Data Processing Addendum
GDPR processor terms for XDP.NETWORK: roles, instructions, security measures, subprocessors, breach notification, deletion, audits, and transfers.
On this page
This Data Processing Addendum (the "DPA") supplements the Terms of Service between XDP.NETWORK ("we", "us"), [[PLACEHOLDER: company legal name]], a PingLess Studios product, and the Customer ("you", the account holder). It governs how we process personal data on your behalf in the course of providing the Services, where that processing is subject to Regulation (EU) 2016/679 or the UK GDPR (together, the "GDPR"). By using the Services to process personal data, you enter into this DPA.
1. Scope & roles
This DPA forms part of the Terms and applies for as long as we process personal data on your behalf. The parties and the subject matter are:
- Controller: you, the Customer. You determine the purposes and means of the processing of personal data relating to your end users and your Protected Infrastructure.
- Processor: [[PLACEHOLDER: company legal name]], trading as XDP.NETWORK, acting on your documented instructions.
- Subject matter: the provision of the Services — DDoS mitigation (OpenShield-XDP), the managed web application firewall (PingLess WAF / WAF Pro), the Console, and the APIs.
- Duration: the term of your account, plus any retention period described in the Deletion & return section.
- Nature and purpose of the processing: providing DDoS mitigation and WAF protection necessarily requires processing network traffic metadata of Protected Infrastructure — source IP addresses, packet rates, attack signatures and records, and WAF edge logs. We also process account data (name, email, credentials, billing details) to operate, secure, and bill your account.
- Categories of data subjects: your users, website visitors, and game players whose traffic reaches Protected Infrastructure, together with your own account users and contacts.
- Types of personal data: online identifiers (in particular IP addresses), network traffic metadata (packet rates, timestamps, attack records, geo data derived from IP addresses), and account data.
2. Documented instructions
We process personal data only on your documented instructions. Those instructions consist of this DPA, the Terms, and the configuration choices you make in the Console and in the Agent — which servers you enroll, which rulesets and rate limits you enable, and which API keys you issue. Any further instruction must be given in writing (including via the Console); we may decline or charge for instructions that go beyond the normal operation of the Services.
We will not process personal data for our own purposes, we do not sell personal data, and we do not use it for advertising. If we believe an instruction infringes the GDPR or other applicable data-protection law, we will inform you without undue delay.
3. Confidentiality & personnel
We limit access to personal data to the personnel and contractors who need it to build, operate, secure, or support the Services. Every person with such access is bound by confidentiality obligations — contractual or statutory — at least as protective as this DPA, and receives appropriate training on data protection and security.
4. Security measures
We implement and maintain technical and organizational measures appropriate to the risk, including at minimum:
- encryption of personal data in transit (TLS) between your Protected Infrastructure, the Agent, the Console, and our APIs;
- server-side storage of the per-server API keys (
osk_…) you use to connect servers to the Console, so keys are held centrally under our access controls; - access control based on least privilege, with individual accounts and strong authentication for administrative systems;
- logging of administrative access to systems that store or process personal data;
- timely patching and vulnerability management across the edge, the control plane, and the build pipeline; and
- backups of control-plane data, encrypted at rest, with tested restoration procedures.
We may update these measures from time to time, provided the overall level of protection is not materially reduced.
5. Subprocessors
You give us general authorization to engage subprocessors to support the Services. Our current subprocessors are:
| Subprocessor | Function |
|---|---|
| [[PLACEHOLDER: hosting provider]] | Infrastructure and hosting for the edge, control plane, and Console |
| [[PLACEHOLDER: email provider]] | Transactional email (account, security, and billing notices) |
| [[PLACEHOLDER: payment processor]] | Payment processing for subscriptions and licenses |
We will give you advance notice of any intended addition or replacement of a subprocessor — by email or a notice in the Console — at least [[PLACEHOLDER: e.g. 14 days]] before the change takes effect. You may object on reasonable data-protection grounds within that period. If you object and we cannot reasonably accommodate the objection, you may terminate the affected Services; that termination is your sole remedy for the change.
We enter into a written agreement with each subprocessor imposing data-protection obligations no less protective than this DPA, and we remain liable to you for each subprocessor's performance of its obligations.
6. Data-subject requests
Taking into account the nature of the processing, we will assist you, by appropriate technical and organizational measures, in fulfilling your obligation to respond to requests from data subjects exercising their GDPR rights — access, rectification, erasure, restriction, data portability, and objection. Where practicable, the Console provides self-service tools to locate, export, and delete data. For anything else, contact [[PLACEHOLDER: privacy contact email or DPO]] and we will assist without undue delay.
If a data subject contacts us directly about personal data we process for you, we will promptly redirect the data subject to you, unless we are legally required to respond ourselves.
7. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting personal data we process on your behalf, targeting notification within [[PLACEHOLDER: e.g. 72 hours]]. The notice will describe, so far as the information is then available:
- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences of the breach; and
- the measures taken or proposed to address the breach and to mitigate its possible adverse effects.
We may provide the information in phases as it becomes available. Notification will be sent to your account email, the Console, or both. Our notification does not relieve you of your own obligation to assess the breach and, where required, to report it to supervisory authorities and data subjects.
8. Deletion & return
On termination of your account, we will delete or, where technically feasible and requested through the Console or the privacy contact before deletion, return the personal data we process on your behalf. Deletion follows the retention schedule in the Privacy Policy, unless applicable law requires longer retention — in which case the data is protected until the retention obligation ends and then deleted. Residual copies in backups are deleted on the normal backup cycle. On request, we will confirm deletion in writing.
9. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits — including inspections — conducted by you or by an independent auditor you mandate that we reasonably approve. Audits may take place [[PLACEHOLDER: e.g. once per year, at Customer's cost, with notice]], must be limited in scope to the Services, and must not disrupt the Services or compromise other customers' data. Where we make third-party audit reports or certifications available for the Services, those may be used to satisfy this audit right to the extent they cover the relevant systems.
10. International transfers
Personal data may be processed in the countries where we and our subprocessors operate. Where personal data subject to the GDPR is transferred to a country outside the EEA or the UK that has not received an adequacy decision, we rely on [[PLACEHOLDER: transfer mechanism]] — for example, the European Commission's Standard Contractual Clauses or the UK equivalent — together with any supplementary measures required by applicable law.
11. Liability & order of precedence
Our aggregate liability arising out of or in connection with this DPA is subject to the limitation of liability in the Terms of Service. If this DPA conflicts with the Terms on a matter of data protection, this DPA prevails; in all other respects the Terms govern. If this DPA conflicts with any applicable Standard Contractual Clauses, the Clauses prevail.
Questions about this DPA: [[PLACEHOLDER: privacy contact email or DPO]].
Version history
| Date | Change |
|---|---|
| Initial publication. |