Personal Data Processing Policy

Current version. This policy is prepared with regard to European Union requirements (including GDPR and ePrivacy) and United States of America requirements (including state privacy laws such as CCPA/CPRA in California, and FTC recommendations). For data processing inquiries, contact us via contacts.

1. General provisions

The EvilFox.Win service ("we", "service", "operator") respects your privacy. This policy (Privacy Notice) describes what personal data we collect, on what legal basis we process it, to whom we transfer it, how long we retain it, and what rights you have.

The policy applies when using the website, account dashboard, VPN services, and other EvilFox.Win services. By using the service, you confirm having read this document. For mandatory processing cases, we rely on applicable EU and US law; requirements of authoritarian jurisdictions do not by themselves define the scope of our privacy policy.

2. Data operator and contacts

Operator (data controller) of personal data within the meaning of GDPR — the owner of the EvilFox.Win service.

A separate Data Protection Officer (DPO) is not appointed; personal data requests are accepted through the channels indicated above.

3. What data we process

Depending on how you use the service, we may process the following categories of data:

3.1. Technical data required for VPN operation

To operate the VPN service, the server infrastructure (including the Remnawave control panel and other access panels) processes the following technical data:

This data is used solely to provide the service, is not disclosed to third parties (other than infrastructure required to run the VPN), and is not retained longer than needed to operate the service: typically no more than 30 days. If retention is required to investigate a security incident — no more than 90 days (see section 8). This is not a log of visited websites and not traffic content.

VPN traffic passes through servers in encrypted form. We do not keep website visit logs and do not reconstruct session content. Technical subscription data (term, device limit, traffic volume for billing) is not a browsing history log.

We do not collect special categories of data (health, biometrics, political views, etc.) and the service is not intended for children under 16 (see Section 12).

4. Data sources

Data is obtained:

5. Cookies and similar technologies (ePrivacy / GDPR)

We use cookies and browser local storage. By purpose, they are divided into:

We do not use third-party advertising or profiling cookies for cross-site tracking. You may delete or block cookies in browser settings; refusing necessary cookies may make account login impossible.

Refusing optional cookies does not affect the ability to use VPN services. You may change your choice at any time via "Cookie settings" in the website footer ("Necessary only" or "Accept all").

Consent cookie retention period — up to 12 months, unless otherwise indicated in your browser.

6. Purposes and legal bases of processing (GDPR)

We process personal data only where a legal basis exists:

7. VPN and data minimization

The VPN service privacy policy is supplemented by VPN usage rules. We adhere to the data minimization principle: we do not conduct targeted monitoring of user traffic content. Technical metadata (e.g., traffic volume on server control panels) may be processed for billing, tariff limits, and abuse prevention — without linkage to content of visited websites.

The Provider does not intentionally analyze or store the content of your VPN traffic (visited websites, transferred files, packet contents). VPN traffic passes through servers in encrypted form; we do not keep visit logs. The absence of such logs means a “browsing history” cannot be restored at the request of a user, a court, or an authority: we do not have that data.

8. Retention periods

Anonymization of financial records means that transaction data (amount, date, payment identifier) is stored without a link to email, IP address, account identifier, or other data that would identify a specific person. Anonymized records cannot be “restored” into a link with the deleted account: the link to identity is broken irreversibly.

Upon expiry of retention periods, data is deleted or anonymized.

9. Data transfers and processors

We do not sell personal data and do not transfer it in exchange for monetary consideration (including within the meaning of CCPA/CPRA — "sale"/"sharing" for behavioral advertising).

Data may be transferred to processors only for service provision:

Data processing agreements (DPAs) or standard contractual terms are concluded with such parties to the extent required by GDPR.

Disclosure to government authorities — only upon a valid and mandatory request under EU, US, or the Provider's country of registration law, typically confirmed by a court decision or other instrument binding on us. Arbitrary requests without legal basis are not fulfilled (see also VPN rules).

Requests from government authorities of the Russian Federation and other authoritarian jurisdictions are not fulfilled unless they are based on EU, US, or the Provider's country of registration law and confirmed by a court decision binding on the Provider. The Provider is not subject to Russian VPN law and does not disclose data in response to arbitrary requests.

10. International data transfers

Servers and contractors may be located outside your country, including outside the EEA. When transferring from the EU/EEA, we apply measures provided by GDPR Chapter V: Standard Contractual Clauses (SCC), European Commission adequacy decisions, or other lawful mechanisms. For US residents, transfer may occur between our systems and contractors in accordance with this policy and processor agreements.

11. Security measures

We apply technical and organizational measures: password encryption, database access restrictions, HTTPS on the website, administrator access segregation, backups. No method of internet transmission or storage guarantees absolute security; we strive to protect data at a reasonable level.

12. Children

The service is not intended for persons under 16 years of age (in certain US states — under 13 without parental consent). We do not knowingly collect children's data. Upon discovery of such an account, we may delete it and related data.

13. Automated decisions

We do not make decisions concerning you based solely on automated processing that produce legal effects or similarly significantly affect you (GDPR Art. 22). Account restrictions for abuse are decided by administration considering circumstances, not by fully automated "scoring".

14. Your rights

Depending on your place of residence, you may have the following rights:

How to exercise rights:

We will respond to requests within 30 days (GDPR) or within the timeframe established by applicable US state law (e.g., 45 days under CCPA with possible extension). We may request identity verification to avoid disclosing data to a third party.

California residents: we do not "sell" or "share" personal data for cross-context behavioral advertising. You have the right to know categories of collected data, request deletion and correction within CCPA/CPRA. We do not discriminate against users for exercising privacy rights.

15. Policy changes

We may update this policy. The current version is always on this page; for material changes we may notify via the website or email. Continued use of the service after changes take effect means acceptance of the updated policy, unless otherwise required by applicable law.

16. Contacts

For all privacy and rights exercise matters:

EU supervisory authorities: list of data protection authorities — on the European Data Protection Board website. For the US — the contact authority depends on your state of residence (e.g., California Attorney General — Privacy).

Home · Site rules · VPN usage rules · Terms of service