Privacy Policy

Privacy Policy

LIMITED LIABILITY COMPANY PROSOX

Effective Date: July 20, 2026 Last Updated: July 20, 2026

1. Introduction and Scope

LIMITED LIABILITY COMPANY PROSOX (”Prosox,” “Company,” “we,” “us,” or “our”) is
committed to protecting the privacy of individuals who interact with the prosox.io website
and our proxy, network, and data-collection services (collectively, the “Service”).

This Privacy Policy (the “Policy”) explains what personal data we collect, how and why we use it, with whom we share it, how long we keep it, how we protect it, and the rights available to you. It applies to visitors to our Site, account holders, and other individuals whose personal data we process, except where a separate notice applies.

This Policy should be read together with our Terms of Service and our Acceptable Use Policy. By using the Service, you acknowledge the practices described here. Where we rely on your consent, we will ask for it separately.

Important — role clarification. When our customers use the Service to route traffic to third-party websites or to collect data, our customers (not Prosox) determine the purposes and means of that processing and act as the controller of any personal data they collect. Prosox provides infrastructure and does not control, review, or endorse our customers’ target sites or use cases. This Policy addresses data that Prosox processes as a controller (for example, account and billing data and Site usage data).

2. Who Is Responsible for Your Data

Prosox is the controller of personal data processed under this Policy.

LIMITED LIABILITY COMPANY PROSOX 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, USA General inquiries: info@prosox.io Privacy / data protection: privacy@prosox.io

3. Categories of Personal Data We Collect

3.1. Data you provide to us

  • Account and identity data — name, username, and similar details you provide when registering.
  • Contact data — email address and any contact details you give us.
  • Billing and transaction data — billing name, address, and payment-related information. Card payments are processed by third-party payment processors; we do not store full card numbers.
  • Communications — messages, support requests, and correspondence you send us.
  • Verification data — information we may collect to verify your identity or business where required (see our Acceptable Use Policy, “Verification and Know-Your Customer”).

3.2. Data collected automatically when you use the Site or Service

  • Technical data — IP address, browser type and settings, device and operating-system information, language settings, and referring URLs.
  • Usage data — pages viewed, features used, dates and times of access, and diagnostic and performance information.
  • Cookies and similar technologies — see Section 7.

3.3. Service connection and logging data

When you use the proxy Service, we process certain connection and usage information necessary to operate, secure, meter, and bill the Service. This is described in Section 5 (“Logging and the Proxy Service”).

3.4. Data from third parties

We may receive limited information from our payment processors (e.g., transaction confirmation), from fraud-prevention or sanctions-screening providers, and from analytics providers, in each case to operate and protect the Service.

We do not intentionally collect special categories of personal data (such as health, biometric, or genetic data) about you through the Site.

4. How We Use Your Data and Our Legal Bases

We use personal data for the purposes below. Where the EU/UK GDPR applies, we rely on the legal bases indicated.

  • Providing the Service — creating and administering your account, delivering the Service, and providing support. Legal basis: performance of a contract.
  • Billing and payments — processing payments, invoicing, and preventing payment fraud. Legal basis: performance of a contract; legal obligation; legitimate interests.
  • Security, abuse prevention, and network integrity — monitoring for and preventing abuse, fraud, and security threats, enforcing our Acceptable Use Policy, and protecting our infrastructure, users, and third parties. Legal basis: legitimate interests; legal obligation.
  • Operating and improving the Site and Service — maintaining functionality, diagnostics, analytics, and product improvement. Legal basis: legitimate interests; consent where required for non-essential cookies.
  • Communications — responding to your requests and sending service-related notices. Legal basis: performance of a contract; legitimate interests.
  • Marketing — sending informational or promotional materials where you have opted in. Legal basis: consent (which you may withdraw at any time).
  • Legal and compliance — complying with law, responding to lawful requests, and establishing, exercising, or defending legal claims. Legal basis: legal obligation; legitimate interests.

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to such processing as described in Section 11.

5. Logging and the Proxy Service

Because the Service routes network traffic, we process certain connection and usage data. We aim to collect the minimum necessary to operate, secure, and bill the Service.

What we process:

  • account identifiers associated with a session;
  • connection metadata such as timestamps, duration, bandwidth/data volume, and the proxy endpoints used;
  • technical information necessary to meter usage, prevent abuse, and maintain network integrity.

What we do not do:

  • We do not sell your connection data.
  • We use connection data only to operate, secure, meter, bill, improve, and lawfully protect the Service, and to comply with law — not for any other purpose.

Retention. We retain connection and usage data only for as long as necessary for the purposes described above and as required by applicable law, after which it is deleted or anonymized/aggregated. A longer period may apply only where necessary to investigate abuse, resolve a dispute, or comply with a legal obligation.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy — including to provide the Service, comply with our legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When personal data is no longer required, we delete, anonymize, or aggregate it.

The specific retention period depends on the type of data, the purpose for which it is used, and applicable legal requirements. Where data must be retained for legal or security reasons, we restrict its use to those purposes. You may request further information about our retention practices using the contact details in Section 18.

7. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Site, remember your preferences, analyze usage, and (where applicable) support marketing.

  • Strictly necessary cookies are required for the Site to function and do not require consent.
  • Analytics and non-essential cookies are used only where permitted. Where required by law (including in the EEA/UK), we request your consent before placing non-essential cookies, through a cookie banner or preference tool.

You can manage cookies through our cookie tool (where available) and through your browser settings. Disabling certain cookies may affect Site functionality. For more detail, see our Cookie Policy.

8. How We Share Your Data

We do not sell your personal data. We share it only with the following categories of recipients, and only as necessary:

  • Infrastructure and hosting providers — data-center, server, and network providers that host or support the Service.
  • Payment processors — to process payments and prevent fraud.
  • Analytics and communication providers — to operate, analyze, and support the Site and Service.
  • Fraud-prevention and sanctions-screening providers — to protect the Service and comply with law.
  • Professional advisers — such as legal, accounting, and audit advisers, under confidentiality obligations.
  • Authorities and legal process — law enforcement, regulators, or other parties where we believe in good faith that disclosure is required by law or necessary to protect rights, property, or safety (see our Acceptable Use Policy, “Cooperation with Law Enforcement”).
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.

We require our service providers to protect personal data and to process it only on our instructions and for the purposes we specify.

9. International Data Transfers

We operate from the United States and may process and store personal data in the United States and other countries whose data-protection laws may differ from those in your country.

Where we transfer personal data from the EEA or the United Kingdom to a country that has not been recognized as providing an adequate level of protection, we implement appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission (and the UK Addendum/IDTA where applicable), together with additional measures where necessary. You may request more information about these safeguards using the contact details in Section 18.

10. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These include access controls limiting data to authorized personnel acting within their duties, encryption in transit, and monitoring for security threats.

    No method of transmission or storage over the Internet is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.

    11. Your Privacy Rights

    Depending on your location and applicable law (including the GDPR), you may have the following rights regarding your personal data:

    • Access — to obtain confirmation of, and a copy of, the data we hold about you.
    • Rectification — to correct inaccurate or incomplete data.
    • Erasure — to request deletion of your data in certain circumstances.
    • Restriction — to request that we limit processing in certain circumstances.
    • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
    • Portability — to receive certain data in a portable format.
    • Withdraw consent — where processing is based on consent, at any time, without affecting prior processing.

    To exercise these rights, contact us using the details in Section 18. We will respond within the timeframe required by applicable law. We may need to verify your identity first.

    12. Your California Privacy Rights (CCPA/CPRA)

    If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, provides you with additional rights.

    Categories of personal information we may collect include: identifiers (such as name, email, IP address); commercial information (such as billing and transaction records); internet or other electronic network activity (such as usage and connection data); and geolocation inferred from IP address. We collect this information from the sources and for the business purposes described in Sections 3–5.

    Sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.

    Sensitive personal information. We do not use or disclose sensitive personal information for purposes that would require us to offer a “limit the use” option.

    Your California rights include the right to: know and access the personal information we collect; delete your personal information; correct inaccurate personal information; opt out of any sale or sharing; and not be discriminated against for exercising your rights.

    To exercise these rights, contact us using the details in Section 18. We will verify your request as required by law. You may use an authorized agent, subject to verification.

      13. Users in the CIS Region

      If you access the Service from a country in the Commonwealth of Independent States (CIS) — such as Uzbekistan, Kazakhstan, Russia, Belarus, Azerbaijan, Armenia, Kyrgyzstan, Tajikistan, or Moldova — this Policy applies to you, and you may have additional rights under your national data-protection law.

      Prosox is established in the United States. Your personal data is processed and stored in the United States and other countries, as described in Section 9 (International Data Transfers). By using the Service, you understand that your personal data is transferred to and processed outside your country of residence, subject to the safeguards described in this Policy. Where your national law requires your consent for such cross-border transfer, by providing your personal data and using the Service you consent to that transfer as described here.

      Some CIS jurisdictions impose specific requirements, including data-localization rules for the personal data of their own citizens. You are responsible for ensuring that your own use of the Service complies with the laws applicable to you. Where required by applicable law, we honor the rights available to you — including the rights to access, correct, and delete your personal data and to withdraw consent. To exercise any such right, contact us using the details in Section 18.

        14. Children’s Privacy

        The Service is intended for businesses and adults and is not directed to children. We do not knowingly collect personal data from children under the age of 16 (or the minimum age required in your jurisdiction). If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

        15. Data Breach Notification

        We maintain procedures to detect and respond to personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals as, and within the timeframes, required by applicable law.

        16. Third-Party Links and Services

        The Site or Service may contain links to third-party websites or services that we do not operate or control. We are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

        17. Changes to This Policy

        We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be posted on this page with a revised “Last Updated” date and takes effect as of that date. We encourage you to review this Policy periodically. Where required by law, we will provide additional notice of material changes.

        18. Contact Us

        For questions about this Policy or to exercise your rights, contact:

        LIMITED LIABILITY COMPANY PROSOX 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, USA General inquiries: info@prosox.io Privacy / data protection: privacy@prosox.io

          By using the Site or Service, you acknowledge that you have read and understood this Privacy Policy.