Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Privacy Policy

Itnetic Technologies

Last updated: 21 June 2026 Effective: 21 June 2026


1. Introduction

This Privacy Policy explains how Petr Chlíbek, an entrepreneur (OSVČ) registered in the Czech Republic under Company ID (IČO) 21210756, trading as Itnetic Technologies ("Itnetic", "we", "us", "our"), collects, uses, shares and protects personal data.

We operate a content delivery network (CDN), Layer-7 (application-layer) DDoS mitigation, web application firewall (WAF), bot management and related security and performance services (together, the "Service"), available at itnetic.com, dashboard.itnetic.com and related subdomains.

We take privacy seriously. We comply with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), Czech Act No. 110/2019 Coll. on the processing of personal data, the EU ePrivacy rules as implemented in the Czech Republic, and — for residents of California — the California Consumer Privacy Act as amended by the CPRA ("CCPA").

If you have any questions, contact us at chlibekbusiness@gmail.com.


2. The two roles we play (please read this first)

Because of how the Service works, we handle personal data in two very different capacities. Understanding which one applies to you is the key to this policy.

CapacityWhen it appliesWho decides why/how data is used
ControllerWhen you visit our websites, create an account, are billed, contact support, or receive our communications.Itnetic decides — see Sections 4–13.
ProcessorWhen traffic from visitors to a customer's website passes through our network (because that customer routed their domain to us).Our customer (the website operator) decides. We act only on their instructions. See Section 3.

If you are an end user / visitor of a website protected by Itnetic and you have questions about your data, your first point of contact is the operator of that website (our customer), because they are the controller. We will support them in responding to you.


3. Data we process on behalf of customers (we act as Processor)

To deliver CDN caching, DDoS mitigation, WAF and bot management, our network sits in front of our customers' websites as a reverse proxy. To do this we terminate TLS and inspect traffic. In the course of this, we process personal data relating to the visitors of our customers' websites, including:

  • Network identifiers — IP address, approximate geolocation derived from IP, ASN/network, connection metadata.
  • Request metadata — timestamp, requested URL/host, HTTP method, status code, bytes transferred, referrer, request and response headers.
  • Device/client signals — user-agent, TLS/HTTP fingerprint, and other signals used to distinguish humans from automated traffic.
  • Security signals & challenge data — bot-detection scores, rate-limit counters, WAF match events, and short-lived cookies or tokens we set on a visitor's browser to remember that a challenge was passed (see Section 9).
  • Request content — because TLS is terminated, request and response bodies pass through our systems and may be inspected by automated security rules (e.g. to detect injection or exploit payloads). We do not mine this content for our own purposes.

Our commitments in this role:

  • We process this data solely to provide and secure the Service on the customer's behalf and on their documented instructions.
  • We do not sell it, and we do not use it to build profiles for our own marketing.
  • Each customer is responsible, as controller, for having a lawful basis to route their visitors' traffic through us and for informing their visitors.
  • Our obligations in this role are set out in our Data Processing Addendum (DPA) (see legal/data-processing-addendum.md), which forms part of our agreement with every customer.

The rest of this policy (Sections 4 onward) describes the data for which we are the controller.


4. Personal data we collect as Controller

4.1 Information you give us

  • Account & identity: name, email address, password (stored hashed), company name, and — for paid/enterprise plans — billing name and address, VAT/tax ID where applicable.
  • Payment information: processed by our payment provider; we receive limited billing details and the last four digits/card type, not full card numbers (see Section 8).
  • Domains & configuration: the domains you protect and your security/CDN settings.
  • Communications: the content of your support tickets, emails, sales enquiries, and survey or feedback responses.

4.2 Information we collect automatically

  • Dashboard usage: log-in events, IP address, browser/device data, pages and features used, and diagnostic logs.
  • Cookies & similar technologies on our own websites — see Section 9.

4.3 Information from third parties

  • Our payment provider (payment status, fraud signals).
  • Anti-fraud and security sources used to protect sign-ups and our own infrastructure.
  • Publicly available business information for B2B/enterprise sales (where lawful).

We do not intentionally collect special-category data (e.g. health, political opinions) as a controller, and we ask you not to send it to us.


5. Why we use your data, and our legal basis

PurposeCategories usedLegal basis (GDPR Art. 6)
Create and administer your account; provide the ServiceAccount, domains, usageContract (Art. 6(1)(b))
Process payments, billing, invoicingAccount, paymentContract; Legal obligation (Art. 6(1)(c)) for tax/accounting
Secure our own platform; prevent fraud and abuse; ensure network & information securityUsage, identifiers, security signalsLegitimate interests (Art. 6(1)(f)) — see Recital 49 GDPR, which recognises network/information security as a legitimate interest
Provide customer supportAccount, communicationsContract; Legitimate interests
Send service/transactional messages (outages, security, billing)AccountContract; Legitimate interests
Send marketing emails and product updatesAccount, marketing preferencesConsent (Art. 6(1)(a)) where required; otherwise Legitimate interests with opt-out
Comply with legal obligations and respond to lawful requestsAny relevantLegal obligation
Maintain accounting recordsAccount, payment, invoicesLegal obligation (Czech Act No. 563/1991 Coll. on Accounting)
Improve and develop the Service (aggregated/analytics)Usage (aggregated)Legitimate interests
Establish, exercise or defend legal claimsAny relevantLegitimate interests; Legal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (Section 12). Where we rely on consent, you may withdraw it at any time without affecting prior processing.


6. Cookies and similar technologies

See Section 9 for the cookie list. Where required by EU/Czech ePrivacy law, we ask for your consent to non-essential cookies through a banner on our websites. Strictly necessary cookies (including the security/anti-bot cookies described in Section 3) do not require consent because they are essential to deliver a service you requested or to keep it secure.


7. Who we share data with

We share personal data only as needed and under appropriate safeguards:

  • Sub-processors / service providers who host and run the Service on our behalf — see the current list in Annex A. They act on our instructions under written contracts.
  • Payment provider for billing and fraud prevention.
  • Professional advisers (accountants, lawyers, auditors) under confidentiality.
  • Authorities / third parties where required by law, to comply with legal process, to enforce our Terms, or to protect the rights, safety and property of Itnetic, our customers or the public — including responding to abuse, security incidents and lawful requests.
  • In a business transfer (merger, acquisition, reorganisation), subject to this policy.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.


8. Payments

Card payments are handled by our third-party payment provider Stripe Payments Europe, Ltd., a PCI-DSS-compliant processor. We do not store full card numbers on our systems. The provider processes your payment data as an independent/third-party controller under its own privacy policy: https://stripe.com/privacy.


9. Cookie list

Cookie / tokenSet byPurposeTypeTypical lifetime
Security challenge token (e.g. clearance)Itnetic (edge)Remember that a visitor passed a bot/DDoS challenge so they are not re-challengedStrictly necessarySession – 30 minutes
Rate-limit / abuse countersItnetic (edge)Detect and throttle abusive trafficStrictly necessaryShort-lived
Session / auth cookieItnetic (dashboard)Keep you logged in to the dashboardStrictly necessarySession
Language preference (lang)Itnetic (website)Remember EN/CS language choiceFunctional12 months
Google Analytics (_ga, _gid)GoogleMeasure website usage (set only with your consent)StatisticsUp to 2 years

Confirm this table against what your edge and dashboard actually set before publishing.


10. International data transfers

We are based in the EU and prefer EU/EEA-based infrastructure. Our primary network/scrubbing and hosting partner OVHcloud operates within the EU. Where a sub-processor (for example, application hosting on Railway) processes data outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses (SCCs), together with supplementary technical and organisational measures where needed. You can request a copy of the relevant safeguards via chlibekbusiness@gmail.com.


11. How long we keep data

DataRetention
Account dataFor the life of your account, then deleted or anonymised within 90 days of closure, unless a longer period is legally required
Edge security/traffic logs containing IPs (mitigation)Rolling 30 days, then deleted or aggregated
Attack/event logs shown in the dashboardUp to 12 months (may vary by plan)
Billing & accounting documentsAs required by Czech law — generally 5 years (Act No. 563/1991 Coll.); tax documents up to 10 years where VAT applies
Support communications24 months
Marketing consents / preferencesUntil you withdraw consent or object, plus a short record of the withdrawal
BackupsRolling, overwritten within 35 days

When acting as processor (Section 3), retention follows the customer's instructions and our DPA.


12. Your rights (GDPR)

If you are in the EEA/UK, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") in certain circumstances.
  • Restrict processing in certain circumstances.
  • Data portability — receive certain data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent at any time, where processing is based on consent.
  • Not be subject to solely automated decisions producing legal or similarly significant effects (see Section 14).

To exercise any right, email chlibekbusiness@gmail.com. We will respond within one month (extendable by two further months for complex requests). We may need to verify your identity. Exercising your rights is free unless requests are manifestly unfounded or excessive.

Right to complain: You may lodge a complaint with the Czech supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic — www.uoou.cz — or with the authority in your country of residence.

If you are an end user of a customer's website, please direct rights requests to that website's operator (the controller); we will assist them as their processor.


13. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls and least-privilege, network segmentation, logging and monitoring, and regular review of our providers. No system is perfectly secure, but we work hard to protect your data and will notify you and/or the relevant authority of a personal data breach where the law requires.


14. Automated decisions and profiling

Our Service automatically scores and may challenge, rate-limit or block traffic to keep sites online and secure (bot management, DDoS mitigation, WAF). This is essential to the Service.

  • For visitors to customers' sites, this filtering is configured by the customer (controller). Edge decisions are generally about an individual request, not decisions producing legal effects about a person; where a visitor is persistently blocked, the website operator can review and adjust the configuration.
  • We do not use these signals to make decisions that produce legal or similarly significant effects about you under Article 22 GDPR. If you believe an automated decision has significantly affected you, contact us (or the relevant website operator) for human review.

15. California privacy rights (CCPA/CPRA)

This section applies to California residents whose data we handle as a business (controller).

Categories of personal information we have collected in the last 12 months: identifiers (name, email, IP); commercial information (plan, billing); internet/network activity (dashboard usage, security/traffic logs); geolocation (approximate, from IP); and inferences used for security/anti-fraud. Sources and purposes are described in Sections 4–5. We disclose data to the recipients in Section 7.

  • We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding 12 months.
  • We do not knowingly collect personal information from individuals under 16.

Your California rights: to know/access, to delete, to correct, to opt out of sale/sharing (not applicable, as we do neither), and to limit use of sensitive personal information (we do not use sensitive PI for purposes that trigger this right). You also have the right to non-discrimination for exercising these rights.

To exercise these rights, email chlibekbusiness@gmail.com. You may use an authorized agent; we may require verification. We will respond within the timeframes required by the CCPA.


16. Children

The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.


17. Changes to this policy

We may update this policy from time to time. We will post the new version here with a revised "Last updated" date and, for material changes, give reasonable notice (e.g. by email or in-dashboard notice). Continued use after the effective date means you accept the updated policy.


18. Contact

  • Controller: Petr Chlíbek (trading as Itnetic Technologies), IČO 21210756, Czech Republic
  • Registered address: Výletní 5258, Chomutov, Czech Republic
  • Privacy enquiries / rights requests: chlibekbusiness@gmail.com
  • Abuse / security reports: chlibekbusiness@gmail.com
  • General / legal: chlibekbusiness@gmail.com

Annex A — Current sub-processors

Sub-processorRoleLocationSafeguard if outside EEA
OVHcloud (OVH SAS)Network DDoS absorption, infrastructure/hostingEU (France)N/A (EU)
Railway Corp.Application/dashboard & website hostingUSASCCs
Stripe Payments Europe, Ltd.Payment processing, fraud preventionEU / USASCCs
Seznam.cz, a.s. (Seznam Profi e-mail)Sending account & support emailCzech Republic (EU)N/A (EU)
Google Ireland Ltd. / Google LLCWebsite analytics (Google Analytics)EU / USASCCs
Functional Software, Inc. (Sentry)Error monitoring & diagnosticsUSASCCs

We update this list as our providers change. The authoritative, current list is maintained at itnetic.com/legal/subprocessors; material changes are notified to customers under the DPA.

Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPA

We use essential cookies to run and secure the site. With your consent we also use Google Analytics to understand usage. Cookie Policy