This policy covers the proxynomad.com website and the ProxyNomad service. The controller is ProxyNomad, reachable through the contact form. We are based in the EU and our infrastructure for the data described here is in the EU. The short version: we collect little, we look at less, and none of it is sold or used for advertising.
1. Visiting this website
- No cookies, no analytics. This site sets no cookies, runs no analytics, loads nothing from third-party domains, and does not fingerprint you. Fonts, styles and scripts are served from our own server. Details in the cookie policy.
- Server logs. Our web server records standard access logs: IP address, requested URL, timestamp, user agent, referrer. We use them for security and capacity, and they are deleted after 30 days. Legal basis: legitimate interest in operating a secure service.
2. The contact form
What you submit, name, email, company if you give one, topic, volume estimate, call windows, and your message, is stored on our EU servers together with your IP address and a timestamp, and used to answer you and to perform the customer vetting our acceptable use policy requires. Legal basis: pre-contractual steps at your request, and legitimate interest in vetting. We keep submissions for 24 months after the conversation ends, then delete them. They are not used for marketing lists and are never shared for advertising.
3. Customer accounts
Account holders' identification and billing data, name, company details, billing address, VAT number, payment records, invoices, are processed to provide the service and to meet tax and accounting law. Legal basis: contract and legal obligation. Retention follows the statutory accounting periods that apply to us.
4. Using the proxy service
This is the part to read closely, because it is where a proxy provider can quietly become a surveillance product. Ours works like this:
- We do not inspect content. The gateway tunnels your connections. TLS is end to end between your client and the target; we cannot read or modify what is inside, and we do not try to read what is not encrypted either.
- We log connection metadata. Per connection: timestamp, your account, bytes in and out, destination host and port, exit assignment. Purpose: billing, capacity, and abuse enforcement. Retention: 90 days, then deleted. Legal basis: contract and legitimate interest in keeping the network lawful.
- Exit supply. Residential and mobile exits belong to people who opted in through partner applications and are compensated. Their traffic-sharing relationship is governed by those applications' own terms; what we receive about them is what routing requires, not their browsing.
5. Sharing
We share personal data with: infrastructure providers hosting our EU systems, under processing agreements; payment and invoicing providers, to the extent a transaction requires; and public authorities, where valid legal process compels it, in which case we review scope and push back on overbreadth before complying. There are no analytics partners, no data brokers, and no advertising recipients, because there is no advertising.
6. Your rights
Under the GDPR you can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Send requests through the contact form; we answer within a month. If you believe we handle your data unlawfully, you can complain to your local supervisory authority or to the Italian Garante per la protezione dei dati personali.
7. Changes
Material changes to this policy are announced to account holders by email before they take effect, and the date at the top always tells you which version you are reading.