LEGAL DOCUMENT

Privacy Policy

Effective date: July 5, 2026

VPNzo ("Service") is operated by Taprise Ltd., a company registered in the United Kingdom. This Privacy Policy explains what personal data we collect, the legal basis on which we process it, how long we retain it, where it is transferred, and your rights as a data subject.

The list of partners you may find at Annex A

This Policy should be read together with our Terms of Use, which govern the legal relationship between you and Taprise Ltd., including the applicable governing law and jurisdiction.

By installing or using VPNzo, you acknowledge that you have read and understood this Policy.

1. Who We Are and How to Reach Us

Data Controller:

UK Controller: Taprise Ltd. acts as data controller for UK residents under the UK GDPR and the Data Protection Act 2018.

2. What Data We Collect — Lawful Basis and Retention

We collect only the minimum data necessary to operate the Service. For each category we specify what is collected, why, the legal basis under GDPR Art. 6, and how long we keep it. A record of our legitimate interest assessments for processing under Art. 6(1)(f) is available on request.

2.1 Account and Authentication Data

What: Email address (if email registration); name or display identifier from Google or Apple Sign-In; authentication token (we never receive your password).

Why: Creating and maintaining your account; authenticating your identity on return.

Lawful basis: Performance of a contract — Art. 6(1)(b). This data is necessary to provide the Service.

Retention: Duration of active account + 30 days after account deletion request (for dispute resolution), then permanently deleted.

2.2 Subscription and Billing Data

What: Subscription status, plan, and billing period; purchase date and renewal date; payment method type (e.g. "card ending 4242") — we do not store full card numbers.

Why: Delivering the paid Service; managing the subscription lifecycle; resolving billing disputes.

Lawful basis: Performance of a contract — Art. 6(1)(b).

Processors:

  • Adapty (USA) — subscription management and analytics; transferred under the EU Standard Contractual Clauses (SCCs) and, for UK personal data, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable
  • Stripe (USA/EU) — payment processing for web purchases; transferred under the EU SCCs and UK IDTA/Addendum as applicable; Stripe's US entity is certified under the EU-US Data Privacy Framework
  • CentroBill (EU) — payment processing for web purchases; EU-based, no international transfer

Retention: 7 years from transaction date, in accordance with UK and EU statutory accounting and tax record-keeping obligations.

2.3 Support and Communication Data

What: Email address; content of support messages and attachments; communication history with our support team.

Why: Responding to support requests; resolving technical issues; maintaining service quality.

Lawful basis: Legitimate interests — Art. 6(1)(f). We have a legitimate interest in providing customer support. This interest does not override your rights given the limited nature of the data and the reasonable expectation that support interactions are retained.

Processor:

  • Freshdesk by Freshworks Inc. (USA) — transferred under the EU SCCs and, for UK personal data, the UK IDTA or UK Addendum, as applicable

Retention: 2 years from the date of the last interaction, then deleted.

2.4 Device and Technical Data

What: Device type and model; operating system and application version; language and regional settings; crash reports and diagnostic logs (anonymised where possible).

Why: Diagnosing technical issues; improving application stability; detecting abuse or fraud.

Lawful basis: Legitimate interests — Art. 6(1)(f). This data is technical in nature and does not identify you personally.

Processors:

  • Adapty (USA) — analytics and crash reporting; transferred under the EU SCCs and UK IDTA/Addendum, as applicable
  • Additional infrastructure providers (details available on request)

Retention: 90 days from collection, then deleted or fully anonymised.

2.5 VPN Session Metadata

What: Session start and end timestamps; server region selected; connection status and performance indicators (e.g. latency).

Why: Operating the VPN tunnel; diagnosing connection failures; capacity planning.

Lawful basis: Performance of a contract — Art. 6(1)(b). These signals are necessary to deliver the VPN connection you requested.

What we do NOT collect:

  • Browsing history or DNS queries
  • Traffic content, messages, or files transmitted through the VPN
  • Destination IP addresses
  • Any data that would allow us to identify which websites or services you visit

Retention: 30 days from session end, then deleted.

2.6 Payment Analytics Data

What: Subscription conversion events (trial started, subscription activated, cancelled); revenue metrics at cohort level; churn and retention signals.

Why: Understanding subscription performance; optimising pricing and trial mechanics; financial planning.

Lawful basis: Legitimate interests — Art. 6(1)(f). Analytics data is processed at an aggregated or pseudonymous level.

Processors:

  • Adapty (USA) — transferred under the EU SCCs and UK IDTA/Addendum, as applicable
  • Merchantro — jurisdiction to be confirmed; data processing agreement in place

Retention: Aggregated analytics: 3 years. Individual-level pseudonymous events: 12 months.

3. International Data Transfers

Some of our processors are located outside the UK and EEA. For transfers of personal data originating in the EEA, we rely on the EU Standard Contractual Clauses (SCCs). For transfers of personal data originating in the UK, EU SCCs alone do not satisfy UK GDPR requirements post-Brexit, so we additionally rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, as applicable.

  • Adapty — United States — EU SCCs; UK IDTA / UK Addendum for UK data
  • Freshdesk (Freshworks) — United States — EU SCCs; UK IDTA / UK Addendum for UK data
  • Stripe — United States / EU — EU SCCs + EU-US Data Privacy Framework; UK IDTA / UK Addendum for UK data
  • CentroBill — European Union — No transfer — EU-based
  • Merchantro — To be confirmed — Not yet confirmed — see Section 2.6

Copies of applicable SCCs, the UK IDTA, and the UK Addendum are available on request: support@vpnzo.app.

4. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

We share data only in the following circumstances:

4.1 With processors listed in Section 2

Solely for the purposes described, under binding data processing agreements compliant with Art. 28 GDPR.

4.2 For legal compliance

When required by applicable law, court order, or a lawful request from a competent authority. We will notify you of such requests where legally permitted.

4.3 To protect our rights

When necessary to prevent fraud, enforce our Terms of Use, or protect the safety of users or the public.

4.4 Business transfers

In the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity. We will provide at least 30 days' advance notice before your data becomes subject to a materially different privacy policy.

5. Your Rights

EEA and UK residents (GDPR / UK GDPR)

  • Access (Art. 15) — Receive a copy of the personal data we hold about you
  • Rectification (Art. 16) — Request correction of inaccurate or incomplete data
  • Erasure (Art. 17) — Request deletion of your personal data
  • Restriction (Art. 18) — Request that we limit processing of your data
  • Portability (Art. 20) — Receive your data in a structured, machine-readable format
  • Objection (Art. 21) — Object to processing based on legitimate interests
  • Withdraw consent (Art. 7(3)) — Where processing relies on consent, withdraw it at any time without affecting prior lawful processing

Note: certain rights, such as erasure, may be limited where we are required to retain data to comply with a legal obligation — for example, the statutory accounting and tax retention period described in Section 2.2.

Automated decision-making: we do not carry out solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning you.

To exercise any right, contact us at support@vpnzo.app. We will respond within 30 days. For complex requests, we may extend this by a further 60 days with written notice.

You also have the right to lodge a complaint with your national supervisory authority, and the right to an effective judicial remedy under Article 79 GDPR:

California residents (CCPA/CPRA)

You have the right to know what personal information we collect, to request deletion, to opt out of the sale or sharing of your personal information (we do not sell or share personal information, including for cross-context behavioural advertising), and to non-discrimination for exercising these rights. Similar rights may be available to you under other applicable US state privacy laws. Submit requests to support@vpnzo.app.

6. Data Security

We apply appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Access controls and least-privilege principles
  • Regular security reviews

No internet-based system is completely secure. In the event of a personal data breach posing a high risk to your rights and freedoms, we will notify you without undue delay as required by applicable law. Where required, we will also notify the competent supervisory authority within 72 hours of becoming aware of a qualifying breach, in accordance with Article 33 GDPR.

7. Children and Minors

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a person under 18 has submitted data through the Service, contact us at support@vpnzo.app and we will delete it promptly.

8. Cookies and Tracking

The VPNzo mobile application does not use cookies. Our website (vpnzo.app) may use essential cookies required for site functionality only. We do not use advertising or behavioural tracking cookies. If this changes, we will update this Policy and obtain consent where required by applicable law.

9. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated at least 14 days before taking effect via in-app notification, website notice, or email where we hold your address. The "Effective date" at the top reflects the most recent revision.

Continued use of the Service after an updated Policy takes effect constitutes acceptance, to the extent permitted by applicable law.

10. Contact

UK supervisory authority:

  • Information Commissioner's Office — ico.org.uk | 0303 123 1113

We respond to all privacy inquiries within 30 days.