1. Who We Are
This privacy policy describes how 33k Networks AB ("we", "us"), a Swedish limited company at backstugevägen 7, Sundbyberg, Sweden, processes personal data in connection with the DynIP service (https://dynip.dev). We are the data controller for personal data processed via the Service.
2. Data We Collect
Account data
- Email address (used for login, verification, and notifications)
- Hashed password (never stored in plaintext; bcrypt)
- Optional: TOTP secret if 2FA is enabled
- Account creation date, last login date
Service data
- Zone names and DNS records you create
- TSIG keys generated for your zones (for DNSUPDATE authentication)
- TLS certificate metadata (expiry dates) and content (encrypted at rest)
- IP addresses associated with DDNS updates (when your hostname's IP changes)
Operational data
- Server access logs (IP address, user agent, request path, response status, timestamp) — retained 30 days for security and abuse prevention
- Email delivery logs — retained 90 days
Payment data
- Payment processing is performed by Paddle.com Market Limited (our merchant of record)
- We receive a transaction reference and subscription status from Paddle but do not handle credit card numbers, bank details, or full billing addresses
- See Paddle's privacy policy at https://www.paddle.com/legal/privacy
3. Why We Process This Data
- Operate the Service: authentication, zone management, certificate issuance, DDNS updates
- Communicate with you: verification emails, security alerts, billing reminders, service updates
- Comply with law: retain billing records for tax/audit purposes (Swedish accounting law: 7 years)
- Prevent abuse: rate limiting, fraud detection, terms enforcement
Legal bases (GDPR Art. 6):
- Contract performance (operating the Service you signed up for)
- Legitimate interests (security, abuse prevention)
- Legal obligation (tax/accounting record retention)
- Consent (where applicable, e.g., marketing emails — you can opt out anytime)
5. International Transfers
Our primary infrastructure is in Sweden (EU). Some replication runs in Microsoft Azure EU regions. Cloudflare's infrastructure is global but configured for EU data routing where supported. Where transfers outside the EU/EEA occur, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent legal mechanisms.
6. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and associated data ("right to erasure") — available via the dashboard
- Object to processing based on legitimate interests
- Receive your data in a portable format
- Restrict processing in certain circumstances
- Withdraw consent for marketing emails (links in every email)
To exercise these rights, contact us using [enable JavaScript to view contact email] or via https://dynip.dev/contact. We respond within 30 days.
You also have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY) at https://www.imy.se/.
7. Data Retention
- Active accounts: retained as long as the account is active
- Closed accounts: account data deleted immediately upon deletion via the dashboard, except billing records (7 years per Swedish accounting law) and server access logs (30 days)
- Server logs: 30 days
- Email logs: 90 days
- DNS query logs: not retained beyond what's needed to deliver responses
9. Security
We implement reasonable technical and organizational measures including:
- Encryption in transit (HTTPS, DNSSEC where supported)
- TLS certificate private keys are encrypted at rest using authenticated symmetric encryption (Fernet/AES-128 with HMAC)
- Per-user rate limiting and lockout on failed authentication
- Off-host encrypted backups
- Limited access controls on production systems
No system is perfectly secure. We will notify affected users without undue delay if a personal data breach is likely to result in a high risk to their rights.
10. Children
The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.
11. Changes to This Policy
We may update this policy. Material changes will be communicated by email and announced on the website at least 30 days before they take effect.
12. Contact
For privacy questions or to exercise your rights: [enable JavaScript to view contact email] or https://dynip.dev/contact.