1. Introduction
This Privacy Policy explains how the applicable Infatica entity collects, uses, discloses, stores, and protects Personal Data in connection with Infatica websites, Trust Center, customer accounts, reseller and partner relationships, dashboards, APIs, proxy and network services, SDK-enabled peer network operations, support, compliance, security, marketing, and related services.
This policy is intended for Trust Center publication. It should be aligned with the Data Protection Addendum, Acceptable Use Policy, SDK & Peer Network Transparency document, customer/reseller agreements, partner agreements, cookie banner, and operational privacy processes.
2. Who we are
The controller responsible for your Personal Data is the Infatica entity that provides or administers the relevant service or relationship. Depending on the applicable agreement or service, this may include INFATICA LTD, Infatica Pte. Ltd., or another Infatica entity identified in the applicable agreement or notice.
| Entity / item | |
|---|---|
| INFATICA LTD address | Unit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom |
| INFATICA PTE. LTD address | 195 Pearl’s Hill Terrace, #03-62A, 168976, Singapore |
| EU / UK representative, if applicable | — |
| Data protection contact | — |
| Trust Center contact | — |
3. Scope
This Privacy Policy applies to Personal Data processed in connection with:
- Infatica websites, Trust Center, forms, and marketing pages
- customer, reseller, prospect, vendor, and partner relationships
- residential proxies, mobile proxies, datacenter proxies, ISP/static proxies, dashboards, APIs, credentials, support, and related services
- KYC/KYB, sanctions screening, use-case review, compliance review, abuse prevention, and security monitoring
- SDK-enabled peer network governance, consent, withdrawal, peer participation, partner compliance, and network integrity
- communications, support tickets, procurement requests, security questionnaires, and legal notices
4. Personal Data we collect
| Category | Examples |
|---|---|
| Account and business contact data | Name, business email, phone, company, role, country, account identifiers, login details, dashboard user data. |
| Customer / reseller / partner relationship data | Agreement details, order or plan details, reseller details, end-client information where provided, use-case information, support tier, relationship history. |
| Billing and payment data | Invoices, payment status, payment method metadata, transaction identifiers, tax information, accounting records. Payment processors may process card or payment details directly. |
| KYC/KYB and compliance data | Business identity information, beneficial ownership information, sanctions screening results, verification status, compliance review notes, restricted-target requests. |
| Service and usage data | Dashboard activity, API logs, authentication events, credentials or token identifiers, service metadata, proxy/session metadata, traffic pattern metadata, bandwidth or usage records. |
| Support and communications data | Support tickets, email messages, chat messages, call notes, attachments, troubleshooting materials, feedback, procurement requests. |
| Website and marketing data | Cookie identifiers, IP address, device/browser information, pages viewed, referrers, campaign parameters, form submissions, email engagement. |
| Security and abuse-prevention data | IP addresses, access logs, domain-category information, blacklist/whitelist requests, abuse reports, security events, fraud signals, investigation notes. |
| SDK / peer network data | IP address, limited device/network metadata, connection metadata, country/region inference, consent status, withdrawal status, partner application identifier, DAU/activity records, traffic volume metadata, abuse/security logs. |
| Legal and rights-request data | Identity verification information, request details, correspondence, records of access/deletion/correction/objection requests, legal notices, complaints. |
5. Sources of Personal Data
We may collect Personal Data directly from you, from your company or organization, from customers, resellers, partners, authorized users, end clients where provided by Customer or Reseller, service providers, payment processors, KYC/KYB providers, analytics tools, security tools, public sources, and through your use of the Services.
For SDK / peer network data, information may be collected through approved partner applications that integrate the Infatica SDK and present the required notice and consent flow.
6. How we use Personal Data
| Purpose | Examples |
|---|---|
| Service access and account administration | Create accounts, authenticate users, manage dashboard/API access, provide services, maintain credentials, communicate service notices. |
| Billing and financial administration | Process payments, invoices, tax, accounting, refunds, chargebacks, and transaction records. |
| Support and troubleshooting | Respond to tickets, diagnose technical problems, provide onboarding assistance, improve support quality. |
| Fraud, abuse, and security prevention | Detect and prevent misuse, technical circumvention, spam, malware, credential abuse, account takeover, unauthorized scraping, child-safety-sensitive abuse, and other prohibited activities. |
| KYC/KYB and compliance review | Verify customers, screen against sanctions, review business purpose, assess restricted targets, maintain compliance records. |
| Network integrity and service operations | Monitor reliability, capacity, routing, usage, quality, infrastructure performance, proxy pools, and network safety. |
| SDK / peer network governance | Manage consent, withdrawal, peer eligibility, partner compliance, DAU calculations, network integrity, traffic routing governance, and abuse prevention. |
| Marketing and business development | Send permitted marketing communications, manage prospect relationships, analyze campaign performance, handle opt-outs. |
| Legal and contractual purposes | Enforce agreements, policies, legal rights, respond to legal requests, establish or defend legal claims, comply with legal obligations. |
7. Legal bases under GDPR / UK GDPR
Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases depending on the context:
| Legal basis | Examples |
|---|---|
| Contract necessity | Providing accounts, services, support, billing, and relationship administration. |
| Legitimate interests | Security, fraud prevention, abuse prevention, compliance review, network integrity, service improvement, business relationship management, legal claims. |
| Consent | Optional cookies, marketing where required, SDK / peer network participation where consent is required. |
| Legal obligation | Tax, accounting, sanctions, compliance, law-enforcement response, regulatory obligations. |
| Vital interests / public interest | Not expected in normal operations; use only where legally applicable. |
8. Cookies and tracking technologies
We use cookies and similar technologies on our websites, dashboard, Trust Center, and online services. Cookies may be set by Infatica or by third-party service providers acting on our behalf.
| Cookie category | Purpose | Status |
|---|---|---|
| Strictly necessary cookies | Authentication, session management, security, load balancing, form functionality, user preferences required for the site or service. | Always active. These cookies are required for the website, dashboard, Trust Center, or online service to function and cannot be disabled through Infatica’s cookie controls. |
| Functional cookies | Remember choices, improve usability, support chat or customer-service functionality. | Optional where not strictly necessary. These cookies may be enabled, disabled, or managed through available cookie settings or browser controls. |
| Analytics cookies | Understand website usage, pages viewed, traffic sources, performance, and product interest. | Optional. These cookies are used only where permitted by law and, where required, only after the user has provided consent. |
| Marketing cookies | Measure campaigns, personalize communications, manage advertising audiences, where used. | Optional. These cookies are used only where permitted by law and, where required, only after the user has provided consent. |
You can control cookies through your browser settings and, where available, through our cookie banner or consent-management tool. Disabling certain cookies may affect site functionality or account access.
9. SDK / peer network privacy
Where an approved partner application integrates the Infatica SDK, users may be offered the option to participate in the Infatica peer network. Participation must be disclosed and voluntary, and users must be able to withdraw through the approved mechanism.
The SDK / peer network may process IP addresses and limited technical, connection, consent, withdrawal, partner application, country/region, DAU, activity, bandwidth, security, and abuse-prevention data.
The SDK is not intended to collect browsing history, application content, precise GPS location, advertising identifiers, IMEI, device fingerprints, messages, contacts, photos, files, passwords, payment credentials, or special category data.
SDK participation and withdrawal details are described in the SDK & Peer Network Transparency / Consent and Opt-Out document.
10. How we share Personal Data
We may share Personal Data with the following categories of recipients where necessary for the purposes described in this Privacy Policy:
- Infatica group entities and authorized personnel
- hosting, infrastructure, CDN, WAF, DDoS, logging, monitoring, and security providers
- payment processors, banks, tax/accounting providers, and billing tools
- KYC/KYB, sanctions screening, fraud prevention, and compliance providers
- CRM, sales, support, email, communications, analytics, and marketing providers
- professional advisers, auditors, insurers, lawyers, and consultants
- partners and resellers where necessary to administer a partner or reseller relationship
- public authorities, regulators, courts, law enforcement, and third parties where required by law or necessary to protect rights, safety, security, and compliance
- successors or acquirers in connection with a merger, acquisition, financing, restructuring, or sale of assets
11. International transfers
We may process and transfer Personal Data internationally. Where required by applicable law, we use appropriate transfer mechanisms such as adequacy decisions, standard contractual clauses, UK transfer addenda or IDTAs, contractual safeguards, or other lawful mechanisms.
| Transfer area | |
|---|---|
| EU/EEA | Where Personal Data is transferred from the EU/EEA to a country or recipient not covered by an applicable adequacy decision, Infatica relies on appropriate transfer mechanisms, including the European Commission’s Standard Contractual Clauses and, where required, supplementary contractual, technical, and organizational safeguards. |
| United Kingdom | Where Personal Data is transferred from the United Kingdom in a restricted transfer, Infatica relies on applicable UK transfer mechanisms, including the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, adequacy regulations, and supplementary safeguards where required. |
| Switzerland | Where Personal Data is transferred from Switzerland to a country or recipient not recognized as providing adequate protection, Infatica relies on appropriate transfer mechanisms, including standard contractual clauses with Swiss-specific adaptations and supplementary safeguards where required. |
| Singapore / APAC | Where Personal Data is transferred from Singapore or other APAC jurisdictions, Infatica uses contractual, technical, and organizational safeguards designed to protect Personal Data in accordance with applicable local data protection laws, including vendor contracts, intra-group safeguards, and recognized model clauses where appropriate. |
| United States | Transfers to the United States may rely on applicable adequacy frameworks where the recipient is eligible and certified, including the EU-U.S. Data Privacy Framework for EU/EEA transfers to participating U.S. companies. Where no such framework applies, Infatica relies on Standard Contractual Clauses, UK transfer mechanisms, Swiss-specific transfer terms, contractual safeguards, and supplementary technical and organizational measures where required. |
12. Retention
We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Retention depends on the type of data, relationship, service, legal obligations, security needs, dispute risk, and operational requirements.
| Data category | Retention |
|---|---|
| Account data | For the duration of the account or customer relationship, and thereafter for as long as reasonably necessary for legal, contractual, compliance, security, audit, and dispute-resolution purposes. |
| Billing / tax / accounting records | For the period required by applicable tax, accounting, and company law. For UK accounting records, this is generally at least 6 years from the end of the relevant financial year; for Singapore tax records, this is generally at least 5 years from the relevant Year of Assessment. |
| KYC/KYB and compliance records | For the duration of the customer relationship and thereafter for as long as reasonably necessary for compliance, sanctions, fraud-prevention, abuse-prevention, audit, legal, and dispute-resolution purposes. |
| Dashboard / API logs | For as long as reasonably necessary to provide, secure, monitor, troubleshoot, and improve the Services, and to investigate misuse, security incidents, or policy violations. |
| Proxy/session metadata | For as long as reasonably necessary for service operation, usage calculation, troubleshooting, abuse prevention, fraud prevention, security, compliance, and dispute-resolution purposes. |
| Security / abuse logs | For as long as reasonably necessary to detect, investigate, prevent, and respond to security threats, abuse, fraud, unlawful activity, policy violations, complaints, and legal requests. |
| Support tickets | For the duration necessary to handle the support request and maintain a record of the interaction, and thereafter as reasonably necessary for service quality, compliance, legal, and dispute-resolution purposes. |
| Marketing contacts | Until the recipient unsubscribes, objects, withdraws consent where applicable, or the data is no longer required for legitimate sales and marketing purposes. Suppression records may be retained to respect opt-out requests. |
| Cookie data | Session cookies are retained for the relevant browsing session. Persistent cookies are retained for the period stated in the applicable cookie notice, cookie banner, or cookie settings, unless deleted earlier by the user. |
| SDK consent / withdrawal records | For as long as reasonably necessary to evidence consent, withdrawal, participation status, partner compliance, network governance, legal compliance, and dispute resolution. |
| SDK connection / DAU records | For as long as reasonably necessary for network operation, partner reporting, DAU calculation, billing/payment reconciliation, abuse prevention, security, compliance, and audit purposes. |
| Backups | Backup copies are retained in accordance with Infatica’s backup and disaster-recovery procedures and are overwritten or deleted in the ordinary backup cycle, unless preservation is required for security, legal, compliance, or dispute-resolution purposes. |
13. Security
We use technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Measures may include role-based access controls, least privilege, encryption in transit and at rest, network security controls, monitoring, vulnerability management, incident response procedures, backup controls, and vendor management. Exact controls should align with the Trust Center security controls section and security documentation available under NDA where appropriate.
14. Your rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, opt-out of certain processing, or other privacy rights. You may submit a request through the Data Subject Rights Request page/form or contact us using the details below.
We may need to verify your identity before responding. We may deny or limit a request where permitted by law, including where retention is required for legal, security, compliance, fraud prevention, billing, tax, accounting, dispute, or network-integrity purposes.
15. California and US state privacy rights
Where California or other US state privacy laws apply, you may have rights to know, access, delete, correct, opt out of certain disclosures or sharing, limit use of sensitive personal information, or not be discriminated against for exercising privacy rights.
| US privacy item | |
|---|---|
| Sale / share status | Infatica does not sell Personal Data for monetary consideration. Infatica may disclose Personal Data to service providers, contractors, vendors, and business partners for the purposes described in this Privacy Policy. Where any disclosure is treated as a “sale” or “sharing” under applicable US privacy laws, individuals may exercise applicable opt-out rights through Infatica’s privacy request process or other available privacy controls. |
| Targeted advertising / cross-context behavior advertising | Infatica may use analytics, measurement, and advertising technologies where permitted by applicable law. Where such technologies involve targeted advertising or cross-context behavioral advertising under applicable US privacy laws, individuals may opt out through applicable privacy controls, cookie settings, opt-out preference signals, or Infatica’s privacy request process. |
| Sensitive personal information | Infatica does not intentionally use or disclose sensitive personal information for purposes that would require a separate right to limit under California law, unless disclosed otherwise at or before collection. Where applicable law provides a right to limit the use or disclosure of sensitive personal information, Infatica will honor such requests as required by law. |
| Authorized agent process | Where permitted by applicable law, an individual may authorize an agent to submit a privacy request on their behalf. Infatica may require proof of authorization and may also require the individual to verify their identity directly or confirm that they authorized the agent to act on their behalf. |
| Do Not Sell or Share link | If Infatica determines that any processing activity constitutes a “sale” or “sharing” under applicable US privacy laws, Infatica will provide an appropriate “Do Not Sell or Share My Personal Information” mechanism or equivalent privacy control as required by law. |
16. Singapore PDPA rights
Where Singapore PDPA applies, individuals may have access and correction rights and may be able to withdraw consent subject to applicable exceptions and legal limitations.
17. Children
The Services are not directed to children, and Infatica does not knowingly collect children’s Personal Data through the Services. Customers, resellers, partners, and SDK partners must not use the Services in a way that bypasses age-verification, age-assurance, parental-control, child-safety, minor-protection, app-store, or platform safety mechanisms. Any suspected child-safety concern should be reported immediately.
18. Marketing communications
We may send service, account, security, legal, and transactional communications. We may also send marketing communications where permitted by law. You may opt out of marketing emails by using the unsubscribe link or contacting us. You cannot opt out of non-marketing service, security, legal, or account communications where they are necessary for the relationship or required by law.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on the Trust Center or website and will indicate the effective date. Where required by law, we will provide additional notice or obtain consent for material changes.
20. Contact us
| Purpose | Contact |
|---|---|
| Privacy requests | sales@infatica.io or the applicable privacy request form |
| Compliance documentation | sales@infatica.io or the applicable Trust Center request process |
| Security reports | sales@infatica.io or the applicable Trust Center request process |
| SDK / platform inquiries | sales@infatica.io or the applicable SDK / Trust Center request process |
| Postal address | Use the postal address of the applicable Infatica contracting entity. Current public site lists:
|