Roles & scope
For personal data processed through the Service on your behalf ("Customer Personal Data"), you are the controller and we are the processor. Where you are yourself a processor for a third party, we act as sub-processor and your instructions must be consistent with that third party's instructions. This DPA applies to the extent the GDPR applies to that processing. The subject matter, duration, nature and purpose of processing, and the types of data and categories of data subjects are set out in Annex A.
Processing on documented instructions
We will process Customer Personal Data only on your documented instructions, including as set out in the Agreement and as given through the Service, unless required to do otherwise by EU or Member State law (in which case we will inform you, unless that law prohibits it). We will inform you if, in our opinion, an instruction infringes data-protection law. You are responsible for the accuracy and lawfulness of your instructions and for having a lawful basis for the processing.
Confidentiality
We ensure that persons authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.
Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art and the nature of the data, as described in Annex B and in the "Security" section of our Privacy Policy.
Sub-processors
You give general authorization for us to engage the sub-processors listed in Annex C. We impose data-protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor (via the portal or email), during which you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service.
Assisting you
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests, and we will assist you in ensuring compliance with your obligations regarding security, breach notification, data-protection impact assessments, and prior consultation (Articles 32–36 GDPR).
Personal-data breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations.
International transfers
We will not transfer Customer Personal Data outside the EEA except in compliance with Chapter V GDPR — for example under an adequacy decision or the Standard Contractual Clauses with appropriate supplementary measures. The infrastructure that stores Customer Personal Data is located in the EU (see Annex C). Traffic reaches that infrastructure through Cloudflare's global edge network, which terminates TLS and filters malicious traffic in transit; requests from Europe are normally served from a European point of presence, but anycast routing means transit processing may occur outside the EEA, and that processing is covered by the Standard Contractual Clauses.
Return & deletion
On termination of the Service, and at your choice, we will delete or return Customer Personal Data and delete existing copies, unless EU or Member State law requires storage. Deletion of a Test, domain, or Workspace through the Service deletes the associated data in accordance with our standard retention and backup cycles.
Audits
We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To protect the security and confidentiality of our systems and other customers, audits are subject to reasonable notice, confidentiality, frequency, and scope limits, and may be satisfied by our providing relevant documentation.
Liability & term
This DPA takes effect when you begin using the Service and continues for as long as we process Customer Personal Data. Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the rest of the Agreement regarding the processing of personal data, this DPA prevails.
Annex A — Details of processing
- Subject matter
- Provision of the ddos-sim.com resilience-testing Service.
- Duration
- For the term of the Agreement and any retention period thereafter.
- Nature & purpose
- Hosting, storage, transmission, and display of data to operate Workspaces, schedule and run Tests, monitor service health, provide support, and secure the Service.
- Types of personal data
- Identification and contact data of your authorized users (name, work email, role, time zone); authentication data; support-ticket content and attachments; and any personal data that may be contained in domains, test configuration, health data, or logs you place into or generate through the Service.
- Categories of data subjects
- Your authorized users, administrators, and any individuals whose data you choose to include in the above.
- Special categories
- Not intended. You must not submit special-category data except as strictly necessary and lawful.
Annex B — Technical & organizational measures
- Tenant isolation: every query scoped to the Workspace; sessions verified on each request.
- Access control: role-based access; two-factor authentication available; least-privilege administration.
- Credential protection: passwords stored as salted hashes; two-factor secrets stored encrypted.
- Encryption in transit: HTTPS for customer-facing traffic; internal service interfaces bound to loopback.
- Edge protection: DDoS mitigation and malicious-traffic filtering through Cloudflare, which fronts our public websites and the customer portal and shields origin servers from direct exposure.
- Content validation: support attachments validated by content type and served only through authenticated, ownership-checked handlers stored outside any web-served directory.
- Test safety controls: single verified domain per Worker; pinned public address; private and loopback destinations blocked; bounded rate, concurrency, and operation limits.
- Logging & monitoring: audit logging of security-relevant events; infrastructure and application metrics.
- Resilience: short-lived, disposable test Workers provisioned per Test and torn down after use.
These measures may evolve; we will not materially reduce the overall level of security during the term.
Annex C — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting and short-lived test Workers | Germany (EU) |
| Cloudflare | Authoritative DNS, DDoS protection, and TLS-terminating reverse proxy for the Service (processes traffic in transit; does not store Customer Personal Data at rest) | Global edge network, EU point of presence for European traffic, under SCCs |
| Resend | Transactional email delivery | As disclosed by Resend |
| Stripe | Payment processing (also acts as an independent controller for payment data) | EU / global under SCCs |
The current list is maintained here and in the Privacy Policy. Contact [email protected] to subscribe to change notifications.