webfilteringdatabase.com
Home Find Your Solution
Features
Domain Categorization API Real-Time Classification 59 Filtering Categories Offline Database (100M) ML Classification Content Classification
Industries
K-12 Schools Corporate Healthcare Government ISPs
Tools
Domain Lookup Bulk Categorization Category Explorer
Resources
Pricing API Documentation Login / Sign Up
Enterprise Data Privacy

Data Privacy Statement

We are committed to protecting your data with the highest standards of security and privacy. Web Filtering Database infrastructure operates within the European Union, fully compliant with GDPR.

Last updated: March 2026
EU-based infrastructure
GDPR compliant

100% EU-Hosted

All servers and data storage are located exclusively in Germany and Finland. Your data never leaves the European Union.

GDPR Compliant

We follow all requirements of the EU General Data Protection Regulation (GDPR) across every aspect of our operations.

Minimal Data Use

Domain and URL queries are processed to return category results. We collect only the minimum metadata needed for billing and reliability.

Offline Database Option

For maximum privacy, we offer an offline downloadable database so domain lookups never leave your own infrastructure.

1

Overview

This Data Privacy Statement explains how Web Filtering Database (operated by Alpha Quantum, Munich, Germany) handles data when you use our domain categorization and web filtering API. We designed our platform with privacy at its core — query data is processed to return category results, never used for purposes beyond service delivery, and never shared with third parties.

2

Data Processing & Storage

When you submit domain or URL queries to our API, the following principles apply:

  • Query data used only for classification — Domains and URLs you submit are used solely to look up or compute category results. They are not used for any secondary purpose.
  • No storage of sensitive content — We do not store the full text or content of websites you query. Only the domain/URL string and associated metadata (timestamps, request counts, response codes) needed for billing and reliability are recorded.
  • No logging of personal data — API request logs do not contain personal information beyond the queried domain/URL and your API key identifier.
  • No use of your queries for model training without consent — Queried domains may be used to improve classification accuracy only in aggregate and anonymized form, never linked back to individual customers.

In Practice

When you send a domain lookup request to our API, the domain is checked against our database of 100 million pre-classified domains. The category result is returned immediately. No personal data about you or your end-users is stored as part of this lookup.

3

Deployment Options

We offer two deployment models to accommodate different data privacy requirements:

Standard

Cloud API

Our standard REST API hosted on EU infrastructure. Submit domain or URL queries and receive category results in under 50ms.

  • Instant access — sign up and start immediately
  • 100 million pre-classified domains across 59 categories
  • Real-time ML classification for new or unknown domains
  • Query data not stored beyond billing metadata
  • 99.9% uptime SLA with EU-based infrastructure
  • Standard and volume-based pricing plans
Available on all standard pricing plans

Which Option Is Right for You?

For most use cases, our Cloud API provides excellent performance with minimal data footprint. If your compliance or regulatory framework requires that queries must never leave your own network, our Offline Database ensures complete data isolation within your own infrastructure. Contact us at [email protected] to discuss your requirements.

4

Infrastructure & Data Residency

All of our infrastructure is hosted exclusively within the European Union. Both the Cloud API and the Offline Database option keep all processing strictly within EU borders.

🇩🇪

Germany

Primary processing and application servers are located in German data centers, operating under strict German and EU data protection laws.

🇫🇮

Finland

Additional infrastructure is hosted in Finnish data centers, ensuring redundancy and high availability — all within the EU.

  • EU-only data processing — Our classification infrastructure keeps all query data within EU borders at all times.
  • EU-governed data centers — Our hosting providers operate Tier III+ certified facilities compliant with EU regulations.
  • Encrypted in transit — All API communication is encrypted using TLS 1.2+ (HTTPS). Data in transit cannot be intercepted or read by any intermediary.
5

GDPR Compliance

We fully adhere to the EU General Data Protection Regulation (GDPR). Our commitment includes:

  • Lawful basis for processing — We process data solely based on the contractual necessity of providing our domain categorization service to you (Article 6(1)(b) GDPR).
  • Data minimization — We collect and process only the minimum data necessary to deliver the service.
  • Purpose limitation — Your query data is used exclusively for the purpose of returning web filtering category results. No secondary use, no profiling, no analytics on your queries.
  • Right to information — This statement provides full transparency into how your data is handled.
  • Data Protection Officer — We have designated a data protection officer who can be reached at [email protected].
  • Data Processing Agreements (DPA) — We provide DPAs to enterprise customers upon request to formalize our data protection commitments.
6

Account & Billing Data

Separately from API content data, we collect limited account information to manage your subscription:

  • Account information — Email address, company name, and contact details provided during registration.
  • Billing records — Transaction history and payment metadata. We do not store full credit card numbers; payment processing is handled by PCI-DSS compliant third-party processors.
  • Usage metrics — API call counts, timestamps, and response codes for billing and reliability monitoring. These records contain no customer content.

This account and billing data is stored within the EU and retained only for as long as your account is active or as required by applicable tax and commercial law.

7

Security Measures

We implement comprehensive technical and organizational measures to protect your data:

  • Encryption in transit — All communications are secured via TLS 1.2+ (HTTPS).
  • Network isolation — Processing servers operate in isolated virtual private networks with strict firewall rules and no public access beyond the API endpoints.
  • Access controls — Internal access is restricted on a need-to-know basis with multi-factor authentication and audit logging.
  • Regular security assessments — We conduct periodic vulnerability assessments and penetration testing of our infrastructure.
  • Incident response — We maintain a documented incident response plan and will notify affected customers within 72 hours in the event of a data breach, in accordance with GDPR Article 33.
8

Sub-processors & Third Parties

We do not sell or share your data for marketing, analytics, or any purpose unrelated to delivering the web filtering service. Our sub-processors include:

  • EU-based hosting providers — Infrastructure providers operating data centers in Germany and Finland, bound by DPAs and GDPR obligations.
  • Payment processor — PCI-DSS compliant payment provider for subscription billing (no query data is shared with the payment processor).

If you require a deployment where no query data is processed by any external party, our Offline Database option eliminates all external sub-processors from the data pipeline.

9

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

  • Right of access — Request a copy of the personal data we hold about you.
  • Right to rectification — Request correction of inaccurate personal data.
  • Right to erasure — Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing — Request limitation of how we process your data.
  • Right to data portability — Receive your data in a structured, machine-readable format.
  • Right to object — Object to specific types of processing.
  • Right to lodge a complaint — File a complaint with your local EU data protection supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

Questions About Data Privacy?

Our team is here to discuss your specific data protection requirements. We also provide Data Processing Agreements (DPAs) for enterprise customers.