Privacy Policy
What personal data HProxy collects, why, on what legal basis, who processes it on our behalf, and the rights you hold over it. In plain language, under the GDPR.
Last updated 11 July 2026
This page always reflects the current version.
Data controller
For the purposes of the GDPR and the German Federal Data Protection Act (BDSG), the controller responsible for personal data processed through HProxy (Art. 4 (7) GDPR) is:
- Controller
- Obsidian UG (haftungsbeschränkt)HRB 20982, Amtsgericht Bad Oeynhausen
- Address
- Leopoldstr. 2-8, 32051 HerfordFederal Republic of Germany
- Privacy contact
- [email protected]Direct line for access, deletion, and portability requests
What we collect
Account data
When you sign up we collect your email address and, if you choose social sign-in, the basic profile information that provider returns. We do not require a name, phone number, or physical address to open an account.
Payment data
Your full card and payment credentials are never stored on our servers. They flow directly to our PCI-DSS-compliant payment partners. We retain only what we need for invoicing, accounting, and chargeback handling, such as a transaction reference and the last four digits of a card.
Telecommunications metadata (Verkehrsdaten)
When you route traffic through our proxy infrastructure we process traffic metadata within the meaning of § 9 (1) TKG: destination host, timestamp, bytes transferred, and response status code. We retain this strictly for (a) billing reconciliation (§ 9 (3) TKG) and (b) the detection of abuse, fraud, and disruption of our systems (§ 10 (3) TKG). We do not log or retain the contents of your traffic: no request bodies, no response bodies, no full URL paths.
Connection and source IP
Your IP address when connecting to our infrastructure is processed for authentication, abuse prevention, and fraud monitoring, on the basis of our legitimate interest under Art. 6 (1) (f) GDPR.
Support correspondence
Emails, chat messages, and ticket history you send to our support or legal addresses, retained for service quality, dispute handling, and legal-hold purposes.
Analytics and site measurement
We measure how the site is used in two ways. Our own analytics (GoatCounter) runs on our own servers in Germany, sets no cookies, and stores no personal data: your IP address is used only transiently to derive an approximate country and a per-day session hash, then discarded, so the result is aggregate and non-identifying (Art. 6 (1) (f) GDPR, legitimate interest). Separately, and only if you opt in, we load Google Analytics 4 and Microsoft Clarity, which set cookies and process data in the United States; they stay off until you accept them in the cookie banner and can be withdrawn at any time (Art. 6 (1) (a) GDPR, consent).
Legal basis & retention
Legal bases (Art. 6 GDPR)
We process personal data on the following legal bases:
- Art. 6 (1) (b), performance of the contract: creating your account, billing you, and delivering the proxy service you signed up for.
- Art. 6 (1) (c), legal obligations: tax and accounting records, and identity checks for cryptocurrency payments above EUR 1,000.
- Art. 6 (1) (f), legitimate interests: fraud prevention, abuse investigation, and the security and integrity of our infrastructure.
- Art. 6 (1) (a), consent: optional analytics cookies, which stay off until you opt in and can be withdrawn at any time.
Retention
Account data is retained for the life of your account plus 6 months after closure. Billing and accounting records are retained for 10 years as required by § 257 HGB and § 147 AO. Traffic metadata and connection IP logs are retained for 30 days, then deleted or anonymised. Support correspondence is retained for 24 months. Our own aggregate analytics contains no personal data and is kept indefinitely to observe long-term trends; any data collected by Google Analytics or Microsoft Clarity exists only where you have consented and is retained under their own settings and policies. Where a shorter statutory or contractual purpose ends sooner, we delete or anonymise the data at that point.
Sub-processors
Who processes data on our behalf
We use a small number of carefully selected sub-processors to run the service. Each is bound by a data processing agreement under Art. 28 GDPR. We do not sell your personal data to anyone, under any circumstances.
- Cloudflare (US / EU edge): DNS, DDoS protection, and content delivery.
- EU-based server hosting (Germany): our application, database, and our own GoatCounter analytics run on our own servers; the data is not handed to a third party.
- Resend (US): transactional email, such as account and billing notifications.
- Upstash (US, EU region): Redis cache for session and rate-limit state.
- Google Ireland Ltd / Google LLC (US), consent-based analytics: Google Analytics 4, loaded only if you opt in.
- Microsoft Ireland / Microsoft Corp (US), consent-based analytics: Microsoft Clarity, loaded only if you opt in.
- Our PCI-DSS-compliant payment partners: card and cryptocurrency processing.
International transfers
Where a sub-processor processes data outside the EU or EEA, the transfer is safeguarded by the European Commission's Standard Contractual Clauses (Art. 46 GDPR), together with a transfer impact assessment and supplementary measures where required. The current sub-processor list and the relevant agreements are available on request.
Data security
Technical and organisational measures (Art. 32 GDPR)
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, strict access controls, network segmentation, and the principle of data minimisation set out above. No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot and do not guarantee absolute security.
Your rights
Rights under the GDPR
In relation to the personal data we hold about you, you have the right to:
- Art. 15, access (Auskunft): obtain a copy of the data we hold about you.
- Art. 16, rectification (Berichtigung): have inaccurate data corrected.
- Art. 17, erasure (Löschung): have your data deleted, subject to our statutory retention obligations.
- Art. 18, restriction (Einschränkung): limit processing while a dispute is resolved.
- Art. 20, portability (Datenübertragbarkeit): receive your data in a structured, machine-readable format.
- Art. 21, objection (Widerspruch): object to processing based on our legitimate interests.
How to exercise your rights
Email [email protected] from the address on your account. We respond within one month, as required by Art. 12 (3) GDPR, and there is no fee for routine requests. Where you have given consent, you may withdraw it at any time without affecting the lawfulness of processing before the withdrawal.
Right to lodge a complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data-protection supervisory authority. The authority competent for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2-4, 40213 Düsseldorf, Germany. You may also complain to the authority in your own place of residence.
Automated decisions
Automated risk scoring (Art. 22 GDPR)
We use automated risk scoring to decide whether to auto-fulfil an order, place it on hold for manual review, or decline it. The scoring considers signals such as order velocity, diversity of payment instruments per user, IP velocity, and payment-attempt patterns. Where an order is held, a human reviews it before any final decision is made. Under Art. 22 (3) GDPR you have the right to obtain human intervention, to express your point of view, and to contest the decision. Email [email protected] to invoke any of these.
Children
Not directed to children
HProxy is a business service and is not directed to children. We do not knowingly collect personal data from children under 16 (Art. 8 GDPR). If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
Changes to this policy
We may update this policy as our processing or our sub-processors change. The date at the top always reflects the current version, and material changes are announced by email. Questions about your data, or any request under the GDPR: [email protected].