Privacy & cookies
Version 1.0 · Effective 8 August 2026 · AS209990
This is a permanent, unchanging copy of version 1.0. Save or print it and it will still match this page later. See the current version
Karmuz Network (AS209990) keeps data collection to a minimum. We do not sell your data, serve advertising, or track you across other websites. We use cookies sparingly, and any analytics is used only with your consent. This page explains, in plain language, what we process and the rights you have over it. It sits alongside our Terms of Service and Acceptable Use Policy, which describe the abuse handling and enforcement processing referred to below.
Who we are
Karmuz Network operates the autonomous system AS209990 and this website, and is the data controller for the processing described here. Karmuz Network is a trade name of Karmuz, a sole proprietorship 'eenmanszaak' registered in the Business Register of the Netherlands Chamber of Commerce under KVK number 83633588, VAT number NL003849619B59, established in the Netherlands. For any privacy matter, contact us at privacy@karmuz.net.
What we collect, why, and on what basis
Server logs
When you visit the site or use our network tools, our servers keep technical logs - your IP address, the time of the request, the page or query, and basic browser information. We use these to keep the service running, protect it against abuse and attacks, and diagnose faults. The legal basis is our legitimate interest in operating and securing the network (Art. 6(1)(f) GDPR).
Cookies
We use strictly necessary cookies to run the site and remember your consent choice. With your consent, we also use analytics cookies to understand how the site is used and functional cookies to enable optional features. You decide which categories to allow, and you can change or withdraw that choice at any time. The legal basis for the optional categories is your consent (Art. 6(1)(a) GDPR). See "Cookies and your choices" below.
Looking glass and network tools
When you run a lookup (DNS, WHOIS, ping, traceroute, routing, TLS), the target you enter - a domain, IP address, prefix, or AS number - is sent to our own servers, which run the check from our network, and passed to the third-party sources needed to answer it (for example RIPE NCC / RIPEstat for routing data, public DNS resolvers, and the host you asked about). We do not build a profile of you from these queries; they are logged with your IP to enforce rate limits and prevent abuse. The legal basis is our legitimate interest in providing and protecting the tool (Art. 6(1)(f) GDPR).
Network traffic records
We keep flow records - source and destination addresses, ports, protocol, volume and time - for traffic crossing AS209990. We use them to detect attacks and abuse, to size capacity and to investigate reported incidents. We do not inspect the content of traffic except where technically necessary for those purposes or required by law. The legal basis is our legitimate interest in operating and securing the network (Art. 6(1)(f) GDPR).
When you email us
If you write to our peering, NOC, abuse, security, legal or privacy addresses, we process your email address and message to handle your request. The legal basis is our legitimate interest in responding to you (Art. 6(1)(f) GDPR), or performance of a contract where you write about an order or a cancellation (Art. 6(1)(b) GDPR).
If you send an abuse or illegal-content notice we also process the evidence you submit, and we keep a record of the notice and of the measure taken, to meet our Digital Services Act obligations (Art. 6(1)(c) GDPR). Where the report concerns a customer's service we may pass it to that customer so they can act on it.
Customers, orders and payments
When you order a service we process your name, company and KVK or VAT details, contact and billing details and order history, to perform the contract (Art. 6(1)(b) GDPR) and to meet our tax and accounting duties (Art. 6(1)(c) GDPR).
Where the risk profile of a service requires it we also verify identity, company registration, control of a domain, IP range or ASN, or who ultimately owns the business - see section 3 of our Acceptable Use Policy. The basis is our legitimate interest in being able to trace abuse to a responsible party (Art. 6(1)(f) GDPR). We view identity documents rather than retaining them, and you may redact your photograph and citizen service number before showing us one.
We screen against the EU consolidated sanctions list before activating a service and when circumstances change, to comply with EU restrictive measures (Art. 6(1)(c) GDPR).
Payments are handled by a payment service provider established in the EU, which acts as an independent controller for the payment transaction. We receive the payment status and never your full card details.
Cookies and your choices
We group cookies into three categories:
- Strictly necessary - always active. These keep the site working and store your consent choice. They cannot be switched off.
- Analytics - used only with your consent, to measure how the site is used so we can improve it.
- Functional - used only with your consent, to enable optional conveniences and enhanced tool features.
Our banner lets you accept or reject the optional categories, and you can change or withdraw your choice at any time - it is as easy to reject as to accept.
Who we share data with
We do not sell your data and we do not share it with advertising networks or data brokers.
We use a small number of service providers, and they act as our processors: they handle data only on our instructions and under a contract. They cover hosting and delivering the site and, only if you have agreed to analytics, the analytics service. A payment service provider handles payments, as described above.
We disclose data to competent authorities - including the ATKM, law enforcement and the Public Prosecution Service - and to the EOKM hotline, where a legal duty requires it or where we report a suspected criminal offence. Where an abuse notice concerns a customer's service or a reseller's customer, we forward it to them so they can act, as sections 10 and 11 of our Acceptable Use Policy describe.
When you use a network tool, your query necessarily reaches the third-party sources and the host you chose to look up, as described above.
Where your data is processed
We process data within the European Economic Area wherever we can. Where a provider processes data outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Where a lookup you run reaches a service or host outside the EEA, that transfer is an inherent part of the tool you chose to use and the destination you entered.
How long we keep it
Technical logs, tool logs and flow records are kept for up to 30 days in our live systems. Copies in backups disappear as those backups age out on their normal rotation.
Where a log forms part of an abuse or security case, or where a legal duty applies - for example the six-month preservation required by Article 6 of Regulation (EU) 2021/784, or a preservation order from a competent authority - we keep the relevant records separately, only for as long as that case or duty lasts, and then delete them.
Your consent cookie lasts up to 180 days, or until you change it. Emails are kept for as long as we need them to deal with your request, and afterwards only where we need a record of what was agreed or a legal retention duty applies. Invoices and the underlying administration are kept for seven years, as article 52 of the Algemene wet inzake rijksbelastingen requires.
Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we process it, and to data portability. Where processing relies on consent, you can withdraw it at any time (for cookies, via "Manage cookie preferences" above) without affecting processing already carried out.
To exercise any of these, email privacy@karmuz.net. If you believe we have handled your data improperly, you can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl (opens in a new tab)), or with the authority in your country of residence.
Automated decisions
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
We do run automated systems that watch for attacks, abuse and routing problems, and we screen against sanctions lists before activating a service. These can flag something for review, but a person decides anything that affects your service or your contract, and you can contest that decision under section 12 of our Acceptable Use Policy.
Changes to this policy
We may update this policy as the service changes. The version and date at the top always reflect the current version; if a change affects the choices you have made, we will ask for your consent again. Every version has a permanent address of its own - karmuz.net/privacy/v1.0 - and superseded versions stay published there.