Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Combahton FlowShield is a security and bot mitigation service. This page explains its cookies, your GDPR and ePrivacy obligations, data transfers and how to deploy it with valid consent.
Combahton FlowShield is a security and bot mitigation service operated by Combahton GmbH. It sits in front of your website to filter malicious traffic, absorb denial of service attacks and challenge suspicious visitors before they reach your origin server.
To tell humans and bots apart, Combahton FlowShield processes connection metadata such as the visitor IP address, the user agent and request patterns, and it stores a strictly necessary cookie that records the result of a security challenge.
Filtering traffic means processing IP addresses, which are personal data under the GDPR, so you need a lawful basis. Most operators rely on legitimate interest in network and information security, recognised in Recital 49 GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The cookies Combahton FlowShield needs are strictly necessary for the service to work, so they are exempt from prior consent under the ePrivacy rules, but you must still inform visitors about them.
Combahton operates its filtering network from data centres in Germany, so visitor traffic stays within the European Union. Even so, record the hosting location in your records of processing to demonstrate accountability under Article 30 GDPR.
Configure Combahton FlowShield so the security cookie is described in your cookie policy, keep challenge logs no longer than necessary, sign a data processing agreement with Combahton GmbH and confirm where traffic is filtered so you can document any transfer.
Websites using Combahton FlowShield must obtain user consent under GDPR regulations.
DPIA considerations
Combahton FlowShield is limited in scope and low risk, so a full DPIA is usually not required, but you should document your screening decision to evidence accountability.
Sample consent text
We use Combahton FlowShield to protect the site against fraud and automated attacks. With your consent we store the cookies described in our cookie policy. You can accept, refuse or withdraw your choice at any time.
Third-party domains contacted
flowshield.iocombahton.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __flowshield | Strictly necessary | 30 minutes | Stores the outcome of the bot mitigation challenge so a verified visitor is not challenged again on every request |
| __fs_rl | Strictly necessary | 10 minutes | Holds a short lived rate limiting token used to throttle abusive automated requests |
Combahton FlowShield is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Combahton FlowShield sets the following cookies: __flowshield, __fs_rl. Each one is listed in the cookie table on this page with its type, duration and purpose, and you should mirror that list in your own cookie policy.
No prior consent is needed for the strictly necessary cookies Combahton FlowShield uses to function, but you must still describe them in your privacy and cookie policy under the transparency rules.
The lawful basis is Legitimate interest (Art. 6(1)(f) GDPR). Record this basis in your records of processing and state it in the privacy notice shown to visitors.
By default no transfer to a third country takes place. Combahton operates its filtering network from data centres in Germany, so visitor traffic stays within the European Union. Reassess if you later enable an external integration.
A DPIA is usually not required for Combahton FlowShield on its own because the processing is limited and low risk, but document your reasoning.
Implement Combahton FlowShield through your consent layer: keep strictly necessary functions always on, gate optional ones behind consent, sign a data processing agreement with Combahton GmbH where it acts as a processor and keep your cookie policy in sync with the real cookies.
Alternatives include other anti bot and denial of service providers such as Cloudflare, Akamai or self managed rate limiting. They follow the same legitimate interest logic, so the compliance steps are similar.
List every cookie Combahton FlowShield sets in your cookie policy with its name, purpose and retention, state the legal basis, name Combahton GmbH where relevant, and update the policy whenever the tool changes so refusals in your banner are always honoured.