Skip to content
Privacy

Privacy Policy

  • Version 2.7

This is a translation provided for convenience. The Russian version is the binding one.

Introduction

1.1. This Policy sets out how information about the Users of the Atlas Secure secure-connection service (the “Service”) is collected, processed, stored and protected.

1.2. The Service works on the principle of data minimisation: only what is indispensable for providing the service, accepting payment and protecting the Service from abuse is collected.

1.3. The Policy is an integral part of the Terms of Use. The terms “Account”, “Subscription”, “Access key”, “Traffic pack”, “Device” and “Balance” are used with the meanings given in the Agreement.

1.4. The User confirms their agreement with the Policy on registration. Where registration is through Telegram, starting the bot and beginning to use the Service counts as agreement. A User who does not agree with the Policy must stop using the Service.

1.5. The Policy applies on the website, in the account area, in the Service’s Telegram bot and when connecting to the Service’s infrastructure. It does not extend to third-party websites, client applications and payment services, which have their own data processing rules.

No logs of network activity are kept

2.1. The Service does not record, store or track:

  • the content of internet traffic and destination addresses;
  • information about the resources visited;
  • DNS queries and their resolution logs;
  • browsing history linked to a User.

2.2. The Service is technically unable to reconstruct a User’s browsing history and cannot provide it to anyone, because no such data exists — including in response to a mandatory request (clause 7.4).

2.3. This does not remove the processing of the operational and account data without which the service does not work. Sections 03 and 05 list it in full and without omissions: the state of the connection and the node it was made to; the volume of a Traffic pack used up; the address from which registration and sign-in were made; events in the Account.

What data the Service processes

3.1. Account credentials:

  • Email addressidentifying the Account, sign-in codes, service notices. Kept for as long as the Account exists.
  • Password, if the User has set one, and passkeyssigning in without a code. A password is stored only as an irreversible hash (bcrypt); signing in with a code from an email works without a password.
  • Telegram ID and usernameon registration through the bot or when claiming the bonus for linking.
  • Subscription term and plan, Device limit, Access key identifiersprovision of the service.
  • Referral code, the “inviter — invited” link, Balance operationsrunning the Referral programme.
  • The address from which registration was madeprotection against obtaining the trial period repeatedly through the same channel and against mass registration of Accounts.

3.2. Payment and operational data:

  • Payment metadata: transaction identifier, amount, date, status, payment method. Kept for the period set by law for financial documents.
  • Account event log: sign-in, issue and change of an Access key, payment, change of plan, blocking — with the date and the network address the action was taken from. Needed to resolve disputes and investigate fraud, kept for no longer than 12 months.
  • Support requests: the text of the correspondence and attachments — up to 2 years from the closure of the request.
  • Records of consents and of opting out of mailingsevidence that processing is lawful.
  • Information about breaches and blockingup to 3 years from the blocking, so that a blocked User does not register again.

3.3. The Service neither receives nor stores bank card details — they are processed by the payment operator.

3.4. The Service does not ask for a name, postal address, identity documents or phone number. The exception is verifying that a payment belongs to the User where fraud is suspected: in that case the Service may ask for confirmation, which is deleted after the check.

3.5. The User may use a separate email address created only for the Service.

3.7. Office pass request. By submitting the form on the “Contacts” page, a visitor provides their first and last name in Latin script, an email address, the date and purpose of the visit, the type of document they will show at the entrance and, optionally, their company and a contact. This information is passed to the management company of the business centre: without it no pass is issued. The legal basis is the visitor’s consent, given by a separate tick in the form. The Service neither asks for nor stores the document number: the document is checked at the desk on entry. The request is kept for no longer than 6 months from the date of the visit, after which it is deleted.

3.6. Job application. By submitting the form on the “Careers” page, a candidate provides their name, an email address, optionally a contact and a covering message, and a CV file. The basis for processing is the candidate’s consent, given by a separate tick in the form and withdrawn by writing to the support address. The data is used only to consider the application, is available to the staff making the hiring decision, and is kept for no longer than 6 months from the date of the application, after which it is deleted together with the file. A candidate is not a User of the Service, and an application does not create an Account.

Purposes and legal bases of processing

4.1. The Service processes data on the following bases:

  • Performance of the Agreementproviding the services, signing in to the Account, managing Subscriptions and Traffic packs, support, running the Referral programme, service notices.
  • Performance of the Agreement and legal requirementsprocessing payments, refunds, accounting.
  • Legitimate interest of the Servicepreventing fraud, abuse and breaches of the Agreement, protecting the infrastructure, defending the Service’s rights in disputes.
  • Separate voluntary consentnews and special offers.

4.2. Service notices are not advertising and are sent regardless of consent to mailings.

4.3. The Service sends news and special offers only with separate consent. Consent is not a condition of using the Service and can be withdrawn at any time: through the “Unsubscribe” link in every email or in the account area.

4.4. The Service does not sell data, does not use it for advertising profiling and does not pass it to third parties for their advertising.

4.5. The Service does not take decisions producing legal effects on the basis of automated processing, except for the technical protection measures under section 05. The User may appeal against such measures through support.

Connection data and protection against abuse

5.1. So that the connection works and the plan’s Device limit is observed, the Service’s infrastructure processes operational data about the connection:

  • the identifier of the Access key and of the Account;
  • the state of the connection and the node it was made to;
  • the network address the connection was established from, and the technical identifier of the Device if the client application sends it;
  • the time the session status last changed.

5.2. This data relates to the current and the last connection and does not add up to a browsing history: it cannot establish which resources the User opened. It contains no information about the content of traffic or about DNS queries.

5.3. For Traffic packs the Service keeps a counter of the volume used up per Access key: without it there is no way to show the remaining gigabytes and to stop service once they run out. The counter holds only the volume, with no information about where that volume went.

5.4. From the operational data the Service determines the number of Devices using one Access key at the same time. Where the limit is exceeded, a new connection may be rejected automatically.

5.5. If the system records signs of a breach of section 08 of the Terms of Use — simultaneous connections from many addresses, publication of an Access key in open sources, resale — a note of the breach is kept in the Account: its type, the date and the number of simultaneous connections.

5.6. To protect against unjustified chargebacks, the Service stores a flag of whether the Subscription was used during the paid period.

5.7. The Service monitors open sources — channels, chats, forums, repositories — for published Access keys. What is processed there is the published key itself and the address of the publication, not data about the User’s network activity.

Storage and protection

6.1. Account credentials are held on protected servers with encryption in transit and at rest. Access to them is given only to staff who need it for their work, on confidential terms.

6.2. Passwords are stored solely as irreversible hashes. The account session is a random token in a cookie with the httpOnly, Secure and SameSite=Lax flags; only its hash is stored on the server. The session is revoked on sign-out and on a password change.

6.3. The credentials database is separated from the servers that carry Users’ connections. The connection servers store no credentials and no payment data.

6.4. Retention periods are set out in section 03. Once the period expires, the data is deleted or anonymised. Backups are overwritten within 30 days.

6.5. After an Account is deleted, the Service may keep the minimum of data required by law or needed to protect against abuse: payment metadata, a record of blocking and a hash of the identifier, so that the trial period and bonuses are not obtained again.

6.6. The Service’s servers are located in different jurisdictions. By using the Service, the User agrees that their data may be processed outside their country of residence.

6.7. No method of storing and transmitting data gives an absolute guarantee. In the event of an incident affecting User data, the Service will notify the affected Users and the competent authority within the periods set by applicable law.

6.8. The User is responsible for keeping their password, Access keys and access to their email and Telegram account safe.

Disclosure to third parties

7.1. The Service does not sell, rent out or pass information to third parties for commercial purposes.

7.2. Disclosure is possible only to the following recipients and only to the extent stated:

  • Payment operatorthe amount, the order identifier, the email address for the receipt: processing the transaction, refunds, payment disputes.
  • Email delivery servicethe email address and the text of the message: delivery of sign-in codes and notices.
  • Telegramthe messages the User sends to the bot themselves: operation of the bot and of support.
  • Hosting providers and data centreshosting the infrastructure.
  • Competent authoritiesonly the data the Service actually holds, and only on a mandatory request.
  • The Service’s successorAccount data upon reorganisation or transfer of the business, on terms no worse than this Policy.

7.3. The Service answers only requests that are mandatory for it under the law of the jurisdiction of its registration and that are made in the established form. Unofficial and improperly made requests are rejected.

7.4. Because no logs of network activity are kept (section 02), the Service cannot provide information about the resources visited, the content of traffic or DNS queries — even on a mandatory request. Only the data listed in sections 03 and 05 can be provided.

7.5. The Service may disclose Account data to the payment operator and to competent authorities where this is necessary to protect against fraud, to contest an unjustified chargeback or to defend the Service’s rights in a dispute with the User.

7.6. Third-party client applications, app stores and payment services process data under their own rules. The Service is not responsible for their actions.

Cookies

8.1. The Service uses functional cookies only: the session cookie (signing in to the account area) and operational ones needed to protect forms and confirm an email address. Signing in is impossible without them, so separate consent for them is not requested.

8.2. Analytics, advertising and cross-site tracking cookies, third-party trackers and pixels are not used.

The User’s rights

9.1. The User may at any time:

  • request a copy of all data connected with the Account;
  • receive the data in a machine-readable format;
  • correct inaccurate data;
  • demand deletion of the Account and connected data;
  • withdraw consent to the processing of data;
  • opt out of news and offers — through the link in an email or in the account area;
  • object to processing based on the Service’s legitimate interest;
  • lodge a complaint with the competent data protection authority.

9.2. The request is sent from the email address or Telegram account linked to the Account. The Service may ask for confirmation that the Account belongs to the requester and reject the request where this is not confirmed.

9.3. The response time is up to 30 days. The first request for a copy of the data is free; for manifestly unfounded or repetitive requests the Service may charge a reasonable fee or refuse.

9.4. Deleting the Account and withdrawing consent to processing make it impossible to provide the services. The Subscription then terminates, money for the unused period is not refunded, and the Balance, bonuses and the remaining volume of Traffic packs are cancelled.

9.5. The Service may refuse deletion or postpone it for the data it is obliged to keep by law, or which is needed to resolve a dispute, contest a payment or prevent a blocked infringer from registering again (clause 6.5).

Age

The Service is intended for persons aged 18 and over. The Service does not knowingly collect data about minors; a minor’s Account is deleted once identified. The 3 days trial period and payment are likewise available only to adults.

Changes to the Policy

11.1. The Service may amend the Policy. A new version is published in the Service stating its version number and the date it takes effect.

11.2. The Service gives notice of material changes — new categories of data, purposes or recipients — by email or in Telegram at least 7 days before they take effect. Continued use of the Service after that date means agreement with the new version.

Contacts

The data controller is Atlas Secure, part of the QoDev group, Hong Kong Special Administrative Region of the PRC. For questions about data processing and the exercise of rights: support@atlassecure.uk and the Telegram bot @atlas_suppbot.