Privacy Policy
This document is a placeholder pending legal review and is not yet binding.
1. Data we collect
Account data (email, hashed password, organisation) and billing records. From your protected services we receive operational metadata: source IP addresses of the connections we filter or your agent reports, event type and time, plus host and firewall statistics. IP addresses are personal data under the GDPR. We do not collect the contents of your game traffic.
2. How we use it
To provide and secure the Service, to show you telemetry and analytics, to handle billing and to send operational or account notices. We do not sell data and we do not use it for advertising.
3. Where your data lives
Player traffic transits our protection nodes and is forwarded to your origin; it is not stored there. The control plane stores only the metadata described above, in the European Union. Passwords are stored only as Argon2id hashes, never in plain text.
4. Third parties
We use Cloudflare for delivery and access control of our own web surfaces, and network providers for the protected addresses and transport. A payment provider will process payments once billing opens. Each processes only the data needed for its function.
5. Retention
Event metadata is kept for 30 days and host or firewall snapshots for 7 days, then deleted automatically. Account, service and billing records are kept while your account is active. You may request deletion of your account data.
6. Your rights
You may access, correct or delete your personal data and request a copy of it. Export and account deletion are available in the dashboard under Account; you can also contact us.
7. Roles
For your account data we act as controller. For the traffic metadata of your players we act on your instructions as processor, and you remain responsible for informing your players. This page describes what we do; it is not legal advice and does not claim certification.
8. Contact
Privacy questions can be sent to [email protected].