Privacy Policy
This Privacy Policy describes how FIVE CYBER HOST SECURITY SRL ("Company", "we", "us", "our"), operating Autonomous System AS210718, collects, uses, stores, and protects information when you use our DDoS protection and network security services (the "Services"). We are committed to protecting your privacy and processing your data in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR) where applicable.
1. Information We Collect
1.1 Account Information
When you register for or use our Services, we collect: name, email address, username, hashed password, billing/company information, and two-factor authentication credentials.
1.2 Network Telemetry Data
As part of providing DDoS protection, our infrastructure (including XDP/eBPF components on AS210718 routers) automatically processes and records network telemetry including: source and destination IP addresses, TCP/UDP port numbers, protocol types, packet sizes, timestamps, flow statistics, and traffic classification labels. This data is necessary for the performance of our security services.
1.3 Panel Usage Data
We log interactions with the control panel including login times, API token usage, configuration changes, and feature usage for audit trail and security purposes.
1.4 Cookies and Session Data
We use strictly necessary session cookies to maintain your authenticated session and CSRF protection tokens. No third-party advertising or tracking cookies are used.
2. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract performance: to provide and maintain the Services you have subscribed to.
- Legitimate interests: to detect and mitigate network attacks, maintain the security and integrity of our infrastructure, and prevent fraud.
- Legal obligation: to comply with applicable laws, regulations, and law enforcement requests.
3. How We Use Your Information
- Providing, operating, and improving the Services.
- Detecting, analysing, and mitigating DDoS attacks and network abuse.
- Generating anonymised threat intelligence and aggregate statistics.
- Sending service-related notifications and security alerts.
- Responding to support requests and abuse reports.
- Complying with legal obligations.
4. Data Retention
Network telemetry and packet sample data is retained for up to 90 days in our ClickHouse database, after which it is automatically purged. Account information is retained for the duration of your contract plus a period necessary to comply with legal obligations (typically up to 3 years). Audit logs are retained for 12 months.
5. Data Sharing
We do not sell your personal data. We may share data with:
- Infrastructure providers: hosting and network providers used to deliver our Services, under appropriate data processing agreements.
- Law enforcement: where required by court order, legal process, or to prevent imminent harm.
- Security partners: anonymised or aggregated threat intelligence may be shared with trusted security communities (e.g. abuse databases) to improve global network security.
6. Data Security
We implement appropriate technical and organisational measures to protect your data, including: encrypted storage, TLS 1.2+ for all data in transit, role-based access control, 2FA enforcement for panel accounts, and regular security assessments of our infrastructure.
7. Your Rights
Subject to applicable law and where you are an EU/EEA resident, you have the right to: access, rectify, or erase your personal data; restrict or object to processing; and data portability. To exercise these rights, contact us at noc@five-host.com. We will respond within 30 days.
8. Cookies
We use only strictly necessary cookies: a session cookie for authentication and a CSRF token cookie for security. These cookies are essential for the Services to function and cannot be disabled. They do not track you across other websites.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by email or via a panel notice.
10. Contact
For privacy-related inquiries:
FIVE CYBER HOST SECURITY SRL · AS210718
noc@five-host.com