Privacy Policy

Last updated: 30 November 2025

AKAERE NETWORKS TECHNOLOGY LTD is committed to protecting your privacy and ensuring your personal data is handled responsibly and in accordance with:

  • General Data Protection Regulation (GDPR) (EU) 2016/679
  • UK GDPR as incorporated into the Data Protection Act 2018
  • Privacy and Electronic Communications Regulations (PECR)
  • All applicable UK and EU data protection legislation
Important This policy complies with GDPR Articles 13 and 14 transparency requirements. For GDPR-specific information, see Section 13.

1. Who we are

AKAERE NETWORKS TECHNOLOGY LTD ("we", "our", or "us") is the data controller for the personal data we process. We provide professional BGP, BGP Tunnel, and IXP network services.

2. Information we collect

We may collect and process the following categories of personal data:

Account and identity information

  • Username and display name
  • Email address (for account verification and notifications)
  • Password (securely hashed with SHA-1 and unique salt)
  • Two-factor authentication settings (TOTP secret, if enabled)
  • Account creation and last login timestamps
  • Account status (active/inactive) and role (user/administrator)

Technical and security information

  • IP address for security monitoring and audit logs
  • Browser type, version, and user agent string
  • Device information and operating system details
  • Session tokens and authentication cookies
  • Login attempts and security events
  • Email verification codes and timestamps

Service usage information

  • Network configuration and routing preferences
  • BGP session data and peering information (for customers)
  • Tunnel configurations and connection logs
  • IXP port assignments and traffic statistics
  • API access logs and rate limiting data

Communications and support

  • Support tickets and technical enquiries
  • Email correspondence and notification history
  • Chat logs and phone call records
  • Feedback, surveys, and testimonials
  • Community forum posts and comments

Financial and billing information

  • Company name, VAT number, and billing address
  • Payment method details (processed by third-party payment providers)
  • Invoice history and payment records
  • Credit check information (for enterprise customers)

3. How we use your information

We process your personal data for the following purposes:

Account management
To create and maintain your account, verify your identity, enable two-factor authentication, and send you important account notifications
Service delivery
To provide BGP, BGP Tunnel, and IXP services, configure network settings, manage routing tables, and ensure optimal performance
Security and fraud prevention
To protect your account, detect unauthorized access, prevent abuse, monitor for security threats, and maintain audit logs of all account activities
Customer support
To respond to your enquiries, troubleshoot technical issues, provide guidance, and improve our support quality
Service improvement
To analyse usage patterns, identify performance bottlenecks, develop new features, and enhance our infrastructure
Legal compliance
To comply with legal obligations, respond to lawful requests from authorities, enforce our terms of service, and protect our legal rights
Marketing communications
To send you service updates, new feature announcements, and promotional offers (only with your consent, and you may opt out at any time)

4. Legal basis for processing

We process your personal data based on:

  • Contract performance - to deliver services you have requested
  • Legitimate interests - to operate our business, improve services, and ensure network security
  • Legal obligation - to comply with applicable laws and regulations
  • Consent - where you have provided explicit consent for specific uses

5. Data sharing and transfers

Warning We do not sell, rent, or trade your personal data to third parties for marketing purposes.

We may share your data with the following categories of recipients:

Service providers and processors

  • Cloudflare - Hosting infrastructure, CDN, and D1 database services
  • Resend - Email delivery service for account notifications and security alerts
  • Payment processors - Stripe or similar for processing payments (PCI-DSS compliant)
  • Monitoring services - Network monitoring and performance analytics tools

Legal and regulatory authorities

  • Law enforcement agencies when required by law or court order
  • Regulatory bodies for telecommunications and network services
  • Tax authorities for financial reporting purposes

Professional advisers

  • Lawyers, accountants, and auditors providing professional services
  • Insurance providers for risk management

Business transfers

In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the new owner, subject to the same privacy protections.

International data transfers

Your data may be processed in countries outside the UK. When transferring data internationally, we ensure adequate protection through:

  • Standard Contractual Clauses approved by the UK ICO
  • Adequacy decisions by the UK Government
  • Binding Corporate Rules where applicable
  • Processing by providers with appropriate certifications (ISO 27001, SOC 2)

6. Data retention

We retain personal data only for as long as necessary for the purposes outlined in this policy. Retention periods vary depending on the type of data and legal requirements:

Account data
Active accounts: retained for the duration of your account plus 30 days after deletion request
Customer service data
Retained for the duration of the service contract plus 7 years for accounting and legal compliance
Audit logs
Security and authentication logs retained for 3 years to comply with security standards
Email verifications
Verification codes deleted 30 minutes after expiry, records retained for 90 days
Technical logs
Network logs and performance data typically retained for 12 months unless longer retention is required
Marketing data
Retained until you withdraw consent or after 3 years of inactivity, whichever is sooner
Financial records
Invoices and payment records retained for 7 years as required by UK tax law

After the retention period expires, we securely delete or anonymize your personal data. Some aggregated, anonymized data may be retained indefinitely for statistical purposes.

7. Your rights

Under UK GDPR and Data Protection Act 2018, you have the following rights regarding your personal data:

Right of access
Request a copy of your personal data and information about how we process it
Right to rectification
Request correction of inaccurate or incomplete personal data
Right to erasure
Request deletion of your personal data (subject to legal retention requirements)
Right to restriction
Request that we limit the processing of your personal data in certain circumstances
Right to data portability
Receive your personal data in a structured, machine-readable format
Right to object
Object to processing based on legitimate interests or for direct marketing
Right to withdraw consent
Withdraw consent at any time where we rely on consent as the legal basis for processing
Right to complain
Lodge a complaint with the Information Commissioner's Office (ICO) if you believe we've mishandled your data

To exercise any of these rights, please contact us at privacy@akae.re. We will respond to your request within one month, or inform you if we need additional time.

ICO Contact Details:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

8. Data security

We implement comprehensive technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, and destruction:

Technical safeguards

  • Encryption - All data transmitted over networks uses TLS 1.3 encryption; passwords stored with SHA-1 hashing and unique salts
  • Two-factor authentication - TOTP-based 2FA available for all user accounts using RFC 6238 compliant implementation
  • Access controls - Role-based access controls with admin privileges required for sensitive operations
  • Session management - Secure session tokens with HttpOnly and SameSite=Lax cookie attributes
  • Rate limiting - Protection against brute force attacks and automated abuse
  • Audit logging - Comprehensive logging of all account activities, security events, and administrative actions
  • Cloudflare Turnstile - Bot protection on registration and login forms

Organizational safeguards

  • Staff training - Regular security awareness training for all employees
  • Access management - Strict access controls limiting who can access personal data
  • Incident response - Documented procedures for detecting and responding to security breaches
  • Vendor management - Due diligence on all third-party processors
  • Regular assessments - Periodic security audits and vulnerability scans
  • Data minimization - Collection of only necessary personal data

Infrastructure security

  • Cloudflare Workers - Edge computing platform with built-in DDoS protection
  • D1 Database - Serverless database with automatic backups and replication
  • Network security - Firewall protection, intrusion detection, and monitoring
  • Physical security - Data centers with 24/7 surveillance and access controls
Warning Despite our security measures, no system is completely secure. Please use strong passwords and enable two-factor authentication to protect your account.

9. Cookies and tracking

We use cookies and similar technologies to operate our service and improve your experience. For detailed information, please see our Cookie Policy.

Essential cookies

  • auth_token - Keeps you signed in (7 days)
  • cookie-consent - Stores your cookie preferences (1 year)

Analytics cookies (optional)

With your consent, we may use analytics cookies to understand how you use our service and improve it. You can opt out at any time via our cookie banner or settings page.

10. Contact us

If you have questions about this privacy policy, want to exercise your GDPR rights, or have concerns about how we handle your data, please contact us:

Data Controller:
AKAERE NETWORKS TECHNOLOGY LTD
Company Number: 16382257
Registered Address: Suite 11320, 61 Bridge Street, Kington, HR5 3DJ, United Kingdom

Data Protection Officer (DPO):
Email: dpo@akae.re (for GDPR rights requests)

General Privacy Enquiries:
Email: privacy@akae.re
Support: support@akae.re
Phone: +44 7999 908 249

We aim to respond to all enquiries within 5 business days. For GDPR data subject access requests (DSARs), we will respond within one month as required by Article 15 GDPR, or inform you if we need to extend this period by up to two additional months for complex requests.

When exercising your GDPR rights, please provide:

  • Your full name and email address associated with your account
  • Clear description of your request and which right(s) you wish to exercise
  • Proof of identity (if we cannot verify you through your account)
  • Specific data or time period (if relevant to your request)

11. Children and young persons' privacy

Important Users under 18 years of age must have parental or guardian consent before using our services.

Age restrictions and requirements

Our professional networking services have the following age-related requirements:

Under 14 years
We do not knowingly collect or process personal data from children under 14 years of age. Our services are strictly prohibited for this age group.
14 to 17 years
Users aged 14-17 must obtain verifiable parental or guardian consent before registering or using our services. Limited data collection applies.
18 years and over
Full access to all services available without parental consent.

Parental consent requirements

For users under 18 years of age, we require verifiable parental or legal guardian consent before we collect, use, or disclose personal information. This consent must be:

  • Provided by a parent or legal guardian with parental responsibility
  • Verified through a secure authentication method (email confirmation, identity verification, or signed consent form)
  • Documented and stored securely in compliance with GDPR requirements
  • Revocable at any time by the parent or guardian

Consent verification process

To verify parental consent for users under 18, we use one or more of the following methods:

  • Email verification: Consent email sent to parent's/guardian's email address with confirmation link
  • Document upload: Signed consent form uploaded and verified by our team
  • Identity verification: Parent/guardian identity verification through Stripe Identity or similar service
  • Payment card verification: Small authorization charge to parent's/guardian's payment card (refunded immediately)

Parental rights and controls

Parents and legal guardians have enhanced rights regarding their child's personal data under GDPR Article 8:

  • Right to access: Review all personal data collected about your child
  • Right to rectification: Correct any inaccurate information
  • Right to erasure: Request immediate deletion of your child's account and all associated data
  • Right to withdraw consent: Revoke consent at any time, resulting in account suspension or deletion
  • Right to restriction: Limit how we process your child's data
  • Right to be informed: Receive clear information about data processing in age-appropriate language
  • Right to monitor: Receive regular reports on account activity and data processing

For parents and guardians:
To exercise these rights or if you believe your child is using our services without proper consent, please contact us immediately at child-safety@akae.reor dpo@akae.re

Limited data collection for minors

For users under 18 with verified parental consent, we apply stricter data minimization principles:

  • Collect only essential information required for service delivery
  • No marketing communications or profiling
  • Enhanced privacy settings enabled by default
  • Restricted data sharing with third parties (only essential service providers)
  • No sale or commercial use of minor's personal data
  • Regular review of necessity for continued data retention

Age verification mechanisms

We employ the following measures to verify user age during registration:

  • Date of birth declaration during account creation
  • Age-gate verification for users declaring under 18 years
  • Automatic parental consent workflow triggered for users under 18
  • Account suspension pending parental verification
  • Periodic re-verification for long-term accounts

Child safety measures

We are committed to protecting children and young persons online:

  • Monitoring: Enhanced monitoring of accounts belonging to minors for safety concerns
  • Reporting: Easy-to-use reporting mechanisms for inappropriate content or behaviour
  • Content filtering: Age-appropriate content controls and restrictions
  • Privacy education: Resources to help young users understand privacy and online safety
  • Incident response: Dedicated child safety team to respond to concerns within 24 hours

Transition to adult status

When a user with parental consent reaches 18 years of age:

  • We notify both the user and the parent/guardian
  • The account transitions to standard adult terms
  • The user may choose to continue, modify settings, or delete their account
  • Parental access is automatically revoked (unless explicitly authorized by the adult user)

Deletion of underage accounts

If we discover that we have inadvertently collected personal data from a child under 14, or from a minor (14-17) without proper parental consent:

  • We will immediately suspend the account
  • Contact the registered email address to verify age and parental status
  • Delete all personal data within 72 hours if no valid consent can be obtained
  • Notify our Data Protection Officer and document the incident
  • Review and improve our age verification processes
Important If you are under 18 and currently using our services without parental consent, please ask your parent or guardian to contact us at child-safety@akae.reto provide the required consent, or your account may be suspended.

Compliance with child protection laws

Our child protection practices comply with and exceed:

  • GDPR Article 8 - Conditions applicable to child's consent in relation to information society services (we apply an age threshold of 14 years, aligning with Italy, Spain, and Portugal's standards, and exceeding the minimum requirement of 13 years set by UK and other EU member states)
  • UK Age Appropriate Design Code (Children's Code)
  • Children's Online Privacy Protection Act (COPPA) principles (14+ exceeds COPPA's 13+ requirement)
  • Online Safety Act 2023 (UK)
  • UN Convention on the Rights of the Child

Note on GDPR Age Requirements:
GDPR Article 8 sets a default age of 16 for children's consent, but allows EU member states to lower this to a minimum of 13 years. Different countries have adopted different thresholds: Germany, France, and Ireland use 16 years; Italy, Spain, and Portugal use 14 years; UK, Netherlands, and Sweden use 13 years. Our 14-year threshold provides strong protection while being accessible to young professionals and students in technical fields.

For more information about our commitment to child safety, please contact our Child Safety Team at child-safety@akae.re.

12. Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will update the "Last updated" date at the top of this page
  • We will notify you by email if you have an active account
  • For significant changes, we may display a prominent notice on our website
  • We may require you to acknowledge the updated policy before continuing to use our services

We encourage you to review this policy periodically. Your continued use of our services after changes have been made constitutes your acceptance of the updated privacy policy.

13. GDPR Compliance

GDPR Statement: AKAERE NETWORKS TECHNOLOGY LTD is committed to full compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the UK GDPR as incorporated into UK law under the Data Protection Act 2018.

Legal grounds for processing (Article 6 GDPR)

We process your personal data based on the following legal grounds under Article 6 GDPR:

Article 6(1)(a) - Consent
For marketing communications, optional analytics, and other non-essential processing where you have given explicit consent
Article 6(1)(b) - Contract
To provide BGP, BGP Tunnel, and IXP services you have subscribed to, including account creation, service delivery, and billing
Article 6(1)(c) - Legal obligation
To comply with legal obligations including tax reporting, telecommunications regulations, and anti-money laundering requirements
Article 6(1)(f) - Legitimate interests
For fraud prevention, network security, service improvement, and business operations (where not overridden by your rights and interests)

Your rights under GDPR

In addition to the rights listed in Section 7, GDPR provides you with enhanced protections:

  • Right to be informed (Articles 13-14): You have the right to clear information about how we process your data (provided in this policy)
  • Right of access (Article 15): You can request a copy of your personal data in a commonly used electronic format, free of charge (first request only)
  • Right to rectification (Article 16): You can correct inaccurate or incomplete personal data within 72 hours
  • Right to erasure (Article 17): Request deletion of your data when no longer necessary or if you withdraw consent (subject to legal retention requirements)
  • Right to restriction (Article 18): Request that we stop processing while disputing accuracy or for establishing legal claims
  • Right to data portability (Article 20): Receive your data in JSON/CSV format and transmit it to another controller
  • Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing (we will stop unless we have compelling grounds)
  • Rights related to automated decision-making (Article 22): Request human review of automated decisions affecting you

Response timeframes

We will respond to your GDPR rights requests without undue delay and within:

  • One month as standard (may be extended by 2 months for complex requests)
  • 72 hours for urgent rectification requests
  • Immediately for withdrawal of consent affecting ongoing processing

Cross-border data transfers

When transferring personal data outside the UK or EEA, we ensure GDPR-compliant safeguards:

  • Standard Contractual Clauses (SCCs): We use the EU Commission's approved SCCs (updated 2021) with all data processors outside the UK/EEA
  • Adequacy decisions: We may transfer data to countries deemed adequate by the UK Government (e.g., Switzerland, Israel, Japan, New Zealand)
  • Cloudflare (USA): Processing under SCCs with supplementary measures including encryption and access controls
  • Transfer Impact Assessments: We conduct TIAs for all international transfers to assess risks and implement additional safeguards where necessary

Data Protection Officer (DPO)

Although not legally required to appoint a DPO, we have designated a Data Protection Officer for GDPR compliance matters:

Data Protection Officer
Email: dpo@akae.re
Privacy enquiries: privacy@akae.re

You can contact our DPO directly regarding any GDPR compliance questions, concerns, or to exercise your rights.

Data Protection Impact Assessments (DPIA)

We conduct DPIAs for high-risk processing activities, including:

  • Large-scale processing of special categories of data
  • Automated decision-making with legal or significant effects
  • Systematic monitoring of publicly accessible areas (CCTV)
  • New technologies or processing methods that present new risks

DPIAs help us identify and minimize data protection risks. You can request a summary of relevant DPIAs by contacting our DPO.

Records of processing activities (Article 30)

We maintain detailed records of all data processing activities including:

  • Purposes of processing and legal basis
  • Categories of data subjects and personal data
  • Recipients of personal data (including international transfers)
  • Retention periods and security measures

These records are available to supervisory authorities upon request.

Data processors and sub-processors

We work with the following data processors under GDPR-compliant Data Processing Agreements (DPAs):

Cloudflare, Inc.
Infrastructure hosting, CDN, D1 database (USA, with SCCs)
Resend
Transactional email delivery (EU/USA, with SCCs)
Stripe, Inc.
Payment processing and identity verification (USA, with SCCs and adequacy mechanisms)

All processors are contractually obligated to process data only on our instructions and maintain appropriate security measures. We notify you of any changes to our sub-processors via email.

Supervisory authority

Our lead supervisory authority is the UK Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO or your local supervisory authority if you believe we have not complied with GDPR.

UK Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Report a concern: ico.org.uk/make-a-complaint/

EU Representative (if applicable)

If we establish substantial operations in the EU or regularly process data of EU residents, we will appoint an EU representative as required by Article 27 GDPR. This information will be updated here when applicable.

14. Additional information

Automated decision-making

We do not use automated decision-making or profiling that produces legal effects or significantly affects you. Some automated systems are used for fraud prevention and spam detection, but you can request human review of any automated decision.

Data breach notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by GDPR Article 33 and 34.

Our breach notification will include:

  • Nature of the breach and categories of data affected
  • Likely consequences and measures we're taking
  • Contact point for further information
  • Recommendations for protecting yourself