PRIVACY POLICY FOR THE PROXYS.IO Client MOBILE APPLICATION

Data Controller: ONLINE CONNECT LTD.

Company Number: 15419378

Registered office: 85 Great Portland Street, First Floor, London, W1W 7LT, United Kingdom

Website: https://proxys.io/

E-mail: mail@proxys.io

Revision date: 10 August 2026

1. General

This Privacy Policy (the “Policy”) describes what personal and technical data may be processed when using the PROXYS.IO Client mobile application for Android and iOS (the “App”), the purposes for which such data is used, to whom it may be disclosed and what rights the User may have.

ONLINE CONNECT LTD. (the “Company”, “we”, “us”) is the data controller in respect of processing carried out by the Company within the App and related services, to the extent provided by applicable law.

This Policy applies to processing directly related to the App.

Processing relating to accounts, orders, payments, the provision of proxies and other PROXYS.IO services may additionally be governed by a separate privacy policy applicable to those services.

This Policy does not constitute consent to processing for which applicable law requires separate consent.

2. How the App Works

The App is a mobile client for the PROXYS.IO service.

Depending on the available version and configuration, it may:

  • obtain a list of available proxies through an API;
  • use an API key or other access credentials;
  • store local connection profiles;
  • route a connection through a selected proxy;
  • check the external IP address;
  • receive technical configuration;
  • create a local proxy profile or network tunnel where required by the operating system to route traffic.

Some data is processed directly on the User’s device and is not transmitted to the Company unless required for a particular function.

3. Data That May Be Processed

3.1. Account and Access Data

Depending on the function used, the App may process:

  • API key;
  • proxy connection parameters;
  • proxy username and password;
  • local profile name;
  • account identifier or other information required to obtain configuration;
  • information entered or obtained by the User through their PROXYS.IO account.

Where such data is stored locally, the App uses secure storage mechanisms provided by the relevant platform, such as Android Keystore or iOS Keychain, where supported by the particular implementation of the App.

The Company does not ask the User to provide a full password or secret API key by e-mail for identity-verification purposes.

3.2. Technical Data

For the operation, security, diagnostics and stability of the App, technical information may be processed, including:

  • device model or type;
  • operating-system version;
  • App version;
  • language and regional interface settings;
  • connection-status information;
  • time and result of technical requests;
  • error codes;
  • crash information;
  • technical identifiers;
  • external IP address where necessary for the relevant function;
  • minimum network metadata required for connection, diagnostics and security.

The specific categories of technical data depend on the App version, operating system and functions used.

3.3. Local Profile Data

When the User creates a local profile, the App may store on the device:

  • profile name;
  • proxy parameters;
  • connection settings;
  • access credentials associated with the profile;
  • other settings required for its operation.

Such data may be stored until the relevant profile is deleted, the App data is cleared or the App is deleted, unless longer retention is required for the relevant function.

3.4. Support Enquiry Data

If the User contacts the Company, the following may be processed:

  • name or other contact details;
  • e-mail address;
  • order number or account identifier;
  • content of the enquiry;
  • information about the problem;
  • screenshots;
  • files and other attachments voluntarily provided by the User.

Users should not send passwords, secret API keys, payment details or other information that is not required to resolve the particular enquiry.

3.5. Network Traffic

When a proxy is used, network packets technically pass through the selected proxy to the destination resource.

This provision should not be understood as a promise of absolute anonymity or the absence of technical logs.

To the extent necessary for operation, security, abuse prevention, diagnostics and service maintenance, minimum technical information about connections may be processed.

Where the Company processes technical logs, the content of User traffic is not used for personalised advertising and is not sold to advertising networks or data brokers.

The Company should not obtain or process more traffic data than is necessary for the relevant function, security, compliance with legal requirements or protection of the Company’s and third parties’ rights, taking into account the actual architecture of the relevant service.

3.6. Data Not Normally Required

Unless the relevant function is expressly added to the App and the User has received the notice or consent request required by law, the App does not require for its core operation:

  • contacts from the address book;
  • photos or media library;
  • microphone;
  • camera;
  • precise geolocation;
  • payment details.

Operating-system permissions may vary depending on the App version and functions used.

4. Purposes of Processing

The Company may process data for the following purposes:

4.1. Providing App Functions

Including:

  • authentication and verification of access credentials;
  • obtaining configuration;
  • connecting to proxies;
  • saving and applying local profiles;
  • performing technical requests;
  • operating the network tunnel;
  • displaying technical information to the User.

4.2. Security

Data may be used for:

  • preventing abuse;
  • detecting suspicious activity;
  • protecting infrastructure;
  • preventing attacks;
  • protecting accounts and access credentials;
  • investigating security incidents.

4.3. Diagnostics and Support

Data may be used for:

  • identifying and correcting errors;
  • diagnosing failures;
  • analysing technical problems;
  • responding to User enquiries;
  • improving the stability and compatibility of the App.

4.4. Compliance with Law

The Company may process and retain data where necessary for:

  • compliance with legal obligations;
  • complying with binding requirements of governmental authorities;
  • protecting the Company’s legal rights and interests;
  • participating in the resolution of disputes;
  • preventing fraud and other violations.

5. Legal Bases for Processing

Depending on the particular processing activity, the Company may rely on one or more legal bases provided by applicable law, including:

  • performance of a contract — where processing is necessary to provide the App or a related service;
  • legitimate interests — for example, security, abuse prevention, diagnostics and infrastructure protection, where those interests are not overridden by the User’s rights;
  • legal obligation — where processing is required by law;
  • consent — where required by applicable law.

Where processing is based on consent, the User may withdraw that consent in accordance with applicable law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

6. Data Retention

The Company retains data for no longer than is necessary for the stated purposes, unless a longer period is required or permitted by applicable law.

The retention period depends on the category of data and the purpose of processing.

In particular:

  • local profiles and local access data may be retained until deleted by the User, the App data is cleared or the App is deleted;
  • technical logs are retained for the period necessary for operation, security, diagnostics, dispute resolution and compliance with mandatory requirements;
  • support enquiries are retained for as long as necessary to handle the enquiry, provide subsequent support, protect the Company’s rights and resolve potential disputes;
  • data required to be retained by law is retained for the applicable mandatory period.

At the end of the necessary retention period, data is deleted, destroyed or anonymised unless further retention is required by law.

7. Disclosure to Third Parties

The Company may provide access to data to:

  • authorised employees;
  • infrastructure providers;
  • technical contractors;
  • cloud and other IT service providers;
  • diagnostic and security providers;
  • other processors where their involvement is necessary for the relevant function.

Such parties receive only the amount of data necessary to perform the relevant task and must comply with applicable confidentiality and security requirements.

The Company does not sell personal data to advertising networks or data brokers.

The Company does not disclose data to governmental authorities arbitrarily. Disclosure takes place where there is an appropriate legal basis or binding requirement, unless otherwise provided by applicable law.

8. International Transfers

The Company and its infrastructure providers may use systems, servers and proxy infrastructure located in different countries.

Depending on the particular processing activity, personal data may be transferred outside the User’s country of residence.

For international transfers, the Company applies the mechanisms and safeguards required by applicable law where necessary.

Such measures may include contractual, organisational and technical data-protection mechanisms.

9. Data Security

The Company applies reasonable technical and organisational measures to protect data against unauthorised access, alteration, disclosure, loss and destruction.

Depending on the relevant function, security measures may include:

  • secure system storage of keys and passwords;
  • restricted employee access;
  • secure connections to APIs;
  • access controls;
  • App updates;
  • security monitoring;
  • abuse-prevention measures.

No method of storing or transmitting data provides absolute security.

The User must also:

  • use a current operating-system and App version where reasonably possible;
  • protect the device with a password or other lock mechanism;
  • not disclose API keys or passwords to third parties;
  • take immediate steps if compromise of access credentials is suspected.

10. Proxies and Encryption

Using a proxy does not mean that all transmitted data is automatically encrypted.

SOCKS5 and ordinary HTTP proxies do not by themselves provide end-to-end encryption of connection content.

For sensitive information, the User should use HTTPS and other secure protocols where available.

The Company cannot guarantee the security, confidentiality or data processing practices of a third-party resource accessed by the User through a proxy.

11. User Rights

Depending on applicable law, the User may have the right to:

  • obtain confirmation as to whether personal data is being processed;
  • request access to data;
  • correct inaccurate or incomplete data;
  • request deletion of data;
  • restrict processing;
  • object to certain types of processing;
  • receive data in a portable format;
  • withdraw previously given consent;
  • lodge a complaint with a competent supervisory authority.

The existence and scope of each right depend on applicable law and the circumstances of the relevant processing.

To fulfil a request, the Company may ask for reasonable proof of identity or control of the relevant account where necessary to protect the data.

The Company does not ask for a full password or secret API key by e-mail to verify identity.

12. How to Delete Data

The User may:

  • delete an individual local profile;
  • clear App data;
  • delete the App;
  • remove a proxy profile created by the App through device settings where it is no longer required;
  • revoke or replace an API key through the account area where that function is available.

Deleting the App from the device does not automatically mean that all data held by the Company is deleted.

To request deletion of data held by the Company, the User may contact:

mail@proxys.io

Data deletion is carried out subject to mandatory retention periods, lawful grounds for continued retention and the need to protect the Company’s rights.

13. Third-Party Services and App Stores

The App may interact with third-party services, including operating systems, app stores, APIs, infrastructure providers and proxy services.

Those third parties may process data independently in accordance with their own terms and privacy policies.

This Policy does not govern processing carried out independently by third parties.

Users are advised to review the applicable policies of the relevant third-party services.

14. Changes to the Policy

The Company may amend this Policy when:

  • App functions change;
  • the infrastructure used changes;
  • data-processing methods change;
  • legislation changes;
  • app-store requirements change;
  • new functions are introduced.

A new version will be published in the App, on the Company’s website or by another available means, with the revision date.

If a change requires new consent under applicable law, such consent will be requested separately.

Continued use of the App after a new version takes effect constitutes acknowledgement of the updated Policy to the extent such acknowledgement is permitted by applicable law.

15. Contact Details

For questions concerning personal-data processing, the exercise of User rights, data deletion or this Policy, please contact:

ONLINE CONNECT LTD.

Company Number: 15419378

85 Great Portland Street, First Floor, London, W1W 7LT United Kingdom

E-mail: mail@proxys.io

Website: https://proxys.io/

For matters directly concerning complaints about proxy use or abuse, the Company also uses the following dedicated channel:

abuse@proxys.io

Last revised: 10 August 2026

ONLINE CONNECT LTD.

Company Number: 15419378