Privacy Policy

Effective date: August 15, 2025

Arvane Holdings OÜ (operating as Atheris) · Republic of Estonia

1. Who We Are

Arvane Holdings OÜ describes how it collects, uses, and safeguards personal data regarding our website, dashboard, APIs, and proxy services. We operate under GDPR and Estonian Personal Data Protection Act requirements, serving primarily B2B customers.

2. Scope & Roles

We act as data controller for account, billing, and support information. For network traffic routing, users/clients act as controllers while Atheris serves as processor—functioning as a "mere conduit" under EU law without monitoring payload content except for security and compliance purposes.

3. Data Collected

Account & Business Information

Names, emails, hashed passwords, company details, VAT numbers, billing addresses, and payment information (via third-party processors).

Operational & Service Data

Authentication IP addresses, connection timestamps, proxy node/region usage, session duration, bytes transferred, and automated abuse-prevention flags.

Website & Analytics

Essential cookies (always active) and non-essential cookies (requiring consent).

Support Data

Communications with support teams and voluntarily-provided files.

Compliance

Basic identifiers may be checked against EU/UN/OFAC sanctions before service use.

We do not intentionally collect special categories of personal data or information from children under 16.

4. Data Collection Methods

Data originates from:

  • Direct user submission (registration, payments, support)
  • Automated systems (logs, security telemetry, cookies)
  • Third parties (payment processors, sanctions screening, company registers)

5. Processing Purposes & Legal Bases

  • Service Delivery (GDPR Art. 6(1)(b)): Contract fulfillment
  • Security & Abuse Prevention (Art. 6(1)(f)): Legitimate business interest
  • Legal Compliance (Art. 6(1)(c)): Tax, accounting, sanctions obligations
  • Analytics & Marketing (Art. 6(1)(a)): Consent-based, revocable anytime

6. Network Traffic Handling

We do not inspect or store payload content beyond transient technical processing. Minimal metadata is retained for billing, performance, and security. Automated systems may block or rate-limit abusive traffic. Enterprise clients can request custom retention controls via Data Processing Agreements.

7. Data Sharing & Recipients

Data may be shared with:

  • Infrastructure providers (hosting, DDoS protection, network operators)
  • Payment processors
  • Support tools and ticketing platforms
  • Regulatory bodies/law enforcement (when legally required)
  • Corporate successors (merger/acquisition scenarios)

All third parties operate under GDPR-compliant contracts.

8. International Transfers

Transfers outside the EEA use Standard Contractual Clauses (SCCs) and additional safeguards per GDPR requirements.

9. Cookies & Tracking

Essential cookies operate continuously. Non-essential cookies require prior consent via banner. Users can modify preferences anytime via Cookie Settings.

10. Data Retention

  • Account/Billing Data: Up to 7 years post-closure (legal requirement)
  • Operational Logs: 30 days (longer if abuse investigations or legal obligations apply)
  • Support Tickets: Up to 24 months

Data is deleted or anonymized when no longer needed.

11. Security Measures

We implement layered security, including encryption in transit, access control, key rotation, and monitoring. Personal data breach notifications go to affected users and the Estonian Data Protection Inspectorate without undue delay.

12. Your Rights

Under GDPR, you can:

  • Access your personal data
  • Correct inaccuracies
  • Request erasure ("right to be forgotten")
  • Restrict or object to processing
  • Port data to other providers
  • Withdraw consent for consent-based processing

Contact [email protected] to exercise rights; identity verification may be required.

13. Sanctions Compliance

We comply with EU/UN sanctions and prohibit use of the Service in violation of export controls or sanctions regimes. Flagged accounts may be suspended.

14. Consumer Rights

While B2B-focused, EU consumers may have 14-day withdrawal rights for distance contracts unless requesting immediate digital service activation (waiving this right afterward). We comply with the EU Consumer Rights Directive.

15. Policy Changes

Updates are announced via dashboard and/or email. Continued service use following updates constitutes acceptance.

Contact

Arvane Holdings OÜ

Harju maakond, Tallinn, Kesklinna linnaosa

Narva mnt 5, 10117

Estonia

Email: [email protected]

Supervisory Authority: Estonian Data Protection Inspectorate (www.aki.ee)