---
title: "Acquia Edge Standard Product Privacy Notice"
date: "2026-05-27T22:18:08+00:00"
summary: "Learn how Acquia Edge Standard handles personal data, privacy controls, retention, and security measures for WAF-protected domains."
image:
type: "page"
url: "/acquia-cloud-platform/acquia-edge-standard-product-privacy-notice"
id: "d3958b9c-b1f2-4d8f-8035-ca50cbe57766"
---

Acquia Edge Standard
--------------------

  
Last revision of this Product Notice: October 20, 2025  
Prior version(s) of this Product Notice: No prior version  
This Product Notice describes the privacy relevant aspects of the above-mentioned Acquia product/services.  
 

**About the Product/Services**  
Acquia Edge Standard is a Web Application Firewall (WAF) service designed to provide essential protection against common DDoS and web application security threats for Acquia-hosted domains. The service is configurable through Acquia’s Edge Console, providing insights into site activity, and enabling customers to reduce the risk and impact of potential attacks against their protected domains.  
 

Akamai is a Sub-processor for the Acquia Edge Standard web application firewall (WAF) service.  
For details about this Product, please refer to the Annex contained within the relevant Order Form or to the product description available online at https://docs.acquia.com/.

###   
1\. Processing Operation(s)

*     
    The objective of Processing of Personal Data by data importer is the performance of the Services pursuant to the Agreement.  
    Processing of Personal Data to deliver its core functionalities required: ☒ yes ☐ no  
    Optional features processing Personal Data: ☒ yes ☐ no  
    The optional features are deactivated by default: ☒ yes ☐ no ☐ n/a\*  
    Processing of sensitive Personal Data: ☒ yes\*\* ☐no ☐ n/a\*  
    Profiling of individuals based on personal characteristics: ☐ yes \*\* ☒no ☐ n/a\*  
    Automated decision making that produces legal or other significant impacts on individuals: ☐ yes ☒ no ☐ n/a\*  
    Processing via an AI tool available with the Product ☐ yes ☒ no  
    The AI feature is deactivated by default: ☐ yes ☐ no ☒ n/a\*  
    The AI feature processes Personal Data: ☐ yes ☐ no ☒ n/a\*  
    The AI feature processes sensitive Personal Data ☐ yes ☐ no ☒ n/a\*  
    The Customer can control what data the AI tool processes: ☐ yes ☐ no ☒ n/a\*

\* (n/a = not applicable)  
\*\* (optional; depends on the Customer’s configuration of the system, the connection to other systems, and the categories chosen by the Customer to be collected from Third Party Users)  
 

### 2\. Details of Personal Data being processed

Categories of Personal Data

Categories of Data Subjects

Purpose of Processing

Categories of Data Recipients

Needed for Core Features

Processing Location

Acquia Inc. acts as Processor

Through the configuration, design, and administration of the Service, Customer in its sole discretion determines and controls the categories of personal data by the Service. These may be names, titles, position, employer, contact information (email, phone, fax, physical address, etc.), identification data, professional life data, personal life data, connection data, or localization data (including IP addresses).

Through the configuration, design, and administration of the service, Customer in its sole discretion determines and controls the categories of data subjects collected by the Service: Natural persons that (i) access or use the Customer’s domains, networks, websites, application programming interfaces (“APIs”), and applications, or (ii) are authorized users such as the Customers’ employees, agents, or contractors.

Provision of the Services by Acquia to Customer

Site administrators

Yes

Globally through Akamai’s network as described here: [https://www.akamai.com/our-thinking/cdn/what-is-a-cdn](https://www.akamai.com/our-thinking/cdn/what-is-a-cdn).

Yes

### 3\. Privacy Enhancements

Objective

Technology / Measure

Data at Rest

Data in Transit

Anonymization and Pseudonymization

Data anonymization at Customer level optional for Customer

 

 

Data confidentiality (incl. encryption)

Access control measures  
Encryption at customer level  
Encryption at Acquia level  
Jurisdiction restrictions for (private) key storage and option to choose data center locations (see [Security Annex](https://security.acquia.com/) and Product Description)

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Data integrity

Anti-tampering technology (see [Security Annex](https://security.acquia.com/))

Yes

Yes

Data availability including restoring availability, restoring access to personal data, and data resilience

Business continuity and disaster recovery measures (see [Security Annex](https://security.acquia.com/))

Yes

N/A

Regular testing, assessing and evaluating TOMs

Regular security and process reviews (see also [Security Annex](https://security.acquia.com/))

Yes

N/A

###   
4\. Certifications

Refer to Acquia’s security portal (security.acquia.com) for the Edge Standard services.. Your Acquia account team may supply you with copies of the relevant compliance documentation as applicable, upon request.  
 

### 5\. Data Subject Rights

Through the Product’s administration console the Customer may manage, update, retrieve, and erase individual Personal Data  
 

### 6\. (Personal) Data Retention Cycles

  
**Customer Account Information** - Customer Account Information includes customer registration and contact information, audit logs, and other logs and data about account configurations and settings. We store Customer Account Information as long as a Customer has an active account, and we set specific timeframes for retaining Customer Account Information following deletion of an account based on the reason for collection and applicable law. In addition, upon deletion of an account or upon receipt of an individual’s request to be forgotten, we may be required to retain the email address associated with the account for an extended period of time, and potentially block that email address from creating a new account in the future, in order to comply with legal obligations and our terms.  
 

**Operational Metrics** - Acquia stores server and network activity data and logs collected by the service in the course of operating the Service and our observations and analysis of traffic data (together, “Operational Metrics”) up to 12 months or as long as we have a legitimate business purpose for retention.

  
Edge Server Logs capture traffic delivery metadata on our edge servers that perform the customer traffic processing & proxying. We do not store the POST body, and we remain oblivious to the content we deliver on behalf of our customers at all times. Edge Server logs contain basic traffic metadata including:  
● Client IP address, forward IP address,  
● URL,  
● HTTP method, Response code,  
● Non-sensitive headers such as Host, Content-type, Accept Language, Content Length,  
● A large number of Akamai-specific indicators for caching, mapping, and performance decisions.  
Potentially sensitive HTTP headers including Cookie, Referrer, and User-agent string are only logged if explicitly configured.  
  
Long term storage depends on the type of log and the applicable requirements. For instance, logs containing personal information such as IP addresses (e.g., Edge Server logs above) are only kept for 45-90 days as GDPR mandates. Security event logs including Authgate accesses are kept for at least 1 year as required for various security compliance regimes.  
 

### 7\. Sub-Processing

The specific list of Acquia’s sub-processors is available from: [https://www.acquia.com/about-us/legal/subprocessors](https://www.acquia.com/about-us/legal/subprocessors). Any current Acquia customer with a data processing agreement in place with Acquia may subscribe to receive notifications of new or changed sub-processors through the above website.  
 

### 8\. Description of the technical and organizational security measures implemented by the data importer in accordance with Clauses 4(d) and 5(c) (or document/legislation attached)

Data importer has implemented and will maintain appropriate administrative, physical, and technical safeguards for the protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in the Acquia Security Annex (available from [https://www.acquia.com/about-us/legal/gdpr](https://www.acquia.com/about-us/legal/gdpr)) applicable to the specific Services purchased by data exporter, as updated from time to time, and made available by data importer upon request. The data exporter is wholly responsible for implementing and maintaining security and data administration within any data exporter applications, configuration settings, or log settings used by data exporter in conjunction with the Services.