Privacy Policy
Last updated 5 August 2026. Written to be read, not to be skipped.
This policy explains what HiVPN sp. z o.o. collects when you use HiVPN, why, on what legal basis, and for how long. It follows the structure required by the EU General Data Protection Regulation, because our company is registered in Poland.
1. How we handle your connection data
We do not log the contents or destinations of your traffic. Specifically, we do not record which sites or applications you open, your DNS queries, your source IP address paired with a timestamp, or session start and end times. There is no browsing history in our systems, so there is none to disclose, sell or lose in a breach.
2. What personal data we collect, why, and on what legal basis
- Telegram user id: needed to deliver your key and answer support. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Key identifier and plan expiry date: without them the service cannot authorise your connection. Legal basis: performance of a contract.
- Aggregate traffic volume per key: used to detect abuse such as spam relaying. Legal basis: legitimate interest in keeping the network usable (Art. 6(1)(f)).
- Payment confirmation from the provider (amount, date, plan): required to prove the transaction. Legal basis: legal obligation (Art. 6(1)(c)).
- Support correspondence, if you write to us: kept only to continue the conversation. Legal basis: legitimate interest.
We never ask for your name, email address, phone number or identity documents. There is no account to create, so there is no profile to build.
3. How long we keep it
- Key identifier and expiry: for the life of the plan, then deleted within 30 days.
- Aggregate traffic counters: reset monthly, not archived.
- Payment records: retained as long as accounting law requires, currently five years in Poland.
- Support correspondence: deleted within 12 months of the last message.
4. Where the data goes
Our servers are located outside India. The CERT-In directive of 2022 requires providers with infrastructure inside India to retain customer records for five years and produce them on request. Because we operate no Indian servers, that obligation does not apply to us. Where data is transferred outside the European Economic Area, it is covered by the European Commission's standard contractual clauses.
5. Who else sees anything
- Telegram, which carries the bot conversation under its own privacy policy.
- Payment providers, which process the transaction and see what payment law requires.
- Hosting providers, which run the physical machines and see traffic volumes but not its content.
We do not sell personal data, and we do not share it for advertising. If a lawful request reaches us, we can only supply what exists: that a key was issued and when it expires.
6. Your rights
- Access: ask what we hold about your key.
- Erasure: ask us to delete it, subject to accounting retention on payment records.
- Rectification: correct anything inaccurate.
- Portability: receive your data in a machine-readable form.
- Objection: object to processing based on legitimate interest.
- Complaint: lodge one with your national supervisory authority, in Poland the UODO.
To exercise any of these, write to [email protected]. We answer within 30 days. Note that with no account system, the practical answer is usually short.
7. Cookies and tracking
The website uses only the cookies needed for it to function, such as remembering your light or dark theme. We run no advertising trackers, no third-party analytics profiles, and no cross-site pixels. Nothing here requires a consent banner because nothing here tracks you.
8. How the data is protected
- Traffic is encrypted with TLS 1.3.
- Server access is restricted to key-based authentication.
- Internal access to key records is limited to the people who run support.
9. Children
The service is not intended for anyone under 16. We do not knowingly process data belonging to children. If you believe a child has used the service, write to us and we will delete the associated record.
10. Controller and contact
The data controller is HiVPN sp. z o.o., ul. Wielicka 28, 30-552 Kraków, Poland. Privacy questions go to [email protected], everything else to [email protected] or to our Telegram bot.
11. Changes
If this policy changes materially, we update the date at the top and announce it in our Telegram channel. Continuing to use the service after a change means you accept the revised policy.