Privacy Policy

Last updated: 2026-05-03

1. Who We Are

This privacy policy describes how 33k Networks AB ("we", "us"), a Swedish limited company at backstugevägen 7, Sundbyberg, Sweden, processes personal data in connection with the DynIP service (https://dynip.dev). We are the data controller for personal data processed via the Service.

2. Data We Collect

Account data

  • Email address (used for login, verification, and notifications)
  • Hashed password (never stored in plaintext; bcrypt)
  • Optional: TOTP secret if 2FA is enabled
  • Account creation date, last login date

Service data

  • Zone names and DNS records you create
  • TSIG keys generated for your zones (for DNSUPDATE authentication)
  • TLS certificate metadata (expiry dates) and content (encrypted at rest)
  • IP addresses associated with DDNS updates (when your hostname's IP changes)

Operational data

  • Server access logs (IP address, user agent, request path, response status, timestamp) — retained 30 days for security and abuse prevention
  • Email delivery logs — retained 90 days

Payment data

  • Payment processing is performed by Paddle.com Market Limited (our merchant of record)
  • We receive a transaction reference and subscription status from Paddle but do not handle credit card numbers, bank details, or full billing addresses
  • See Paddle's privacy policy at https://www.paddle.com/legal/privacy

3. Why We Process This Data

  • Operate the Service: authentication, zone management, certificate issuance, DDNS updates
  • Communicate with you: verification emails, security alerts, billing reminders, service updates
  • Comply with law: retain billing records for tax/audit purposes (Swedish accounting law: 7 years)
  • Prevent abuse: rate limiting, fraud detection, terms enforcement

Legal bases (GDPR Art. 6):

  • Contract performance (operating the Service you signed up for)
  • Legitimate interests (security, abuse prevention)
  • Legal obligation (tax/accounting record retention)
  • Consent (where applicable, e.g., marketing emails — you can opt out anytime)

4. Who We Share Data With

We share data only with the following:

  • Paddle.com Market Limited (Ireland) — payment processing. Receives your email and transaction details.
  • Cloudflare, Inc. (USA, with EU data residency) — DNS, CDN, DDoS protection for the public website. Sees IP addresses and HTTP requests but no account data.
  • Our infrastructure providers (Sweden and Microsoft Azure EU regions) — host our servers. They cannot access account data without authorized access.

We do NOT:

  • Sell your data
  • Use your data for advertising
  • Share data with analytics or tracking providers
  • Use third-party email or notification services (we run our own SMTP)

5. International Transfers

Our primary infrastructure is in Sweden (EU). Some replication runs in Microsoft Azure EU regions. Cloudflare's infrastructure is global but configured for EU data routing where supported. Where transfers outside the EU/EEA occur, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent legal mechanisms.

6. Your Rights

Under GDPR, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data ("right to erasure") — available via the dashboard
  • Object to processing based on legitimate interests
  • Receive your data in a portable format
  • Restrict processing in certain circumstances
  • Withdraw consent for marketing emails (links in every email)

To exercise these rights, contact us using or via https://dynip.dev/contact. We respond within 30 days.

You also have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY) at https://www.imy.se/.

7. Data Retention

  • Active accounts: retained as long as the account is active
  • Closed accounts: account data deleted immediately upon deletion via the dashboard, except billing records (7 years per Swedish accounting law) and server access logs (30 days)
  • Server logs: 30 days
  • Email logs: 90 days
  • DNS query logs: not retained beyond what's needed to deliver responses

8. Cookies and Local Storage

The Service uses minimal browser storage:

  • Authentication tokens (JWT) — stored in browser localStorage for session management
  • No tracking cookies, no analytics, no third-party scripts

You can clear localStorage anytime via your browser; this will log you out.

9. Security

We implement reasonable technical and organizational measures including:

  • Encryption in transit (HTTPS, DNSSEC where supported)
  • TLS certificate private keys are encrypted at rest using authenticated symmetric encryption (Fernet/AES-128 with HMAC)
  • Per-user rate limiting and lockout on failed authentication
  • Off-host encrypted backups
  • Limited access controls on production systems

No system is perfectly secure. We will notify affected users without undue delay if a personal data breach is likely to result in a high risk to their rights.

10. Children

The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.

11. Changes to This Policy

We may update this policy. Material changes will be communicated by email and announced on the website at least 30 days before they take effect.

12. Contact

For privacy questions or to exercise your rights: or https://dynip.dev/contact.