Skip to content

Privacy policy

Effective · Version 1.0

In plain language

We collect what an account needs to work: who you are, what you paid, and the connection metadata that billing and abuse handling depend on. We do not inspect, store or sell the content of your traffic. You can ask to see, correct or delete what we hold, and a person answers.

This summary is a reading aid. The text below is the document that applies.

This policy explains how Unidatum LLC, operating ProxyHive, handles personal data where we decide why and how it is processed, as a controller. It covers visitors to proxyhive.io, people who contact us, and our customers and their authorised users. Where we process personal data on a customer’s behalf in the course of routing their traffic, we act as a processor and the data processing addendum applies instead.

1. Who we are

The controller is Unidatum LLC, 1007 N Orange St. 4th Floor Suite #6091, Wilmington, DE 19801, United States. For anything about this policy or your personal data, write to [email protected].

2. What we collect, why, and on what basis

The lawful bases named below are those of the EU and UK General Data Protection Regulation. Where another law applies to you, we rely on the equivalent grounds it provides.

  • Account data. When you register we collect your email address, password (stored only as a hash), and any name, company and contact details you add, together with the settings, sub-users, API keys and webhooks you configure. We use it to provide the service, to secure your account, and to send you service messages such as order confirmations, expiry reminders and security alerts. Lawful basis: performance of our contract with you.
  • Billing and payment data. We hold your balance, top-ups, orders, invoices and billing details such as billing address and tax identification number. Payments are processed by our payment providers: Stripe for cards, PayPal, and CoinGate for cryptocurrency. Card details are entered with Stripe and never reach our systems; we receive a transaction reference and limited details such as the card brand, last four digits and expiry date, or the PayPal account or cryptocurrency transaction identifier, and, for a cryptocurrency refund, the address of the wallet the payment was sent from and any exchange withdrawal record you show us. Where a refund has to be paid by bank transfer, we also receive the bank account details you give us for it. Lawful bases: performance of our contract, and compliance with tax and accounting obligations.
  • Identity verification and sanctions screening. We screen accounts against sanctions lists and may ask you to verify your identity or organisation, as the terms of service describe. Where we do, Sumsub, our verification provider, collects the identity document and other information it asks you for, and returns the result to us. Lawful bases: compliance with legal obligations, and our legitimate interest in preventing fraud and misuse of the network.
  • Usage and connection metadata. Operating the network produces connection metadata: timestamps, the account and sub-user responsible, bytes transferred, destination hostname and the exit address used. We use it to bill traffic, investigate abuse reports and resolve disputes. We also record sign-ins and account activity, including IP address and browser information, to secure accounts and detect fraud. Lawful bases: performance of our contract, and our legitimate interests in securing the service and preventing abuse.
  • Support and correspondence. When you write to us, we keep the correspondence and anything you attach. We use it to answer you and to keep a record of what was agreed. Lawful bases: performance of our contract, and our legitimate interest in answering enquiries.
  • The contact form. When you submit the contact form we collect your name, email address, the topic you choose and your message. We use them to answer you and for nothing else. Lawful basis: our legitimate interest in answering an enquiry, and steps taken at your request before entering into a contract.
  • Website, cookies and advertising. This site and the dashboard use cookies for analytics and for measuring which adverts bring people to us. The cookie policy lists every cookie, what it does and how long it lasts, and explains where we ask for consent first. Lawful basis: consent where the law requires it, and otherwise our legitimate interest in understanding how the site is used. You can change your choice at any time through Cookie settings, in the footer of every page.
  • Product and marketing emails. We may email account holders about features, offers and their use of the service. Lawful basis: our legitimate interest in telling existing customers about similar services, or your consent where the law requires it. Every such email has an unsubscribe link.
  • People who share bandwidth through partner applications. Residential addresses come from people who opted in through a partner application. The partner collects that consent and holds the person’s details under its own privacy notice. We receive the network identifiers needed to route traffic and to honour a withdrawal, and the consent evidence the partner provides. We do not receive or seek names or contact details.

We do not inspect, store or sell the content of requests or responses that pass through the network. We do not build profiles of the people who use the websites our customers reach.

3. Automated checks

Orders and payments pass through automated fraud and sanctions checks, which can hold an order or ask for verification. No account is closed on the result of an automated check alone. If an automated check affects you, you can ask for a person to review it at [email protected].

4. Who we share it with

We do not sell personal data. We share it only with the following categories of recipient, each bound by a contract that limits its use to providing its service to us:

  • Hosting and infrastructure: Amazon Web Services, which hosts our platform and databases.
  • Payment processing: Stripe (cards), PayPal, and CoinGate (cryptocurrency).
  • Email delivery: Twilio SendGrid, which delivers account, service and marketing emails and contact-form messages.
  • Customer support: our support ticketing provider.
  • Identity verification: Sumsub, when we ask you to verify.
  • Analytics and advertising: Google, and any other advertising platform named in the cookie policy, within the limits of the choice you made there.
  • Network providers: the upstream network operators that carry proxied traffic, which receive only the connection data needed to route it.

We also disclose personal data to professional advisers bound by confidentiality, to a buyer or successor if our business is transferred, and to authorities where the law requires us to or where it is necessary to establish, exercise or defend legal claims. The providers that handle customer data on our customers’ behalf are listed on the subprocessors page.

5. International transfers

We are based in the United States. Our platform is hosted with Amazon Web Services in the European Union, and some of our service providers process data in the United States and other countries. Where personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission’s standard contractual clauses, with the UK international data transfer addendum and the Swiss adaptations where they apply. You can ask for a copy of the relevant safeguards at [email protected].

6. How long we keep it

  • Account data: for as long as the account is open. When an account is closed and deleted, we erase or anonymise its personal data, except the records below that we must keep.
  • Billing records and invoices: 7 years after the transaction, for tax and accounting.
  • Verification and sanctions-screening records: 7 years after the account closes.
  • Connection metadata: 30 days.
  • Server and security logs: 30 days.
  • Support correspondence: while the account is open, and 24 months after the last contact.
  • Contact-form messages: 24 months after the last contact.
  • Cookies: for the lifetimes listed in the cookie policy.

We keep data longer only where the law requires it, or for as long as it is needed for an ongoing investigation or legal claim.

7. Your rights

Depending on where you live, and in particular under the EU and UK GDPR, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, including processing based on legitimate interests and all direct marketing, and to receive it in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting processing that took place before.

To exercise a right, write to [email protected]. We may need to confirm your identity first. We respond within one month, which the law allows us to extend by up to two further months for complex requests; if we do, we tell you why. Exercising your rights is free.

8. California residents

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect, use and disclose; to have it deleted or corrected; and not to be discriminated against for exercising these rights. The categories we collect, their sources, purposes and recipients, and how long we keep them, are set out above. We do not use or disclose sensitive personal information beyond what is needed to provide the service.

We do not sell personal information. Advertising cookies described in the cookie policy may count as “sharing” for cross-context behavioural advertising; you can opt out by turning marketing off in Cookie settings. Make a request, or appoint an authorised agent to make one for you, at [email protected].

9. Complaints

If you are unhappy with how we handle your data, please write to us first so we can put it right. You also have the right to complain to a supervisory authority, in particular in the country where you live or work or where you believe an infringement took place; in the United Kingdom that is the Information Commissioner’s Office, and in California the California Privacy Protection Agency.

10. Children

The service is for business use by people aged 18 or over and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to [email protected] and we will delete it.

11. Security

Access to production systems requires multi-factor authentication and is granted on a least-privilege basis. Data is encrypted in transit. Card details are handled by Stripe and never reach our systems. No system is perfectly secure; if a breach affects your personal data in a way that puts your rights at risk, we tell you without undue delay.

12. Changes to this policy

We publish revisions here with a new version and effective date. We tell account holders about material changes by email before they take effect.

13. Contact

Unidatum LLC, 1007 N Orange St. 4th Floor Suite #6091, Wilmington, DE 19801, United States. [email protected]