Personal Data Processing Policy

Current version. This policy is prepared with regard to European Union requirements (including GDPR and ePrivacy) and United States of America requirements (including state privacy laws such as CCPA/CPRA in California, and FTC recommendations). For data processing inquiries, contact us via contacts.

1. General provisions

The EvilFox.Win service ("we", "service", "operator") respects your privacy. This policy (Privacy Notice) describes what personal data we collect, on what legal basis we process it, to whom we transfer it, how long we retain it, and what rights you have.

The policy applies when using the website, account dashboard, VPN services, and other EvilFox.Win services. By using the service, you confirm having read this document. For mandatory processing cases, we rely on applicable EU and US law; requirements of authoritarian jurisdictions do not by themselves define the scope of our privacy policy.

2. Data operator and contacts

Operator (data controller) of personal data within the meaning of GDPR — the owner of the EvilFox.Win service.

A separate Data Protection Officer (DPO) is not appointed; personal data requests are accepted through the channels indicated above.

3. What data we process

Depending on how you use the service, we may process the following categories of data:

We do not collect special categories of data (health, biometrics, political views, etc.) and the service is not intended for children under 16 (see Section 12).

4. Data sources

Data is obtained:

5. Cookies and similar technologies (ePrivacy / GDPR)

We use cookies and browser local storage. By purpose, they are divided into:

We do not use third-party advertising or profiling cookies for cross-site tracking. You may delete or block cookies in browser settings; refusing necessary cookies may make account login impossible.

Consent cookie retention period — up to 12 months, unless otherwise indicated in your browser.

6. Purposes and legal bases of processing (GDPR)

We process personal data only where a legal basis exists:

7. VPN and data minimization

The VPN service privacy policy is supplemented by VPN usage rules. We adhere to the data minimization principle: we do not conduct targeted monitoring of user traffic content. Technical metadata (e.g., traffic volume on server control panels) may be processed for billing, tariff limits, and abuse prevention — without linkage to content of visited websites.

8. Retention periods

Upon expiry of retention periods, data is deleted or anonymized.

9. Data transfers and processors

We do not sell personal data and do not transfer it in exchange for monetary consideration (including within the meaning of CCPA/CPRA — "sale"/"sharing" for behavioral advertising).

Data may be transferred to processors only for service provision:

Data processing agreements (DPAs) or standard contractual terms are concluded with such parties to the extent required by GDPR.

Disclosure to government authorities — only upon valid and mandatory request under EU, US, or other jurisdiction law binding on us. Arbitrary requests without legal basis are not fulfilled (see also VPN rules, section on authority requests).

10. International data transfers

Servers and contractors may be located outside your country, including outside the EEA. When transferring from the EU/EEA, we apply measures provided by GDPR Chapter V: Standard Contractual Clauses (SCC), European Commission adequacy decisions, or other lawful mechanisms. For US residents, transfer may occur between our systems and contractors in accordance with this policy and processor agreements.

11. Security measures

We apply technical and organizational measures: password encryption, database access restrictions, HTTPS on the website, administrator access segregation, backups. No method of internet transmission or storage guarantees absolute security; we strive to protect data at a reasonable level.

12. Children

The service is not intended for persons under 16 years of age (in certain US states — under 13 without parental consent). We do not knowingly collect children's data. Upon discovery of such an account, we may delete it and related data.

13. Automated decisions

We do not make decisions concerning you based solely on automated processing that produce legal effects or similarly significantly affect you (GDPR Art. 22). Account restrictions for abuse are decided by administration considering circumstances, not by fully automated "scoring".

14. Your rights

Depending on your place of residence, you may have the following rights:

How to exercise rights:

We will respond to requests within 30 days (GDPR) or within the timeframe established by applicable US state law (e.g., 45 days under CCPA with possible extension). We may request identity verification to avoid disclosing data to a third party.

California residents: we do not "sell" or "share" personal data for cross-context behavioral advertising. You have the right to know categories of collected data, request deletion and correction within CCPA/CPRA. We do not discriminate against users for exercising privacy rights.

15. Policy changes

We may update this policy. The current version is always on this page; for material changes we may notify via the website or email. Continued use of the service after changes take effect means acceptance of the updated policy, unless otherwise required by applicable law.

16. Contacts

For all privacy and rights exercise matters:

EU supervisory authorities: list of data protection authorities — on the European Data Protection Board website. For the US — the contact authority depends on your state of residence (e.g., California Attorney General — Privacy).

Home · Site rules · VPN usage rules · Terms of service