TECHNICAL ANNEX — DDOS DEFINITION
Technical criteria and operational procedure for managing DDoS attacks.
This document is an English translation of the French original.
It is provided so that our English-speaking customers can read our terms in their own language.
Only the French version has legal value. If a sentence here differs from the French text, the French text applies. The French original is available at winheberg.com/autres/legal/annexe-ddos.
DDoS technical annex — Qualification, availability exclusions and force majeure
Version 2.0 — In force from 17 June 2026
This annex (hereinafter "the Annex") is issued under Article 19 of the Winheberg General Terms of Sale and Use (hereinafter "the GTSU"), entitled "Termination and compensation in the event of persistent DDoS attacks". It forms an integral part of the contract concluded between Winheberg and the Client and prevails, on the matters it expressly addresses, over the GTSU and the applicable Specific Terms.
Article 1 — Definitions
For the purposes of this Annex, the following terms have the meanings set out below:
"DDoS attack" means any deliberate and coordinated attempt to degrade, interrupt or render unavailable a network or application service by saturating the targeted processing, bandwidth or connectivity resources, by means of an abnormal volume of requests or packets sent from multiple sources.
"Qualified DDoS incident" means a DDoS attack that has met the qualification criteria set out in Article 2 of this Annex and has been formally documented within the meaning of Article 3.
"Infrastructure providers" means the network operators, bare-metal server suppliers, datacentres and third-party filtering providers that Winheberg relies upon for the physical delivery and network protection of the services. These entities operate their own mitigation systems autonomously.
"Mitigation" means all technical measures implemented by the Infrastructure providers to reduce or neutralise the impact of a DDoS attack on the network resources concerned (volumetric filtering, scrubbing, blackholing, rate limiting and so on).
"Availability" and "SLA" have the meaning defined in Article 4 of the GTSU.
Article 2 — Criteria for qualifying a DDoS attack
2.1 Qualification indicators
An incident may be qualified as a DDoS attack when it meets all of the following conditions:
- External origin: the abnormal traffic originates from sources outside the Winheberg infrastructure and outside the services of the Client concerned;
- Deliberate nature: the structure of the traffic (vectors, distribution of sources, timing) is inconsistent with a legitimate spike in activity or an unintentional technical failure;
- Measurable impact: the incident causes an actual and documented degradation of the service's performance or availability indicators.
2.2 Reference volumetric thresholds
The thresholds below are internal reference values, indicative and non-contractual, used to trigger the formal qualification procedure. Exceeding them creates a presumption of a DDoS attack, without being systematically necessary or sufficient.
| Indicator | Reference threshold |
|---|---|
| Inbound traffic volume (bandwidth) | ≥ 10 Gbps over 5 consecutive minutes |
| Packet rate | ≥ 1 Mpps (1,000,000 packets per second) over 5 minutes |
| Abnormal concurrent connection rate | ≥ 10 times the baseline measured over the previous 30 days |
| Service availability affected | Loss ≥ 50% over the period considered, as measured by Winheberg's monitoring tools |
Winheberg reserves the right to adjust these thresholds to reflect changes in the infrastructure, in attack profiles or in the configuration specific to the service concerned, without such adjustment altering the contractual obligations of the parties.
2.3 Attack vectors covered
Without prejudice to the qualification of other vectors not listed, the following attack types are in particular covered by this Annex: UDP flood, SYN flood, ICMP flood, HTTP/S flood, amplification attacks (DNS, NTP, SSDP, Memcached), connection table exhaustion attacks (TCP state exhaustion).
Attacks operating exclusively at the application layer (layer 7), such as floods targeting an application, a socket or an API, fall under the Client's responsibility pursuant to Article 4.2 of this Annex and do not give rise to any SLA exclusion.
Article 3 — Roles and scope of intervention
3.1 Winheberg's scope
Winheberg carries out the detection, qualification and documentation of DDoS incidents affecting its services. Its operational role is limited to:
- monitoring availability and traffic indicators through its supervision tools;
- initiating the formal qualification procedure when the criteria of Article 2 are met;
- coordinating with the Infrastructure providers on the handling of the incident;
- compiling and retaining the documentation of the Qualified DDoS incident, available on request from the Client through the client area.
3.2 Scope of the Infrastructure providers
Network mitigation operations (volumetric filtering, scrubbing, blackholing, traffic rerouting) fall exclusively to Winheberg's Infrastructure providers, which implement them within their own policies and technical capabilities. Winheberg does not act directly on the physical network or transport layers.
3.3 No guarantee of complete mitigation
Winheberg does not guarantee the complete neutralisation of any DDoS attack. Mitigation capabilities depend on the systems of the Infrastructure providers and may be exceeded in the event of an attack of exceptional scale or vector.
Article 4 — Client obligations
The Client undertakes to:
- Not be the direct or indirect origin of traffic liable to be qualified as a DDoS attack against third parties or against Winheberg's infrastructure, failing which the provisions of Article 17 of the GTSU shall apply;
- Implement, at its own expense, the application-level security measures appropriate to its service (application firewall, rate limiting, CAPTCHA protection and so on), which fall under its sole responsibility;
- Cooperate in good faith with Winheberg during any incident, providing the relevant information available to it as promptly as possible.
The Client may not rely on this Annex to obtain compensation for an unavailability of which it is directly or indirectly the origin.
Article 5 — Consequences for availability and the SLA
5.1 Exclusion from the availability calculation
In accordance with Article 4.1 of the GTSU, periods of unavailability resulting from a DDoS incident formally qualified and documented within the meaning of Articles 2 and 3.1 of this Annex are excluded from the monthly availability calculation and give rise to no SLA compensation.
This SLA exclusion applies irrespective of any qualification as force majeure under Article 6.
In the absence of formal qualification within the meaning of Article 3.1, the unavailability is included in the SLA calculation under the usual conditions.
5.2 Notifying the Client
Winheberg does not inform the Client of every attack it detects.
The formal qualification of a DDoS incident that has caused an actual and measurable unavailability of the service is published on the Winheberg status page (status.winheberg.com) within a maximum of 48 hours following the end of the observed period of unavailability. That publication states the observed duration of the unavailability.
By way of derogation from Article 4.2 of the GTSU, for incidents falling under this Article 5.2, the incident reporting period runs from the date this qualification is published on status.winheberg.com.
5.3 Challenging a qualification
A Client challenging the qualification of an incident may request its review under the conditions set out in Article 22.4 of the GTSU. The documentation compiled by Winheberg in accordance with Article 3.1 constitutes the technical reference in the event of a dispute, without prejudice to the Client's right to submit evidence to the contrary.
Article 6 — Qualification as force majeure
6.1 Legal criteria
In accordance with Article 18 of the GTSU, a DDoS attack does not automatically constitute a case of force majeure within the meaning of Article 1218 of the French Civil Code. Its qualification as such requires all three of the following criteria to be met:
- Unforeseeability: at the time it occurs, the attack presents a scale or technical characteristics that could not reasonably have been anticipated given the state of the art and the profile of the service concerned;
- Irresistibility: the mitigation systems of the Infrastructure providers prove insufficient to contain the attack despite being effectively activated, making the unavailability unavoidable;
- Externality: the attack is initiated by a third party with no connection to Winheberg or the Client, and the Client is neither its direct nor indirect origin, including through negligence in securing its service.
6.2 Effects of qualification as force majeure
Where the three criteria of Article 6.1 are met, Winheberg is released from all liability for the unavailability concerned, in accordance with Articles 12 and 18 of the GTSU. The SLA exclusion of Article 5.1 applies as of right.
Article 7 — Termination for persistent attack and compensation
Where a Qualified DDoS incident persists over time and compromises the stability of the infrastructure or the services of other clients, Winheberg may decide to terminate the contract on its own initiative, under the conditions of Article 19 of the GTSU ("Termination and compensation in the event of persistent DDoS attacks").
In this exclusive case where termination is decided by Winheberg:
- the Client is informed by email before the termination takes effect;
- a credit calculated pro rata to the remaining days of the invoiced period is granted in the client area;
- payments made by Paysafecard give rise to a credit in the client area only, as it is technically impossible to refund this payment method.
No compensation is due where the termination follows a DDoS attack of which the Client is directly or indirectly the origin.
Article 8 — Distinction from the abuse policy
This Annex governs exclusively the situations in which Winheberg or its Clients are the victims of a DDoS attack.
Any use of Winheberg's services to initiate or facilitate a DDoS attack against third parties is strictly prohibited under Article 17.1 of the GTSU and constitutes a serious breach giving rise to immediate termination without compensation, without prejudice to applicable criminal proceedings (Article 323-2 of the French Criminal Code).
Article 9 — General provisions
9.1 Order of precedence
In the event of a contradiction between this Annex and the GTSU or the Specific Terms on the matters it expressly addresses, this Annex prevails.
9.2 Severability
If any clause of this Annex is declared void or unenforceable, the remaining clauses remain fully in force.
9.3 Changes to the Annex
Winheberg may update this Annex to reflect technical, regulatory or operational developments. Any substantial change is notified to Clients under the conditions of Article 27 of the GTSU. The version in force is the one published on the Winheberg website at the time of consultation.