Itnetic logo Itnetic Technologies
PlatformLogsNetworkPricing
Log inStart free
PlatformLogsNetworkPricing
Log inStart free

Data Retention Policy

Itnetic Technologies

Last updated: 31 July 2026


This policy states how long Itnetic keeps each category of data and what enforces that limit. It expands Section 11 of the Privacy Policy and supports Section 11 of the DPA.

The principle throughout: a retention period that depends on someone remembering to run a clean-up is not a retention period. Wherever the data lives in our database, expiry is enforced by a TTL index — the database itself deletes the record when it expires.


1. End-user traffic data (Itnetic acts as processor)

DataRetentionEnforced by
Request logs — IP, timestamp, host, path (query string stripped), method, status, bytes, user-agent, referer, country/ASN, TLS and HTTP version, cache status, security signals30 daysDatabase TTL
Per-minute analytics aggregates derived from those logs30 days — the same window as the raw logs they summariseDatabase TTL
Request and response bodiesNever storedNot written in the first place
Cached response bodies (CDN cache)Until the cache TTL expires or the cache is evicted or purged; per-node disk cache, wiped on redeployCache LRU + TTL
Rate-limit and traffic countersMinutes to hours — the length of the counting windowDatabase TTL
Mitigation counters (attack graphs)1 hourDatabase TTL
Bot-detection modelNumeric weights only, refreshed continuously. Contains no personal data and nothing traceable to a request, a visitor or a site—
Kernel firewall blocks and solver allowlistsMinutes to a maximum of 1 hour, in memory on the edge node onlyIn-process expiry

Nothing in this section is recoverable after its window closes. A law-enforcement preservation request must reach us inside the 30 days to be actionable.


2. Customer account data (Itnetic acts as controller)

DataRetentionEnforced by
Account record, domains and configurationLife of the account. Deleting your account in the dashboard removes it immediatelySelf-service deletion
API tokens and their usage countersDeleted with the account. Usage counters otherwise: 90 days (per-minute buckets), 400 days (daily buckets)Deletion + database TTL
Stored origin credentials (object-storage keys, AES-GCM encrypted)Deleted with the account or when you remove themSelf-service deletion
PasskeysDeleted with the account or when you remove themSelf-service deletion
Dashboard session records (IP, user-agent)30 days after last activity; deleted immediately on account deletionDatabase TTL + deletion
Email-verification tokensUntil they expire (short-lived)Database TTL
Unverified domain claims7 daysDatabase TTL
Anything remaining after account deletionDeleted or anonymised within 90 daysManual review

3. Everything else

DataRetentionWhy
Billing and accounting documents5 years generally; up to 10 years for tax documents where VAT appliesCzech Act No. 563/1991 Coll.; tax law
Support communications24 monthsLegitimate interest — continuity of support and defence of claims
Website analytics (self-hosted Umami, no cookies)12 monthsConsent-based; deleted on withdrawal
Marketing preferences and consent recordsUntil withdrawn, plus a short record of the withdrawalProof of compliance
Incident records3 yearsAccountability (Art. 5(2) GDPR)
BackupsRolling, overwritten within 35 daysProvider backup cycle

Backups and erasure. An erasure request removes the live data immediately. Backups are not surgically edited — the deleted data disappears as the backup cycle rolls over, within 35 days. In the meantime it is not used for any purpose other than restoring a failed system.


4. Customer control over retention

Request logging is currently a fixed part of the Service: it is not switchable per domain, and the 30-day window is not shortenable in the dashboard. If your data-protection assessment needs a shorter window or no logging at all, contact us before routing traffic — we will tell you honestly whether we can meet it.

You can, at any time and without asking us:

  • delete a domain, which stops any further logging for it;
  • delete your account, which removes everything in Section 2 immediately.

5. Questions

chlibekbusiness@gmail.com. For rights requests (access, erasure, portability), see Section 12 of the Privacy Policy.

Itnetic logo Itnetic Technologies

Advanced DDoS mitigation and web performance solutions for modern businesses. Protect your infrastructure across multiple regions.

Product

  • DDoS Mitigation
  • Web CDN
  • Network
  • Pricing

Resources

  • Learn
  • Changelog
  • FAQ
  • Status

Legal

  • Acceptable Use
  • SLA
  • Security
  • Abuse
  • Sub-processors
  • Data Retention
  • Incident Response

Company

  • Founder
  • Contact
Petr ChlíbekIČO: 21210756Neplátce DPH
© 2026 Itnetic Technologies. All rights reserved.
Terms of ServicePrivacy PolicyCookie PolicyDPAIP geolocation by DB-IP (CC BY 4.0)

We use essential cookies to run and secure the site. With your consent we also use Umami analytics (self-hosted, no cross-site tracking) to understand usage. Cookie Policy