Ethically-sourced proxies: Learn More External link arrow

Privacy Policy

Last updated on 14.01.2026

1. Introduction

This Privacy Policy explains how the applicable Infatica entity collects, uses, discloses, stores, and protects Personal Data in connection with Infatica websites, Trust Center, customer accounts, reseller and partner relationships, dashboards, APIs, proxy and network services, SDK-enabled peer network operations, support, compliance, security, marketing, and related services.

This policy is intended for Trust Center publication. It should be aligned with the Data Protection Addendum, Acceptable Use Policy, SDK & Peer Network Transparency document, customer/reseller agreements, partner agreements, cookie banner, and operational privacy processes.

2. Who we are

The controller responsible for your Personal Data is the Infatica entity that provides or administers the relevant service or relationship. Depending on the applicable agreement or service, this may include INFATICA LTD, Infatica Pte. Ltd., or another Infatica entity identified in the applicable agreement or notice.

Entity / item
INFATICA LTD addressUnit A, 82 James Carter Road, Mildenhall, Suffolk, IP28 7DE, United Kingdom
INFATICA PTE. LTD address195 Pearl’s Hill Terrace, #03-62A, 168976, Singapore
EU / UK representative, if applicable
Data protection contact
Trust Center contact

3. Scope

This Privacy Policy applies to Personal Data processed in connection with:

  • Infatica websites, Trust Center, forms, and marketing pages
  • customer, reseller, prospect, vendor, and partner relationships
  • residential proxies, mobile proxies, datacenter proxies, ISP/static proxies, dashboards, APIs, credentials, support, and related services
  • KYC/KYB, sanctions screening, use-case review, compliance review, abuse prevention, and security monitoring
  • SDK-enabled peer network governance, consent, withdrawal, peer participation, partner compliance, and network integrity
  • communications, support tickets, procurement requests, security questionnaires, and legal notices

4. Personal Data we collect

CategoryExamples
Account and business contact dataName, business email, phone, company, role, country, account identifiers, login details, dashboard user data.
Customer / reseller / partner relationship dataAgreement details, order or plan details, reseller details, end-client information where provided, use-case information, support tier, relationship history.
Billing and payment dataInvoices, payment status, payment method metadata, transaction identifiers, tax information, accounting records. Payment processors may process card or payment details directly.
KYC/KYB and compliance dataBusiness identity information, beneficial ownership information, sanctions screening results, verification status, compliance review notes, restricted-target requests.
Service and usage dataDashboard activity, API logs, authentication events, credentials or token identifiers, service metadata, proxy/session metadata, traffic pattern metadata, bandwidth or usage records.
Support and communications dataSupport tickets, email messages, chat messages, call notes, attachments, troubleshooting materials, feedback, procurement requests.
Website and marketing dataCookie identifiers, IP address, device/browser information, pages viewed, referrers, campaign parameters, form submissions, email engagement.
Security and abuse-prevention dataIP addresses, access logs, domain-category information, blacklist/whitelist requests, abuse reports, security events, fraud signals, investigation notes.
SDK / peer network dataIP address, limited device/network metadata, connection metadata, country/region inference, consent status, withdrawal status, partner application identifier, DAU/activity records, traffic volume metadata, abuse/security logs.
Legal and rights-request dataIdentity verification information, request details, correspondence, records of access/deletion/correction/objection requests, legal notices, complaints.

5. Sources of Personal Data

We may collect Personal Data directly from you, from your company or organization, from customers, resellers, partners, authorized users, end clients where provided by Customer or Reseller, service providers, payment processors, KYC/KYB providers, analytics tools, security tools, public sources, and through your use of the Services.

For SDK / peer network data, information may be collected through approved partner applications that integrate the Infatica SDK and present the required notice and consent flow.

6. How we use Personal Data

PurposeExamples
Service access and account administrationCreate accounts, authenticate users, manage dashboard/API access, provide services, maintain credentials, communicate service notices.
Billing and financial administrationProcess payments, invoices, tax, accounting, refunds, chargebacks, and transaction records.
Support and troubleshootingRespond to tickets, diagnose technical problems, provide onboarding assistance, improve support quality.
Fraud, abuse, and security preventionDetect and prevent misuse, technical circumvention, spam, malware, credential abuse, account takeover, unauthorized scraping, child-safety-sensitive abuse, and other prohibited activities.
KYC/KYB and compliance reviewVerify customers, screen against sanctions, review business purpose, assess restricted targets, maintain compliance records.
Network integrity and service operationsMonitor reliability, capacity, routing, usage, quality, infrastructure performance, proxy pools, and network safety.
SDK / peer network governanceManage consent, withdrawal, peer eligibility, partner compliance, DAU calculations, network integrity, traffic routing governance, and abuse prevention.
Marketing and business developmentSend permitted marketing communications, manage prospect relationships, analyze campaign performance, handle opt-outs.
Legal and contractual purposesEnforce agreements, policies, legal rights, respond to legal requests, establish or defend legal claims, comply with legal obligations.

7. Legal bases under GDPR / UK GDPR

Where GDPR or UK GDPR applies, we rely on one or more of the following legal bases depending on the context:

Legal basisExamples
Contract necessityProviding accounts, services, support, billing, and relationship administration.
Legitimate interestsSecurity, fraud prevention, abuse prevention, compliance review, network integrity, service improvement, business relationship management, legal claims.
ConsentOptional cookies, marketing where required, SDK / peer network participation where consent is required.
Legal obligationTax, accounting, sanctions, compliance, law-enforcement response, regulatory obligations.
Vital interests / public interestNot expected in normal operations; use only where legally applicable.

8. Cookies and tracking technologies

We use cookies and similar technologies on our websites, dashboard, Trust Center, and online services. Cookies may be set by Infatica or by third-party service providers acting on our behalf.

Cookie categoryPurposeStatus
Strictly necessary cookiesAuthentication, session management, security, load balancing, form functionality, user preferences required for the site or service.Always active. These cookies are required for the website, dashboard, Trust Center, or online service to function and cannot be disabled through Infatica’s cookie controls.
Functional cookiesRemember choices, improve usability, support chat or customer-service functionality.Optional where not strictly necessary. These cookies may be enabled, disabled, or managed through available cookie settings or browser controls.
Analytics cookiesUnderstand website usage, pages viewed, traffic sources, performance, and product interest.Optional. These cookies are used only where permitted by law and, where required, only after the user has provided consent.
Marketing cookiesMeasure campaigns, personalize communications, manage advertising audiences, where used.Optional. These cookies are used only where permitted by law and, where required, only after the user has provided consent.

You can control cookies through your browser settings and, where available, through our cookie banner or consent-management tool. Disabling certain cookies may affect site functionality or account access.

9. SDK / peer network privacy

Where an approved partner application integrates the Infatica SDK, users may be offered the option to participate in the Infatica peer network. Participation must be disclosed and voluntary, and users must be able to withdraw through the approved mechanism.

The SDK / peer network may process IP addresses and limited technical, connection, consent, withdrawal, partner application, country/region, DAU, activity, bandwidth, security, and abuse-prevention data.

The SDK is not intended to collect browsing history, application content, precise GPS location, advertising identifiers, IMEI, device fingerprints, messages, contacts, photos, files, passwords, payment credentials, or special category data.

SDK participation and withdrawal details are described in the SDK & Peer Network Transparency / Consent and Opt-Out document.

10. How we share Personal Data

We may share Personal Data with the following categories of recipients where necessary for the purposes described in this Privacy Policy:

  • Infatica group entities and authorized personnel
  • hosting, infrastructure, CDN, WAF, DDoS, logging, monitoring, and security providers
  • payment processors, banks, tax/accounting providers, and billing tools
  • KYC/KYB, sanctions screening, fraud prevention, and compliance providers
  • CRM, sales, support, email, communications, analytics, and marketing providers
  • professional advisers, auditors, insurers, lawyers, and consultants
  • partners and resellers where necessary to administer a partner or reseller relationship
  • public authorities, regulators, courts, law enforcement, and third parties where required by law or necessary to protect rights, safety, security, and compliance
  • successors or acquirers in connection with a merger, acquisition, financing, restructuring, or sale of assets

11. International transfers

We may process and transfer Personal Data internationally. Where required by applicable law, we use appropriate transfer mechanisms such as adequacy decisions, standard contractual clauses, UK transfer addenda or IDTAs, contractual safeguards, or other lawful mechanisms.

Transfer area
EU/EEAWhere Personal Data is transferred from the EU/EEA to a country or recipient not covered by an applicable adequacy decision, Infatica relies on appropriate transfer mechanisms, including the European Commission’s Standard Contractual Clauses and, where required, supplementary contractual, technical, and organizational safeguards.
United KingdomWhere Personal Data is transferred from the United Kingdom in a restricted transfer, Infatica relies on applicable UK transfer mechanisms, including the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, adequacy regulations, and supplementary safeguards where required.
SwitzerlandWhere Personal Data is transferred from Switzerland to a country or recipient not recognized as providing adequate protection, Infatica relies on appropriate transfer mechanisms, including standard contractual clauses with Swiss-specific adaptations and supplementary safeguards where required.
Singapore / APACWhere Personal Data is transferred from Singapore or other APAC jurisdictions, Infatica uses contractual, technical, and organizational safeguards designed to protect Personal Data in accordance with applicable local data protection laws, including vendor contracts, intra-group safeguards, and recognized model clauses where appropriate.
United StatesTransfers to the United States may rely on applicable adequacy frameworks where the recipient is eligible and certified, including the EU-U.S. Data Privacy Framework for EU/EEA transfers to participating U.S. companies. Where no such framework applies, Infatica relies on Standard Contractual Clauses, UK transfer mechanisms, Swiss-specific transfer terms, contractual safeguards, and supplementary technical and organizational measures where required.

12. Retention

We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. Retention depends on the type of data, relationship, service, legal obligations, security needs, dispute risk, and operational requirements.

Data categoryRetention
Account dataFor the duration of the account or customer relationship, and thereafter for as long as reasonably necessary for legal, contractual, compliance, security, audit, and dispute-resolution purposes.
Billing / tax / accounting recordsFor the period required by applicable tax, accounting, and company law. For UK accounting records, this is generally at least 6 years from the end of the relevant financial year; for Singapore tax records, this is generally at least 5 years from the relevant Year of Assessment.
KYC/KYB and compliance recordsFor the duration of the customer relationship and thereafter for as long as reasonably necessary for compliance, sanctions, fraud-prevention, abuse-prevention, audit, legal, and dispute-resolution purposes.
Dashboard / API logsFor as long as reasonably necessary to provide, secure, monitor, troubleshoot, and improve the Services, and to investigate misuse, security incidents, or policy violations.
Proxy/session metadataFor as long as reasonably necessary for service operation, usage calculation, troubleshooting, abuse prevention, fraud prevention, security, compliance, and dispute-resolution purposes.
Security / abuse logsFor as long as reasonably necessary to detect, investigate, prevent, and respond to security threats, abuse, fraud, unlawful activity, policy violations, complaints, and legal requests.
Support ticketsFor the duration necessary to handle the support request and maintain a record of the interaction, and thereafter as reasonably necessary for service quality, compliance, legal, and dispute-resolution purposes.
Marketing contactsUntil the recipient unsubscribes, objects, withdraws consent where applicable, or the data is no longer required for legitimate sales and marketing purposes. Suppression records may be retained to respect opt-out requests.
Cookie dataSession cookies are retained for the relevant browsing session. Persistent cookies are retained for the period stated in the applicable cookie notice, cookie banner, or cookie settings, unless deleted earlier by the user.
SDK consent / withdrawal recordsFor as long as reasonably necessary to evidence consent, withdrawal, participation status, partner compliance, network governance, legal compliance, and dispute resolution.
SDK connection / DAU recordsFor as long as reasonably necessary for network operation, partner reporting, DAU calculation, billing/payment reconciliation, abuse prevention, security, compliance, and audit purposes.
BackupsBackup copies are retained in accordance with Infatica’s backup and disaster-recovery procedures and are overwritten or deleted in the ordinary backup cycle, unless preservation is required for security, legal, compliance, or dispute-resolution purposes.

13. Security

We use technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. Measures may include role-based access controls, least privilege, encryption in transit and at rest, network security controls, monitoring, vulnerability management, incident response procedures, backup controls, and vendor management. Exact controls should align with the Trust Center security controls section and security documentation available under NDA where appropriate.

14. Your rights

Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, opt-out of certain processing, or other privacy rights. You may submit a request through the Data Subject Rights Request page/form or contact us using the details below.

We may need to verify your identity before responding. We may deny or limit a request where permitted by law, including where retention is required for legal, security, compliance, fraud prevention, billing, tax, accounting, dispute, or network-integrity purposes.

15. California and US state privacy rights

Where California or other US state privacy laws apply, you may have rights to know, access, delete, correct, opt out of certain disclosures or sharing, limit use of sensitive personal information, or not be discriminated against for exercising privacy rights.

US privacy item
Sale / share statusInfatica does not sell Personal Data for monetary consideration. Infatica may disclose Personal Data to service providers, contractors, vendors, and business partners for the purposes described in this Privacy Policy. Where any disclosure is treated as a “sale” or “sharing” under applicable US privacy laws, individuals may exercise applicable opt-out rights through Infatica’s privacy request process or other available privacy controls.
Targeted advertising / cross-context behavior advertisingInfatica may use analytics, measurement, and advertising technologies where permitted by applicable law. Where such technologies involve targeted advertising or cross-context behavioral advertising under applicable US privacy laws, individuals may opt out through applicable privacy controls, cookie settings, opt-out preference signals, or Infatica’s privacy request process.
Sensitive personal informationInfatica does not intentionally use or disclose sensitive personal information for purposes that would require a separate right to limit under California law, unless disclosed otherwise at or before collection. Where applicable law provides a right to limit the use or disclosure of sensitive personal information, Infatica will honor such requests as required by law.
Authorized agent processWhere permitted by applicable law, an individual may authorize an agent to submit a privacy request on their behalf. Infatica may require proof of authorization and may also require the individual to verify their identity directly or confirm that they authorized the agent to act on their behalf.
Do Not Sell or Share linkIf Infatica determines that any processing activity constitutes a “sale” or “sharing” under applicable US privacy laws, Infatica will provide an appropriate “Do Not Sell or Share My Personal Information” mechanism or equivalent privacy control as required by law.

16. Singapore PDPA rights

Where Singapore PDPA applies, individuals may have access and correction rights and may be able to withdraw consent subject to applicable exceptions and legal limitations.

17. Children

The Services are not directed to children, and Infatica does not knowingly collect children’s Personal Data through the Services. Customers, resellers, partners, and SDK partners must not use the Services in a way that bypasses age-verification, age-assurance, parental-control, child-safety, minor-protection, app-store, or platform safety mechanisms. Any suspected child-safety concern should be reported immediately.

18. Marketing communications

We may send service, account, security, legal, and transactional communications. We may also send marketing communications where permitted by law. You may opt out of marketing emails by using the unsubscribe link or contacting us. You cannot opt out of non-marketing service, security, legal, or account communications where they are necessary for the relationship or required by law.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on the Trust Center or website and will indicate the effective date. Where required by law, we will provide additional notice or obtain consent for material changes.

20. Contact us

PurposeContact
Privacy requestssales@infatica.io or the applicable privacy request form
Compliance documentationsales@infatica.io or the applicable Trust Center request process
Security reportssales@infatica.io or the applicable Trust Center request process
SDK / platform inquiriessales@infatica.io or the applicable SDK / Trust Center request process
Postal address

Use the postal address of the applicable Infatica contracting entity. Current public site lists:

  • INFATICA LTD
    Unit A, 82 James Carter Road
    Mildenhall, Suffolk, IP28 7DE
    United Kingdom
  • INFATICA PTE. LTD.
    195 Pearl’s Hill Terrace, #03-62A
    168976
    Singapore