Legal · Privacy Policy

Privacy Policy

This policy explains what we collect, what we deliberately do not collect, how long we keep things, and what you can demand from us. Effective date: [EFFECTIVE DATE].

内部说明(中文,发布前删除本块)

这是给海外用户看的正式隐私政策正文(英文)。它不是法律意见——你如果在 EEA / 英国 / 加州 有真实用户量,上线前请让当地律师过一遍,尤其是第 6 节的跨境传输和第 9 节的法域特定条款。

发布前必须替换的占位符: [COMPANY LEGAL NAME](营业执照上的主体名)、[JURISDICTION](注册法域)、 [DOMAIN]、[EFFECTIVE DATE]、第 11 节的联系邮箱。 另外第 4 节的第三方清单必须换成你实际在用的服务商——写错比不写更糟。

最容易翻车的一点是第 2 节的"无日志"承诺。别写"我们不记录任何东西"——你至少要有账号和计费记录。 如实写清楚记录什么、不记录什么。夸大隐私承诺在美英欧都属于可被处罚的欺骗性宣传。

01

Who we are

[COMPANY LEGAL NAME] ("Aegis VPN", "we", "us"), a company registered in [JURISDICTION], operates the Aegis VPN service and the website at [DOMAIN]. For the purposes of the UK and EU General Data Protection Regulation, we are the data controller for the personal data described here.

02

The core promise: what we do not log

The point of a VPN is that your traffic is none of our business. Our systems are built so that the following are never recorded in a way that can be tied back to you:

What we genuinely cannot avoid processing. To run a service we must keep an account (email, subscription status, credentials) and billing records. We also keep aggregate, non-identifying metrics: total concurrent sessions per server, total bytes transferred per server, and per-plan aggregate usage. These numbers cannot be traced to an individual user, and we do not hold the data that would let anyone — including us — reconstruct who did what.

If a server is located in a jurisdiction whose law compels retention, that is disclosed on our website and in the app before you connect. We do not offer servers in restricted jurisdictions without telling you what that means for your data.

03

What we do collect

DataWhyLegal basis (EEA / UK)Retention
Account data
Email, hashed password, account ID
Create and secure your account, deliver the service, send service notices Performance of a contract Life of the account + 30 days
Subscription data
Plan, status, renewal date, country of payment
Provide paid features, handle renewals and refunds Performance of a contract Life of the account + 30 days
Billing records
Transaction ID, amount, card brand and last 4 digits
Accounting, tax, chargeback defence Legal obligation; legitimate interests As tax law requires (commonly 7 years)
Support correspondence Answer your request, keep a record of what we told you Legitimate interests 24 months from last contact
Aggregate service metrics
Per-server load and throughput, no identifiers
Capacity planning, abuse prevention, status page Legitimate interests 90 days
Security and abuse logs
Failed sign-ins, rate-limit events
Protect accounts and the network from abuse Legitimate interests 90 days

We never receive your full card number. Card details go directly to our payment processor. We receive only the last four digits, the card brand, and whether the payment succeeded.

04

Who we share data with

We do not sell personal data. We do not share it for cross-context behavioural advertising. We use these processors:

ProcessorWhat they getPurpose
[PAYMENT PROCESSOR]Payment and billing identifiersTake payment, handle refunds
[EMAIL / SUPPORT PROVIDER]Email address, ticket contentSend service mail, run support
[CDN / HOSTING]IP address, request metadataServe the website, mitigate attacks
[ANALYTICS, IF ANY]Pseudonymous usage eventsUnderstand which pages fail to convert
Replace this table with your actual vendors before publishing. Naming a provider you do not use is a false statement; omitting one you do use is a worse one. If you use website analytics, say so here and in your cookie notice — silent analytics on a privacy product is the fastest way to lose trust.
05

Government and third-party requests

We respond only to legally valid requests from a court or authority with proper jurisdiction over us. Because of section 02, in most cases we have nothing to hand over beyond account and billing records. Where we are legally permitted to notify you, we will. Where we are not, we will still challenge overbroad requests.

可选(推荐):发布一份透明度报告,定期公开收到的请求数量与结果。对隐私类产品这是低成本、高信任的动作。

06

International transfers

We operate globally, so your data may be processed outside your country. Where we transfer personal data out of the EEA or the UK, we rely on Standard Contractual Clauses (or the UK equivalent) together with a transfer risk assessment and supplementary technical measures such as encryption in transit and at rest.

07

How we protect it

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority where the law requires it.

08

Your rights

Depending on where you live, you can ask us to:

Email privacy@[DOMAIN] and we will respond within 30 days. We may ask you to verify that you control the account before we act. Deleting your account ends your subscription; it does not entitle you to a refund beyond our refund policy, and we may retain billing records that tax law requires us to keep.

If you are in the EEA or the UK and you are unhappy with our response, you can complain to your local supervisory authority.

09

Region-specific terms

RegionWhat applies to you
EEA / UK GDPR / UK GDPR rights as listed in section 08. If we have no establishment in the EEA, we will appoint an Article 27 representative and name them here.
California CCPA / CPRA rights: know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of.
Brazil, Canada, and others Local privacy statutes give broadly equivalent access and deletion rights; use the same contact address and we will honour them.
10

Children

Aegis VPN is not for children. You must be at least 16 (or the age of digital consent in your country, if higher) to create an account. We do not knowingly collect data from children under 13. If you believe a child has given us data, contact us and we will delete it.

11

Changes, and how to reach us

If we change this policy in a way that materially affects you, we will email account holders at least 30 days before the change takes effect and update the effective date at the top. Minor clarifications take effect when posted.

Questions, requests, or complaints: privacy@[DOMAIN]. Postal address for formal notices: [REGISTERED ADDRESS]. Data protection contact: [DPO OR CONTACT NAME, if required].

Terms of Service · Refund Policy · Product site · Service status

本页为隐私政策模板 · 占位符与内部说明须处理后再发布 · 合规与风控规划见 运营规划台