Privacy Policy

What personal data HProxy collects, why, on what legal basis, who processes it on our behalf, and the rights you hold over it. In plain language, under the GDPR.

Last updated 11 July 2026

This page always reflects the current version.

Data controller

For the purposes of the GDPR and the German Federal Data Protection Act (BDSG), the controller responsible for personal data processed through HProxy (Art. 4 (7) GDPR) is:

Controller
Obsidian UG (haftungsbeschränkt)HRB 20982, Amtsgericht Bad Oeynhausen
Address
Leopoldstr. 2-8, 32051 HerfordFederal Republic of Germany
Privacy contact
[email protected]Direct line for access, deletion, and portability requests

What we collect

Account data

When you sign up we collect your email address and, if you choose social sign-in, the basic profile information that provider returns. We do not require a name, phone number, or physical address to open an account.

Payment data

Your full card and payment credentials are never stored on our servers. They flow directly to our PCI-DSS-compliant payment partners. We retain only what we need for invoicing, accounting, and chargeback handling, such as a transaction reference and the last four digits of a card.

Telecommunications metadata (Verkehrsdaten)

When you route traffic through our proxy infrastructure we process traffic metadata within the meaning of § 9 (1) TKG: destination host, timestamp, bytes transferred, and response status code. We retain this strictly for (a) billing reconciliation (§ 9 (3) TKG) and (b) the detection of abuse, fraud, and disruption of our systems (§ 10 (3) TKG). We do not log or retain the contents of your traffic: no request bodies, no response bodies, no full URL paths.

Connection and source IP

Your IP address when connecting to our infrastructure is processed for authentication, abuse prevention, and fraud monitoring, on the basis of our legitimate interest under Art. 6 (1) (f) GDPR.

Support correspondence

Emails, chat messages, and ticket history you send to our support or legal addresses, retained for service quality, dispute handling, and legal-hold purposes.

Analytics and site measurement

We measure how the site is used in two ways. Our own analytics (GoatCounter) runs on our own servers in Germany, sets no cookies, and stores no personal data: your IP address is used only transiently to derive an approximate country and a per-day session hash, then discarded, so the result is aggregate and non-identifying (Art. 6 (1) (f) GDPR, legitimate interest). Separately, and only if you opt in, we load Google Analytics 4 and Microsoft Clarity, which set cookies and process data in the United States; they stay off until you accept them in the cookie banner and can be withdrawn at any time (Art. 6 (1) (a) GDPR, consent).

Sub-processors

Who processes data on our behalf

We use a small number of carefully selected sub-processors to run the service. Each is bound by a data processing agreement under Art. 28 GDPR. We do not sell your personal data to anyone, under any circumstances.
  • Cloudflare (US / EU edge): DNS, DDoS protection, and content delivery.
  • EU-based server hosting (Germany): our application, database, and our own GoatCounter analytics run on our own servers; the data is not handed to a third party.
  • Resend (US): transactional email, such as account and billing notifications.
  • Upstash (US, EU region): Redis cache for session and rate-limit state.
  • Google Ireland Ltd / Google LLC (US), consent-based analytics: Google Analytics 4, loaded only if you opt in.
  • Microsoft Ireland / Microsoft Corp (US), consent-based analytics: Microsoft Clarity, loaded only if you opt in.
  • Our PCI-DSS-compliant payment partners: card and cryptocurrency processing.

International transfers

Where a sub-processor processes data outside the EU or EEA, the transfer is safeguarded by the European Commission's Standard Contractual Clauses (Art. 46 GDPR), together with a transfer impact assessment and supplementary measures where required. The current sub-processor list and the relevant agreements are available on request.

Data security

Technical and organisational measures (Art. 32 GDPR)

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, strict access controls, network segmentation, and the principle of data minimisation set out above. No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot and do not guarantee absolute security.

Your rights

Rights under the GDPR

In relation to the personal data we hold about you, you have the right to:
  • Art. 15, access (Auskunft): obtain a copy of the data we hold about you.
  • Art. 16, rectification (Berichtigung): have inaccurate data corrected.
  • Art. 17, erasure (Löschung): have your data deleted, subject to our statutory retention obligations.
  • Art. 18, restriction (Einschränkung): limit processing while a dispute is resolved.
  • Art. 20, portability (Datenübertragbarkeit): receive your data in a structured, machine-readable format.
  • Art. 21, objection (Widerspruch): object to processing based on our legitimate interests.

How to exercise your rights

Email [email protected] from the address on your account. We respond within one month, as required by Art. 12 (3) GDPR, and there is no fee for routine requests. Where you have given consent, you may withdraw it at any time without affecting the lawfulness of processing before the withdrawal.

Right to lodge a complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a data-protection supervisory authority. The authority competent for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2-4, 40213 Düsseldorf, Germany. You may also complain to the authority in your own place of residence.

Automated decisions

Automated risk scoring (Art. 22 GDPR)

We use automated risk scoring to decide whether to auto-fulfil an order, place it on hold for manual review, or decline it. The scoring considers signals such as order velocity, diversity of payment instruments per user, IP velocity, and payment-attempt patterns. Where an order is held, a human reviews it before any final decision is made. Under Art. 22 (3) GDPR you have the right to obtain human intervention, to express your point of view, and to contest the decision. Email [email protected] to invoke any of these.

Children

Not directed to children

HProxy is a business service and is not directed to children. We do not knowingly collect personal data from children under 16 (Art. 8 GDPR). If you believe a child has provided us with personal data, contact [email protected] and we will delete it.

Cookies

How we use cookies

We use a small number of cookies for session authentication, security, and fraud prevention. We run no analytics or marketing cookies at present; any we introduce in future would require your consent and stay off until you give it. The full per-cookie breakdown of names, purposes, lifetimes, categories, and providers is set out on the Cookie Policy page.

Changes to this policy

We may update this policy as our processing or our sub-processors change. The date at the top always reflects the current version, and material changes are announced by email. Questions about your data, or any request under the GDPR: [email protected].