annex II (Article 32 GDPR);
  4. respect the conditions for engaging sub-processors (Section 6);
  5. assist the Customer, taking into account the nature of processing, by appropriate measures, in responding to Data Subject requests (Section 5);
  6. assist the Customer with security, breach notification, data protection impact assessments, and prior consultation under Articles 32–36 GDPR (Sections 7–8);
  7. at the Customer's choice, delete or return Personal Data after the end of the Service (Section 11);
  8. make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 10).

5. Data subject requests

If Itnetic receives a request from a Data Subject (e.g. access, erasure, objection), it will, where the request relates to Customer data, promptly forward it to the Customer and not respond directly except as legally required or as the Customer instructs. Itnetic will provide reasonable assistance to enable the Customer to fulfil its obligations.


6. Sub-processors

  • The Customer gives general authorisation for Itnetic to engage sub-processors to provide the Service. The current list is in Annex III (and at itnetic.com/legal/subprocessors).
  • Itnetic imposes on each sub-processor data-protection obligations equivalent to those in this DPA, and remains liable for its sub-processors' performance.
  • Itnetic will give the Customer at least 30 days prior notice of adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve it, and if they cannot, the Customer may terminate the affected Service.

7. Personal data breach

Itnetic will notify the Customer without undue delay and, where feasible, within 72 hours after becoming aware of a Personal Data Breach affecting Customer data, with the information reasonably available to help the Customer meet its own notification duties (Articles 33–34 GDPR). Itnetic will take reasonable steps to contain and remediate the breach.


8. Assistance with DPIAs

Taking into account the nature of processing and the information available to it, Itnetic will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35–36 GDPR.


9. International transfers

  • Itnetic will not transfer End-User Personal Data outside the EEA except where a valid transfer mechanism under Chapter V GDPR is in place.
  • Where transfers occur (e.g. to a non-EEA sub-processor in Annex III), the parties agree that the European Commission's Standard Contractual Clauses (SCCs) are incorporated by reference, with Itnetic as data importer/exporter as applicable, supplemented by appropriate measures.
  • Module and details for the SCCs are set out in Annex III.

10. Audits

Itnetic will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, by the Customer or an auditor it mandates. To minimise disruption, the Customer will give reasonable notice, conduct audits during business hours no more than once per year (unless required by an authority or following a breach), and treat findings as confidential. Itnetic may satisfy audit requests by providing existing reports/certifications where available.


11. Deletion or return

On termination of the Service, Itnetic will, at the Customer's choice, delete or return all End-User Personal Data and delete existing copies, unless EU or Member-State law requires storage. Edge logs are deleted on the rolling schedule in the Privacy Policy. Backups are deleted on their ordinary cycle.


12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms, except where mandatory data-protection law provides otherwise.


Annex I — Details of processing

  • Controller: the Customer.
  • Processor: Itnetic Technologies (Petr Chlíbek, IČO 21210756, Czech Republic).
  • Categories of Data Subjects: the Customer's End Users and visitors of the Customer's protected websites/applications.
  • Categories of Personal Data: IP addresses; approximate geolocation; connection/request metadata (timestamps, URLs, headers, status, bytes); device/client signals (user-agent, TLS/HTTP fingerprints); security signals (bot scores, rate-limit and WAF events, challenge tokens); and request/response content traversing the proxy (which may incidentally contain personal data placed there by End Users).
  • Special categories: not intended; may incidentally appear in request content. Not used by Itnetic for any purpose beyond transit/security.
  • Nature & purpose: CDN delivery, DDoS mitigation, WAF, bot management, rate limiting, logging — to provide and secure the Service.
  • Duration: for the term of the Service plus the deletion/return period.

Annex II — Technical and organisational security measures (Article 32)

  • Encryption: TLS for data in transit between End Users, the edge, and origin where configured.
  • Access control: role-based, least-privilege access to systems handling Personal Data; strong authentication for staff; revocation on role change.
  • Network security: segmentation, firewalling, DDoS-resilient architecture, hardening of edge nodes.
  • Logging & monitoring: security logging, anomaly detection, alerting.
  • Confidentiality: staff and sub-processors under confidentiality obligations.
  • Resilience: redundancy across the edge network; absorption of volumetric attacks upstream (OVHcloud).
  • Data minimisation & retention: edge logs kept on a short rolling window; aggregation where possible.
  • Vendor management: written contracts and review of sub-processors.
  • Incident response: documented breach-handling and notification process.

Confirm and expand this list to reflect your actual controls before publishing.


Annex III — Sub-processors

Sub-processorRoleLocationTransfer mechanism
OVHcloud (OVH SAS)Network DDoS absorption, infrastructureEU (France)N/A (EU)
Railway Corp.Application/dashboard & website hostingUSASCCs
Stripe Payments Europe, Ltd.Billing (limited; primarily Customer-account data)EU / USASCCs
Seznam.cz, a.s. (Seznam Profi e-mail)NotificationsCzech Republic (EU)N/A (EU)
Google Ireland Ltd. / Google LLCWebsite analytics (Google Analytics)EU / USASCCs
Functional Software, Inc. (Sentry)Error monitoring & diagnosticsUSASCCs
Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPA

We use essential cookies to run and secure the site. With your consent we also use Google Analytics to understand usage. Cookie Policy