Every vendor review asks a CDN the same question: do you process our users’ personal data, and in what role? This page answers it in plain language. It describes what our network touches when it delivers your content, what it does not do with that data, and which controls stay in your hands. It is not a substitute for the contract; the binding terms are in the Master Service Agreement and, for processing on your behalf, in the Data Processing Agreement described below.
The short answer
- You are the controller of the traffic that flows through our network. You decide what is delivered, on what legal basis, for how long it is cached and what you tell your users about it.
- We are the processor for that traffic. We transport, cache and log it on your instructions and for no other purpose.
- For your own account we are the controller. Registration, contact details, billing, customer verification (KYC) and support tickets are processed by us under our own Privacy Policy. These two roles do not mix.
Why a CDN cannot claim it never touches personal data
Under Article 4(2) GDPR, “processing” means any operation performed on personal data, including collection, storage, transmission and erasure. It does not require reading, analysing or profiling. An IP address is personal data in the hands of someone who can link it to a person. Every request that reaches one of our edge nodes carries the requester’s IP address and user agent, and every cached file is a stored copy of what you asked us to deliver. That is processing in the legal sense, even though we do nothing with the content itself. Recognising this honestly is what makes the controller and processor roles, and the Data Processing Agreement, meaningful.
What we technically touch when delivering your content
The list below is limited to what our platform actually does. Everything on it happens on your behalf.
- Request metadata in access logs. To route, serve and secure a request, the edge node records the client IP address, user agent, requested URL, time of the request and the country derived from the IP address, together with technical fields such as the response status. These logs exist to operate the service, investigate incidents and produce your statistics.
- Raw logs delivered to you. If you enable it, we deliver raw access logs in JSON to your own Graylog or ELK stack. Once delivered, those copies are under your control.
- Real client IP pass-through. When your origin needs the visitor’s real IP address, we forward it to your origin in the request. Your own systems then see it and are responsible for what they do with it.
- Cached copies of your content on edge nodes. Files fetched from your origin, or uploaded by you to our storage, are kept on our nodes for as long as your cache settings say. If those files contain personal data, they are cached exactly as you provided them.
- Statistics per resource and domain. The customer panel shows aggregated traffic, requests and cache performance for each of your resources. These figures are derived from the access logs and are shown only to you.
What we do not do with this data
- We do not read, analyse or classify the content you deliver. The network does not know whether a file is a video, a software build or a page containing someone’s name, and it does not need to.
- We do not use your users’ data for our own marketing, advertising, profiling, analytics products or for training machine learning models.
- We do not sell it, rent it or share it with third parties, other than the infrastructure providers that host our nodes under contract and public authorities where the law obliges us.
- We do not moderate your content in the ordinary course of the service. We act on specific abuse reports and legal orders under the Claim Consideration Policy and the Acceptable Use Policy, and we tell you when we do, unless the law prevents it.
- We do not keep operational logs longer than is needed to run, secure and support the service and to meet our legal obligations. Where you require a specific retention period, it is agreed in writing.
Data minimisation controls in your hands
Most of the decisions that determine how much personal data passes through the network, and for how long it stays there, are settings in your account.
- Cache lifetime. Active, Inactive and Browser TTL are set per resource, with separate TTL per HTTP status code, or inherited from your origin headers. A short TTL means a short life for any cached object.
- Purge. A total purge in one action, or purge by path, single or in bulk, removes cached copies from the edge whenever you need it, for example after a deletion request from one of your users.
- Access restrictions. Country allowlists and blocklists, IP lists with mask support, referrer allowlists and blocklists, and rate counters per IP or subnet limit who can reach your content at all.
- Signed URLs. Links in secure_link style, optionally bound to a client IP address, keep content available only to the people you intended.
- Log delivery. Raw log delivery is optional. You decide whether to enable it and where the logs are sent.
Keeping everything inside the European Union
If your review requires cached content, logs and support access to stay inside the EU, this can be written into your agreement with the data centres named before the build, and content does not fail over to a node outside the agreed region. The details of what we put in writing, and what stays with you, are on the GDPR Cache Servers page.
Data Processing Agreement
The terms on which we process personal data on your behalf are set out in our Data Processing Agreement. It covers the subject matter and duration of the processing, our obligations as a processor under Article 28 GDPR, confidentiality of staff, security measures, the use of sub-processors, assistance with data subject requests and impact assessments, notification of personal data breaches, and the return or deletion of data at the end of the service. The agreement is available on request: write to support@blazingcdn.com and we will send it to you for review and signature.
Questions your DPO will ask
Do you process personal data at all? Yes, in the limited technical sense described above: request metadata, cached copies and statistics, on your behalf. Claiming otherwise would be false.
Do you hold ISO 27001 or SOC 2? We do not advertise certifications we do not hold, and you will not find badges on this page for that reason. What we offer instead is a contractual answer about roles, geography and the processing we perform.
Who is our counterparty? The contract and the invoicing come from ADVANCED ADMINISTRATIONS Sp. z o.o., Niepodleglosci Avenue 18, floor 4, 02-653 Warsaw, Poland, trading as BlazingCDN, a company established in the European Union.
Related documents
- Privacy Policy: what we process as a controller, on what legal basis, and your rights.
- Cookie Notice: the cookies used on this website and how to change your choice.
- GDPR Cache Servers: EU-only delivery written into the agreement.
- Legal Information: the Master Service Agreement and all our policies in one place.
Questions from your DPO, legal or procurement team can be sent to support@blazingcdn.com. If we cannot meet a clause in your review, we will say so plainly.