Last updated 19 August 2026
1. Who is responsible
APTRANET LIMITED (“Aptranet”, “we”, “us” or “our”) is the controller of personal data described in this Privacy Policy, except where we process data only on a customer’s instructions as explained in section 8. We are registered in England and Wales under company number 14849936. Our registered office is 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
This Policy covers www.aptranet.com, the Management Console, billing, support, and the personal data we handle as a provider of Cloud CDN and Cloud DNS. It does not cover independent third-party websites we link to.
We handle personal data in line with the UK GDPR, the Data Protection Act 2018, and the EU GDPR where it applies to people in the European Economic Area. Depending on where you live, other laws may also give you rights, including the California Consumer Privacy Act as amended by the CPRA.
2. Personal data we collect
The data we collect depends on how you use Aptranet.
Account and identity data. When you register or join an organisation we collect your name, email address, password or passkey data, organisation and project details, and role. We also store session and multi-factor authentication records.
Billing data. When you subscribe we collect billing profile details such as legal name, address, country, tax identifiers and contact email. Payment cards are collected and stored by Stripe. We receive tokens, last four digits, brand, expiry month and year, and payment status. We do not store full card numbers.
Enquiry data. Contact and emergency forms collect the fields you submit, including name, work email, company, optional phone number, country, role, topic or attack type, website, and message.
Security and usage data. We collect IP address, user agent, timestamps, requested URLs, and diagnostic logs needed to operate accounts, APIs and the Website. Score-based reCAPTCHA Enterprise assessments are created when you submit a protected form or sign in.
Service configuration data. For Cloud CDN and Cloud DNS we store the configuration you enter, such as hostnames, origins, zones and records. That configuration may include personal data if you put personal data into it.
We do not require special-category (sensitive) personal data to use Aptranet, and you should not send it to us through website forms. We do not knowingly collect personal data from children under 16.
3. How we collect it
- Directly from you, when you create an account, complete billing details, submit a form, email us, or call us.
- Automatically, through cookies, logs and security tools when you use the Website or Console.
- From people in your organisation who invite you or manage your access.
- From processors who help us run the service, including Stripe for payments and Google for reCAPTCHA assessments.
If you give us personal data about someone else, you must have the authority to do so.
4. Why we use personal data
We use personal data to:
- provide the Website, accounts, Cloud CDN, Cloud DNS and support — necessary to perform a contract or take steps at your request before a contract;
- bill you, collect payment, issue invoices and handle tax — contract and legal obligation;
- keep the service secure, prevent abuse and investigate incidents — legitimate interests and, where relevant, legal obligation;
- reply to sales, support and emergency requests — contract or legitimate interests;
- send transactional email such as verification, password reset, invitations and billing notices — contract;
- improve reliability and understand how the Website is used at an aggregate level — legitimate interests; and
- comply with law, including accounting, tax, sanctions and lawful requests — legal obligation.
We do not sell personal data. We do not use personal data for third-party advertising. We do not make solely automated decisions that produce legal or similarly significant effects about you.
5. Cookies and similar technologies
We use cookies and similar technologies as follows.
- Strictly necessary cookies for Management Console and admin sessions, including host-only session and CSRF cookies. These are required for sign-in and cannot be switched off if you use those products.
- Security: Google reCAPTCHA Enterprise on sign-in and public website forms, which may set cookies or read device signals to distinguish people from automated abuse.
- The Network page loads map tiles from a third-party tile service and flag images so published points of presence can be displayed. Those requests may be logged by those providers.
We do not currently use advertising cookies or a third-party marketing analytics suite on the public Website. Your browser controls can block cookies, but accounts and forms that rely on security cookies may then fail.
6. Who we share data with
We share personal data only as needed to run Aptranet:
- Stripe, for checkout, subscriptions, invoices, tax IDs and saved payment methods;
- Google, to create reCAPTCHA Enterprise assessments;
- our transactional email provider, to deliver verification, invitation and billing messages;
- infrastructure, hosting, object-storage and connectivity providers that carry the Website, Console and edge services;
- professional advisers, such as accountants or lawyers, under confidentiality duties; and
- a buyer or successor if we sell or reorganise the business, with notice where the law requires.
We may also disclose personal data if required by law, a court, or a competent public authority, or if we reasonably believe disclosure is necessary to protect rights, safety or the security of the service.
Staff and contractors only access personal data when their role requires it.
7. International transfers
We are established in the United Kingdom. Some processors, including payment and security providers, may handle data in the United States or other countries. Where we transfer personal data out of the UK or EEA to a country without an adequacy decision, we use the UK International Data Transfer Addendum and/or the European Commission Standard Contractual Clauses, together with appropriate technical and organisational measures.
Cloud CDN and Cloud DNS are delivered from many countries so that content and DNS answers can be served close to users. Traffic you send through those services will be processed at the locations needed to deliver it.
8. Customer traffic on Cloud CDN and Cloud DNS
When you use Cloud CDN or Cloud DNS, you decide what is published, which hostnames resolve, and which origins we fetch. For that customer traffic you are the controller (or a processor for your own customers). Aptranet is the processor. We process that traffic only to provide the service, keep it secure, measure usage for billing, and comply with law.
To operate a CDN and authoritative DNS we must make and store copies of objects and DNS data you ask us to serve, and we may log request metadata such as IP address, URL, response code, user agent and timing. We use those logs for security, abuse handling, debugging and usage metering. We do not use end-user request logs to build advertising profiles.
You must have a lawful basis to send personal data through the services and must not use Aptranet to process data that you are not allowed to process. A data processing addendum is available on request for customers that need one.
9. How long we keep data
We keep personal data only as long as needed for the purpose collected, including:
- account data, for the life of the account and a short period afterwards so we can close it securely;
- billing and invoice records, for the period required by UK tax and accounting law, typically six years;
- support and enquiry messages, for as long as needed to handle the request and keep a reasonable business record;
- security and access logs, for a limited operational period unless a longer period is needed for an investigation; and
- cached CDN objects and DNS records, for the time your configuration and cache rules require, then they are evicted or deleted.
When data is no longer required we delete it or irreversibly anonymise it.
10. Security
We use organisational and technical measures appropriate to the risk, including TLS for data in transit, access control, session security, and least-privilege access for staff. No method of transmission or storage is completely secure. You must also protect your own accounts, origins and DNS configuration.
If a personal-data breach is likely to result in a risk to people, we will notify the ICO and, where required, affected individuals.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to restrict or object to certain processing, to withdraw consent where we rely on it, and not to be discriminated against for exercising your rights. California residents may also have the right to opt out of “sale” or “sharing” as those words are defined in California law. We do not sell personal data.
To exercise these rights, email privacy@aptranet.com. We may need to verify your identity. We will respond within the time the law requires.
If you are in the United Kingdom you can complain to the Information Commissioner’s Office at ico.org.uk. If you are in the EEA you can complain to your local supervisory authority. We would rather resolve the issue first if you contact us.
12. Children
Aptranet is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact privacy@aptranet.com and we will delete it.
13. Changes to this Policy
We may update this Policy. The “Last updated” date will change when we do. If a change is material we will provide a more prominent notice, such as an email to account holders or a notice in the Console.
14. How to contact us
Privacy requests: privacy@aptranet.com.
Support and other enquiries: support@aptranet.com or Contact.
Postal address: APTRANET LIMITED, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.