Legal
Privacy Policy
Information under Art. 13 and 14 GDPR about how we process personal data.
Last updated: September 2026
This Privacy Policy informs you, pursuant to Art. 13 and Art. 14 of Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR / DSGVO) and applicable national rules (in particular the BDSG), about the processing of personal data in connection with Templass (websites, customer panel, and DDoS protection / mitigation services).
1. Controller
The controller responsible for data processing is:
Templass, operated by Ali Rayan
Sole trader / Kleinunternehmen (§ 19 UStG)
Welserstraße 3
87463 Dietmannsried
Germany
VAT ID: DE462682632
Public contact for privacy & support: [email protected]
Discord (community / support): https://discord.com/invite/av38fYfdtc
This is the only public contact address for privacy requests. Internal operational addresses (e.g. admin@) are used for operations and are not intended as a public privacy contact.
No data protection officer (DPO) has been appointed (Kleinunternehmen; the statutory appointment obligation under § 38 BDSG / Art. 37 GDPR does not, in our assessment, apply). Please send privacy requests to [email protected].
2. General information on processing
2.1 Scope of processing
We process personal data only to the extent necessary to provide a functional website, the customer panel, and our DDoS protection / remote mitigation services (Layer 3-Layer 7), to perform contractual and pre-contractual obligations, to comply with legal obligations, or where we have a legitimate interest that is not overridden by your interests or fundamental rights.
2.2 Legal bases
Unless otherwise stated in the following sections, we rely on:
- Art. 6(1)(b) GDPR - performance of a contract or pre-contractual measures (e.g. customer account, panel, mitigation service, billing);
- Art. 6(1)(c) GDPR - compliance with legal obligations (e.g. commercial and tax retention);
- Art. 6(1)(f) GDPR - legitimate interests (e.g. IT security, abuse prevention, operation and protection of infrastructure, improving service stability), unless overridden by your interests or fundamental rights.
We use consent under Art. 6(1)(a) GDPR only where we actually obtain it. On the website we set no first-party tracking cookies. Theme preferences are stored on-device via localStorage (not a cookie). Whether and to what extent a cookie/consent banner is used for other cases depends on the live website configuration (no invented banner status in this draft).
2.3 Scope of the offering (brief overview)
Templass provides DDoS protection and remote mitigation (L3-L7) for game servers, hosts, and networks. The offering focuses primarily on operators, hosts, and game networks with a Germany/EU focus (B2B-leaning), but is not exclusively limited to businesses. The primary scrubbing location includes Frankfurt (Equinix FR5); connectivity to your origin is typically via GRE or cross-connect.
Related online offerings / Templass properties include in particular:
| Offering | Domain / note |
|---|---|
| Website | templass.com (hosted on our VPS (Skrime) behind Cloudflare) |
| Customer panel | panel.templass.com |
| Documentation | docs.templass.com |
| Looking Glass | lg.templass.com (Templass property; operational stack beyond that not further specified here) |
| Status | status.templass.com (Templass property; operational stack beyond that not further specified here) |
Further publicly linked legal texts on templass.com: /imprint, /privacy, /terms, and a service/SLA page.
Plans: Essential (€25), Standard (€50), Premium (€100), and Custom. The main commercial difference among the standard plans is the available Clean Mbps capacity. Billing is handled via Stripe Checkout and the Stripe Customer Portal. Access to panel features (including individual ops areas) may be administratively provisioned or time-gated.
3. Website, hosting, and Cloudflare
3.1 Provision of the website and server log files
When you access our publicly reachable websites (in particular templass.com and related pages, and the Templass properties docs.templass.com, lg.templass.com, and status.templass.com), the respective hosting or proxy service processes technically necessary connection data, typically:
- IP address,
- date and time of the request,
- requested URL / resource,
- HTTP status code,
- amount of data transferred (bytes),
- referrer URL (if transmitted),
- user agent (browser/client information).
Purpose: technical delivery, stability, error analysis, abuse and security defence.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation).
Retention: hosting/access logs are generally deleted or anonymised no later than after 14 days, unless longer retention is required to investigate or defend against a concrete security incident.
3.2 Cloudflare
For protection against attacks, bots, and abuse, and for performance, we use Cloudflare (Cloudflare, Inc., USA) as a content-delivery / security proxy for templass.com. Cloudflare may process connection data (including IP address and security metadata) and may run bot/security checks (challenge pages).
Legal basis: Art. 6(1)(f) GDPR.
Third country: see section 14.
Note: The exact retention period for Cloudflare logs depends on the respective Cloudflare configuration and the provider’s terms and must be documented operationally .
3.3 Hosting (Skrime VPS)
Applications and databases for the website and/or the panel run on a Skrime VPS (self-managed Docker Compose stack) with PostgreSQL on the same host, behind Cloudflare. The VPS provider and Cloudflare process technically necessary operational and connection data; application data is stored in our hosted systems.
Legal basis: Art. 6(1)(b) and (f) GDPR.
Third country: see section 14.
3.4 No first-party tracking cookies on the website
The website sets no first-party tracking cookies. Technically necessary processing by the proxy/hosting stack (e.g. Cloudflare) remains unaffected.
4. Theme preference (localStorage)
To store your display preference (e.g. light/dark mode), the browser key templass-theme may be set in localStorage.
- This is not a cookie.
- Storage is exclusively on your device; we do not receive an automatic server transmission of this preference as a tracking signal.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a user-friendly presentation) or - where applicable - the technical necessity of the UI feature.
- You can delete the entry at any time via your browser settings.
5. Contact form and email delivery (Resend)
5.1 Contact
If you contact us via the contact form or by email, we process the information you provide, in particular:
- name,
- email address,
- reason / subject,
- message content,
- optionally: origin IP, ports, hostname, or comparable technical details about your protection needs.
Purpose: handling your enquiry, pre-contractual communication, support.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual/contractual) and/or Art. 6(1)(f) GDPR (efficient communication and documentation of enquiries).
5.2 Delivery via Resend
Sending form or notification emails to [email protected] is handled via Resend, Inc. (USA) as a processor / service provider for transactional delivery.
Third country: see section 14.
Retention: We retain enquiries for as long as needed for handling and traceability, and thereafter in line with statutory retention periods or until legitimate interests in documentation expire (typically within ordinary support/correspondence periods; tax-relevant matters may be longer - see section 15).
6. Customer account and customer panel (panel.templass.com)
6.1 Registration and account data
Use of the customer panel requires registration. We process in particular:
- name,
- email address,
- password (stored only as a hash; we do not store plaintext passwords),
- administrative details of service access (e.g. plan/access periods, where managed by us).
Purpose: contract performance, authentication, provision of panel features.
Legal basis: Art. 6(1)(b) GDPR.
Password requirement: at least 8 characters (technical requirement of the service).
6.2 Authentication and session cookies (Auth.js)
The panel uses session-based authentication (Auth.js / session cookies). On login, session/auth cookies are set that technically secure your login state.
We deliberately do not invent cookie names here; these are the login-required cookies set by the Auth.js/session stack of the panel.
Purpose: sign-in, session management, abuse prevention.
Legal basis: Art. 6(1)(b) GDPR; additionally Art. 6(1)(f) GDPR (security of authentication).
Retention: until logout or session expiry according to the configured session/cookie lifetime (as configured for the service).
6.3 Operational and configuration data in the panel
In the panel, you and we may process operational data required to deliver the mitigation service, in particular:
- tunnel/connectivity configuration (e.g. GRE/connectivity parameters),
- port openings / port requests,
- firewall and rate-limit settings,
- attack telemetry and dashboard analytics (metrics, logs, status displays for mitigation events),
- billing-related metadata and linkage to the Stripe customer account.
Individual ops areas of the panel (including Attacks / Firewall / Rate Limiting / Port Requests) may be administratively provisioned; visibility and usability therefore depend on the respective account status and provisioning.
Legal basis: Art. 6(1)(b) GDPR; for security and quality analysis additionally Art. 6(1)(f) GDPR.
6.4 Note on customer responsibility
Where IP addresses and traffic metadata of end users of your games, websites, or networks are processed via the mitigation service (players, visitors, clients), this is technically necessary to provide protection (see section 8). You as the customer remain - where applicable - responsible for your own information obligations towards your end users (e.g. your own privacy notice for your game/service).
7. Payments (Stripe)
Payments and subscriptions are processed via Stripe (Stripe Payments Europe, Ltd. / Stripe, Inc. - depending on the processing path). Standard plans offered include in particular Essential (€25), Standard (€50), and Premium (€100); Custom arrangements may also exist. The main commercial difference among the standard plans is Clean Mbps capacity.
We ourselves do not store full payment details (e.g. full card numbers). Payment processing is handled by Stripe. We typically receive customer, subscription, invoice, and status metadata as well as technical references (e.g. customer/subscription/invoice IDs).
Features:
- Stripe Checkout for the purchase/checkout flow,
- Stripe Customer Portal for you to manage subscription and payment methods.
Purpose: contract performance, billing, fraud prevention.
Legal bases: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (commercial/tax retention); Art. 6(1)(f) GDPR (abuse and payment-fraud prevention).
Third country: see section 14.
Further information: https://stripe.com/privacy
8. Network and mitigation processing (traffic / DDoS protection)
8.1 Technical necessity
To provide DDoS protection and remote mitigation (L3-L7), we necessarily process network traffic routed through our scrubbing/mitigation infrastructure (including the Frankfurt PoP / Equinix FR5 and possibly further interconnection points). This includes in particular:
- IP packets and header information,
- source and destination IP addresses,
- ports, protocols, packet sizes, and related traffic metadata,
- signatures and patterns for detecting abusive or anomalous load,
- telemetry and logs derived therefrom (including those visible in the customer panel).
Purpose: filtering and forwarding legitimate connections, defending against DDoS and abusive traffic, operations, capacity and quality control, and traceability of attack events for the customer.
Legal basis: Art. 6(1)(b) GDPR (contract performance towards the customer) and Art. 6(1)(f) GDPR (security and integrity of the infrastructure, defence against attacks).
8.2 No advertising use
This traffic-related processing is not for advertising and not for profiling for marketing purposes. It is technical processing to provide the protection service.
8.3 Data subjects
Data subjects may include: customers or their contacts and - indirectly - end users (e.g. players or website visitors) whose connections run through the protected service. Towards end users, the customer is typically the one offering the service; we process the traffic data described as a technical service provider for mitigation.
8.4 Retention of mitigation / attack telemetry
Attack and telemetry data are retained for as long as required for operations, traceability, and support. The exact retention period in days must be set operationally (as configured for the service). Thereafter the data are deleted, anonymised, or aggregated, unless statutory retention obligations require otherwise.
9. Discord (support / community)
For community and support communication we operate or use a Discord server (invite). If you use Discord, Discord’s privacy terms also apply (Discord Inc. / Discord Netherlands BV - depending on region).
There we typically process the profile data visible to you (e.g. Discord username, avatar), message content, and technical metadata, insofar as you participate on the server or contact us.
Legal basis: Art. 6(1)(b) GDPR (support in a contractual relationship) and/or Art. 6(1)(f) GDPR (efficient community communication).
Third country: see section 14.
Note: Discord is an independent provider; use of the Discord client is subject to Discord’s terms.
10. Session check between website and panel
The website may - if you are signed in to the panel - request the panel API (/api/session) with existing session credentials to show login status in the header (credentialed request / cookie transmission within the browser same-site/CORS configuration).
Purpose: display of login status and consistent user experience (website ↔ panel).
Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.
No additional website tracking cookies are set; the existing panel session status is evaluated.
11. Analytics and error monitoring (if/where enabled)
Where configured in the respective environment (“if/where enabled”), the following services may be used:
11.1 Plausible (cookieless analytics)
Plausible is cookieless web analytics. Where enabled, aggregated usage statistics are collected without tracking cookies and without cross-device profiling in the sense of classic advertising trackers.
Legal basis (if/where enabled): Art. 6(1)(f) GDPR (interest in understanding reach and usage of the website).
11.2 Sentry (error monitoring)
Sentry may - if/where enabled - process technical events for error and performance monitoring (e.g. error messages, stack traces, possibly environment/request metadata). Personal data (e.g. IP address, user agent, or details contained in error messages) may be transmitted along with them.
Legal basis (if/where enabled): Art. 6(1)(f) GDPR (stability, debugging, security).
Whether Plausible and/or Sentry are currently enabled in production must be confirmed operationally .
12. Recipients and processors
Personal data are disclosed only where necessary for the stated purposes, a legal basis exists, and - where required - appropriate safeguards are in place (in particular processing under Art. 28 GDPR).
Key recipients / service providers (not an exhaustive list of all subprocessors of the named providers):
| Recipient | Role / purpose |
|---|---|
| Cloudflare, Inc. | Proxy, CDN, bot/DDoS protection for the website |
| Skrime (VPS provider) | Hosting of app(s) and PostgreSQL |
| Stripe (Payments Europe / Inc.) | Payment processing, subscriptions, Customer Portal |
| Resend, Inc. | Transactional email delivery (e.g. contact form) |
| Discord | Community and support communication |
| Plausible (if/where enabled) | Cookieless web analytics |
| Sentry (if/where enabled) | Error/performance monitoring |
| Hosting/colocation and network partners of the scrubbing infrastructure (including Frankfurt / Equinix FR5) | Operation of the mitigation infrastructure |
| Authorities / courts | Only where legally required |
We do not sell personal data.
13. Categories of personal data (overview)
Depending on use, the following categories may be affected in particular:
- Identity and contact data (name, email),
- Access credentials (password hash, session information),
- Communication content (support, contact form, Discord),
- Billing and contract metadata (without full card data held by us),
- Technical usage and log data (IP, UA, logs),
- Configuration and operational data of the mitigation service,
- Network traffic and telemetry data in the course of mitigation (including source IPs of attackers and - unavoidably - of end users of protected services).
14. Third-country transfers
Some of the providers named have seats or processing locations in the USA or other third countries (in particular Cloudflare, Stripe, Resend, Discord; VPS hosting remains in the EU; possibly Plausible/Sentry depending on the operating model).
Transfers to third countries take place only where
- an adequacy decision of the European Commission applies (where applicable, e.g. EU-US Data Privacy Framework for certified organisations), and/or
- appropriate safeguards under Art. 46 GDPR exist, in particular Standard Contractual Clauses (SCCs), and/or
- an exception under Art. 49 GDPR applies (only in individual cases).
Further details are available in the privacy information of the respective providers. On request we will - where available and reasonable - provide further information on the safeguards used.
15. Retention
Unless a more specific period is stated in the individual sections:
- Account data: for the duration of the customer relationship; after contract end, deletion or blocking unless statutory retention obligations require otherwise.
- Website hosting logs: generally ≤ 14 days, except in security incidents.
- Session cookies / Auth sessions: until logout or session expiry.
- Support/contact correspondence: for as long as needed for handling and documentation.
- Invoice and accounting data: according to commercial and tax retention periods (regularly up to 10 years, § 147 AO / § 257 HGB - depending on document type).
- Mitigation/attack telemetry: operationally limited period ; thereafter deletion, anonymisation, or aggregation.
- localStorage theme: until you delete it on the device.
16. Rights of data subjects
Subject to statutory requirements, you have the following rights:
- Access (Art. 15 GDPR),
- Rectification (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR) - an informal notice to [email protected] is sufficient,
- Withdrawal of consent (Art. 7(3) GDPR), where processing is based on consent; withdrawal takes effect only for the future.
To exercise your rights, contact: [email protected].
We may request suitable proof of identity.
17. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
The authority competent for us / mentioned as supervisory authority:
Der Bayerische Landesbeauftragte für den Datenschutz
Wagmüllerstraße 18
80538 München
Germany
Website: https://www.datenschutz-bayern.de
18. Obligation to provide data
Providing certain data is required for concluding a contract and using the service:
- Without account data (name, email, password), panel registration is not possible.
- Without required technical configuration data (e.g. connectivity, ports), the mitigation service cannot be provided.
- Without the technically necessary processing of traffic data (including IP addresses), DDoS protection in the form described is not possible.
- Payment data are required for paid plans via Stripe.
Failure to provide the data means the respective service cannot be used in whole or in part.
19. No automated decision-making
There is no automated decision-making including profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. Technical filtering and mitigation decisions in the network (e.g. blocking anomalous packets) serve solely security and contract-performance purposes and are not designed as a personal “decision about you” within the meaning of Art. 22 GDPR.
20. Security
Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing as well as the varying likelihood and severity of risks, we implement appropriate technical and organisational measures (Art. 32 GDPR), in particular:
- transport encryption (TLS) for web offerings,
- hashing of passwords,
- access restrictions and role-based administration,
- network and infrastructure hardening of mitigation,
- use of established payment and hosting providers.
Absolute security cannot be guaranteed. Please report suspicious activity to [email protected].
21. Minors
Our offerings are aimed primarily at operators, hosts, and game networks (B2B-leaning, focus Germany/EU), without claiming an exclusive restriction to businesses. We do not intentionally collect personal data from children. If you become aware that a minor has submitted data without parental/guardian consent, contact us so we can review and, where appropriate, delete the data.
22. Changes to this Privacy Policy
We reserve the right to adapt this Privacy Policy if the legal situation, services, or processing processes change. The current version is published at templass.com/privacy. For material changes we will - where appropriate and reasonable - provide additional notice (e.g. by email or a notice in the panel).