Privacy policy
Effective · Version 1.0
In plain language
We collect what an account needs to work: who you are, what you paid, and the connection metadata that billing and abuse handling depend on. We do not inspect, store or sell the content of your traffic. You can ask to see, correct or delete what we hold, and a person answers.
This summary is a reading aid. The text below is the document that applies.
This policy explains how Unidatum LLC, operating ProxyHive, handles personal data where we decide why and how it is processed, as a controller. It covers visitors to proxyhive.io, people who contact us, and our customers and their authorised users. Where we process personal data on a customer’s behalf in the course of routing their traffic, we act as a processor and the data processing addendum applies instead.
1. Who we are
The controller is Unidatum LLC, 1007 N Orange St. 4th Floor Suite #6091, Wilmington, DE 19801, United States. For anything about this policy or your personal data, write to [email protected].
2. What we collect, why, and on what basis
The lawful bases named below are those of the EU and UK General Data Protection Regulation. Where another law applies to you, we rely on the equivalent grounds it provides.
- Account data. When you register we collect your email address, password (stored only as a hash), and any name, company and contact details you add, together with the settings, sub-users, API keys and webhooks you configure. We use it to provide the service, to secure your account, and to send you service messages such as order confirmations, expiry reminders and security alerts. Lawful basis: performance of our contract with you.
- Billing and payment data. We hold your balance, top-ups, orders, invoices and billing details such as billing address and tax identification number. Payments are processed by our payment providers: Stripe for cards, PayPal, and CoinGate for cryptocurrency. Card details are entered with Stripe and never reach our systems; we receive a transaction reference and limited details such as the card brand, last four digits and expiry date, or the PayPal account or cryptocurrency transaction identifier, and, for a cryptocurrency refund, the address of the wallet the payment was sent from and any exchange withdrawal record you show us. Where a refund has to be paid by bank transfer, we also receive the bank account details you give us for it. Lawful bases: performance of our contract, and compliance with tax and accounting obligations.
- Identity verification and sanctions screening. We screen accounts against sanctions lists and may ask you to verify your identity or organisation, as the terms of service describe. Where we do, Sumsub, our verification provider, collects the identity document and other information it asks you for, and returns the result to us. Lawful bases: compliance with legal obligations, and our legitimate interest in preventing fraud and misuse of the network.
- Usage and connection metadata. Operating the network produces connection metadata: timestamps, the account and sub-user responsible, bytes transferred, destination hostname and the exit address used. We use it to bill traffic, investigate abuse reports and resolve disputes. We also record sign-ins and account activity, including IP address and browser information, to secure accounts and detect fraud. Lawful bases: performance of our contract, and our legitimate interests in securing the service and preventing abuse.
- Support and correspondence. When you write to us, we keep the correspondence and anything you attach. We use it to answer you and to keep a record of what was agreed. Lawful bases: performance of our contract, and our legitimate interest in answering enquiries.
- The contact form. When you submit the contact form we collect your name, email address, the topic you choose and your message. We use them to answer you and for nothing else. Lawful basis: our legitimate interest in answering an enquiry, and steps taken at your request before entering into a contract.
- Website, cookies and advertising. This site and the dashboard use cookies for analytics and for measuring which adverts bring people to us. The cookie policy lists every cookie, what it does and how long it lasts, and explains where we ask for consent first. Lawful basis: consent where the law requires it, and otherwise our legitimate interest in understanding how the site is used. You can change your choice at any time through Cookie settings, in the footer of every page.
- Product and marketing emails. We may email account holders about features, offers and their use of the service. Lawful basis: our legitimate interest in telling existing customers about similar services, or your consent where the law requires it. Every such email has an unsubscribe link.
- People who share bandwidth through partner applications. Residential addresses come from people who opted in through a partner application. The partner collects that consent and holds the person’s details under its own privacy notice. We receive the network identifiers needed to route traffic and to honour a withdrawal, and the consent evidence the partner provides. We do not receive or seek names or contact details.
We do not inspect, store or sell the content of requests or responses that pass through the network. We do not build profiles of the people who use the websites our customers reach.
3. Automated checks
Orders and payments pass through automated fraud and sanctions checks, which can hold an order or ask for verification. No account is closed on the result of an automated check alone. If an automated check affects you, you can ask for a person to review it at [email protected].
5. International transfers
We are based in the United States. Our platform is hosted with Amazon Web Services in the European Union, and some of our service providers process data in the United States and other countries. Where personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission’s standard contractual clauses, with the UK international data transfer addendum and the Swiss adaptations where they apply. You can ask for a copy of the relevant safeguards at [email protected].
6. How long we keep it
- Account data: for as long as the account is open. When an account is closed and deleted, we erase or anonymise its personal data, except the records below that we must keep.
- Billing records and invoices: 7 years after the transaction, for tax and accounting.
- Verification and sanctions-screening records: 7 years after the account closes.
- Connection metadata: 30 days.
- Server and security logs: 30 days.
- Support correspondence: while the account is open, and 24 months after the last contact.
- Contact-form messages: 24 months after the last contact.
- Cookies: for the lifetimes listed in the cookie policy.
We keep data longer only where the law requires it, or for as long as it is needed for an ongoing investigation or legal claim.
7. Your rights
Depending on where you live, and in particular under the EU and UK GDPR, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, including processing based on legitimate interests and all direct marketing, and to receive it in a portable format. Where processing rests on consent, you may withdraw it at any time without affecting processing that took place before.
To exercise a right, write to [email protected]. We may need to confirm your identity first. We respond within one month, which the law allows us to extend by up to two further months for complex requests; if we do, we tell you why. Exercising your rights is free.
8. California residents
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the right to know what personal information we collect, use and disclose; to have it deleted or corrected; and not to be discriminated against for exercising these rights. The categories we collect, their sources, purposes and recipients, and how long we keep them, are set out above. We do not use or disclose sensitive personal information beyond what is needed to provide the service.
We do not sell personal information. Advertising cookies described in the cookie policy may count as “sharing” for cross-context behavioural advertising; you can opt out by turning marketing off in Cookie settings. Make a request, or appoint an authorised agent to make one for you, at [email protected].
9. Complaints
If you are unhappy with how we handle your data, please write to us first so we can put it right. You also have the right to complain to a supervisory authority, in particular in the country where you live or work or where you believe an infringement took place; in the United Kingdom that is the Information Commissioner’s Office, and in California the California Privacy Protection Agency.
10. Children
The service is for business use by people aged 18 or over and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to [email protected] and we will delete it.
11. Security
Access to production systems requires multi-factor authentication and is granted on a least-privilege basis. Data is encrypted in transit. Card details are handled by Stripe and never reach our systems. No system is perfectly secure; if a breach affects your personal data in a way that puts your rights at risk, we tell you without undue delay.
12. Changes to this policy
We publish revisions here with a new version and effective date. We tell account holders about material changes by email before they take effect.
13. Contact
Unidatum LLC, 1007 N Orange St. 4th Floor Suite #6091, Wilmington, DE 19801, United States. [email protected]