ddos-sim.com Back to site

Legal

Privacy Policy

This policy explains how we collect, use, share, and protect personal data when you use ddos-sim.com, in line with the EU General Data Protection Regulation (GDPR) and Dutch data-protection law.

Last updated: 25 July 2026 Version: 1.0
Terms of Service Acceptable Use Policy Privacy Policy Data Processing Addendum

On this page

  1. Who we are
  2. Data we collect
  3. Purposes & legal bases
  4. Sharing & processors
  5. International transfers
  6. Retention
  7. Security
  8. Your rights
  9. Cookies
  10. Children
  11. Changes
  12. Contact & complaints

Our role as controller

This policy covers our role as controller for account, billing, and site data. Where we process personal data on behalf of a Customer as part of running Tests, we act as a processor under our Data Processing Addendum, and the Customer is the controller.

for questions, reach out to [email protected].

Data we collect

You give us

  • Account & workspace: name, work email address, organization/workspace name, role, time zone, and password (stored only as a salted hash).
  • Authentication: two-factor (TOTP) configuration, stored encrypted; email-verification status.
  • Test configuration: domains you add and verify, test plans, and health-check paths.
  • Support: the content of support tickets and any files you attach.
  • Billing: billing and tax details you provide. Card payments are processed by Stripe; we do not receive or store full card numbers.

We generate or collect automatically

  • Test & health data: results and service-health samples (such as latency and HTTP response codes) produced while your Tests run.
  • Audit & log data: logins, approvals, changes, and lifecycle events, together with IP address, timestamps, and technical metadata used for security and abuse prevention.
  • Session data: a session identifier stored in a cookie and checked on each request.
  • Network & edge-security data: connection metadata — including IP address, request headers, and TLS details — inspected at our network edge by Cloudflare to filter malicious traffic and absorb denial-of-service attacks before they reach our servers.

Purposes & legal bases

PurposeLegal basis (GDPR Art. 6)
Create and operate your account and Workspace; provide the ServicePerformance of a contract (6(1)(b))
Run Tests, provision Workers, and show health dataPerformance of a contract (6(1)(b))
Take payment and issue invoicesContract (6(1)(b)); legal obligation for tax/accounting (6(1)(c))
Secure the Service, prevent abuse, verify authorization, keep audit logsLegitimate interests (6(1)(f)) — protecting the Service and third parties
Provide supportContract (6(1)(b)); legitimate interests (6(1)(f))
Comply with legal requests and enforce our termsLegal obligation (6(1)(c)); legitimate interests (6(1)(f))
Optional product updatesConsent (6(1)(a)) or legitimate interests, with opt-out

Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to that processing (see Your rights).

Sharing & processors

We do not sell personal data. We share it only with service providers who process it on our instructions and under a data-processing agreement, and where required by law. Our main sub-processors are:

ProviderPurposeLocation
StripePayment processing and invoicingEU / global (as Stripe's own controller for payments)
Hetzner Online GmbHHosting and short-lived test WorkersGermany (EU)
CloudflareAuthoritative DNS, DDoS protection, and TLS-terminating reverse proxy in front of our websites and the customer portalGlobal edge network, with an EU point of presence serving European visitors; safeguarded by Standard Contractual Clauses
ResendTransactional email (verification, notifications)As disclosed by Resend

We may also disclose data to professional advisers, or to authorities and affected infrastructure providers where necessary to comply with law or to investigate abuse of the Service. If we are involved in a merger or acquisition, data may transfer subject to this policy.

International transfers

We aim to keep personal data within the European Economic Area (EEA). Our hosting and test Workers run in the EU, all data at rest is stored in the EU, and we use email providers' EU regions where available. Traffic to our sites and portal passes through Cloudflare's global edge network before reaching those EU servers; requests from Europe are normally handled at a European point of presence, but Cloudflare's anycast routing means a request may be processed outside the EEA. Where a provider (such as Cloudflare or Stripe) processes or routes data outside the EEA, that transfer is protected by an adequacy decision or by Standard Contractual Clauses together with additional safeguards. You can ask us for details of the safeguards in place.

Retention

  • Account data — for as long as your Workspace is active, then deleted or anonymized within 30 days after closure.
  • Test and health data — retained as long as your Workspace is active to let you review results, unless you delete a Test earlier.
  • Invoices and tax records — retained for 7 years, as required by Dutch tax law.
  • Audit and security logs — retained for 12 months for security and abuse prevention.
  • Support tickets and attachments — retained for 24 months after resolution.

Security

We apply technical and organizational measures appropriate to the risk, including: strict tenant isolation with every query scoped to your Workspace and sessions re-checked on each request; passwords stored only as salted hashes; two-factor secrets stored encrypted; support attachments validated by content and served only through authenticated, ownership-checked handlers; encryption in transit (HTTPS); loopback-only internal interfaces; DDoS protection and malicious-traffic filtering at our network edge through Cloudflare, which fronts our websites and the customer portal; and audit logging. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal-data breach where required.

Your rights

Subject to conditions in the GDPR, you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; and to withdraw consent where processing is based on consent. To exercise these rights, contact [email protected]. We will respond within the time limits set by law. If your data is processed by us on a Customer's behalf (as a processor), we will refer your request to that Customer.

Cookies

The portal uses a small number of strictly necessary cookies — chiefly a session cookie that keeps you signed in and protects against cross-site request forgery. Cloudflare, which provides our DDoS protection, may additionally set its own strictly necessary security cookies (such as __cf_bm and cf_clearance) to tell automated traffic from human visitors and to record that a security challenge was passed. These are required for the Service to function safely and are not used for advertising or cross-site tracking. If we introduce any non-essential or analytics cookies, we will ask for your consent first.

Changes

We may update this policy from time to time. We will post the updated version here and, for material changes, notify you through the portal or by email. The "last updated" date shows when it last changed.

Contact & complaints

For any privacy question or request, contact [email protected].

If you believe we have not handled your data properly, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority where you live or work.

← Back to ddos-sim.com
© - ddos-sim.com · Authorized testing only. Terms · Privacy · Acceptable use · DPA