1. Who we are
This policy is issued by WipZen SAS ("WipZen", "we", "us"), a société par actions simplifiée registered in France under SIREN 487897894, listed on the RCS of Toulon, with its registered office at Les Maurels Bât. I1, Rond-Point des Commandos d’Afrique, 83400 Hyères, France.
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), WipZen SAS is the controller of the personal data described in this policy, except where section 13 states that we act as a processor on behalf of a customer.
We have not appointed a Data Protection Officer (délégué à la protection des données), as we are not required to under Article 37 GDPR. Privacy questions are handled directly by our compliance contact at [email protected].
2. Scope
This policy applies to:
- visitors to wipzen.com and its subdomains;
- people who create or administer a WipZen account, including sub-accounts;
- people who contact our support, sales or emergency channels; and
- end users — the players and clients whose connections traverse our network on the way to a customer's server.
It does not apply to the servers our customers operate. What a game server does with your account, chat messages or purchases is governed by that server's own policies, not by ours.
3. Data we collect
3.1 Account data
When you register we collect your email address, a hashed password, your display name, and — if you enable it — two-factor authentication secrets and recovery codes. Where you create sub-accounts, we collect the same for each.
3.2 Billing data
We collect your billing name, billing address, country, VAT identification number where supplied, and the invoices and payment records generated by your subscription.
We do not receive or store full card numbers. Card details are entered directly with our payment processor, which returns to us only a token, the card brand, the last four digits and the expiry date.
3.3 Configuration data
The domains, hostnames, origin addresses, firewall rules, CIDR entries and routing preferences you configure. Origin addresses are treated as confidential and are never exposed publicly by our systems.
3.4 Support data
The content of tickets, emails and emergency-line conversations, together with any diagnostics you choose to attach. Emergency calls may be recorded for incident review; you are told at the start of the call when they are.
3.5 Website data
Pages visited, referring URL, approximate location derived from IP at country level, browser and device type. See section 6.
4. Connection and traffic data
This section describes the processing that is specific to a DDoS mitigation service, and it is the part worth reading carefully.
To distinguish legitimate players from attack traffic, our edge necessarily observes, for every connection that reaches it:
- the source IP address and port;
- the destination hostname, address and port;
- protocol, packet sizes, packet rates and connection timings;
- TCP/UDP header characteristics and handshake behaviour; and
- the point of presence that handled the connection.
An IP address is personal data under the GDPR, so this observation is processing of personal data about end users, even though we hold no name, account or identity for them.
4.1 What we do not do
- We do not inspect or store the contents of your game sessions — chat, gameplay packets, voice audio, player positions or credentials.
- We do not build advertising, behavioural or identity profiles of end users.
- We do not sell, rent or licence traffic data to anyone, and we do not share it with data brokers.
4.2 The IP reputation database
On Enterprise plans we maintain a reputation database of addresses observed participating in attacks across our network. Entries record the address, the attack characteristics and timestamps. They are not linked to any player identity, expire automatically, and can be appealed by writing to [email protected].
5. Purposes and legal bases
| What we do | Data used | Legal basis |
|---|---|---|
| Provide the service, route traffic, apply your configuration | Account, configuration, traffic | Contract — Art. 6(1)(b) |
| Detect and mitigate attacks; protect our network and our customers | Traffic, connection metadata | Legitimate interests — Art. 6(1)(f), and Recital 49, which names network and information security as a legitimate interest |
| Take payment, issue invoices, meet tax obligations | Billing | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Answer support requests and staff the emergency line | Account, support, configuration | Contract — Art. 6(1)(b) |
| Investigate abuse of the service and enforce our Terms | Account, traffic, support | Legitimate interests — Art. 6(1)(f) |
| Send product news and marketing email | Account, email | Consent — Art. 6(1)(a), withdrawable at any time |
| Optional analytics on our marketing website | Website | Consent — Art. 6(1)(a) |
| Respond to lawful requests from authorities | Whatever is lawfully required | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that filtering attack traffic cannot be achieved by less intrusive means, that the data involved is limited to connection metadata, and that end users benefit directly because the service they are trying to reach stays available. You may object to this processing — see section 10.
6. Cookies and analytics
We use three categories of cookie and similar technology.
| Category | Purpose | Consent needed |
|---|---|---|
| Strictly necessary | Session, authentication, CSRF protection, load balancing, remembering your cookie choice | No |
| Preferences | Interface settings such as your default network and table density | No — set only after you change a setting |
| Analytics | Aggregate page and referral statistics on the marketing site | Yes |
Google Maps. Our About page embeds a Google Maps frame showing our office. The map loads only when you scroll to it, and loading it sends your IP address and browser details to Google, which may set its own cookies. If you would rather not load it, the same address is printed as plain text beside the map and blocking third-party frames in your browser will suppress it without affecting the rest of the site.
We do not use advertising cookies, cross-site tracking pixels or social media trackers. You can withdraw analytics consent at any time from the cookie link in the footer, and your browser settings can block or delete cookies — though blocking the strictly necessary ones will prevent you from signing in.
We honour Global Privacy Control signals as a withdrawal of consent to analytics.
7. Sharing and sub-processors
We do not sell personal data. We share it only as set out here.
| Category | What they receive | Where |
|---|---|---|
| Data centre and transit providers | Traffic in transit at each point of presence | EU, UK, US, SG, JP, AU, BR, ZA |
| Payment processor | Billing details and card data entered directly with them | EU / US |
| Transactional email provider | Email address and message content | EU |
| Support desk software | Ticket content and contact details | EU |
| Error and performance monitoring | Technical diagnostics, truncated IP addresses | EU |
| Google Maps (map embed on the About page only) | IP address and browser details of visitors who load the map | US |
Every sub-processor is bound by a written agreement meeting Article 28 GDPR. A current, named list is available on request from [email protected], and customers under a data processing agreement are notified before we add one.
We may also disclose personal data:
- to law enforcement or a regulator where we are legally required to, having first checked that the request is valid and proportionate;
- to our professional advisers where necessary and under a duty of confidence; and
- to a buyer in connection with a merger or acquisition, in which case you will be told before your data becomes subject to a different policy.
8. International transfers
Our network spans five continents, so traffic is necessarily processed outside the European Economic Area — a player connecting from Brazil is handled in São Paulo.
Where personal data leaves the EEA we rely on:
- an adequacy decision by the European Commission, where one covers the destination; or
- the Standard Contractual Clauses adopted in Commission Implementing Decision (EU) 2021/914, together with a transfer impact assessment and technical measures including encryption in transit.
Our own staff. WipZen’s support and engineering team works from our operations office in Tashkent, Uzbekistan, which is outside the EEA and is not covered by a European Commission adequacy decision. That team can access account data, support tickets and mitigation dashboards in order to answer you and to run the network. Access is role-based, logged, and limited to what each role needs, and the transfer is made under the safeguards described above.
You can request a copy of the safeguards applying to a specific transfer from [email protected].
9. How long we keep data
| Data | Retention | Why |
|---|---|---|
| Raw packet-level traffic data | Up to 72 hours | Live mitigation and immediate incident review |
| Aggregated traffic statistics | 13 months | Analytics, monthly reports, capacity planning. No individual IPs |
| Attack event records | 12 months | Incident history and repeat-attacker detection |
| IP reputation entries | 90 days from last observation | Blocking known attack sources |
| Account and configuration data | Life of the account, then 30 days | Providing the service; the window allows for reactivation |
| Invoices and accounting records | 10 years | Article L123-22 of the French Code de commerce |
| Support tickets | 24 months | Continuity of support and dispute handling |
| Emergency call recordings | 90 days | Post-incident review |
When a period ends, data is deleted or irreversibly aggregated. Backups roll off on their own schedule, and deletion requests are applied to backups as those cycles complete, within 90 days at the latest.
10. Your rights
Under the GDPR you have the rights below. They apply whether you are a customer, a visitor, or a player whose connection passed through our edge.
- Access (Art. 15)
- Get confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16)
- Have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17)
- Have your data deleted where we no longer need it, where you withdraw the consent it rested on, or where you successfully object.
- Restriction (Art. 18)
- Have processing paused while an accuracy dispute or objection is resolved.
- Portability (Art. 20)
- Receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Objection (Art. 21)
- Object to processing based on legitimate interests. You may object to direct marketing at any time and we will stop without exception.
- Withdraw consent (Art. 7(3))
- Withdraw consent at any time, which does not affect processing already carried out.
- Automated decisions (Art. 22)
- We take no decision producing legal effects about you by automated means alone. Automatic blocking is a network measure applied to traffic, and any customer-account decision is reviewed by a person.
10.1 Exercising your rights
Write to [email protected]. We reply within one month, extendable by two further months for complex requests, in which case we tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.
We may ask for information to confirm your identity — only what is necessary, and never more sensitive than what we already hold.
A note on end-user requests. If you were a player rather than a customer, we hold no account for you and cannot identify you from a name. If you can give us the approximate time and the IP address you were using, we can search our short-lived logs. Under Article 11 GDPR we are not obliged to acquire extra data purely to identify you, and after 72 hours the raw records will in any case be gone.
10.2 Complaints
You may lodge a complaint with a supervisory authority. Ours is the French Commission Nationale de l’Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr. You may also complain to the authority where you live or work. We would rather you gave us the chance to fix it first, but that is your choice, not a condition.
11. Security
Our technical and organisational measures include:
- encryption in transit for all dashboard and API traffic, and at rest for databases and backups;
- optional two-factor authentication on every plan, and mandatory on all WipZen staff accounts;
- role-based access control, with sub-accounts limited to what their role requires;
- least-privilege administrative access, reviewed quarterly and logged;
- network segregation between the mitigation edge, the control plane and the billing systems;
- independent penetration testing at least once a year; and
- a documented incident response plan, rehearsed periodically.
If a breach is likely to result in a risk to your rights and freedoms we notify the CNIL within 72 hours of becoming aware, and we notify you without undue delay where the risk is high.
Nobody can promise perfect security. We can promise that we will tell you plainly when something has gone wrong.
12. Children's data
Our service is sold to the operators of game servers, not to players. A WipZen account may only be created by someone aged 16 or over, or by an adult acting for an organisation. We do not knowingly allow younger account holders, and we close any account we discover to be held by one.
We are conscious that the players passing through our network include children. We hold no account, name, age or identity for them; the connection metadata described in section 4 is retained briefly and used only to separate players from attackers. We do not profile end users and we never direct marketing at them.
A parent or guardian who believes we hold data about their child should write to [email protected] and we will act promptly.
13. If you are our customer
The relationship works in two directions, and it is worth being precise about which is which.
- For your own account, billing and support data, WipZen is the controller and this policy governs.
- For the end-user connection data we handle in delivering the service to you, we act as your processor under Article 28 GDPR. You are the controller and decide the purposes.
A Data Processing Agreement incorporating the Article 28 terms and the Standard Contractual Clauses is available at [email protected] and is executed on request at no charge. As a controller you are responsible for telling your own players that their connections pass through a mitigation provider.
Separately, we are the controller of the security processing described in section 4, because protecting our own network is our own legitimate interest and not something you instruct us to do.
14. Changes to this policy
We update this policy when our processing changes. The version number and both dates at the top of the page always reflect the current text.
For material changes — a new purpose, a new category of data, a materially different retention period — we email account holders at least 30 days before the change takes effect. Superseded versions are archived and available from [email protected].
15. Contact us
Privacy questions and rights requests:
- Privacy and data protection
- [email protected]
- Legal and contractual
- [email protected]
- General support
- [email protected]
- Post
- WipZen SAS, Les Maurels Bât. I1, Rond-Point des Commandos d’Afrique, 83400 Hyères, France — SIREN 487897894, RCS Toulon, VAT FR69487897894
See also our Terms of Service, which govern your use of the service itself.