ddos- sim.com Back to site

Legal

Data Processing Addendum

This Addendum ("DPA") applies where we process personal data on your behalf as a processor under Article 28 GDPR. It forms part of, and uses terms defined in, our Terms of Service (together, the "Agreement").

Last updated: 25 July 2026 Version: 1.0
Terms of Service Acceptable Use Policy Privacy Policy Data Processing Addendum

On this page

  1. Roles & scope
  2. Processing on instructions
  3. Confidentiality
  4. Security
  5. Sub-processors
  6. Assisting you
  7. Breach notification
  8. International transfers
  9. Return & deletion
  10. Audits
  11. Liability & term
  12. Annex A — Details
  13. Annex B — Measures
  14. Annex C — Sub-processors

Roles & scope

For personal data processed through the Service on your behalf ("Customer Personal Data"), you are the controller and we are the processor. Where you are yourself a processor for a third party, we act as sub-processor and your instructions must be consistent with that third party's instructions. This DPA applies to the extent the GDPR applies to that processing. The subject matter, duration, nature and purpose of processing, and the types of data and categories of data subjects are set out in Annex A.

Processing on documented instructions

We will process Customer Personal Data only on your documented instructions, including as set out in the Agreement and as given through the Service, unless required to do otherwise by EU or Member State law (in which case we will inform you, unless that law prohibits it). We will inform you if, in our opinion, an instruction infringes data-protection law. You are responsible for the accuracy and lawfulness of your instructions and for having a lawful basis for the processing.

Confidentiality

We ensure that persons authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.

Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, as described in Annex B and in the "Security" section of our Privacy Policy.

Sub-processors

You give general authorization for us to engage the sub-processors listed in Annex C. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor (via the portal or email), during which you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service.

Assisting you

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests, and we will assist you in ensuring compliance with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation (Articles 32–36 GDPR).

Personal-data breach notification

We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations.

International transfers

We will not transfer Customer Personal Data outside the EEA except in compliance with Chapter V GDPR — for example under an adequacy decision or the Standard Contractual Clauses with appropriate supplementary measures. The infrastructure that stores Customer Personal Data is located in the EU (see Annex C). Traffic reaches that infrastructure through Cloudflare's global edge network, which terminates TLS and filters malicious traffic in transit; requests from Europe are normally served from a European point of presence, but anycast routing means transit processing may occur outside the EEA, and that processing is covered by the Standard Contractual Clauses.

Return & deletion

On termination of the Service, and at your choice, we will delete or return Customer Personal Data and delete existing copies, unless EU or Member State law requires storage. Deletion of a Test, domain, or Workspace through the Service deletes the associated data in accordance with our standard retention and backup cycles.

Audits

We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To protect the security and confidentiality of our systems and other customers, audits are subject to reasonable notice, confidentiality, frequency, and scope limits, and may be satisfied by our providing relevant documentation.

Liability & term

This DPA takes effect when you begin using the Service and continues for as long as we process Customer Personal Data. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the rest of the Agreement regarding the processing of personal data, this DPA prevails.

Annex A — Details of processing

Subject matter
Provision of the ddos-sim.com resilience-testing Service.
Duration
For the term of the Agreement and any retention period thereafter.
Nature & purpose
Hosting, storage, transmission, and display of data to operate Workspaces, schedule and run Tests, monitor service health, provide support, and secure the Service.
Types of personal data
Identification and contact data of your authorized users (name, work email, role, time zone); authentication data; support-ticket content and attachments; and any personal data that may be contained in domains, test configuration, health data, or logs you place into or generate through the Service.
Categories of data subjects
Your authorized users, administrators, and any individuals whose data you choose to include in the above.
Special categories
Not intended. You must not submit special-category data except as strictly necessary and lawful.

Annex B — Technical & organizational measures

  • Tenant isolation: every query scoped to the Workspace; sessions verified on each request.
  • Access control: role-based access; two-factor authentication available; least-privilege administration.
  • Credential protection: passwords stored as salted hashes; two-factor secrets stored encrypted.
  • Encryption in transit: HTTPS for customer-facing traffic; internal service interfaces bound to loopback.
  • Edge protection: DDoS mitigation and malicious-traffic filtering through Cloudflare, which fronts our public websites and the customer portal and shields origin servers from direct exposure.
  • Content validation: support attachments validated by content type and served only through authenticated, ownership-checked handlers stored outside any web-served directory.
  • Test safety controls: single verified domain per Worker; pinned public address; private and loopback destinations blocked; bounded rate, concurrency, and operation limits.
  • Logging & monitoring: audit logging of security-relevant events; infrastructure and application metrics.
  • Resilience: short-lived, disposable test Workers provisioned per Test and torn down after use.

These measures may evolve; we will not materially reduce the overall level of security during the term.

Annex C — Approved sub-processors

Sub-processor Purpose Location
Hetzner Online GmbH Application hosting and short-lived test Workers Germany (EU)
Cloudflare Authoritative DNS, DDoS protection, and TLS-terminating reverse proxy for the Service (processes traffic in transit; does not store Customer Personal Data at rest) Global edge network, EU point of presence for European traffic, under SCCs
Resend Transactional email delivery As disclosed by Resend
Stripe Payment processing (also acts as an independent controller for payment data) EU / global under SCCs

The current list is maintained here and in the Privacy Policy. Contact [email protected] to subscribe to change notifications.

← Back to ddos-sim.com
© 2026 ddos-sim.com · Authorized testing only. Terms · Privacy · Acceptable use · DPA