CDNShark Policies

GDPR Privacy Statement

Last updated: Jul 02, 2026

This GDPR Privacy Statement supplements our Privacy Policy and describes how Nath Network & Telecom Inc. (“CDNShark”, “we”, “us”, or “our”) processes personal data of individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”) in accordance with the EU General Data Protection Regulation and the UK GDPR (together, the “GDPR”).

1. Controller and Processor Roles

When we process personal data about our customers and website visitors for our own purposes (such as account management and billing), we act as a controller. When we process personal data on behalf of a customer in order to deliver, cache, or route their traffic and content, we act as a processor, and the customer is the controller responsible for that data.

2. Legal Bases for Processing

We process personal data on one or more of the following legal bases:

  • Contract — to provide the Services you have requested and fulfil our agreement with you;
  • Legitimate interests — to secure, maintain, and improve the Services and prevent abuse, provided these interests are not overridden by your rights;
  • Legal obligation — to comply with applicable laws and lawful requests;
  • Consent — where required, for example for certain marketing communications or non-essential cookies.

3. Your Rights Under the GDPR

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request erasure of your data (“right to be forgotten”);
  • Restrict or object to certain processing;
  • Data portability, where applicable;
  • Withdraw consent at any time, without affecting prior processing;
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact us using the details below. We will respond within the timeframes required by law.

4. International Data Transfers

Because CDNShark operates a global network, personal data may be transferred to and processed in countries outside the EEA or UK, including the United States. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum, where applicable) or other lawful transfer mechanisms.

5. Data Processing for Customers (Sub-Processors)

Where we act as a processor for a customer, we process personal data only on the customer’s documented instructions, maintain appropriate security measures, assist with data-subject requests where reasonably possible, and engage sub-processors under written agreements consistent with the GDPR. A data processing agreement is available to customers who require one.

6. Data Retention

We retain personal data only for as long as necessary for the purposes described in our Privacy Policy, or as required by law, after which it is deleted or anonymized.

7. Complaints

If you are in the EEA or UK and believe our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. We would, however, appreciate the opportunity to address your concerns first.

8. Contact Us

For GDPR-related requests or questions, contact us at legal@cdnshark.com.