Privacy Policy

Revision 1.1 · Effective as of August 22, 2026

1. Data Controller

1.1. The controller of personal data is Global Reach — a company incorporated and existing under the laws of the State of Delaware, USA (hereinafter, the “Company,” “we”). For purposes of operational coordination and interaction, the Company uses an address in Hong Kong: SUITE C, LEVEL 7, WORLD TRUST TOWER, 50 STANLEY STREET, CENTRAL, HONG KONG, as well as an address in Vietnam: 229 Chinh Huu Street, An Hai Ward, Da Nang City. The indication of these addresses in this Policy does not constitute a representation that a separate legal entity, branch, or representative office has been established in the relevant jurisdiction. The legal status of the Company’s activities in each jurisdiction is determined by the actual nature of such activities and applicable law.

1.2. For matters concerning the processing of personal data: privacy@proxyma.io.

2. Scope of Application

2.1. This Policy describes what personal data the Company collects in connection with the use of the website https://proxyma1.io, the personal account, the API, and other services (collectively, the “Service”), how and on what legal bases such data is processed, and the rights of users.

2.2. The Company complies with the requirements of data protection legislation applicable to the specific processing at issue. In particular, where the relevant law is applicable: for consumers in certain U.S. states — the CCPA/CPRA and other applicable state laws; for individuals in the European Union / EEA — the GDPR; for individuals in the United Kingdom — the UK GDPR and the Data Protection Act 2018; for the processing of personal data in Vietnam, as well as the data of Vietnamese citizens — the Law on Personal Data Protection (Law No. 91/2025/QH15) and Decree No. 356/2025/ND-CP. The mention of a given law in this Policy does not, in itself, mean that the Company is subject to it in all cases.

3. What Data We Collect

3.1. Account data: name, email address, login, password (in encrypted form), contact details.

3.2. Payment data: information necessary to process payments. Full payment card details are processed by payment providers; the Company does not store them.

3.3. Service usage data: technical connection logs, traffic volume, date and time of sessions, endpoints used — to the extent necessary for the provision of the Services, billing, security, and compliance with legal requirements.

3.4. Technical data: IP address, device and browser type, identifiers collected through cookies (see the Cookie Policy).

3.5. Support inquiries: the content of correspondence and related data.

3.6. Sources of data. As a general rule, the Company obtains data directly from the user, automatically through use of the Service, from payment providers and other service providers, and, with respect to Network Participants, in connection with their connection to the network and use of the corresponding software or partner connection channel.

3.7. Sensitive and special categories of data. The Company does not request special categories of personal data within the meaning of Article 9 GDPR and asks users not to submit such data through the Service unless expressly required by law or by a separately agreed procedure. If such data is nonetheless received, the Company processes it only where an appropriate legal basis exists.

4. Data of Proxy Network Participants

4.1. The residential and mobile proxy infrastructure includes individuals who voluntarily provide network resources (IP address, a portion of device traffic) — hereinafter, “Network Participants.”

4.2. Enrollment and legal basis. Participants join the network solely on the basis of express, informed, and revocable consent (opt-in). The use of the devices, IP addresses, and traffic of individuals without their verifiable consent is not permitted. For users subject to the GDPR, such consent constitutes the legal basis for processing (Article 6(1)(a) GDPR).

4.3. Disclosure. Prior to obtaining consent, the Participant is informed, in a clear and comprehensible manner, of: which resources are used, the nature and estimated volume of traffic, the consideration to be received in return, and the procedure for withdrawing consent and exiting the network.

4.4. Consideration. In exchange for participation in the network, the Participant receives consideration (remuneration or other benefits).

4.5. Withdrawal of consent and exit. The Participant may withdraw consent and exit the network at any time, following which use of that Participant’s network resources shall cease. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

4.6. Data processed. With respect to Participants, the Company processes IP addresses and technical logs to the extent necessary for the network’s operation, security, and compliance with legal requirements.

4.7. Confirmation of consent. The Company and/or the relevant connection partner retains records sufficient to confirm the fact and parameters of the opt-in, for the period and to the extent necessary to comply with legal requirements, resolve disputes, prevent abuse, and confirm the lawfulness of participation in the network.

5. Purposes of Processing

We process personal data for the following purposes. For users subject to the GDPR, the corresponding legal basis (Article 6) is indicated:

PurposeLegal Basis (for EU/UK users — GDPR)
Provision of the Services and performance of the contractPerformance of a contract (Art. 6(1)(b))
Payment processing and billingPerformance of a contract; legal obligation (Art. 6(1)(b), (c))
Security, prevention of abuse and fraudLegitimate interest (Art. 6(1)(f))
Compliance with legal requirements (tax, sanctions, requests from authorities)Legal obligation (Art. 6(1)(c))
User supportPerformance of a contract; legitimate interest (Art. 6(1)(b), (f))
Marketing communicationsConsent (Art. 6(1)(a))
Analytics and marketing cookiesConsent (Art. 6(1)(a))

5.1. Legitimate interests. Where the Company relies on Article 6(1)(f) GDPR/UK GDPR, the relevant interests are: protecting the Service and infrastructure, preventing fraud and abuse, ensuring network and information security, providing user support, establishing and asserting legal claims, and improving the reliability of the Service. The Company takes into account the necessity and proportionality of the processing and the rights of data subjects.

5.2. Necessity of providing data. Data marked as mandatory upon registration, payment, or conclusion of a contract are necessary for creating an account, providing the Service, issuing invoices, or complying with the law. If such data is not provided, the Company may be unable to conclude or perform the contract or to provide the relevant feature.

5.3. Automated decision-making. The Company does not make decisions concerning users based solely on automated processing that produce legal effects concerning them or similarly significantly affect them, unless otherwise expressly disclosed to the user prior to the commencement of such processing, together with the safeguards required by law.

6. Cookies

6.1. The Company uses cookies and similar technologies. The manner in which they are used and managed is described in the Cookie Policy (https://proxyma1.io/cookie-policy), which forms an integral part of this Policy.

7. Disclosure of Data to Third Parties

7.1. The Company may disclose personal data to:

•  service providers (processors) — hosting, payment providers, analytics and support tools — on the basis of agreements ensuring data protection and processing solely on the Company’s instructions;

•  competent authorities — where there is a lawful request;

•  successors in interest — in the event of a reorganization, merger, or sale of the business.

7.2. Sale and sharing. The Company does not sell personal data for monetary consideration. To the extent that the use of advertising or cross-context behavioral technologies qualifies as “sharing” under the CCPA/CPRA, the consumer has the right to opt out of such disclosure through the “Do Not Sell or Share My Personal Information” mechanism available on the Service and/or through cookie settings, where such a mechanism is required by law.

7.3. For purposes of the CCPA/CPRA, to the extent that law is applicable to the Company, within the preceding 12 months the Company may have collected the categories of identifiers and internet/network activity, commercial information, account information, and other categories described in Section 3; the sources and purposes are set out in Sections 3 and 5. This data may have been disclosed to service providers/contractors, payment providers, infrastructure, analytics, security, and support providers for the corresponding business purposes. The Company does not sell personal data. The categories actually used with respect to a specific user depend on that user’s interaction with the Service.

8. Data Storage and Transfer

8.1. Personal data is processed and stored by processors engaged by the Company, including outside the country in which the user is located.

8.2. For international transfers of data subject to the GDPR/UK GDPR, the Company relies on an applicable lawful transfer mechanism: an adequacy decision — where in effect; the European Commission’s Standard Contractual Clauses (SCCs) and, where necessary, supplementary measures — for transfers under the GDPR; the UK International Data Transfer Agreement (IDTA), the UK Addendum to the SCCs, or another permissible mechanism — for transfers under the UK GDPR; or another basis provided for under applicable law. Information regarding applicable safeguards may be requested at privacy@proxyma.io.

9. Retention Periods

9.1. Personal data is retained for the period necessary to achieve the purposes of processing, namely:

•  account data — for the duration of the account and for 12 months following its deletion;

•  payment and accounting data — for the period established by applicable law (generally up to 7 years);

•  technical logs — for 12 months, unless a longer period is required for security or legal purposes;

•  support inquiries — for 24 months;

•  Network Participant data and opt-in confirmations — for the duration of participation in the network and thereafter for the period reasonably necessary to comply with the law, ensure security, resolve disputes, and defend legal claims;

•  retention periods for cookies and similar identifiers — as set out in the Cookie Policy and the settings of the relevant tool.

9.2. Upon expiry of the retention period, data is deleted or anonymized.

10. User Rights

10.1. Rights under U.S. State Laws (including the CCPA/CPRA — California)

If you are a resident of a state granting corresponding rights (for example, California), you have the right to:

•  know / access — request which categories and specific items of personal data about you have been collected, as well as their sources and purposes;

•  delete personal data collected about you (subject to exceptions established by law);

•  correct inaccurate personal data;

•  opt out of the sale or sharing («Do Not Sell or Share») of personal data;

•  limit the use and disclosure of sensitive personal data — where such right is applicable and the Company uses such data in a manner covered by the corresponding right;

•  non-discrimination for exercising your rights.

10.2. Rights under the GDPR / UK GDPR (users in the EU / EEA / United Kingdom)

Where the GDPR/UK GDPR applies to the processing, you additionally have the right to access, rectification, erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest and to direct marketing, and the right to withdraw consent.

10.3. To exercise your rights, please send a request to privacy@proxyma.io or use another method specified in the Service interface. The Company may request information reasonably necessary to verify the identity and authority of the requester and does not use such information for any other purpose. Where applicable law permits requests to be submitted through an authorized agent, the Company accepts such requests upon confirmation of authority in the manner prescribed by law. The Company responds within the periods established by applicable law. In cases provided for by the laws of certain U.S. states, the user also has the right to appeal a denial of a request; the appeal procedure will be communicated in the Company’s response.

10.4. Complaints. The user has the right to lodge a complaint with the competent supervisory authority: in the EU/EEA — with the data protection authority, in particular of the place of habitual residence, place of work, or place of the alleged infringement; in the United Kingdom — with the Information Commissioner’s Office (ICO); in Vietnam — with the Ministry of Public Security (the relevant cybersecurity division); in the United States — with the competent state authority, where the corresponding right is provided for under applicable law.

11. Security

11.1. The Company applies reasonable technical and organizational measures to protect data against unauthorized access, loss, alteration, and disclosure, including encryption, access controls, and oversight of processors’ activities.

11.2. No method of data transmission or storage is completely secure; the Company cannot guarantee absolute data security.

12. Breach Notification

12.1. In the event of a personal data breach, the Company takes response measures and fulfills its applicable notification obligations. In particular, where the GDPR applies, the Company notifies the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach, if the breach is likely to result in a risk to the rights and freedoms of natural persons; where the risk is high, affected data subjects are notified without undue delay. Notifications in the United States are made in accordance with applicable federal and state requirements.

13. Data of Minors

13.1. The Service is intended solely for individuals over the age of 18. The Company does not knowingly collect data from individuals under the age of 18; where such data is identified, it is deleted.

13.2. The Company has no actual knowledge of selling or sharing the personal data of consumers under the age of 16. If the Company learns that such data has been collected or disclosed in violation of this Policy, it takes reasonable steps to cease such processing and delete the data, unless its retention is required by law.

14. Representative in the EU / United Kingdom

14.1. Where, pursuant to Article 27 GDPR and/or the corresponding provisions of the UK GDPR, the Company is required to appoint a representative in the EU/EEA and/or the United Kingdom, such representative shall be appointed in writing, and its name and contact details shall be published in this Policy and/or in another readily accessible notice prior to the commencement of the processing for which such appointment is required. Pending publication of such details, this Section shall not be construed as a representation that a representative has already been appointed.

15. Amendments to the Policy

15.1. The Company may update this Policy. The current version is posted on the Service, indicating its effective date. Users will be notified of material changes through the Service and/or by email.

16. Governing Law, Language, and Contacts

16.1. This Policy applies subject to the mandatory data protection rules in effect at the user’s location (in particular, the CCPA/CPRA and the GDPR/UK GDPR). This Policy does not designate a single country of governing law.

16.2. This Policy is drawn up in the Russian language. Translations may be provided for the convenience of users. In the event of discrepancies, the Russian version shall serve as the primary contractual text to the extent permitted by applicable law; mandatory requirements of law concerning transparency and the rights of data subjects shall prevail.

16.3. Questions and requests regarding data protection: privacy@proxyma.io.

Global Reach · Company incorporated in the State of Delaware, USA · Addresses for operational coordination: Hong Kong — SUITE C, LEVEL 7, WORLD TRUST TOWER, 50 STANLEY STREET, CENTRAL, HONG KONG; Vietnam — 229 Chinh Huu Street, An Hai Ward, Da Nang City · privacy@proxyma.io · https://proxyma1.io · © 2026 Global Reach. All rights reserved. PROXYMA® is a trademark of Global Reach.

Unleash the Power of Proxies with Proxyma

START NOW Contact us