Privacy Policy
Last updated: 30 November 2025
AKAERE NETWORKS TECHNOLOGY LTD is committed to protecting your privacy and ensuring your personal data is handled responsibly and in accordance with:
- General Data Protection Regulation (GDPR) (EU) 2016/679
- UK GDPR as incorporated into the Data Protection Act 2018
- Privacy and Electronic Communications Regulations (PECR)
- All applicable UK and EU data protection legislation
1. Who we are
AKAERE NETWORKS TECHNOLOGY LTD ("we", "our", or "us") is the data controller for the personal data we process. We provide professional BGP, BGP Tunnel, and IXP network services.
2. Information we collect
We may collect and process the following categories of personal data:
Account and identity information
- Username and display name
- Email address (for account verification and notifications)
- Password (securely hashed with SHA-1 and unique salt)
- Two-factor authentication settings (TOTP secret, if enabled)
- Account creation and last login timestamps
- Account status (active/inactive) and role (user/administrator)
Technical and security information
- IP address for security monitoring and audit logs
- Browser type, version, and user agent string
- Device information and operating system details
- Session tokens and authentication cookies
- Login attempts and security events
- Email verification codes and timestamps
Service usage information
- Network configuration and routing preferences
- BGP session data and peering information (for customers)
- Tunnel configurations and connection logs
- IXP port assignments and traffic statistics
- API access logs and rate limiting data
Communications and support
- Support tickets and technical enquiries
- Email correspondence and notification history
- Chat logs and phone call records
- Feedback, surveys, and testimonials
- Community forum posts and comments
Financial and billing information
- Company name, VAT number, and billing address
- Payment method details (processed by third-party payment providers)
- Invoice history and payment records
- Credit check information (for enterprise customers)
3. How we use your information
We process your personal data for the following purposes:
- Account management
- To create and maintain your account, verify your identity, enable two-factor authentication, and send you important account notifications
- Service delivery
- To provide BGP, BGP Tunnel, and IXP services, configure network settings, manage routing tables, and ensure optimal performance
- Security and fraud prevention
- To protect your account, detect unauthorized access, prevent abuse, monitor for security threats, and maintain audit logs of all account activities
- Customer support
- To respond to your enquiries, troubleshoot technical issues, provide guidance, and improve our support quality
- Service improvement
- To analyse usage patterns, identify performance bottlenecks, develop new features, and enhance our infrastructure
- Legal compliance
- To comply with legal obligations, respond to lawful requests from authorities, enforce our terms of service, and protect our legal rights
- Marketing communications
- To send you service updates, new feature announcements, and promotional offers (only with your consent, and you may opt out at any time)
4. Legal basis for processing
We process your personal data based on:
- Contract performance - to deliver services you have requested
- Legitimate interests - to operate our business, improve services, and ensure network security
- Legal obligation - to comply with applicable laws and regulations
- Consent - where you have provided explicit consent for specific uses
5. Data sharing and transfers
We may share your data with the following categories of recipients:
Service providers and processors
- Cloudflare - Hosting infrastructure, CDN, and D1 database services
- Resend - Email delivery service for account notifications and security alerts
- Payment processors - Stripe or similar for processing payments (PCI-DSS compliant)
- Monitoring services - Network monitoring and performance analytics tools
Legal and regulatory authorities
- Law enforcement agencies when required by law or court order
- Regulatory bodies for telecommunications and network services
- Tax authorities for financial reporting purposes
Professional advisers
- Lawyers, accountants, and auditors providing professional services
- Insurance providers for risk management
Business transfers
In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the new owner, subject to the same privacy protections.
International data transfers
Your data may be processed in countries outside the UK. When transferring data internationally, we ensure adequate protection through:
- Standard Contractual Clauses approved by the UK ICO
- Adequacy decisions by the UK Government
- Binding Corporate Rules where applicable
- Processing by providers with appropriate certifications (ISO 27001, SOC 2)
6. Data retention
We retain personal data only for as long as necessary for the purposes outlined in this policy. Retention periods vary depending on the type of data and legal requirements:
- Account data
- Active accounts: retained for the duration of your account plus 30 days after deletion request
- Customer service data
- Retained for the duration of the service contract plus 7 years for accounting and legal compliance
- Audit logs
- Security and authentication logs retained for 3 years to comply with security standards
- Email verifications
- Verification codes deleted 30 minutes after expiry, records retained for 90 days
- Technical logs
- Network logs and performance data typically retained for 12 months unless longer retention is required
- Marketing data
- Retained until you withdraw consent or after 3 years of inactivity, whichever is sooner
- Financial records
- Invoices and payment records retained for 7 years as required by UK tax law
After the retention period expires, we securely delete or anonymize your personal data. Some aggregated, anonymized data may be retained indefinitely for statistical purposes.
7. Your rights
Under UK GDPR and Data Protection Act 2018, you have the following rights regarding your personal data:
- Right of access
- Request a copy of your personal data and information about how we process it
- Right to rectification
- Request correction of inaccurate or incomplete personal data
- Right to erasure
- Request deletion of your personal data (subject to legal retention requirements)
- Right to restriction
- Request that we limit the processing of your personal data in certain circumstances
- Right to data portability
- Receive your personal data in a structured, machine-readable format
- Right to object
- Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent
- Withdraw consent at any time where we rely on consent as the legal basis for processing
- Right to complain
- Lodge a complaint with the Information Commissioner's Office (ICO) if you believe we've mishandled your data
To exercise any of these rights, please contact us at privacy@akae.re. We will respond to your request within one month, or inform you if we need additional time.
ICO Contact Details:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
8. Data security
We implement comprehensive technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, and destruction:
Technical safeguards
- Encryption - All data transmitted over networks uses TLS 1.3 encryption; passwords stored with SHA-1 hashing and unique salts
- Two-factor authentication - TOTP-based 2FA available for all user accounts using RFC 6238 compliant implementation
- Access controls - Role-based access controls with admin privileges required for sensitive operations
- Session management - Secure session tokens with HttpOnly and SameSite=Lax cookie attributes
- Rate limiting - Protection against brute force attacks and automated abuse
- Audit logging - Comprehensive logging of all account activities, security events, and administrative actions
- Cloudflare Turnstile - Bot protection on registration and login forms
Organizational safeguards
- Staff training - Regular security awareness training for all employees
- Access management - Strict access controls limiting who can access personal data
- Incident response - Documented procedures for detecting and responding to security breaches
- Vendor management - Due diligence on all third-party processors
- Regular assessments - Periodic security audits and vulnerability scans
- Data minimization - Collection of only necessary personal data
Infrastructure security
- Cloudflare Workers - Edge computing platform with built-in DDoS protection
- D1 Database - Serverless database with automatic backups and replication
- Network security - Firewall protection, intrusion detection, and monitoring
- Physical security - Data centers with 24/7 surveillance and access controls
9. Cookies and tracking
We use cookies and similar technologies to operate our service and improve your experience. For detailed information, please see our Cookie Policy.
Essential cookies
- auth_token - Keeps you signed in (7 days)
- cookie-consent - Stores your cookie preferences (1 year)
Analytics cookies (optional)
With your consent, we may use analytics cookies to understand how you use our service and improve it. You can opt out at any time via our cookie banner or settings page.
10. Contact us
If you have questions about this privacy policy, want to exercise your GDPR rights, or have concerns about how we handle your data, please contact us:
Data Controller:
AKAERE NETWORKS TECHNOLOGY LTD
Company Number: 16382257
Registered Address: Suite 11320, 61 Bridge Street, Kington, HR5 3DJ, United Kingdom
Data Protection Officer (DPO):
Email: dpo@akae.re (for GDPR rights requests)
General Privacy Enquiries:
Email: privacy@akae.re
Support: support@akae.re
Phone: +44 7999 908 249
We aim to respond to all enquiries within 5 business days. For GDPR data subject access requests (DSARs), we will respond within one month as required by Article 15 GDPR, or inform you if we need to extend this period by up to two additional months for complex requests.
When exercising your GDPR rights, please provide:
- Your full name and email address associated with your account
- Clear description of your request and which right(s) you wish to exercise
- Proof of identity (if we cannot verify you through your account)
- Specific data or time period (if relevant to your request)
11. Children and young persons' privacy
Age restrictions and requirements
Our professional networking services have the following age-related requirements:
- Under 14 years
- We do not knowingly collect or process personal data from children under 14 years of age. Our services are strictly prohibited for this age group.
- 14 to 17 years
- Users aged 14-17 must obtain verifiable parental or guardian consent before registering or using our services. Limited data collection applies.
- 18 years and over
- Full access to all services available without parental consent.
Parental consent requirements
For users under 18 years of age, we require verifiable parental or legal guardian consent before we collect, use, or disclose personal information. This consent must be:
- Provided by a parent or legal guardian with parental responsibility
- Verified through a secure authentication method (email confirmation, identity verification, or signed consent form)
- Documented and stored securely in compliance with GDPR requirements
- Revocable at any time by the parent or guardian
Consent verification process
To verify parental consent for users under 18, we use one or more of the following methods:
- Email verification: Consent email sent to parent's/guardian's email address with confirmation link
- Document upload: Signed consent form uploaded and verified by our team
- Identity verification: Parent/guardian identity verification through Stripe Identity or similar service
- Payment card verification: Small authorization charge to parent's/guardian's payment card (refunded immediately)
Parental rights and controls
Parents and legal guardians have enhanced rights regarding their child's personal data under GDPR Article 8:
- Right to access: Review all personal data collected about your child
- Right to rectification: Correct any inaccurate information
- Right to erasure: Request immediate deletion of your child's account and all associated data
- Right to withdraw consent: Revoke consent at any time, resulting in account suspension or deletion
- Right to restriction: Limit how we process your child's data
- Right to be informed: Receive clear information about data processing in age-appropriate language
- Right to monitor: Receive regular reports on account activity and data processing
For parents and guardians:
To exercise these rights or if you believe your child is using our services without proper consent, please contact us immediately at child-safety@akae.reor dpo@akae.re
Limited data collection for minors
For users under 18 with verified parental consent, we apply stricter data minimization principles:
- Collect only essential information required for service delivery
- No marketing communications or profiling
- Enhanced privacy settings enabled by default
- Restricted data sharing with third parties (only essential service providers)
- No sale or commercial use of minor's personal data
- Regular review of necessity for continued data retention
Age verification mechanisms
We employ the following measures to verify user age during registration:
- Date of birth declaration during account creation
- Age-gate verification for users declaring under 18 years
- Automatic parental consent workflow triggered for users under 18
- Account suspension pending parental verification
- Periodic re-verification for long-term accounts
Child safety measures
We are committed to protecting children and young persons online:
- Monitoring: Enhanced monitoring of accounts belonging to minors for safety concerns
- Reporting: Easy-to-use reporting mechanisms for inappropriate content or behaviour
- Content filtering: Age-appropriate content controls and restrictions
- Privacy education: Resources to help young users understand privacy and online safety
- Incident response: Dedicated child safety team to respond to concerns within 24 hours
Transition to adult status
When a user with parental consent reaches 18 years of age:
- We notify both the user and the parent/guardian
- The account transitions to standard adult terms
- The user may choose to continue, modify settings, or delete their account
- Parental access is automatically revoked (unless explicitly authorized by the adult user)
Deletion of underage accounts
If we discover that we have inadvertently collected personal data from a child under 14, or from a minor (14-17) without proper parental consent:
- We will immediately suspend the account
- Contact the registered email address to verify age and parental status
- Delete all personal data within 72 hours if no valid consent can be obtained
- Notify our Data Protection Officer and document the incident
- Review and improve our age verification processes
Compliance with child protection laws
Our child protection practices comply with and exceed:
- GDPR Article 8 - Conditions applicable to child's consent in relation to information society services (we apply an age threshold of 14 years, aligning with Italy, Spain, and Portugal's standards, and exceeding the minimum requirement of 13 years set by UK and other EU member states)
- UK Age Appropriate Design Code (Children's Code)
- Children's Online Privacy Protection Act (COPPA) principles (14+ exceeds COPPA's 13+ requirement)
- Online Safety Act 2023 (UK)
- UN Convention on the Rights of the Child
Note on GDPR Age Requirements:
GDPR Article 8 sets a default age of 16 for children's consent, but allows EU member states to lower this to a minimum of 13 years. Different countries have adopted different thresholds: Germany, France, and Ireland use 16 years; Italy, Spain, and Portugal use 14 years; UK, Netherlands, and Sweden use 13 years. Our 14-year threshold provides strong protection while being accessible to young professionals and students in technical fields.
For more information about our commitment to child safety, please contact our Child Safety Team at child-safety@akae.re.
12. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will update the "Last updated" date at the top of this page
- We will notify you by email if you have an active account
- For significant changes, we may display a prominent notice on our website
- We may require you to acknowledge the updated policy before continuing to use our services
We encourage you to review this policy periodically. Your continued use of our services after changes have been made constitutes your acceptance of the updated privacy policy.
13. GDPR Compliance
GDPR Statement: AKAERE NETWORKS TECHNOLOGY LTD is committed to full compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the UK GDPR as incorporated into UK law under the Data Protection Act 2018.
Legal grounds for processing (Article 6 GDPR)
We process your personal data based on the following legal grounds under Article 6 GDPR:
- Article 6(1)(a) - Consent
- For marketing communications, optional analytics, and other non-essential processing where you have given explicit consent
- Article 6(1)(b) - Contract
- To provide BGP, BGP Tunnel, and IXP services you have subscribed to, including account creation, service delivery, and billing
- Article 6(1)(c) - Legal obligation
- To comply with legal obligations including tax reporting, telecommunications regulations, and anti-money laundering requirements
- Article 6(1)(f) - Legitimate interests
- For fraud prevention, network security, service improvement, and business operations (where not overridden by your rights and interests)
Your rights under GDPR
In addition to the rights listed in Section 7, GDPR provides you with enhanced protections:
- Right to be informed (Articles 13-14): You have the right to clear information about how we process your data (provided in this policy)
- Right of access (Article 15): You can request a copy of your personal data in a commonly used electronic format, free of charge (first request only)
- Right to rectification (Article 16): You can correct inaccurate or incomplete personal data within 72 hours
- Right to erasure (Article 17): Request deletion of your data when no longer necessary or if you withdraw consent (subject to legal retention requirements)
- Right to restriction (Article 18): Request that we stop processing while disputing accuracy or for establishing legal claims
- Right to data portability (Article 20): Receive your data in JSON/CSV format and transmit it to another controller
- Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing (we will stop unless we have compelling grounds)
- Rights related to automated decision-making (Article 22): Request human review of automated decisions affecting you
Response timeframes
We will respond to your GDPR rights requests without undue delay and within:
- One month as standard (may be extended by 2 months for complex requests)
- 72 hours for urgent rectification requests
- Immediately for withdrawal of consent affecting ongoing processing
Cross-border data transfers
When transferring personal data outside the UK or EEA, we ensure GDPR-compliant safeguards:
- Standard Contractual Clauses (SCCs): We use the EU Commission's approved SCCs (updated 2021) with all data processors outside the UK/EEA
- Adequacy decisions: We may transfer data to countries deemed adequate by the UK Government (e.g., Switzerland, Israel, Japan, New Zealand)
- Cloudflare (USA): Processing under SCCs with supplementary measures including encryption and access controls
- Transfer Impact Assessments: We conduct TIAs for all international transfers to assess risks and implement additional safeguards where necessary
Data Protection Officer (DPO)
Although not legally required to appoint a DPO, we have designated a Data Protection Officer for GDPR compliance matters:
Data Protection Officer
Email: dpo@akae.re
Privacy enquiries: privacy@akae.re
You can contact our DPO directly regarding any GDPR compliance questions, concerns, or to exercise your rights.
Data Protection Impact Assessments (DPIA)
We conduct DPIAs for high-risk processing activities, including:
- Large-scale processing of special categories of data
- Automated decision-making with legal or significant effects
- Systematic monitoring of publicly accessible areas (CCTV)
- New technologies or processing methods that present new risks
DPIAs help us identify and minimize data protection risks. You can request a summary of relevant DPIAs by contacting our DPO.
Records of processing activities (Article 30)
We maintain detailed records of all data processing activities including:
- Purposes of processing and legal basis
- Categories of data subjects and personal data
- Recipients of personal data (including international transfers)
- Retention periods and security measures
These records are available to supervisory authorities upon request.
Data processors and sub-processors
We work with the following data processors under GDPR-compliant Data Processing Agreements (DPAs):
- Cloudflare, Inc.
- Infrastructure hosting, CDN, D1 database (USA, with SCCs)
- Resend
- Transactional email delivery (EU/USA, with SCCs)
- Stripe, Inc.
- Payment processing and identity verification (USA, with SCCs and adequacy mechanisms)
All processors are contractually obligated to process data only on our instructions and maintain appropriate security measures. We notify you of any changes to our sub-processors via email.
Supervisory authority
Our lead supervisory authority is the UK Information Commissioner's Office (ICO). You have the right to lodge a complaint with the ICO or your local supervisory authority if you believe we have not complied with GDPR.
UK Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk
Report a concern: ico.org.uk/make-a-complaint/
EU Representative (if applicable)
If we establish substantial operations in the EU or regularly process data of EU residents, we will appoint an EU representative as required by Article 27 GDPR. This information will be updated here when applicable.
14. Additional information
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects or significantly affects you. Some automated systems are used for fraud prevention and spam detection, but you can request human review of any automated decision.
Data breach notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the Information Commissioner's Office within 72 hours of becoming aware of the breach, as required by GDPR Article 33 and 34.
Our breach notification will include:
- Nature of the breach and categories of data affected
- Likely consequences and measures we're taking
- Contact point for further information
- Recommendations for protecting yourself