Privacy Policy
Last updated: September 2026 · In accordance with the GDPR, BDSG and TMG
1. Data Controller
2. Data of Our Account Holders
2.1 When you visit this website
When you access edgeshield.one, our servers automatically process the following data in temporary log/telemetry records:
- IP address of the requesting device
- Date and time of access
- Requested path and referring website
- Browser type / User-Agent and operating system
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and stable operation of the website). These records are retained for a maximum of 14 days.
2.2 When you register an account
To create an account we collect:
- Email address
- Password (stored only as a salted hash — never in plain text)
- Timestamp of registration and the IP address at that time
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
2.3 When you use the service
While you use the EdgeShield dashboard and platform, we process:
- The domains you add and their configuration (protection mode, firewall rules, cache and DNS settings)
- The authoritative DNS zone records you create for your delegated domains
- Aggregated traffic, security and analytics statistics for your domains
- Account balance, plan and transaction history
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory retention of billing data — 10 years under § 147 AO).
2.4 Payments (cryptocurrency)
EdgeShield accepts cryptocurrency payments only, processed through our payment provider Plisio (see section 4). We store the wallet addresses and transaction hashes associated with your top-ups as proof of payment. These may constitute personal data under the GDPR and are used solely for billing and legal-compliance purposes.
Legal basis: Art. 6(1)(b) and Art. 6(1)(c) GDPR.
3. Visitor Data Processed on Behalf of Our Customers
Because EdgeShield is a web application firewall and reverse proxy, traffic to a protected customer domain passes through our edge network before reaching that customer's origin server. In doing so we process data relating to the end visitors of our customers' websites, including:
- The visitor's IP address (used to filter floods and bots, to apply rate limits, and for the country-level geolocation shown in analytics)
- Request metadata: requested path, User-Agent, referrer and headers
- A coarse country/region derived from the IP via an embedded MaxMind GeoLite2 database (no exact location)
- Passive TLS (JA4) and HTTP/2 fingerprints, and automated-client signals, used solely to distinguish real browsers from bots and attack tools
For this visitor data, the operator of the protected website is the data controller, and EdgeShield acts as a data processor on that operator's behalf. We process visitor data only to provide the security and delivery service the site operator has configured — never to build cross-site profiles, and never for advertising. This processing is short-lived: security counters and fingerprints are held only transiently for filtering decisions; sampled traffic records used for the operator's dashboard analytics are retained no longer than needed to produce those statistics.
Legal basis: Art. 6(1)(f) GDPR (the site operator's and our legitimate interest in protecting the website from attacks and abuse), on the instructions of the site operator (controller).
4. Third-Party Services
4.1 Plisio (payment processing)
Cryptocurrency payments are processed by Plisio. When you make a payment, the transaction data necessary to complete and verify it is shared with Plisio. Please refer to Plisio's own privacy policy for details of their processing.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
4.2 Google Fonts
Our pages load fonts from Google Fonts (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Your IP address is transmitted to Google, constituting a transfer to the USA; Google LLC is certified under the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR. Google's privacy policy: policies.google.com/privacy
4.3 MaxMind GeoLite2
We use an embedded MaxMind GeoLite2 database to derive a coarse country/region from an IP address for routing and analytics. The database runs locally on our own servers — no visitor IP is sent to MaxMind, and no exact location is determined.
5. Cookies
The EdgeShield dashboard uses only technically necessary cookies and local storage (e.g. your login session and your light/dark theme preference). These are required for the service to function and are not used for tracking or marketing. The security clearance cookie set on protected customer domains is a technically necessary anti-bot token, not a tracking cookie.
Legal basis: Art. 6(1)(f) GDPR and § 25(2) TTDSG.
6. Your Rights Under the GDPR
You have the following rights regarding your personal data:
- Access (Art. 15): information about the data we store about you.
- Rectification (Art. 16): correction of inaccurate data.
- Erasure (Art. 17): deletion of your data, unless legal retention obligations apply.
- Restriction (Art. 18): restriction of processing.
- Portability (Art. 20): your data in a machine-readable format.
- Objection (Art. 21): objection to processing based on legitimate interests.
- Complaint: the right to lodge a complaint with the competent supervisory authority.
To exercise your rights, contact us at admin@edgeshield.one. If you are a visitor of a website protected by EdgeShield and wish to exercise your rights regarding that visit, please contact the operator of that website (the controller); we will support them in responding.
7. Data Security
We apply appropriate technical and organizational measures to protect data against accidental or unlawful manipulation, loss, destruction or unauthorized access, and update them in line with technological developments. All data in transit is encrypted via HTTPS/TLS.
8. Retention Periods
- Website log/telemetry records: up to 14 days
- Account data: for the duration of the contract, then deleted within 30 days of termination
- Billing data: 10 years pursuant to § 147 AO (German Tax Code)
- Visitor security data (counters, fingerprints): transient — held only as long as needed for the filtering decision; sampled analytics records only as long as needed to produce the statistics
9. Changes to This Policy
We may update this Privacy Policy as needed. The current version is always available on this page. Registered users will be notified by email of any material changes.
