Personal Data Processing Policy
Current version. This policy is prepared with regard to European Union requirements (including GDPR and ePrivacy) and United States of America requirements (including state privacy laws such as CCPA/CPRA in California, and FTC recommendations). For data processing inquiries, contact us via contacts.
1. General provisions
The EvilFox.Win service ("we", "service", "operator") respects your privacy. This policy (Privacy Notice) describes what personal data we collect, on what legal basis we process it, to whom we transfer it, how long we retain it, and what rights you have.
The policy applies when using the website, account dashboard, VPN services, and other EvilFox.Win services. By using the service, you confirm having read this document. For mandatory processing cases, we rely on applicable EU and US law; requirements of authoritarian jurisdictions do not by themselves define the scope of our privacy policy.
2. Data operator and contacts
Operator (data controller) of personal data within the meaning of GDPR — the owner of the EvilFox.Win service.
A separate Data Protection Officer (DPO) is not appointed; personal data requests are accepted through the channels indicated above.
3. What data we process
Depending on how you use the service, we may process the following categories of data:
- Identification and contact: email, name or alias, account identifier;
- Credentials: password hash, two-factor authentication data (if enabled), Telegram linkage (if used);
- Contract and payment: balance, top-up and debit history, tariff and subscription information (without full bank card details — processed by payment providers);
- VPN services: information on purchased configurations, subscription terms, selected servers; we do not intentionally analyze or store the content of your VPN traffic;
- Support: ticket subject and text, attachments you send;
- Referral program (if participating): linkage to referring user, accruals;
- Technical data: IP address when accessing the website and API, browser and OS type, cookies, local storage, error and security logs (in limited scope).
We do not collect special categories of data (health, biometrics, political views, etc.) and the service is not intended for children under 16 (see Section 12).
4. Data sources
Data is obtained:
- directly from you (registration, payment, tickets, profile settings);
- automatically when visiting the website (technical logs, cookies);
- from payment and other contractors — to the extent necessary to complete a transaction (e.g., payment status).
5. Cookies and similar technologies (ePrivacy / GDPR)
We use cookies and browser local storage. By purpose, they are divided into:
- Strictly necessary — login session, security, account dashboard operation. Legal basis: contract performance and legitimate interest (GDPR Art. 6(1)(b), (f)); consent is not required for these.
- Functional / preferences — remembering choice in the cookie banner (
cookie_consent). Legal basis: consent (GDPR Art. 6(1)(a)), given via "Accept all" or "Necessary only" buttons.
- Optional (third parties) — online support chat widget (Tawk.to), if enabled on the website. Loaded only after selecting "Accept all"; may set Tawk.to cookies and transfer data to the US. Legal basis: consent (GDPR Art. 6(1)(a)). Refusal — "Necessary only" or "Cookie settings" in the footer.
We do not use third-party advertising or profiling cookies for cross-site tracking. You may delete or block cookies in browser settings; refusing necessary cookies may make account login impossible.
Consent cookie retention period — up to 12 months, unless otherwise indicated in your browser.
6. Purposes and legal bases of processing (GDPR)
We process personal data only where a legal basis exists:
- Contract performance (Art. 6(1)(b) GDPR) — registration, VPN issuance, balance debits, support at your request;
- Legal obligations (Art. 6(1)(c)) — accounting and tax records, responses to mandatory requests from EU/US authorities as provided by law;
- Legitimate interest (Art. 6(1)(f)) — service security, fraud and abuse prevention, rights protection in disputes, website stability improvement (without excessive profiling);
- Consent (Art. 6(1)(a)) — optional cookies, marketing communications (if ever introduced and only with separate consent). Consent may be withdrawn without prejudice to lawful processing before withdrawal.
7. VPN and data minimization
The VPN service privacy policy is supplemented by VPN usage rules. We adhere to the data minimization principle: we do not conduct targeted monitoring of user traffic content. Technical metadata (e.g., traffic volume on server control panels) may be processed for billing, tariff limits, and abuse prevention — without linkage to content of visited websites.
8. Retention periods
- account and subscription data — while the account is active and for a reasonable period after deletion (for backups and disputes), typically no more than 90 days after final deletion, unless law requires longer;
- financial records — for periods established by tax and accounting law (often up to 6–7 years depending on jurisdiction);
- support tickets — until the issue is closed and up to 3 years for inquiry history, unless you request earlier deletion;
- server technical logs — typically up to 30–90 days, unless longer retention is required for security incident investigation.
Upon expiry of retention periods, data is deleted or anonymized.
9. Data transfers and processors
We do not sell personal data and do not transfer it in exchange for monetary consideration (including within the meaning of CCPA/CPRA — "sale"/"sharing" for behavioral advertising).
Data may be transferred to processors only for service provision:
- payment systems (payment processing);
- hosting providers and data centers (website and infrastructure hosting);
- email/notification delivery services (if used);
- Tawk.to online chat widget (if enabled and you gave "Accept all" consent);
- security and availability monitoring contractors (without access to VPN traffic content).
Data processing agreements (DPAs) or standard contractual terms are concluded with such parties to the extent required by GDPR.
Disclosure to government authorities — only upon valid and mandatory request under EU, US, or other jurisdiction law binding on us. Arbitrary requests without legal basis are not fulfilled (see also VPN rules, section on authority requests).
10. International data transfers
Servers and contractors may be located outside your country, including outside the EEA. When transferring from the EU/EEA, we apply measures provided by GDPR Chapter V: Standard Contractual Clauses (SCC), European Commission adequacy decisions, or other lawful mechanisms. For US residents, transfer may occur between our systems and contractors in accordance with this policy and processor agreements.
11. Security measures
We apply technical and organizational measures: password encryption, database access restrictions, HTTPS on the website, administrator access segregation, backups. No method of internet transmission or storage guarantees absolute security; we strive to protect data at a reasonable level.
12. Children
The service is not intended for persons under 16 years of age (in certain US states — under 13 without parental consent). We do not knowingly collect children's data. Upon discovery of such an account, we may delete it and related data.
13. Automated decisions
We do not make decisions concerning you based solely on automated processing that produce legal effects or similarly significantly affect you (GDPR Art. 22). Account restrictions for abuse are decided by administration considering circumstances, not by fully automated "scoring".
14. Your rights
Depending on your place of residence, you may have the following rights:
- Access — obtain a copy of data processed about you;
- Rectification — correct inaccurate data (partly in profile);
- Erasure ("right to be forgotten") — request deletion where no lawful basis for further retention exists;
- Restriction of processing — in cases provided by GDPR;
- Portability — receive data in a structured machine-readable format (for data processed on contract or consent basis);
- Objection — to processing based on legitimate interest;
- Withdrawal of consent — at any time for processing based on consent;
- Complaint — to the data protection supervisory authority in your country of residence in the EU/EEA or to the competent US state authority (e.g., California Privacy Protection Agency for California residents).
How to exercise rights:
- data export — "Download my data" button in the account dashboard (
profile.php?action=gdpr_export);
- account deletion — form in profile with password confirmation;
- other requests — ticket in support or email admin@evilfox.cc.
We will respond to requests within 30 days (GDPR) or within the timeframe established by applicable US state law (e.g., 45 days under CCPA with possible extension). We may request identity verification to avoid disclosing data to a third party.
California residents: we do not "sell" or "share" personal data for cross-context behavioral advertising. You have the right to know categories of collected data, request deletion and correction within CCPA/CPRA. We do not discriminate against users for exercising privacy rights.
15. Policy changes
We may update this policy. The current version is always on this page; for material changes we may notify via the website or email. Continued use of the service after changes take effect means acceptance of the updated policy, unless otherwise required by applicable law.
16. Contacts
For all privacy and rights exercise matters:
EU supervisory authorities: list of data protection authorities — on the European Data Protection Board website. For the US — the contact authority depends on your state of residence (e.g., California Attorney General — Privacy).
Home · Site rules · VPN usage rules · Terms of service