Our role as controller
This policy covers our role as controller for account, billing, and site data. Where we process personal data on behalf of a Customer as part of running Tests, we act as a processor under our Data Processing Addendum,
and the Customer is the controller.
for questions, reach out to [email protected].
Data we collect
You give us
- Account & workspace: name, work email address, organization/workspace name, role, time zone, and password (stored only as a salted hash).
- Authentication: two-factor (TOTP) configuration, stored encrypted; email-verification status.
- Test configuration: domains you add and verify, test plans, and health-check paths.
- Support: the content of support tickets and any files you attach.
- Billing: billing, invoicing, and tax details you provide.
We generate or collect automatically
- Test & health data: results and service-health samples (such as latency and HTTP response codes) produced while your Tests run.
- Audit & log data: logins, approvals, changes, and lifecycle events, together with IP address, timestamps, and technical metadata used for security and abuse prevention.
- Session data: a session identifier stored in a cookie and checked on each request.
- Network & edge-security data: connection metadata — including IP address, request headers, and TLS details — inspected at our network edge by Cloudflare to filter malicious traffic and absorb denial-of-service
attacks before they reach our servers.
- Website analytics data (only with your consent): if you accept analytics cookies on our public website, Google Analytics collects usage data — pages viewed, referring site, approximate location derived from
a truncated IP address, and device and browser type — to help us measure and improve the site.
Purposes & legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|
| Create and operate your account and Workspace; provide the Service | Performance of a contract (6(1)(b)) |
| Run Tests, provision Workers, and show health data | Performance of a contract (6(1)(b)) |
| Issue invoices and process billing | Contract (6(1)(b)); legal obligation for tax/accounting (6(1)(c)) |
| Secure the Service, prevent abuse, verify authorization, keep audit logs | Legitimate interests (6(1)(f)) — protecting the Service and third parties |
| Provide support | Contract (6(1)(b)); legitimate interests (6(1)(f)) |
| Comply with legal requests and enforce our terms | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) |
| Measure and improve our public website (analytics) | Consent (6(1)(a)) |
| Optional product updates | Consent (6(1)(a)) or legitimate interests, with opt-out |
Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to that processing (see Your rights).
Sharing & processors
We do not sell personal data. We share it only with service providers who process it on our instructions and under a data-processing agreement, and where required by law. Our main sub-processors are:
| Provider | Purpose | Location |
|---|
| Stripe | Billing and invoicing | EU / global (as Stripe's own controller for payments) |
| Hetzner Online GmbH | Hosting and short-lived test Workers | Germany (EU) |
| Cloudflare | Authoritative DNS, DDoS protection, and TLS-terminating reverse proxy in front of our websites and the customer portal | Global edge network, with an EU point of presence serving European visitors; safeguarded by Standard Contractual Clauses |
| Google (Google Analytics) | Website analytics on our public marketing site, loaded only after you consent to analytics cookies | United States; safeguarded by the EU–US Data Privacy Framework and Standard Contractual Clauses |
| Resend | Transactional email (verification, notifications) | As disclosed by Resend |
We may also disclose data to professional advisers, or to authorities and affected infrastructure providers where necessary to comply with law or to investigate abuse of the Service. If we are involved in a merger or acquisition,
data may transfer subject to this policy.
International transfers
We aim to keep personal data within the European Economic Area (EEA). Our hosting and test Workers run in the EU, all data at rest is stored in the EU, and we use email providers' EU regions where available. Traffic to our sites
and portal passes through Cloudflare's global edge network before reaching those EU servers; requests from Europe are normally handled at a European point of presence, but Cloudflare's anycast routing means a request may be
processed outside the EEA. Where a provider (such as Cloudflare or Stripe) processes or routes data outside the EEA, that transfer is protected by an adequacy decision or by Standard Contractual Clauses together with additional
safeguards. You can ask us for details of the safeguards in place.
Retention
- Account data — for as long as your Workspace is active, then deleted or anonymized within 30 days after closure.
- Test and health data — retained as long as your Workspace is active to let you review results, unless you delete a Test earlier.
- Invoices and tax records — retained for 7 years, as required by Dutch tax law.
- Audit and security logs — retained for 12 months for security and abuse prevention.
- Support tickets and attachments — retained for 24 months after resolution.
Security
We apply technical and organizational measures appropriate to the risk, including: strict tenant isolation with every query scoped to your Workspace and sessions re-checked on each request; passwords stored only as salted hashes;
two-factor secrets stored encrypted; support attachments validated by content and served only through authenticated, ownership-checked handlers; encryption in transit (HTTPS); loopback-only internal interfaces; DDoS protection
and malicious-traffic filtering at our network edge through Cloudflare, which fronts our websites and the customer portal; and audit logging. No system is perfectly secure, but we work to protect your data and will notify you
and the relevant authority of a personal-data breach where required.
Your rights
Subject to conditions in the GDPR, you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To
exercise these rights, contact
[email protected]. We will respond within the time limits set by law. If your data is processed by us on a Customer's behalf (as a processor), we will refer your request to that
Customer.
Cookies
The portal uses a small number of strictly necessary cookies — chiefly a session cookie that keeps you signed in and protects against cross-site request forgery. Cloudflare, which provides our DDoS protection,
may additionally set its own strictly necessary security cookies (such as __cf_bm and cf_clearance) to tell automated traffic from human visitors and to record that a security challenge was passed.
These are required for the Service to function safely, are not used for advertising or cross-site tracking, and do not require consent.
Analytics (optional, consent-based). On our public website we use
Google Analytics to understand how visitors find and use the site so we can improve it. It runs only after you accept in the cookie banner — nothing is loaded and no analytics cookie is set
unless you opt in. When enabled, Google Analytics sets its own cookies (for example _ga and _ga_<id>) to distinguish visitors and measure sessions, and processes usage and device data — including
a truncated IP address — on our behalf. Google acts as our processor for this and may transfer data to the United States under the EU–US Data Privacy Framework and Standard Contractual Clauses. See Google's privacy policy and how Google Analytics uses data.
You can change or withdraw your choice at any time —
— or block and delete cookies in your browser settings.
Children
The Service is a business-to-business offering intended for organisations and their authorised staff. It is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a
child has provided us with personal data, contact
[email protected] and we will delete it.
Changes
We may update this policy from time to time. We will post the updated version here and, for material changes, notify you through the portal or by email. The "last updated" date shows when it last changed.
← Back to ddos-simulation.com