# Privacy policy
Source: https://proxuno.com/privacy
Updated: 2026-10-03

Legal

Which personal data Proxuno processes, why, on which legal basis, with which processors and for how long — and how to exercise your rights under the GDPR.

Last reviewed 3 October 2026

**Version 4.1** · Effective from 3 October 2026  [Version history](#version-history) Print or save as PDF

### On this page

- [1. Controller and contact](#1-controller-and-contact)
- [2. Data we collect](#2-data-we-collect)
- [3. Purposes and legal bases](#3-purposes-and-legal-bases)
- [4. Processors and recipients](#4-processors-and-recipients)
- [5. International transfers](#5-international-transfers)
- [6. Retention](#6-retention)
- [7. Your rights](#7-your-rights)
- [8. Security](#8-security)
- [9. Minors](#9-minors)
- [10. Changes](#10-changes)
- [Version history](#version-history)

This policy explains how [Company legal name] ("Proxuno", "we") processes personal data when you visit proxuno.com, create an account, buy and use our proxies, or contact us. It applies under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the national laws that supplement it.

## 1. Controller and contact

The controller is [Company legal name], [Legal form], [Registered address], [Country of registration], registration number [Company registration no.].

Data protection contact: [Data protection officer or privacy contact — name or role]. You can reach them at [support@proxuno.com](mailto:support@proxuno.com) with the subject "Privacy request", or by post at the address above.

## 2. Data we collect

**2.1 Account data.** Email address (required), name and Telegram handle (optional), password stored only as a bcrypt hash, two-factor authentication secret if you enable it, language, notification preferences, IP whitelist entries, API key metadata (name, prefix, last four characters, last use — never the key itself), your referral code and, if you signed up through a referral link, the referring account.

**2.2 Security logs.** Login times, IP addresses and browser user agents of your sessions, failed login attempts, and changes to sensitive settings (password, email, two-factor authentication, API keys, IP whitelist).

**2.3 Payment metadata.** Order and top-up references, amounts, the cryptocurrency and network used, invoice identifiers, the receiving address, amounts received, submitted transaction references, manual verification records and balance movements. **We never collect payment card data**: we do not accept card payments. Blockchain transactions are public by nature; a transaction reference is used to verify and attribute a payment to its invoice.

**2.4 Proxy traffic metadata.** For each connection through our gateways: timestamp, proxy or residential session concerned, source IP address, destination host and port, and the volume of data transferred. **We do not record the content of your traffic** — no URLs beyond the host, no request or response bodies, no headers, no credentials typed into third-party sites.

**2.5 Usage data.** Daily traffic totals per proxy, product and country (shown in your dashboard and used for billing), IP rotation history of your mobile proxies.

**2.6 Communications.** Support tickets, contact form messages (name, email, company, topic, message, IP address and page language), and a log of the emails we send you.

**2.7 Website visits.** Our servers keep technical access logs (IP address, time, requested path, response code, user agent) for security. We do not use analytics, advertising or tracking cookies, and pages load no third-party scripts. See the [cookie policy](/cookies).

## 3. Purposes and legal bases

| Purpose | Data | Legal basis (GDPR) |
| --- | --- | --- |
| Creating and running your account, delivering proxies, support | Account, usage, communications | Performance of a contract — art. 6(1)(b) |
| Taking and verifying payments, balance, invoices | Payment metadata | Performance of a contract — art. 6(1)(b) |
| Keeping accounting records | Payment metadata, account identification | Legal obligation — art. 6(1)(c) |
| Securing accounts and detecting unauthorised access | Security logs, access logs | Legitimate interests (protecting you and our systems) — art. 6(1)(f) |
| Handling abuse reports and preventing illegal use of the network | Traffic metadata, account | Legitimate interests (protecting the network, carriers and third parties) — art. 6(1)(f) |
| Answering legal requests from authorities | Data held at the time of the request | Legal obligation — art. 6(1)(c) |
| Affiliate programme: attributing referrals, paying commissions | Referral link, referred account, commissions | Performance of a contract — art. 6(1)(b) |
| Service and product announcements by email | Email address, notification preferences | Legitimate interests; you can opt out in Settings at any time — art. 6(1)(f) |
| Answering contact form messages | Contact form data | Legitimate interests (answering your request) or steps prior to a contract — art. 6(1)(f) and (b) |

We do not make decisions based solely on automated processing that produce legal effects concerning you. Automated abuse detection only triggers a human review.

## 4. Processors and recipients

We use a small number of processors, bound by data processing agreements under art. 28 GDPR:

- **Hosting**: [Hosting provider name and address] — servers running the website, dashboard, API and database.
- **Payments**: crypto top-ups are sent directly to the Proxuno receiving wallet shown on the invoice. Proxuno staff review the transaction reference and payment details before crediting the account. Market-rate services provide currency quotes; public blockchain data can be consulted to verify the submitted transfer. The sending wallet or exchange has its own data practices.
- **Email delivery**: [Email delivery provider — name and country] — sends transactional emails (verification, invoices, expiry reminders, support replies).

Upstream network providers and carriers see the traffic leaving our modems and IP addresses as any internet traffic, but receive no account data from us.

We disclose data to authorities only under a valid legal request, as described in the [acceptable use policy](/acceptable-use). We never sell personal data.

## 5. International transfers

Our systems are hosted in the European Economic Area. If a processor transfers data outside the EEA, the transfer is covered by an adequacy decision of the European Commission or by the Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of the applicable safeguards.

## 6. Retention

| Data | Retention |
| --- | --- |
| Proxy traffic metadata | 30 days, then deleted |
| Account security logs | 90 days, then deleted |
| Website access logs | 14 days |
| Account data | While the account exists; deleted within 30 days of an account deletion request |
| Payment metadata and invoices | For the period required by accounting law ([statutory period]) |
| Support tickets | 24 months after the last message |
| Contact form messages | 12 months |
| Email log | 12 months |
| Affiliate records | For the period required by accounting law, then deleted |

Data that we must keep beyond these periods because of a legal hold, an ongoing investigation or a dispute is kept only as long as that situation requires.

## 7. Your rights

Under the GDPR you have the right to:

- **access** your data and receive a copy;
- **rectify** inaccurate data — most of it directly in Settings;
- **erase** your data, subject to our legal retention obligations;
- **restrict** processing while a request is examined;
- **data portability** for the data you provided, in a structured, machine-readable format;
- **object** to processing based on our legitimate interests, including at any time to product announcements.

To exercise a right, write to [support@proxuno.com](mailto:support@proxuno.com) from the email address of your account, or with enough information for us to identify you. We answer within one month, which may be extended by two further months for complex requests; we will tell you if that happens.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live, work or where the alleged infringement took place. Our lead supervisory authority is [Lead supervisory authority — name and website].

## 8. Security

We protect personal data with technical and organisational measures adapted to the risks: password hashing with bcrypt, optional two-factor authentication, API keys stored only as hashes, encrypted connections, restricted staff access with an audit log, and minimal logging. The [security page](/security) describes these measures and how to report a vulnerability.

If a personal data breach is likely to result in a risk to your rights and freedoms, we notify the supervisory authority within 72 hours and inform you without undue delay when the risk is high.

## 9. Minors

The services are not intended for persons under 18. We do not knowingly collect data about minors.

## 10. Changes

We update this policy when our processing changes. Each version is numbered and dated below. For material changes, we inform account holders by email before they take effect.

## Version history

| Version | Effective from | Summary of changes |
| --- | --- | --- |
| 4.1 | 3 October 2026 | Direct wallet payments, submitted transaction references and manual verification records (sections 2.3 and 4). |
| 4.0 | 23 June 2026 | Rewritten for dashboard v5; processors and retention tables updated; website access logs limited to 14 days. |
| 3.1 | 1 October 2025 | Prepaid balance and balance movements; affiliate records retention. |
| 3.0 | 1 September 2024 | Two-factor authentication; account security logs kept 90 days. |
| 2.0 | 1 September 2023 | Rotating residential proxies; traffic metadata kept 30 days for abuse handling. |
| 1.0 | 1 March 2021 | First version, at launch. |

Questions about this document

Write to [support@proxuno.com](mailto:support@proxuno.com) or use the [contact form](/contact). Legal and privacy requests are answered in English within two business days.
