Last updated: 29 August 2026
This Privacy Policy explains how boxbank s.r.o., operating under the WEBDANGER brand, collects, uses, stores, shares and otherwise processes personal data in connection with WEBDANGER websites, applications, accounts, client dashboards, purchases, subscriptions, projects, domains, hosting, cloud, servers, support, AI-enabled features and related services.
It also explains the rights available to individuals and how to contact us about privacy.
We aim to process personal data lawfully, fairly, transparently and proportionately.
References in this Policy to a provider, feature or category of processing that is described conditionally (for example, “where used”, “where enabled” or “may”) apply only when that provider, feature or processing activity is actually active for the relevant Service. WEBDANGER keeps its production data inventory and provider disclosures under review as the platform changes.
1. Who we are
WEBDANGER is operated by:
boxbank s.r.o.
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Company identification number (IČO):
24048232
Commercial Register:
Registered in the Commercial Register maintained by the Municipal Court in Prague (Městský soud v Praze), Section C, File No. 437675.
Primary website:
webdanger.com
Privacy contact:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
For privacy requests, email is the preferred channel because it provides a written record.
2. Controller
For personal data that WEBDANGER processes for its own purposes, the controller is boxbank s.r.o.
This includes, for example, processing relating to visitors to WEBDANGER websites, prospective customers, account holders, purchasers, billing contacts, support contacts, fraud and security monitoring, marketing administration, legal compliance, contractual records, and WEBDANGER's own business operations.
3. When WEBDANGER acts as a processor
For some Services, a Customer may upload, host, transmit or otherwise make personal data available to WEBDANGER and determine why that personal data is processed.
Examples may include Customer websites, databases, CRM systems, application users, mailing lists, backups, files uploaded to hosting, analytics datasets, support databases, or personal data processed through a custom application on the Customer's instructions.
In those situations, the Customer may be the controller and WEBDANGER may act as a processor.
Processor activities are governed by the applicable contract and, where required, a Data Processing Addendum (“DPA”).
This Privacy Policy primarily describes processing for which boxbank s.r.o. acts as controller. It does not replace the Customer's own privacy notice where the Customer is the controller.
If you are an end user of one of our Customers and your question concerns data controlled by that Customer, you should normally contact that Customer first.
4. Joint or independent controller situations
Some external providers may process certain information as our processor, subprocessor, independent controller or, in limited cases, joint controller, depending on the service and processing purpose.
For example, payment processors, registrars, fraud-prevention providers and advertising platforms may process some data under their own legal obligations and purposes.
5. Scope
This Privacy Policy may apply to personal data processed through:
- webdanger.com and WEBDANGER subdomains;
- registration and user accounts;
- client and administrative dashboards;
- billing interfaces;
- internal service-credit balances;
- checkout;
- Stripe or other payment integrations;
- bank-transfer and invoice payments;
- domain registration and management;
- hosting, cloud and virtual servers;
- backups;
- DNS/CDN services;
- website and software projects;
- CRM/ERP products;
- APIs;
- monitoring and security tools;
- support systems;
- chat and AI assistants;
- analytics and marketing;
- and other WEBDANGER Services.
A specific Service may provide additional privacy information.
6. What counts as personal data
“Personal data” means information relating to an identified or identifiable natural person.
Depending on context, this may include name, email, telephone number, postal address, online identifiers, account identifiers, IP address, device information, domain-registration information, billing information, payment metadata, communications, project files and usage logs.
Information does not cease to be personal data merely because it is publicly available.
DATA WE MAY PROCESS
7. Account and identity data
When you create or use a WEBDANGER account, we may process:
- first and last name;
- display name;
- email address;
- telephone number;
- country;
- language;
- preferred currency;
- account ID and status;
- creation date;
- last-login information;
- authentication events;
- password hash;
- multi-factor-authentication configuration;
- and account-security information.
For WEBDANGER-managed password authentication, plaintext passwords must not be retained as the stored authentication credential; passwords are represented using an appropriate one-way password-hashing mechanism.
8. Business and professional data
For Business Customers or professional contacts, we may process:
- company name and trading name;
- job title;
- professional email and phone;
- company address;
- company identification number;
- VAT/tax identification information where relevant and lawful;
- billing contacts;
- authorised representatives;
- and other business-registration information.
9. Consumer data
Where a Customer purchases as a Consumer, we may process information required to identify the Customer, conclude and perform the contract, deliver legally required consumer information, record withdrawal requests, handle complaints, process refunds, demonstrate contract acceptance and comply with consumer-protection obligations.
10. Order, contract and evidence data
We may process records showing:
- the Service ordered;
- quotation and Statement of Work;
- applicable price and currency;
- order date;
- Terms version;
- accepted policies;
- checkboxes and consents;
- withdrawal information;
- request to begin performance early;
- Project milestones and approvals;
- revisions and Change Requests;
- delivery events;
- subscription state and renewals;
- cancellations;
- refunds;
- and dispute history.
We process such records to perform contracts, administer Services, resolve disputes, meet legal obligations and establish or defend legal claims.
11. WEBDANGER Service Credit Balance
WEBDANGER may provide an internal Service Credit Balance within a Customer account.
The Service Credit Balance may allow a Customer to prepay or hold credit for the future purchase or renewal of eligible WEBDANGER Services.
We may process:
- credit-balance amount;
- currency or denomination;
- top-up amount and date;
- payment-source metadata;
- credit grants and promotional credits;
- debits;
- purchases funded using credits;
- refunds or reversals;
- expiration where lawfully applicable;
- fraud/security flags;
- and ledger history.
The WEBDANGER Service Credit Balance is intended as an internal mechanism for purchasing eligible WEBDANGER Services.
Unless a separate regulated product is expressly introduced, it is not presented as a bank account, deposit account, payment account, investment product or general-purpose money-transfer service.
The Service Credit Balance is not intended for peer-to-peer transfers or purchases from unrelated third-party merchants.
If a legally required cash refund is due, the refund may be returned through the original or another legally appropriate payment method rather than through an unrestricted transferable balance.
12. Payment and billing data
When you make or receive a payment in connection with WEBDANGER, we may process:
- payer/customer name;
- billing address;
- company details;
- invoice details;
- bank-transfer reference;
- IBAN/account details visible to us through a bank transaction where applicable;
- transaction identifier;
- payment-provider customer ID;
- payment-intent or charge ID;
- payment status;
- amount and currency;
- date/time;
- refund information;
- chargeback/dispute information;
- card brand and last four digits where supplied by the processor;
- and fraud/risk information.
Where card payment is handled by a payment processor such as Stripe, WEBDANGER does not need to receive or store the complete card number or card security code (CVC/CVV) in its own application database.
Payment providers may process payment information under their own legal and regulatory obligations.
13. Domain-registration data
When you register, transfer, renew, restore or manage a domain through WEBDANGER, we may process data required by the applicable registry, sponsoring registrar, ICANN policy, country-code registry, TLD policy or law.
This may include:
- registrant name;
- organisation;
- postal address;
- country;
- email;
- telephone number;
- business details;
- domain name;
- registration dates;
- nameserver information;
- domain status;
- verification status;
- transfer status;
- registrar/registry identifiers;
- and documentation required for a specific TLD.
Some TLDs may require additional eligibility or identity information.
We collect only data reasonably required for the relevant registration, management, compliance or security purpose.
14. Domain-registration recipients
Domain-registration data may need to be sent to or made available to:
- an upstream domain provider;
- sponsoring registrar;
- domain registry;
- ICANN-authorised system or process;
- dispute-resolution provider;
- competent authority;
- or another entity required for registration and administration.
WEBDANGER may use an upstream provider such as Openprovider where that integration is active.
The exact registrar/registry chain depends on the relevant TLD.
15. Hosting, cloud and server data
When you purchase or use hosting, cloud or server Services, we may process:
- Customer account information;
- server identifiers;
- IP addresses;
- server region;
- resource usage;
- bandwidth and storage use;
- operating-system information;
- configuration;
- access and authentication logs;
- infrastructure logs;
- billing information;
- abuse/security events;
- backup metadata;
- and support records.
Where Customer content stored on infrastructure contains personal data controlled by the Customer, WEBDANGER generally processes that content on the Customer's instructions under the applicable DPA.
16. Customer content
Depending on the Service, Customer content may include:
- website files;
- databases;
- media;
- source code;
- documents;
- customer lists;
- end-user information;
- CRM records;
- application content;
- uploaded files;
- backups;
- and other material submitted to a Service.
WEBDANGER does not treat Customer-controlled hosted content as its own general marketing database.
Access to Customer content is limited to circumstances such as supplying the Service, responding to support, security, backup/recovery, lawful abuse handling or legal compliance, subject to the applicable role, contract and permissions.
17. Project and development data
When WEBDANGER designs or develops a website, application, software system or other Project, we may process:
- project requirements;
- business information;
- branding and logos;
- content and photographs;
- files and source code;
- repository information;
- development tickets;
- staging URLs;
- test data;
- integration information;
- API configuration;
- feedback;
- milestone approvals;
- and Customer communications.
Customers should avoid supplying real personal data in development/test environments where representative synthetic data can reasonably be used.
18. Credentials and secrets
A Project may require access to hosting, DNS, registrar, CMS, API, analytics, advertising, repository, email or other Customer systems.
Where possible, we prefer delegated access, role-based accounts, scoped API tokens, temporary credentials, secret-management tools and credential rotation instead of permanent master passwords.
WEBDANGER does not intentionally use ordinary application logs or analytics systems as storage for plaintext credentials.
19. Support and communications data
When you contact us, we may process:
- name;
- email;
- phone;
- account ID;
- company;
- order;
- message;
- attachments;
- chat history;
- support-ticket information;
- diagnostic details;
- resolution;
- and related correspondence.
We may retain communications where reasonably necessary for support continuity, contract performance, complaints, fraud prevention, quality assurance, security, evidence or legal compliance.
20. Website forms and enquiries
If you use a form on our website, we may collect information such as name, email, phone, company, website, domain, country, selected Service, budget range, Project description, preferred contact method and attachments.
Form fields are limited to what is reasonably necessary for the relevant form and purpose.
21. Website and device data
When you use WEBDANGER websites or online Services, our systems or service providers may process:
- IP address;
- date and time;
- requested URL;
- HTTP request information;
- referrer;
- browser;
- operating system;
- device type;
- language;
- approximate region inferred from IP;
- cookies or similar identifiers;
- session information;
- and network/security signals.
IP addresses and security logs may constitute personal data.
22. Authentication and security logs
We may process logs relating to successful and failed login, password reset, MFA activity, session issuance/revocation, account changes, administrative actions, API keys, access-control changes, rate limits, suspicious activity, attacks, malware, abuse, fraud and security incidents.
These records are used to protect WEBDANGER, Customers, users and third parties.
23. Usage and product analytics
Depending on consent requirements and configuration, we may process information about pages visited, feature usage, button interactions, account activity, Service usage, conversion events, campaign source, error events, performance and aggregate product metrics.
Non-essential analytics and tracking technologies are subject to the applicable Cookie & Tracking Policy and consent controls where required.
24. Advertising and attribution data
Where advertising or retargeting tools are activated and legally permitted, we may process or share identifiers and events for campaign measurement, attribution, audience measurement, conversion tracking, retargeting and advertising optimisation.
Providers may include, when actually activated:
- Google;
- Meta;
- Microsoft;
- Seznam/Sklik;
- LinkedIn;
- TikTok;
- or other advertising providers.
Such tools will be reflected in the current Cookie & Tracking Policy and consent manager.
WEBDANGER will not activate consent-dependent advertising technologies before the required consent has been obtained in jurisdictions where prior consent is required.
25. Chat data
If WEBDANGER provides chat, we may process text entered into chat, account/session information, attachments, support context, selected Service, timestamps and technical metadata.
Do not submit sensitive or confidential data to a public pre-sales chat unless it is reasonably necessary and the interface is intended to receive such information.
26. AI-enabled features and AI-assisted work
WEBDANGER may use artificial-intelligence systems for purposes such as chat, coding, debugging, document analysis, design assistance, support assistance, classification, translation, summarisation, automation, security analysis and other product or delivery workflows.
Depending on the feature, data sent to an AI provider may include prompt text, chat messages, source-code fragments, project context, documents, attachments, technical logs or other content necessary for the requested operation.
WEBDANGER may use AI-routing or model providers such as OpenRouter where that integration is active.
The actual downstream AI model/provider may vary according to configuration.
We aim to configure AI use in a manner appropriate to the sensitivity of the data, including limiting retention or training use where suitable controls are available.
Customers should not intentionally send special-category, highly sensitive or regulated personal data to an AI feature unless the feature is expressly intended and contractually approved for that use.
More detailed information may be provided in our Data & AI Transparency Notice and DPA.
27. Error and performance monitoring
Where error-monitoring or application-observability services are enabled, we may process error messages, stack traces, URL, browser/device information, account or pseudonymous user identifiers, IP addresses where applicable, application state, performance timing and technical context.
We seek to configure monitoring so that passwords, complete payment-card details and unnecessary Customer content are not captured.
28. Publicly available business information
WEBDANGER may process limited business/professional information obtained from publicly available sources for legitimate business purposes such as:
- identifying potential commercial partners;
- market research;
- understanding businesses that may need our Services;
- maintaining business directories;
- fraud/security verification;
- or preparing relevant business outreach where lawful.
Sources may include company websites, public business registers, professional directories, public professional profiles, public maps/business listings and similar sources.
The categories processed in this context are generally limited to professional or business-related information such as a person's name, professional role or title, organisation, publicly listed business contact details, business location, company website, public professional-profile URL, industry/category and other information directly relevant to the business context.
Public availability does not mean that personal data can be used without legal restrictions.
Where Article 14 GDPR or another transparency rule applies, WEBDANGER will provide the required privacy information within the applicable time.
For electronic commercial communications, WEBDANGER follows applicable direct-marketing rules. Publicly available email addresses or phone numbers are not treated as blanket permission to send unsolicited electronic advertising.
29. Marketing data
Where permitted by law, we may process email address, name, customer status, previous Services, marketing preferences, campaign interactions and relevant business interests for marketing purposes.
The legal basis and consent requirements depend on the recipient, jurisdiction, existing customer relationship, type of communication and channel.
Where prior consent is required, we will request it.
Where a lawful existing-customer exception applies, we may send offers concerning similar products or services, subject to the required opt-out mechanism.
You can object to direct marketing at any time.
Every marketing email will provide an easy opt-out where required.
Opting out of marketing does not stop necessary operational messages such as invoices, password resets, security notices, domain-expiration notices or service notices.
30. Marketing suppression data
If you opt out of marketing, we may retain limited information such as email address, telephone number, opt-out status, date and source on a suppression list.
This helps us respect your request and avoid re-adding you to a campaign.
31. Recruitment data
If WEBDANGER accepts applications for employment, contracting or collaboration, we may process name, contact details, CV, employment history, education, portfolio, professional profile, interview notes, compensation expectations and other information supplied by the candidate.
A separate recruitment notice may be provided where appropriate.
32. Identity-verification data
WEBDANGER does not ordinarily require a passport or identity document merely to browse the website.
However, identity or verification data may be required for a TLD/registry requirement, registrar verification, fraud investigation, sanctions screening, account recovery, high-risk transaction review, legal obligation or a valid rights request where identity cannot otherwise reasonably be confirmed.
We aim to avoid retaining copies of identity documents longer than necessary.
33. Special-category and highly sensitive data
WEBDANGER does not intentionally request special-category personal data for ordinary website, hosting, domain or web-development Services.
This includes information concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health, sex life or sexual orientation.
Do not provide such information unless the relevant Service expressly requires it and appropriate legal and security arrangements are in place.
34. Children
WEBDANGER's commercial Services are not directed at children.
A person entering into a paid WEBDANGER contract should generally be at least 18 years old or act through a lawful representative.
We do not knowingly design our ordinary commercial account system to collect children's personal data as customers.
Customer-hosted websites may have their own audiences. Where WEBDANGER acts only as processor for Customer content, the Customer remains responsible for determining lawful basis and child-protection requirements applicable to its service.
SOURCES OF DATA
35. Data you provide directly
We may receive personal data directly when you register, complete a form, purchase a Service, top up a Service Credit Balance, pay an invoice, register a domain, configure hosting, upload a file, communicate with support, use chat, submit a privacy request or otherwise interact with us.
36. Data generated by your use
We may generate or collect data through your use of the Services, such as logs, account activity, Service usage, transaction history, domain events, server events, security events and support history.
37. Data from payment and financial providers
We may receive information from Stripe, banks, payment providers and fraud-prevention systems.
We generally receive payment status and transaction metadata rather than complete card credentials.
38. Data from domain providers
For domain Services, we may receive data from Openprovider, sponsoring registrars, registries, ICANN-related systems, WHOIS/RDAP services where lawful and TLD verification systems.
39. Data from infrastructure and security providers
We may receive network, security, performance or account data from providers such as Cloudflare, Hetzner, hosting infrastructure, security tools, monitoring providers and other technical vendors actually used by WEBDANGER.
40. Public sources
As described above, we may obtain limited professional/business information from public sources.
Where GDPR Article 14 applies, we will provide required transparency information unless a lawful exception applies.
41. Customers and authorised users
A company Customer may provide information about employees, contractors, administrators, billing contacts, authorised users, domain contacts or other representatives.
The Customer should ensure it has authority to provide such information where required.
WHY WE PROCESS PERSONAL DATA
42. Contract performance
We may process personal data where necessary to take steps at your request before a contract, create your account, process an Order, provide a Service, create or maintain a Project, register a domain, operate hosting, maintain a server, manage subscriptions, administer Service Credits, provide support, bill you, deliver work and otherwise perform the contract.
For GDPR purposes, this is generally based on Article 6(1)(b) where the individual is the contracting party.
For a corporate Customer's employee or representative, legitimate interests may be the more appropriate basis because the individual is not personally party to the contract.
43. Legal obligations
We may process data where necessary to comply with legal obligations, such as accounting, tax, corporate law, consumer law, valid authority requests, court orders, domain-registration obligations and record-retention requirements.
For GDPR purposes, this is generally based on Article 6(1)(c).
44. Legitimate interests
Where permitted, we may rely on legitimate interests including:
- securing systems;
- preventing fraud;
- detecting abuse;
- operating and improving Services;
- managing business relationships;
- establishing and defending legal claims;
- maintaining contractual evidence;
- network security;
- service analytics that do not require consent;
- B2B relationship management;
- limited market research;
- and direct marketing where applicable law permits that basis.
Before relying on legitimate interests for processing that may materially affect individuals, we assess whether our interests are overridden by their rights and freedoms.
For GDPR purposes, this is generally based on Article 6(1)(f).
45. Consent
We rely on consent where required, including potentially for non-essential cookies, certain analytics, advertising/retargeting, some marketing, optional AI/data uses or another processing activity where consent is appropriate.
For GDPR purposes, this is generally Article 6(1)(a).
Consent can be withdrawn at any time for future processing.
46. Other lawful bases
In uncommon circumstances, another lawful basis may apply, for example protection of vital interests where necessary.
WEBDANGER does not ordinarily rely on public-task powers.
47. Contract data that is required
Some data is necessary to enter into or perform a contract.
We may be unable to provide a Service if you do not provide contact information, billing data, information required for domain registration, Service configuration or another necessary contractual input.
Fields that are not required for the relevant purpose are identified or treated as optional where appropriate.
SPECIFIC PURPOSES
48. Account operation
We use account data to register and authenticate users, maintain sessions, provide dashboards, manage permissions, show purchases, manage balances, manage domains, manage servers and support account recovery.
49. Internal credit ledger
We process Service Credit Balance data to record top-ups and credits, pay for eligible WEBDANGER Services, reconcile transactions, prevent double-spending and fraud, process reversals/refunds, maintain accounting records and answer Customer questions.
We use a ledger/history rather than silently modifying account balances without an auditable transaction record.
50. Payment processing
We process payment information to collect money, confirm payment, issue invoices, reconcile bank transfers, prevent fraud, manage subscriptions, provide refunds and handle chargebacks/disputes.
51. Domain administration
We process registration data to check availability, register, verify, renew, transfer, restore, administer nameservers, respond to registrar/registry requirements and maintain required records.
52. Hosting and server operation
We process infrastructure data to provision Services, allocate resources, monitor availability, secure infrastructure, prevent abuse, support Customers, bill usage, maintain backups where included and comply with legal obligations.
53. Websites and software projects
We process Project data to understand requirements, create Deliverables, communicate, test, deploy, document, provide revisions, maintain projects and establish what was approved or delivered.
54. Support
We process support information to answer questions, diagnose problems, restore access, investigate errors, handle complaints and improve support.
55. Security
We process security data to detect attacks, prevent account takeover, investigate malware, block abuse, enforce rate limits, identify compromised credentials and protect infrastructure.
56. Fraud, payment risk and chargebacks
We may process transaction, account, device and activity information to identify fraud, validate suspicious transactions, respond to payment disputes, demonstrate delivery, prevent repeated abuse and protect WEBDANGER and other users.
We do not fabricate evidence.
57. Sanctions and legal restrictions
Where appropriate, we may process information needed to evaluate whether a transaction, Customer or Service is restricted by EU sanctions, Czech sanctions obligations, export controls, payment-provider restrictions or other binding law.
Screening must be proportionate to the risk and Service.
58. Service improvement
We may use appropriately limited product information to identify errors, improve usability, understand feature adoption, improve performance, plan infrastructure and improve security.
Where consent is legally required for the collection method, we obtain consent.
COOKIES AND TRACKING
59. Cookies
WEBDANGER may use cookies and similar technologies, including strictly necessary, authentication, security, preference, analytics and advertising technologies.
Detailed information is provided in the Cookie & Tracking Policy.
60. Consent management
Where law requires prior consent, non-essential cookies or similar technologies will not be activated before valid consent.
Where consent controls apply, users are provided with controls to accept, reject and manage the relevant categories without unnecessary friction.
61. Consent records
Where consent is the legal basis, we may retain evidence such as consent category, policy version, timestamp, withdrawal and technical identifier necessary to demonstrate the choice.
RECIPIENTS AND SERVICE PROVIDERS
62. General recipient categories
We may disclose or make data available to recipients such as:
- hosting/cloud providers;
- CDN/DNS/security providers;
- payment processors and banks;
- registrars and registries;
- email/communications providers;
- support providers;
- analytics and advertising providers;
- AI providers;
- development and error-monitoring providers;
- professional advisers;
- courts and authorities;
- and persons involved in a corporate transaction.
Personal data is disclosed only to recipient categories relevant to the applicable purpose, subject to applicable law and contractual requirements.
63. Hetzner — active production infrastructure
WEBDANGER currently uses Hetzner to host its production application and supporting infrastructure. Depending on the relevant Service, Hetzner may process infrastructure-hosted data, IP addresses, connection metadata, logs and Customer data stored through WEBDANGER. Customer-facing automated server provisioning is a separate feature and is not active unless explicitly made available in the applicable product interface.
64. Resend — active transactional email
WEBDANGER currently uses Resend to deliver transactional email such as account verification and password-reset messages. Resend receives the destination email address, message content and technical delivery metadata required to provide and secure that service.
65. Zoho Mail — active business communications
WEBDANGER currently uses Zoho Mail for business, support and legal communications sent to or from WEBDANGER email addresses. Zoho may process sender and recipient details, message content, attachments and technical delivery metadata.
66. Openprovider and domain infrastructure
Openprovider is WEBDANGER's selected upstream provider for domain registration and related domain operations. When a Customer searches for, registers, renews, transfers or manages a domain through WEBDANGER, the registration data required for that operation may be processed by Openprovider and the relevant sponsoring registrar, registry, ICANN-related system or verification provider.
The Customer remains the registrant of a Customer domain unless the applicable order expressly and lawfully states otherwise. Provider credentials are never exposed to the browser. This section applies when the relevant domain Service is made available and used; it does not represent that every domain feature is available in every market or for every top-level domain.
67. Hetzner Cloud customer infrastructure
Hetzner Cloud is WEBDANGER's selected upstream infrastructure provider for Customer cloud servers. When a Customer orders or manages an eligible WEBDANGER Cloud Service, Hetzner may process server configuration, IP addresses, infrastructure metadata, logs and Customer data hosted on that infrastructure as required to provide and secure the Service.
WEBDANGER remains the Customer-facing service provider and does not expose Hetzner credentials to Customers. Availability, locations, features and capacity remain subject to the applicable WEBDANGER product description and upstream technical availability.
68. Payments and AI providers
Stripe, Comgate and OpenRouter are not described as active Customer-data recipients unless and until the corresponding production integration is enabled. Before activation, WEBDANGER will identify the relevant purpose, data categories, provider role, retention and international-transfer safeguards.
68A. Namecheap and Cloudflare
The webdanger.com domain may be registered through Namecheap. That fact alone does not make Namecheap a processor of ordinary WEBDANGER Customer data. Cloudflare is not described as an active Customer-data recipient unless a Cloudflare product that processes such data is actually enabled and reflected in the current provider information.
69. Analytics and advertising providers
Analytics and advertising providers that are actually activated are identified in the applicable Cookie & Tracking Policy and consent-management interface.
WEBDANGER will not maintain an intentionally misleading provider list that names tools that are not actually deployed.
70. Professional advisers
We may provide information to accountants, auditors, lawyers, tax advisers, security consultants or insurers where reasonably necessary and subject to appropriate confidentiality duties.
71. Authorities and legal disclosures
We may disclose data where required by law, court order, binding authority request, applicable domain policy or another valid legal process.
We may challenge or narrow requests where legally available and appropriate.
72. Corporate transactions
If all or part of the WEBDANGER business is reorganised, financed, acquired, sold or merged, relevant personal data may be shared with professional advisers and prospective or actual transaction parties subject to appropriate safeguards.
INTERNATIONAL DATA TRANSFERS
73. International transfers
Because WEBDANGER uses global technology providers and serves international Customers, personal data may be processed in countries outside the country in which the individual is located.
Where GDPR applies to a transfer outside the European Economic Area, WEBDANGER uses a transfer mechanism permitted by Chapter V GDPR where required, which may include adequacy decisions, Standard Contractual Clauses or another legally approved safeguard.
74. Transfer risk
Data-protection laws and government-access rules may differ between countries.
Where required, WEBDANGER and/or the relevant provider assess transfer safeguards and implement supplementary technical, contractual or organisational measures as appropriate.
75. United Kingdom transfers
Where UK data-protection law applies, international transfers are handled using mechanisms permitted under UK law as amended by the Data (Use and Access) Act 2025.
76. Brazil transfers
Where Brazil's LGPD and ANPD international-transfer rules apply, WEBDANGER will use a legally recognised transfer mechanism and provide the transparency required by applicable Brazilian law.
For a targeted Brazilian service, required international-transfer information must be made available in Portuguese in the manner required by ANPD rules.
RETENTION
77. Retention principle
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing Services, account operation, legal obligations, accounting, security, fraud prevention, complaints, domain obligations, backups and establishing, exercising or defending legal claims.
78. Indicative retention schedule
Unless a different period is required by law, contract, litigation hold, registrar/registry requirement or another justified purpose, WEBDANGER aims to apply a schedule broadly along the following lines.
Enquiries and leads that do not become Customers
Usually up to 24 months from the last meaningful contact.
Marketing consent and preferences
For as long as the relevant marketing permission remains valid and is relied upon; after withdrawal or expiry, limited evidence may be retained for the period necessary to demonstrate compliance with applicable enforcement or limitation periods.
Suppression list
Limited identifier and opt-out record may be retained for as long as necessary to ensure the person is not mistakenly re-subscribed.
Account profile
For the life of the active account and thereafter only for the period needed to complete termination, resolve outstanding contractual or payment matters, meet legal obligations, prevent fraud/security abuse or preserve records needed for legal claims.
Contract / Order / SOW / acceptance evidence
For the contract and an appropriate period after termination based on statutory limitation, dispute and legal-record requirements.
Accounting records
Czech accounting documents and accounting books are generally retained for 5 years from the end of the relevant accounting period, while financial statements and annual reports are generally retained for 10 years, subject to statutory exceptions and future changes.
Payment transaction records
For accounting, fraud, dispute, chargeback and legal periods appropriate to the transaction and applicable provider/network requirements.
Service Credit ledger
For the active account and for accounting, dispute, fraud and legal-record periods after the balance or account is closed.
Domain-registration records
For the registration lifecycle and any additional period required by registrar, registry, ICANN policy, dispute process or law.
Support tickets
Usually up to 3 years after closure, unless needed for an active contract, security matter, complaint or legal claim.
Security/authentication logs
Usually between 90 days and 12 months depending on sensitivity, system, threat model and purpose. High-risk incidents or fraud evidence may be retained longer where justified.
Project files
For the Project, any agreed support or maintenance period, and thereafter only for the period justified by unresolved contractual obligations, security requirements or legal claims.
Backups
According to the relevant backup cycle. Deleted data may remain in rolling backups temporarily until overwritten or expired.
Privacy requests
For the time necessary to resolve the request and an additional period sufficient to demonstrate compliance and handle complaints.
Recruitment data
Ordinarily for the recruitment process and a limited period after completion unless the candidate validly agrees to longer talent-pool retention or law requires otherwise.
79. Litigation and legal holds
Retention may be extended where information is reasonably required for ongoing litigation, threatened claims, regulatory investigation, security incident, fraud investigation, debt recovery or another legal hold.
80. Backups
Deletion from the production environment may not result in immediate deletion from every backup.
Backup copies may remain until the relevant cycle expires.
We restrict ordinary access to backup data and do not restore deleted personal data merely for unrelated use.
YOUR RIGHTS
81. GDPR/EEA rights
Where GDPR applies, you may have rights including:
- right to be informed;
- right of access;
- right to rectification;
- right to erasure;
- right to restriction;
- right to data portability;
- right to object;
- rights concerning automated decision-making;
- and right to withdraw consent.
Rights are subject to legal conditions and exceptions.
82. Access
You may ask whether we process personal data about you and request a copy of personal data to which you have a legal right of access.
83. Correction
You may ask us to correct inaccurate personal data and, where appropriate, complete incomplete data.
84. Deletion
You may ask us to delete personal data where legal conditions are met.
Deletion is not absolute. We may retain information where necessary for legal obligations, accounting, legal claims, fraud prevention, domain obligations or another lawful exemption.
85. Restriction
Where applicable, you may ask us to restrict processing while a dispute concerning accuracy, lawfulness, objection or legal-claims retention is resolved.
86. Portability
Where processing is based on consent or contract and carried out by automated means, you may have a right to receive certain personal data in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.
This privacy right is separate from any EU Data Act switching right applicable to cloud/data-processing Services.
87. Objection
Where we rely on legitimate interests, you may object to the processing in circumstances provided by law.
88. Direct marketing objection
You may object to processing for direct marketing at any time.
When you object, we stop using your personal data for that direct-marketing purpose.
We may retain a suppression entry so that your opt-out is respected.
89. Withdraw consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal applies prospectively.
90. Automated decision-making
WEBDANGER may use automated tools for fraud detection, security, spam/abuse filtering, risk prioritisation, recommendations and AI-assisted processing.
Payment processors, registrars, security providers or other independent providers may also perform automated risk, fraud, security or compliance assessments under their own legal roles and policies.
WEBDANGER does not intend its own ordinary Services to subject individuals to solely automated decisions producing legal effects or similarly significant effects without the safeguards required by applicable law.
If WEBDANGER introduces solely automated decision-making that falls within Article 22 GDPR, the UK automated-decision framework or an equivalent applicable rule, WEBDANGER will provide the additional information, lawful basis and safeguards required by that law.
91. Exercising rights
Privacy requests may be sent to:
contact@webdanger.com
A dedicated privacy-request interface may also be made available.
Please describe who you are, the right you wish to exercise, the relevant account/Service and enough information for us to locate the relevant data.
Do not send unnecessary identity documents unless requested.
92. Identity verification for rights requests
We may request proportionate verification where necessary to avoid disclosing personal data to the wrong person.
Where existing account authentication is sufficient to verify a requester, WEBDANGER generally uses that method rather than automatically requesting government-issued identification.
93. GDPR response timing
Where GDPR applies, we generally respond to valid data-subject requests without undue delay and in any event within one month, subject to lawful extensions for complex or numerous requests.
COMPLAINTS AND AUTHORITIES
94. Privacy complaints to WEBDANGER
If you believe we have handled personal data incorrectly, please contact:
contact@webdanger.com
95. Czech supervisory authority
Our primary supervisory authority in the Czech Republic is:
Úřad pro ochranu osobních údajů Office for Personal Data Protection Pplk. Sochora 27 170 00 Praha 7 Czech Republic
Website:
https://uoou.gov.cz/
Your right to contact another competent supervisory authority where applicable is not restricted.
UNITED KINGDOM
96. UK privacy framework
Where UK data-protection law applies, WEBDANGER processes personal data in accordance with the UK GDPR and Data Protection Act framework as amended by the Data (Use and Access) Act 2025 (DUAA).
As of 19 June 2026, the data-protection provisions of the DUAA are in force.
97. UK privacy complaints procedure
Where UK complaint requirements apply, WEBDANGER will provide a clear way to raise a data-protection complaint.
WEBDANGER will:
- acknowledge an applicable complaint within 30 days;
- investigate it without undue delay;
- take appropriate steps;
- keep the complainant informed where appropriate;
- and communicate the outcome without undue delay.
A dedicated electronic privacy-complaint form may be provided.
98. UK Information Commissioner's Office
Individuals may also have the right to complain to the UK Information Commissioner's Office (“ICO”).
Website:
https://ico.org.uk/
UNITED STATES / CALIFORNIA
99. United States
United States privacy rights depend on the state, processing, business size and statutory thresholds.
Where a specific US privacy law applies to WEBDANGER, we will provide the notices, rights and opt-out mechanisms that law requires.
100. California online privacy notice
This Privacy Policy is intended to provide a conspicuous online privacy notice for WEBDANGER's collection of personal information, including where the California Online Privacy Protection Act (“CalOPPA”) applies.
Categories of personal data collected and categories of recipients are described throughout this Policy.
101. California “Do Not Track”
Browsers may transmit a “Do Not Track” signal.
There is no single universally adopted technical standard governing all Do Not Track signals.
Where California law requires recognition of an approved opt-out preference signal, such as a Global Privacy Control signal in a context subject to CCPA, WEBDANGER will implement the legally required response.
102. CCPA / CPRA where applicable
WEBDANGER does not assume that CCPA applies merely because a person in California visits the website.
If WEBDANGER meets applicable statutory thresholds, California residents may receive rights including, subject to law:
- right to know/access;
- right to delete;
- right to correct;
- right to opt out of sale/sharing;
- right to limit certain uses/disclosures of sensitive personal information;
- and right to non-discrimination.
103. Sale and sharing of personal information
WEBDANGER does not operate a personal-data brokerage business and does not sell Customer personal data as a product for cash consideration.
However, some US state laws define “sale” or “sharing” more broadly than an ordinary cash sale. In particular, certain transfers for cross-context behavioural advertising may qualify even where money is not paid specifically for the personal information.
If WEBDANGER engages in processing that constitutes regulated “sale” or “sharing” under an applicable US privacy law, WEBDANGER will provide the notices, contractual controls and opt-out mechanisms required by that law.
CANADA
104. Canada
Where Canadian private-sector privacy law applies, including PIPEDA or applicable provincial privacy law, WEBDANGER will process personal information in accordance with applicable Canadian requirements.
Additional provincial requirements may apply, including in Québec.
BRAZIL
105. Brazil / LGPD
Where Brazilian LGPD applies, individuals in Brazil may have rights provided by LGPD, subject to applicable conditions.
WEBDANGER will identify the lawful basis applicable to relevant processing and provide a Portuguese-language privacy layer where required for a targeted Brazilian Service.
106. Brazil international-transfer transparency
Where required by ANPD Resolution CD/ANPD No. 19/2024, WEBDANGER will make information available in Portuguese, in clear and accessible language, concerning international transfers, including as applicable:
- form;
- duration;
- purpose;
- destination country;
- controller identity/contact;
- data sharing;
- responsibilities;
- security measures;
- rights;
- and a channel for exercising rights and petitioning ANPD.
This English master is not intended to replace a mandatory Portuguese disclosure.
OTHER REGIONS
107. Other privacy laws
WEBDANGER may make its website available in multiple languages and jurisdictions.
A language option does not automatically mean that every WEBDANGER product has been legally launched in every country using that language.
Before intentionally targeting a jurisdiction with materially different privacy requirements, WEBDANGER may provide regional addenda, local-language notices, representatives, local contact points, local consent mechanisms or additional rights interfaces.
SECURITY
108. Security measures
WEBDANGER applies technical and organisational measures appropriate to the Service and the risks presented by the processing.
Depending on the Service and production deployment, measures may include encryption in transit, encryption at rest where appropriate, password hashing, MFA, access controls, least privilege, secret management, network and edge security, logging, monitoring, patching, backups, incident response, vulnerability management and provider due diligence.
No internet-connected system can be guaranteed absolutely secure.
109. Passwords
For WEBDANGER-managed password authentication, passwords are stored using an appropriate modern one-way password-hashing method rather than in plaintext.
We do not need to know your plaintext account password.
110. Payment-card security
Where a hosted or tokenised payment integration is used, complete payment-card details are handled by the payment processor and are not stored in the ordinary WEBDANGER application database.
111. Secret management
API keys, passwords, private keys and tokens supplied for Project work are handled using access controls and secret-management practices appropriate to their sensitivity.
WEBDANGER does not intentionally place secrets in analytics events, client-side public code, crash reports, public repositories, ordinary support notes or AI prompts unless the use is specifically necessary and appropriately safeguarded.
112. Breach response
Where WEBDANGER identifies a personal-data breach, we will investigate, contain/remediate where possible, assess risk, document the incident, notify the relevant controller where we act as processor and notify supervisory authorities/affected individuals where applicable law requires.
Under GDPR, a controller may be required to notify the supervisory authority within 72 hours after becoming aware of a qualifying personal-data breach.
DATA MINIMISATION AND PRODUCT DESIGN
113. Data minimisation
WEBDANGER aims to collect data that is adequate, relevant and limited to what is necessary for stated purposes.
114. Privacy by design
Where practical, WEBDANGER aims to build privacy into product architecture, including role-based access, minimum logging, configurable retention, deletion workflows, data export, separate marketing preferences, processor controls, secure defaults and separation of production/test data.
115. Data protection impact assessments
Where a planned processing activity is likely to result in a high risk to individuals, WEBDANGER will assess whether a Data Protection Impact Assessment (“DPIA”) is required before launch.
116. Records of processing
WEBDANGER maintains internal documentation of material processing activities to the extent required by applicable law and appropriate to the nature and scale of its operations.
AI AND AUTOMATED PROCESSING
117. AI provider selection
AI provider selection may vary by feature.
For Customer or personal data, WEBDANGER aims to consider retention, training use, subprocessor chain, security, region, contractual protections and transfer mechanism.
118. OpenRouter settings
Where OpenRouter is used, WEBDANGER may configure OpenRouter's privacy/data policies to restrict provider routing or prompt retention where appropriate.
OpenRouter states that prompt retention on its own platform is opt-in; underlying providers may have separate data policies.
119. Human review
Where an AI tool assists with decisions, support or Project work, WEBDANGER may use human review where appropriate to the risk and context.
DIRECT MARKETING AND PUBLIC DATA
120. Public data is not automatic marketing consent
Finding an email address or telephone number on a public website, directory, social profile, company register or map listing does not automatically create consent to send electronic commercial communications.
For Czech electronic marketing, WEBDANGER follows Act No. 480/2004 Coll. and related ÚOOÚ guidance.
Prospective recipients who are not existing Customers generally require the applicable prior consent for electronic commercial communications unless another specific lawful exception applies.
121. Existing-customer marketing
Where applicable law permits use of an existing Customer's electronic contact for marketing similar WEBDANGER Services, we will provide an opportunity to object when required, identify commercial communications appropriately and provide an easy opt-out in each message.
122. Legitimate interest and electronic marketing are separate questions
A GDPR legitimate interest may support some underlying personal-data processing, such as B2B relationship management or maintaining a prospect record.
It does not by itself override separate ePrivacy/electronic-communications rules governing whether a promotional email or SMS may actually be sent.
CHANGES
123. Changes to this Privacy Policy
WEBDANGER may update this Policy when Services, providers, laws, processing or jurisdictions change.
The current version will show its latest revision date.
Where a change materially affects processing and applicable law requires additional notice or consent, we will take the required steps.
124. Historical versions
WEBDANGER may retain archived Privacy Policy versions for accountability and to demonstrate what information was provided at a particular time.
CONTACT
125. Privacy contact
For privacy questions, rights requests or complaints:
boxbank s.r.o. / WEBDANGER Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Email:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
Email is recommended for privacy matters.
APPENDIX A — PROCESSING PURPOSE / LEGAL BASIS MATRIX
| Processing | Typical data | Typical GDPR basis |
|---|---|---|
| Pre-contract enquiries | Contact, Project requirements | Art. 6(1)(b), or Art. 6(1)(f) for corporate representatives |
| Account creation | Identity, email, security | Art. 6(1)(b) |
| Contract/order administration | Order, Terms, milestones | Art. 6(1)(b); Art. 6(1)(f); Art. 6(1)(c) where required |
| Service Credit Balance | Ledger, payments, purchases | Art. 6(1)(b); Art. 6(1)(c); Art. 6(1)(f) fraud/security |
| Payments | Billing, transaction metadata | Art. 6(1)(b); Art. 6(1)(c); Art. 6(1)(f) fraud/legal claims |
| Domain registration | Registrant, domain, contact | Art. 6(1)(b); Art. 6(1)(c); legitimate interests where appropriate |
| Hosting/server account administration | Account, infrastructure metadata | Art. 6(1)(b); Art. 6(1)(f) |
| Customer-hosted personal data | Customer-controlled content | Processor activity under Art. 28 / Customer instructions |
| Security logs | IP, authentication, event logs | Art. 6(1)(f); Art. 6(1)(c) where required |
| Support | Messages, account, diagnostics | Art. 6(1)(b); Art. 6(1)(f) |
| Contract evidence / disputes | Acceptance, delivery, communications | Art. 6(1)(f); Art. 6(1)(c) where applicable |
| Accounting | Invoices, transactions | Art. 6(1)(c) |
| Necessary cookies | Session/security data | Contract/legitimate interests plus applicable ePrivacy exemption |
| Non-essential analytics | Cookie/device analytics | Consent where required |
| Advertising / retargeting | Identifiers, events | Consent where required |
| Existing-customer similar-service marketing | Contact, customer relationship | Legitimate interests plus applicable electronic-marketing exception |
| Prospect/public business research | Public business information | Art. 6(1)(f), subject to balancing and Art. 14 transparency |
| Marketing to non-customers | Contact | Consent where required by electronic-marketing law |
| AI processing to deliver requested Service | Prompt/content | Art. 6(1)(b) or processor instructions; context dependent |
| Fraud prevention | Device/transaction/security data | Art. 6(1)(f); legal obligation where applicable |
| Privacy requests | Identity/request/history | Art. 6(1)(c); Art. 6(1)(f) compliance evidence |
APPENDIX B — CATEGORIES OF RECIPIENTS
Depending on Service:
- infrastructure/cloud providers;
- DNS/CDN/security providers;
- domain registrars and registries;
- payment processors;
- banking providers;
- email/communications providers;
- support providers;
- analytics providers;
- advertising providers;
- AI providers;
- monitoring/error providers;
- professional advisers;
- public authorities where legally required;
- corporate transaction participants subject to safeguards.
APPENDIX C — CONTROLLER / PROCESSOR EXAMPLES
WEBDANGER normally acts as controller for:
- its own website visitors;
- account registration;
- billing;
- Service Credit Balance;
- Stripe transaction administration;
- contract evidence;
- its own marketing;
- fraud/security;
- support administration;
- domain reseller administration where it determines its own purposes;
- legal compliance.
WEBDANGER normally acts as processor for:
- personal data a Customer stores in its hosting account;
- Customer databases;
- Customer CRM data;
- Customer application end-user data;
- Customer backups;
- personal data processed through a custom system solely on Customer instructions.
Mixed role example:
A hosting Customer controls the contents of its database, while WEBDANGER independently controls billing records, security logs necessary to protect WEBDANGER infrastructure, abuse records and contractual evidence.
Effective / review date: 29 August 2026