Data Policy


https://webwall.scriptnet.net Data Policy for the processing of IP addresses


Last updated: [Date]


This Data Policy describes how https://webwall.scriptnet.net (hereinafter "the Site") collects, uses and protects Data relating to the IP addresses of users who visit the website. This Policy complies with the General Data Protection Regulation (GDPR) and applies to all Operations relating to the processing of IP addresses through our Protection and monitoring system.


1. Information collected

The Site collects and records the IP addresses of users who access the site, in order to monitor, analyze and block malicious activities, such as Bots, Data Scrapers, Spam and automated intrusion attempts.

To guarantee the Privacy of legitimate Users, standard traffic IP addresses are anonymized (e.g. 123.123.xxx.xxx) before storage in our system, ensuring they cannot be used to personally identify individuals.

Exception for Malicious Activity: If an IP address is mathematically identified as engaging in malicious behavior (e.g., unauthorized attempts to access system files, restricted paths, or admin configurations), the IP address is processed and temporarily stored in clear text. This is strictly necessary to enforce network security and block the ongoing threat.


2. Purpose of processing

The Data collected (IP addresses) are used only for the following purposes:


  1. Protection against malicious traffic and attempted automated attacks.
  2. Real-time analysis to optimize the performance and security of the site.
  3. Blocking of malicious IP addresses through automatic updates from external sources (e.g. Project Honeypot).
  4. Enforcing edge-level firewall rules (e.g., via Cloudflare) to drop malicious connections before they reach the server.
  5. Participation in a decentralized threat-intelligence network to proactively identify and block global threats.


3. Processing methods

The only Data collected (IP addresses) are processed automatically by the system without profiling users or recording personal information (such as user-agents). The processing occurs in compliance with applicable Laws and Security measures are adopted to prevent unauthorized access, disclosure or modification of the Data. Processing of malicious IP addresses is based on the Legitimate Interest of securing the network against cyber threats.


4. Data retention

  1. The anonymized IP addresses of legitimate users are stored for a maximum of 3 months.
  2. The IP addresses included in the local blacklist are stored for a maximum of 90 days, after which they are automatically deleted from the system.
  3. Cloudflare Edge Lists: If enabled, malicious IPs sent to Cloudflare for edge-blocking are retained for a maximum of 30 days and are actively managed and purged by a daily automated cleanup process.
  4. Threat Intelligence Network: Malicious IPs shared with our global threat network are retained for a period strictly determined by the local administrator's security settings.


These data are not used for profiling or marketing purposes. The management of collected and blocked IPs is dynamic, with automatic updates from external sources like Project Honeypot, Google, and Bing, to ensure the site's protection.


5. Data Sharing

Users' IP addresses are not shared with third parties for marketing purposes. Data sharing only occurs for strict security enforcement in the following cases:


  1. Cloudflare Integration (if active): Non-anonymized malicious IP addresses may be transmitted to Cloudflare to create strict edge-level firewall blocking rules.
  2. Scriptnet (Hive Mind) Network: In the event of a proven malicious intrusion attempt (e.g., unauthorized access to system files), the malicious IP address (in clear text), an event hash, and this installation's URL are securely transmitted to the central threat database. This data is shared with other authenticated installations in the network to proactively block the threat globally.
  3. External Security Sources: When data is sent to external protection sources such as Project Honeypot, to identify malicious IP addresses, or consulted via DNS to check for blacklisted IPs.


6. User Rights

Under the GDPR, users have the right to:


  1. Access personal Data concerning them.
  2. Request correction or deletion of Data.
  3. Restrict Data processing.
  4. File a complaint with a data protection authority.
  5. To exercise your rights, you can contact the site administrator at [email protected].


Site administrators are responsible for the correct and secure handling of IP addresses, particularly when manually blocking or unblocking them. Administrators are required to comply with relevant data protection regulations and ensure that all actions respect users' privacy.


7. Cookies and similar technologies

The site may use cookies and other similar technologies to improve the user experience.

For more details, see our website Cookie Policy.


8. Security

The Site adopts technical and organizational measures to protect IP addresses and other information from unauthorized access, alteration or disclosure. However, no data transmission or storage system can be completely secure, and we cannot guarantee the absolute Security of any Data.


9. Changes to the Privacy Policy

This Privacy Policy may be updated from time to time. Any changes will be posted on this page with the date of the last update. We encourage you to check this page regularly for any updates.


For any questions or requests regarding this Data Policy or to exercise your rights concerning the processing of your data, please contact our Data Protection Officer (DPO) at [email protected].