Privacy Policy
How XDP.NETWORK collects, uses, shares, and protects personal data across the Console, the OpenShield-XDP Agent, and PingLess WAF.
On this page
- 1. Who we are and scope
- 2. Data we collect
- 2.1. Account data
- 2.2. Technical and telemetry data
- 2.3. Usage data
- 2.4. Support data
- 2.5. Payment data
- 3. How we use data
- 4. Legal bases under the GDPR
- 5. Cookies and similar technologies
- 6. How we share data
- 7. International transfers
- 8. Retention
- 9. Security measures
- 10. Your rights
- 11. Children
- 12. Changes to this policy
- 13. Contact us
This Privacy Policy explains what personal data XDP.NETWORK ("we", "us") collects when you use our services, why we collect it, how long we keep it, and the rights you have over it. XDP.NETWORK is operated by [[PLACEHOLDER: company legal name]], a PingLess Studios product.
This policy applies to the Services: the OpenShield-XDP protection products (including the Game and Game Pro editions), the PingLess WAF and WAF Pro managed web application firewall, the Console (the XDP.NETWORK dashboard), and our APIs, together. It applies to you as the Customer — the account holder — and covers personal data processed in connection with your Protected Infrastructure: the servers, game servers, sites, and APIs you enroll in the Services.
Please read this policy together with our Terms of Service, Data Processing Addendum, and Cookie Policy.
1. Who we are and scope
The data controller for the personal data described in this policy is:
[[PLACEHOLDER: company legal name]] [[PLACEHOLDER: registered address]] Privacy contact: [[PLACEHOLDER: privacy contact email or DPO]]
This policy covers three main processing contexts:
- Console accounts — the data we hold about you as a registered user of the Console.
- Protected Infrastructure telemetry — the network traffic metadata we necessarily process to detect and mitigate attacks against your servers and sites. The Agent (the OpenShield-XDP software installed on Customer servers) runs on your own server; the Console polls its metrics API. For PingLess WAF customers, protection is enabled by a DNS change and we process logs at our edge.
- Support and billing — the data generated when you contact us or pay for the Services.
Where we process personal data contained in your traffic strictly on your behalf and on your instructions, our Data Processing Addendum applies and forms part of our agreement with you.
2. Data we collect
2.1. Account data
When you register for the Console we collect:
- your name and email address;
- your password, stored only as a cryptographic hash — we never store plaintext passwords;
- your product entitlements: the OpenShield-XDP licenses (Game or Game Pro) you have purchased and the PingLess WAF or WAF Pro subscriptions attached to your account;
- the per-server API keys (
osk_…) and metrics API URLs used to connect your servers to the Console. Keys are stored server-side by the Console.
2.2. Technical and telemetry data
To provide DDoS mitigation we necessarily process network traffic metadata of your Protected Infrastructure. This is inherent to how the Services work: we cannot distinguish an attack from legitimate traffic without observing the traffic itself. Concretely, we process:
- the server IP addresses and hostnames of your Protected Infrastructure;
- the source IP addresses of inbound traffic to your Protected Infrastructure;
- packet and byte rates and protocol distributions;
- attack records: attack type, peak rates, and country attribution;
- ban lists — the IP addresses the Agent has blocked on your server;
- Agent diagnostics: the Agent version, network interface, and kernel version of the host server.
For PingLess WAF and WAF Pro customers, we additionally process edge logs: the requested hosts and paths, client IP addresses, user agents, and WAF rule matches for traffic passing through our edge.
2.3. Usage data
When you use the Console we automatically collect standard usage data: Console logs (such as sign-in times, IP addresses, and actions taken), device and browser type, and your approximate location derived from your IP address.
2.4. Support data
When you contact support we keep the tickets, messages, and any attachments you choose to upload. Please avoid including unnecessary personal data — especially other people's — in attachments.
2.5. Payment data
Payments are processed by [[PLACEHOLDER: payment processor]]. We never see or store full card numbers. We receive only what we need to administer your purchase: a transaction reference, payment status, billing country, and the product purchased.
3. How we use data
We use the data described above to:
- Deliver the Services — operate the Console, connect your servers, run detection and mitigation, enforce per-player rate limits and rule sets, and display your traffic and attack statistics;
- Secure the Services — detect abuse, fraud, and attacks against XDP.NETWORK itself, and enforce our Acceptable Use Policy;
- Provide support — respond to tickets and troubleshoot issues with your Protected Infrastructure;
- Improve the Services — analyse aggregated or de-identified telemetry (for example, global attack trends) to tune detection models and plan capacity. We do not use identifiable Customer traffic data for advertising;
- Billing and account administration — process purchases, manage entitlements, and send service-related notices;
- Comply with the law — meet tax, accounting, and regulatory obligations and respond to lawful requests.
4. Legal bases under the GDPR
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the Services and mitigation | Account, telemetry, usage | Performance of a contract (Art. 6(1)(b)) |
| Secure the Services and prevent abuse | Telemetry, usage, Console logs | Legitimate interest (Art. 6(1)(f)) |
| Improve the Services | Aggregated / de-identified telemetry | Legitimate interest (Art. 6(1)(f)) |
| Provide support | Support tickets, account data | Performance of a contract (Art. 6(1)(b)) |
| Billing, tax, and accounting | Payment and invoice records | Legal obligation (Art. 6(1)(c)) |
| Optional analytics cookies | Cookie identifiers | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interest, we have balanced our interest against your rights and freedoms — you may ask us for details of that assessment. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.
5. Cookies and similar technologies
The Console uses strictly necessary cookies to keep you signed in and protect the Service, plus optional analytics cookies that only load with your consent. The full list of cookies, their purposes, their lifetimes, and how to change your choices is in our Cookie Policy.
6. How we share data
We share personal data only in the following circumstances.
Subprocessors. We use a small number of service providers to operate the Services. Each is bound by a data processing agreement and may process personal data only on our instructions.
| Subprocessor | Purpose | Location |
|---|---|---|
| [[PLACEHOLDER: hosting provider]] | Infrastructure and hosting | [[PLACEHOLDER: location]] |
| [[PLACEHOLDER: email provider]] | Transactional and service email | [[PLACEHOLDER: location]] |
| [[PLACEHOLDER: payment processor]] | Payment processing | [[PLACEHOLDER: location]] |
| [[PLACEHOLDER: error monitoring provider]] | Error and crash monitoring | [[PLACEHOLDER: location]] |
Legal requests. We may disclose personal data where we are required to do so by law, regulation, or a valid request from a public authority, or where disclosure is necessary to protect our rights, your rights, or the safety of others. Where the law allows, we will tell you before we disclose.
Business transfers. If XDP.NETWORK is involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy. We will notify you of any change of control.
We do not sell personal data. We do not rent it, trade it, or share it with third parties for their own marketing.
7. International transfers
Some of our subprocessors process data outside the European Economic Area or the United Kingdom. Where we transfer personal data internationally, we rely on an adequacy decision or on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. Details: [[PLACEHOLDER: transfer mechanism details]]. You may request a copy of the relevant safeguards via the contact details below.
8. Retention
We keep personal data only as long as we need it for the purposes described in this policy.
| Data type | Retention period |
|---|---|
| Account data | Life of the account, plus [[PLACEHOLDER: e.g. 30 days]] after closure |
| Telemetry and attack records | [[PLACEHOLDER: e.g. 90 days]] |
| Support tickets | [[PLACEHOLDER: e.g. 24 months]] |
| Backups | [[PLACEHOLDER: e.g. 30 days]] |
| Server API keys and connection details | Until the server is removed from the Console |
When retention ends, we delete or irreversibly anonymise the data. We may retain limited records longer where the law requires it (for example, tax records) or where necessary to establish or defend legal claims.
9. Security measures
We protect personal data with measures appropriate to the risk, including:
- encryption in transit (TLS) for the Console, APIs, and edge traffic;
- server-side storage of your per-server API keys, never on your server image or in our client code;
- access controls on a least-privilege basis, so staff can only reach the data their role requires;
- logging and monitoring of administrative access.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we suffer a personal data breach that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
10. Your rights
Where the GDPR or UK GDPR applies, you have the right to:
- Access — obtain a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Erasure — ask us to delete your data, subject to legal retention duties;
- Restriction — limit how we process your data in certain circumstances;
- Portability — receive the data you provided to us in a structured, machine-readable format;
- Objection — object to processing based on legitimate interest, including any profiling;
- Withdraw consent — where processing is based on consent, withdraw it at any time;
- Complain — lodge a complaint with your local supervisory authority. [[PLACEHOLDER: lead supervisory authority, if established]].
To exercise any of these rights, contact [[PLACEHOLDER: privacy contact email or DPO]]. We respond within 30 days. We may need to verify your identity before acting on a request.
11. Children
The Services are business products and are not directed at anyone under 18. We do not knowingly collect personal data from children. If we learn that we have, we will delete it promptly. If you believe a child has provided us personal data, contact us at [[PLACEHOLDER: privacy contact email or DPO]].
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by a notice in the Console before the change takes effect. The version history at the bottom of this page records every published revision.
13. Contact us
Questions, requests, or complaints about this policy or our handling of personal data:
- Privacy contact: [[PLACEHOLDER: privacy contact email or DPO]]
- Postal address: [[PLACEHOLDER: company legal name]], [[PLACEHOLDER: registered address]]
Version history
| Date | Change |
|---|---|
| Initial publication. |