Privacy Policy
Effective date: August 15, 2025
Arvane Holdings OÜ (operating as Atheris) · Republic of Estonia
1. Who We Are
Arvane Holdings OÜ describes how it collects, uses, and safeguards personal data regarding our website, dashboard, APIs, and proxy services. We operate under GDPR and Estonian Personal Data Protection Act requirements, serving primarily B2B customers.
2. Scope & Roles
We act as data controller for account, billing, and support information. For network traffic routing, users/clients act as controllers while Atheris serves as processor—functioning as a "mere conduit" under EU law without monitoring payload content except for security and compliance purposes.
3. Data Collected
Account & Business Information
Names, emails, hashed passwords, company details, VAT numbers, billing addresses, and payment information (via third-party processors).
Operational & Service Data
Authentication IP addresses, connection timestamps, proxy node/region usage, session duration, bytes transferred, and automated abuse-prevention flags.
Website & Analytics
Essential cookies (always active) and non-essential cookies (requiring consent).
Support Data
Communications with support teams and voluntarily-provided files.
Compliance
Basic identifiers may be checked against EU/UN/OFAC sanctions before service use.
We do not intentionally collect special categories of personal data or information from children under 16.
4. Data Collection Methods
Data originates from:
- Direct user submission (registration, payments, support)
- Automated systems (logs, security telemetry, cookies)
- Third parties (payment processors, sanctions screening, company registers)
5. Processing Purposes & Legal Bases
- Service Delivery (GDPR Art. 6(1)(b)): Contract fulfillment
- Security & Abuse Prevention (Art. 6(1)(f)): Legitimate business interest
- Legal Compliance (Art. 6(1)(c)): Tax, accounting, sanctions obligations
- Analytics & Marketing (Art. 6(1)(a)): Consent-based, revocable anytime
6. Network Traffic Handling
We do not inspect or store payload content beyond transient technical processing. Minimal metadata is retained for billing, performance, and security. Automated systems may block or rate-limit abusive traffic. Enterprise clients can request custom retention controls via Data Processing Agreements.
7. Data Sharing & Recipients
Data may be shared with:
- Infrastructure providers (hosting, DDoS protection, network operators)
- Payment processors
- Support tools and ticketing platforms
- Regulatory bodies/law enforcement (when legally required)
- Corporate successors (merger/acquisition scenarios)
All third parties operate under GDPR-compliant contracts.
8. International Transfers
Transfers outside the EEA use Standard Contractual Clauses (SCCs) and additional safeguards per GDPR requirements.
9. Cookies & Tracking
Essential cookies operate continuously. Non-essential cookies require prior consent via banner. Users can modify preferences anytime via Cookie Settings.
10. Data Retention
- Account/Billing Data: Up to 7 years post-closure (legal requirement)
- Operational Logs: 30 days (longer if abuse investigations or legal obligations apply)
- Support Tickets: Up to 24 months
Data is deleted or anonymized when no longer needed.
11. Security Measures
We implement layered security, including encryption in transit, access control, key rotation, and monitoring. Personal data breach notifications go to affected users and the Estonian Data Protection Inspectorate without undue delay.
12. Your Rights
Under GDPR, you can:
- Access your personal data
- Correct inaccuracies
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Port data to other providers
- Withdraw consent for consent-based processing
Contact [email protected] to exercise rights; identity verification may be required.
13. Sanctions Compliance
We comply with EU/UN sanctions and prohibit use of the Service in violation of export controls or sanctions regimes. Flagged accounts may be suspended.
14. Consumer Rights
While B2B-focused, EU consumers may have 14-day withdrawal rights for distance contracts unless requesting immediate digital service activation (waiving this right afterward). We comply with the EU Consumer Rights Directive.
15. Policy Changes
Updates are announced via dashboard and/or email. Continued service use following updates constitutes acceptance.
Contact
Arvane Holdings OÜ
Harju maakond, Tallinn, Kesklinna linnaosa
Narva mnt 5, 10117
Estonia
Email: [email protected]
Supervisory Authority: Estonian Data Protection Inspectorate (www.aki.ee)