Last updated: 29 August 2026
This Digital Services Act Notice explains how boxbank s.r.o., operating under the WEBDANGER brand, handles obligations that may apply under Regulation (EU) 2022/2065 on a Single Market for Digital Services (“Digital Services Act” or “DSA”).
This Notice is intended for WEBDANGER Services that qualify as intermediary services under the DSA.
Not every WEBDANGER product falls within the same DSA category.
This Notice should be read together with our:
- Terms of Service;
- Acceptable Use & Abuse Policy;
- Privacy Policy;
- and any service-specific terms.
1. Provider identity
WEBDANGER is operated by:
boxbank s.r.o.
Registered office:
Jana Palacha 510/50 278 01 Kralupy nad Vltavou Czech Republic
Company identification number (IČO):
24048232
Commercial Register:
Municipal Court in Prague, Section C, File No. C 437675
Primary website:
webdanger.com
General contact:
contact@webdanger.com
Telephone / SMS:
+420 734 627 827
DSA SCOPE
2. Service-by-service classification
The DSA distinguishes different categories of intermediary services.
Depending on the technical function of a WEBDANGER Service, a Service may qualify as:
- a “mere conduit” service;
- a “caching” service;
- a “hosting” service;
- or, if the statutory conditions are met, an “online platform”.
A Service is classified according to what it actually does, not merely according to its marketing name.
3. Web-development services
Ordinary website design, software development, consulting, branding or other professional services do not automatically become intermediary services merely because WEBDANGER provides them.
Where WEBDANGER only creates or maintains Customer software and does not perform a relevant intermediary function, the DSA intermediary-service rules may not apply to that activity.
4. Hosting and cloud services
Where a WEBDANGER Service stores information provided by and at the request of a Customer, that Service may qualify as a hosting service under the DSA.
Examples may include certain:
- web-hosting services;
- cloud storage;
- server-based storage;
- managed website hosting;
- or other Customer-content storage.
The exact classification depends on the production architecture and contractual role.
5. Online-platform distinction
A hosting service is not automatically an online platform.
An online platform generally stores information at the request of recipients and also disseminates that information to the public at their request, subject to the statutory definition and its ancillary-function exception.
Infrastructure hosting that supports a Customer's website or application does not by itself mean that WEBDANGER is the online platform operated through that infrastructure.
If WEBDANGER later launches a marketplace, social network, public user-content feed or another service that itself disseminates user-provided information to the public, WEBDANGER will reassess the applicable DSA obligations.
6. Domains, DNS and infrastructure
Domain-registration, DNS, CDN, proxy, network and infrastructure functions may have different DSA classifications depending on the exact service.
WEBDANGER does not represent that every domain/DNS transaction is legally identical to a hosting service.
Where an upstream registrar, registry, DNS provider, infrastructure provider or other intermediary has independent obligations, those obligations remain separate from WEBDANGER's obligations.
DSA POINTS OF CONTACT
7. Article 11 — authorities, Commission and Board
For WEBDANGER intermediary Services within the DSA, the current single electronic point of contact for communications from Member State authorities, the European Commission and the European Board for Digital Services under Article 11 DSA is:
contact@webdanger.com
This address may later be replaced or supplemented by a dedicated DSA address when that address is operational and publicly announced.
8. Languages for Article 11 communications
WEBDANGER currently accepts Article 11 communications in:
- Czech
- English
Additional languages may be supported where operationally feasible.
9. Article 12 — recipients of the Service
Recipients of WEBDANGER intermediary Services can communicate directly and rapidly with WEBDANGER electronically.
The current published email contact is:
contact@webdanger.com
Where the relevant Service provides an additional contact form, support-ticket interface or other electronic support channel, recipients may use that channel as an alternative means of communication.
For abuse or illegal-content reports, WEBDANGER provides a dedicated electronic reporting mechanism at webdanger.com/abuse. It is available without a WEBDANGER account.
WEBDANGER does not rely solely on automated tools for the Article 12 point of contact.
Where an AI or automated support system is used for initial triage, a route to human handling remains available.
10. No separate Article 13 EU legal representative
boxbank s.r.o. is established in the Czech Republic.
Accordingly, WEBDANGER does not currently require the separate EU legal representative described in Article 13 DSA for providers that have no establishment in the European Union.
TERMS AND CONTENT RESTRICTIONS
11. Rules applying to Customer information
Restrictions that WEBDANGER may apply to Customer information or use of an intermediary Service are described in:
- the Terms of Service;
- Acceptable Use & Abuse Policy;
- this Notice;
- and applicable service-specific rules.
Those documents may describe:
- prohibited content;
- prohibited conduct;
- abuse handling;
- automated tools;
- human review;
- suspension;
- removal;
- quarantine;
- security measures;
- and available review mechanisms.
12. Fundamental rights and proportionality
Where the DSA requires it, WEBDANGER applies relevant Terms restrictions in a diligent, objective and proportionate manner with due regard to the rights and legitimate interests of the parties involved, including applicable fundamental rights such as freedom of expression and information.
WEBDANGER does not treat content as illegal merely because it is unpopular, controversial or critical.
Where an intermediary Service is primarily directed at minors or predominantly used by minors, the applicable Terms information is provided in a manner that minors can understand, as required by Article 14(3) DSA.
Recipients are informed of significant changes to applicable intermediary-service Terms in accordance with Article 14 where required.
NO GENERAL MONITORING
13. No general monitoring obligation
The DSA does not impose a general obligation on intermediary-service providers to monitor all information that they transmit or store or actively seek facts or circumstances indicating illegal activity.
WEBDANGER therefore does not promise to manually inspect every Customer file, domain, website, server or communication.
14. Voluntary security and abuse measures
The absence of a general monitoring obligation does not prevent WEBDANGER from using proportionate measures such as:
- malware detection;
- phishing detection;
- WAF/security controls;
- fraud detection;
- spam controls;
- abuse triage;
- or other voluntary investigations
where lawful and appropriate.
ORDERS FROM AUTHORITIES
15. Article 9 — orders to act against illegal content
Where WEBDANGER receives an order to act against one or more specific items of illegal content issued by a relevant national judicial or administrative authority under applicable Union or national law compliant with Union law, WEBDANGER handles the order according to Article 9 DSA and other applicable law.
WEBDANGER may verify:
- issuing authority;
- authenticity;
- legal basis;
- specific content/location;
- territorial scope;
- required action;
- applicable redress information;
- and procedural requirements.
16. Effect given to an Article 9 order
Where Article 9 applies, WEBDANGER informs the issuing authority, or another authority specified in the order, without undue delay of the effect given to the order, including whether and when effect was given.
WEBDANGER may delay notification to an affected Customer where applicable law validly requires confidentiality or delayed disclosure.
17. Article 10 — orders to provide information
Where WEBDANGER receives an order to provide specific information concerning one or more specific recipients of the Service, WEBDANGER handles the order according to Article 10 DSA and applicable data-protection, procedural and other law.
An Article 10 order is limited, under the DSA framework, to information that has already been collected for the purpose of providing the Service and that lies within the provider's control.
WEBDANGER does not treat an informal request for unrestricted Customer data as automatically equivalent to a valid Article 10 order.
18. Verification of information orders
WEBDANGER may verify matters including:
- legal basis;
- identity and authority of the issuing body;
- the specific Customer/recipient concerned;
- scope of information requested;
- whether the requested information is already collected for Service provision and within WEBDANGER's control;
- necessity/proportionality stated in the order where required;
- confidentiality rules;
- redress information;
- and the correct authority for confirmation of execution.
Where Article 10 applies, WEBDANGER informs the affected recipient of the order and the effect given to it at the latest when effect is given, or at the time specified by the issuing authority, and provides the required statement of reasons and available redress information, subject to any valid procedural or confidentiality rule governing timing or disclosure.
NOTICE AND ACTION
19. Article 16 notice-and-action mechanism
Where WEBDANGER provides a hosting service within the scope of Article 16 DSA, WEBDANGER provides an electronic mechanism through which any individual or entity can notify WEBDANGER of specific information that the reporter considers to be illegal content.
The mechanism is intended to be:
- electronically accessible;
- user-friendly;
- sufficiently precise;
- and capable of identifying the specific information concerned.
A reporter is not required to purchase a WEBDANGER Service merely to submit an applicable illegal-content notice.
20. Information requested in a notice
For an ordinary Article 16 notice, WEBDANGER requests information sufficient to support a diligent decision, including:
- a sufficiently substantiated explanation of why the information is alleged to be illegal;
- the exact electronic location, such as exact URL(s), and additional identifying information where necessary;
- the reporter's name and email address, subject to the statutory child-safety exception described below;
- a statement confirming the reporter's good-faith belief that the information and allegations are accurate and complete.
The reporting interface may request additional optional evidence where useful.
21. Child-safety reporter identity exception
Article 16 DSA provides a specific exception to the ordinary name/email requirement for information considered to involve offences referred to in Articles 3 to 7 of Directive 2011/93/EU concerning sexual abuse or sexual exploitation of children and related offences.
Where that exception applies, WEBDANGER's reporting process does not require the reporter's name and email merely to defeat the statutory protection.
Reporters should not redistribute suspected child sexual abuse material through ordinary support email.
22. Exact location
A report should identify the content as precisely as reasonably possible.
Depending on the Service, this may include:
- exact URL;
- hostname/domain;
- file path/reference;
- server/resource ID;
- public object identifier;
- or another electronic locator.
A vague statement that “something illegal is somewhere on this server” may not be sufficient for a diligent decision without additional information.
23. Acknowledgement
Where an Article 16 notice contains electronic contact information, WEBDANGER sends confirmation of receipt without undue delay.
A report may receive a case/reference number.
24. Processing standard
Applicable Article 16 notices are processed in a:
- timely;
- diligent;
- non-arbitrary;
- and objective
manner.
WEBDANGER may request additional information where the notice is insufficient to support a reliable decision.
25. Automated assistance
WEBDANGER may use automated tools or AI to:
- classify reports;
- detect duplicates;
- identify likely phishing/malware;
- extract URLs;
- prioritise urgent safety cases;
- or assist abuse analysts.
Where Article 16 requires disclosure of automated means used for processing or decision-making, that disclosure is included in the reporter notification.
Automation does not eliminate the need for appropriate safeguards.
26. Decision to the reporter
Where Article 16 applies, WEBDANGER notifies the reporter without undue delay of its decision concerning the reported information and provides information on available redress possibilities as required.
Possible decisions include:
- content/action restricted;
- Service suspended;
- issue remediated;
- no action;
- insufficient information;
- referral/escalation to an upstream provider;
- or another appropriate outcome.
The reporter is not automatically entitled to confidential Customer information merely because a report was submitted.
27. Actual knowledge or awareness
A sufficiently precise and adequately substantiated Article 16 notice may give rise to actual knowledge or awareness regarding a specific item of information for the purposes of the applicable hosting liability framework where it enables a diligent hosting provider to identify the illegality without a detailed legal examination.
WEBDANGER therefore treats credible, specific notices as operationally important.
HOSTING LIABILITY FRAMEWORK
28. Hosting-service liability framework
Where the DSA hosting-liability rules apply, the statutory exemption can depend on whether the provider has actual knowledge of illegal activity or illegal content or, in relation to damages claims, awareness of facts or circumstances from which illegality is apparent, and on acting expeditiously to remove or disable access once the relevant knowledge or awareness exists.
The exemption is also subject to the other statutory conditions and limitations in Article 6. In particular, it does not apply where the recipient acts under the authority or control of the provider within Article 6(2). A separate consumer-protection limitation can also apply to an online platform allowing consumers to conclude distance contracts with traders where the relevant statutory presentation test in Article 6(3) is met.
This Notice does not expand or waive the statutory conditions.
29. Voluntary investigations
Good-faith voluntary own-initiative investigations or measures aimed at detecting, identifying, removing, disabling access to or otherwise addressing illegal content do not by themselves prevent reliance on DSA liability exemptions where Article 7 applies.
STATEMENT OF REASONS
30. Article 17
Where Article 17 DSA applies, WEBDANGER provides the affected recipient with a clear and specific statement of reasons when WEBDANGER imposes certain restrictions because information supplied by that recipient is considered:
- illegal content; or
- incompatible with WEBDANGER's Terms.
31. Restrictions covered
Depending on Article 17 applicability, restrictions may include:
- removal of specific information;
- disabling access;
- reducing visibility;
- suspension/restriction of monetary payments;
- suspension or termination of part/all of a Service;
- suspension or termination of an account.
32. Timing
Where Article 17 applies and WEBDANGER knows the relevant electronic contact details, the statement is provided at the latest from the time the restriction is imposed.
33. Information in a statement of reasons
Where required, a statement may include:
- the restriction and its territorial scope;
- duration;
- relevant facts and circumstances;
- whether the decision followed a notice or WEBDANGER's own investigation;
- legal ground where the information is considered illegal;
- relevant Terms/AUP ground where the information is considered incompatible with the Service rules;
- use of automated means where relevant;
- and available redress.
34. Article 17 exceptions
Article 17 contains statutory exceptions.
In particular, the statement-of-reasons duty does not apply in the same manner to deceptive high-volume commercial content, and Article 17 does not apply to orders referred to in Article 9.
WEBDANGER applies Article 17 according to its actual statutory scope.
THREATS TO LIFE OR SAFETY
35. Article 18
Where WEBDANGER is acting as a hosting-service provider and becomes aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of a person or persons:
- has taken place;
- is taking place;
- or is likely to take place,
WEBDANGER follows the prompt notification requirements of Article 18 DSA where applicable.
36. Authorities notified
Where Article 18 applies, WEBDANGER promptly informs the law-enforcement or judicial authorities of the Member State or Member States concerned and provides the relevant information available.
If WEBDANGER cannot identify the Member State concerned with reasonable certainty, Article 18 provides for notification to the law-enforcement authorities of the Member State in which WEBDANGER is established and/or Europol as applicable.
MODERATION AND CUSTOMER REVIEW
37. Proportionate action
Depending on severity and legal obligations, WEBDANGER may:
- request remediation;
- warn;
- quarantine;
- block specific content;
- disable a malicious function;
- restrict traffic;
- suspend a Service;
- suspend a domain/DNS function;
- terminate a Service/account;
- preserve evidence;
- escalate upstream;
- or comply with a valid authority order.
Where practical, a compromised legitimate Customer site may be remediated or quarantined instead of being treated as intentionally malicious.
38. Review requests
A Customer who believes a WEBDANGER moderation or abuse decision is erroneous may request review through:
contact@webdanger.com
or another review mechanism published for the relevant Service.
A review request does not automatically stay an urgent safety, security, authority or upstream action.
39. Judicial and statutory remedies
Nothing in this Notice removes judicial or statutory remedies available under applicable law.
Where additional DSA redress rights apply to a particular type of Service, they are provided according to the relevant classification and statutory requirements.
UPSTREAM PROVIDERS
40. Hetzner infrastructure
WEBDANGER may use Hetzner infrastructure for cloud, server, hosting or related technical Services.
Hetzner remains an independent upstream provider with its own contractual, security, abuse and legal obligations.
Where a Customer Service is technically dependent on Hetzner, WEBDANGER may be required to implement valid Hetzner restrictions, suspensions, network protections or other upstream measures.
The use of Hetzner infrastructure does not make WEBDANGER an agent or legal representative of Hetzner.
41. Openprovider domain infrastructure
WEBDANGER may use Openprovider / Hosting Concepts B.V. for domain-registration and related upstream Services.
Where WEBDANGER resells an Openprovider product:
- WEBDANGER acts in its own name as reseller;
- WEBDANGER is not entitled to give the impression that it acts as Openprovider's representative or agent;
- the identity of the sponsoring/upstream registrar is made available where required;
- applicable registrar, registry, ICANN and upstream rules may apply.
42. Openprovider abuse escalation
Where an abuse matter concerns a domain sponsored or managed through Openprovider, WEBDANGER may:
- investigate within its role;
- request Customer remediation;
- provide required information to Openprovider;
- comply with applicable registrar/registry mitigation;
- or escalate the matter to Openprovider.
Openprovider may take independent action where permitted or required by its terms, ICANN/registry rules or applicable law.
43. No false “partnership” representation
A technical supply, resale, referral, reseller, infrastructure or commercial relationship does not by itself mean that WEBDANGER is:
- an agent;
- representative;
- subsidiary;
- affiliate;
- authorised legal spokesperson;
- or ICANN-accredited registrar.
Any public description such as “official partner” is used only where supported by an actual agreement and permitted brand/trademark rules.
TRANSPARENCY REPORTING
44. Article 15
Article 15 DSA provides annual transparency-reporting obligations for intermediary-service providers concerning content moderation and certain orders/notices, subject to the statutory scope and exemptions.
WEBDANGER assesses Article 15 separately based on its actual intermediary Services and enterprise status.
45. Micro/small-enterprise exemption
Article 15(2) provides an exemption from Article 15(1) for providers of intermediary services that qualify as micro or small enterprises under Recommendation 2003/361/EC and are not very large online platforms.
WEBDANGER does not rely permanently on this exemption without reassessing:
- employee headcount;
- turnover;
- balance-sheet total;
- partner/linked-enterprise rules;
- and relevant changes in business structure.
46. Harmonised reporting
Where WEBDANGER becomes subject to DSA transparency-reporting obligations, WEBDANGER uses the then-current harmonised EU reporting format and reporting period required by applicable implementing rules.
Commission Implementing Regulation (EU) 2024/2835 requires the harmonised templates to be used from 1 July 2025.
For ordinary providers of intermediary, hosting and online-platform Services, the first full annual harmonised reporting period is 1 January to 31 December 2026. Where a reporting obligation applies, an annual report must be made publicly available no later than two months after the end of the reporting period.
Reports subject to that Implementing Regulation must remain publicly available and be retained for at least five years after publication.
ONLINE-PLATFORM GATE
47. Additional online-platform rules are conditional
WEBDANGER does not currently represent every hosting/cloud Service as an online platform.
If a WEBDANGER Service becomes an online platform within the DSA definition, additional obligations may apply depending on enterprise size and other statutory conditions.
Article 19 exempts qualifying micro and small online-platform providers from most of Chapter III, Section 3, subject to its statutory conditions. The Article 24(3) obligation remains outside that exemption, and the Section 3 exemption can continue for 12 months after loss of micro/small status under the conditions in Article 19, unless the Service is designated a very large online platform.
Where the Article 19 exemption does not apply, relevant online-platform obligations may include rules concerning:
- internal complaint handling;
- out-of-court dispute settlement;
- trusted flaggers;
- misuse;
- additional transparency;
- publication of average monthly active recipients where Article 24(2) applies;
- interface design;
- recommender systems;
- advertising transparency;
- protection of minors;
- and other platform-specific requirements.
If a WEBDANGER online platform allows consumers to conclude distance contracts with traders, the separate Section 4 / Article 29 micro-small exemption and the marketplace-specific obligations must also be assessed.
48. Transparency Database
Article 24(5) DSA requires providers of online platforms to submit relevant Article 17 decisions/statements of reasons to the European Commission's DSA Transparency Database without undue delay, while ensuring that the submitted information does not contain personal data.
This database-submission obligation does not apply merely because a Service is a hosting service.
If WEBDANGER operates only infrastructure hosting for a Customer's public website/application, that alone does not automatically make WEBDANGER the online platform operated on top of that infrastructure.
CZECH DIGITAL SERVICES COORDINATOR
49. Czech coordinator
The designated Digital Services Coordinator in the Czech Republic is the:
Czech Telecommunication Office (Český telekomunikační úřad — ČTÚ).
ČTÚ coordinates DSA matters in the Czech Republic within the powers available to it under the EU and Czech legal framework.
50. Czech implementation status
As of the review date of this Notice, ČTÚ publicly states that the relevant Czech adaptation legislation remains in the legislative process and that the Office can currently exercise only those DSA competences that do not affect the rights and obligations of persons.
The DSA itself is an EU Regulation and has been generally applicable since 17 February 2024.
WEBDANGER monitors changes to the Czech enforcement framework.
CONTACTS
51. DSA authority contact
Article 11 communications:
contact@webdanger.com
Accepted languages:
Czech / English
52. Recipient/user contact
Article 12 communications:
contact@webdanger.com
53. Illegal-content and abuse reports
Until a dedicated reporting endpoint/email is publicly activated:
contact@webdanger.com
An electronic abuse and illegal-content reporting interface is available at webdanger.com/abuse without requiring a WEBDANGER account.
APPENDIX A — DSA SERVICE CLASSIFICATION EXAMPLES
| WEBDANGER activity | Indicative treatment | Final classification required? |
|---|---|---|
| Website design/development | Professional service; not automatically intermediary | Yes |
| Customer web hosting | Potential hosting service | Yes |
| Customer cloud/file storage | Potential hosting service | Yes |
| VPS infrastructure | Depends on actual role/function | Yes |
| DNS | Potential intermediary function; classification depends on architecture | Yes |
| Domain resale | Registrar/reseller/intermediary analysis required | Yes |
| CDN/cache | Potential caching/intermediary service | Yes |
| Public user-content marketplace/community | Potential online platform | Yes |
| Customer website hosted on WEBDANGER infrastructure | WEBDANGER hosting does not automatically become the Customer's online platform | Yes |
This table is indicative and not a legal classification of a Service that has not yet launched.
APPENDIX B — ARTICLE 16 NOTICE TEMPLATE
Affected Service/resource: ________________________________
Exact URL/electronic location: ________________________________
Category of alleged illegal content: ________________________________
Why do you believe the information/activity is illegal? ________________________________
Relevant legal provision/right, if known: ________________________________
Additional evidence: ________________________________
Reporter name: ________________________________
Reporter email: ________________________________
Good-faith declaration: I believe in good faith that the information and allegations provided in this notice are accurate and complete.
For the statutory child-sexual-abuse offence exception under Article 16(2)(c), the production system must not require reporter identity/contact where the DSA says those fields need not be provided.
APPENDIX C — EXAMPLE STATEMENT OF REASONS STRUCTURE
Decision reference: ________________________________
Affected resource/information: ________________________________
Restriction: ________________________________
Territorial scope: ________________________________
Duration: ________________________________
Facts and circumstances: ________________________________
Source of decision: Notice / own initiative / other
Legal basis, if illegal content: ________________________________
Terms/AUP basis, if contractual: ________________________________
Automated means used: Yes / No / Partly
Available review/redress: ________________________________
Effective / review date: 29 August 2026