Privacy · updated 22 August 2026

We don't track you.

This site has no analytics scripts, no tracking, no advertising, and sets no cookies of its own. We don't know who you are and we don't want to.

Who we are

Smet.cz is a non-commercial research project. The data controller for the purposes of the GDPR is reachable at [email protected], which is the contact point for everything on this page.

Visitors to this site

Cloudflare

This site is served through Cloudflare, which may set strictly technical cookies (such as bot-mitigation or security challenge cookies) and processes connection data like IP addresses to deliver and protect the site. This is standard infrastructure operation rather than tracking by us. See Cloudflare's privacy policy for details.

Transfers outside the EU

Cloudflare is based in the United States, so connection data processed to deliver and protect this site is transferred there. The transfer relies on the safeguards in Cloudflare's data processing agreement, which include the European Commission's standard contractual clauses. See Cloudflare's privacy policy.

Why we process it

We process publicly available domain information on the basis of legitimate interests under Article 6(1)(f) GDPR: measurement of the public internet, security research, and publication of aggregate statistics in the public interest. You can object to that processing at any time, and the section below is how.

How we give notice

We obtain domain information from public sources rather than from the people it may relate to, so notifying each of them individually is not possible at the scale this project works. Article 14(5)(b) GDPR provides that where individual notification would require disproportionate effort, the information is made publicly available instead. This page is that notice.

Removal and objections

Any domain can be excluded. Email [email protected] with the domain and we will remove its information from the published files and stop processing it in future cycles. There may be delays between removal and when copies stop circulating, and files already downloaded by others are outside our control. Published files are in any case deleted after 90 days.

Your rights

Where our processing involves personal data, you have the right to request access to it, correction, erasure, or restriction of processing, and to object to processing. Write to [email protected]. You also have the right to complain to a supervisory authority; in the Czech Republic that is the Office for Personal Data Protection (ÚOOÚ).

Security

Connections to this site require TLS 1.2 at minimum, negotiate TLS 1.3 by default, and support HTTP/3. Clients that support it also negotiate hybrid post-quantum key agreement (X25519MLKEM768), so recorded traffic stays protected against decryption by a future quantum computer. Session encryption uses AES-256-GCM, the cipher standard relied on for banking and approved for classified government traffic. The site is served through Cloudflare, with DDoS mitigation and a managed web application firewall in front of it, and the origin server accepts connections from Cloudflare's network alone; it cannot be reached directly. There are no accounts, no logins and no visitor database on this site, so there is no store of personal visitor data to compromise.

Changes to this policy

This is the first published version of this policy, effective 22 August 2026. The date of the most recent change is shown at the top of this page, and material changes will be reflected there.

Contact

Privacy questions: [email protected]