Privacy Policy
MELTRIX SL
Version: 2.0 (GDPR‑Compliant)
Last updated: 18 June 2026 | Effective as of: 18 June 2026
Controller
MELTRIX SL
NIF: B27641562
Registered Office: Calle Caballero de Rodas, Número 120, Escalera PBJ, 03182 Torrevieja, Alicante, Spain
Email: hello@proxynode.app
(hereinafter referred to as "we", "us", "our", or "Controller")
This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you visit our website, register for an account, or use our proxy services (the "Services"). We are committed to protecting your privacy in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679 – "GDPR") and applicable Spanish data protection laws, including the Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD).
This Privacy Policy is server‑side rendered and accessible without JavaScript. It is available prior to account registration or any purchase.
1. Categories of Personal Data We Collect
We collect only the data necessary to provide, secure, and improve our Services, and to comply with legal obligations.
1.1 Data you provide directly
- Account information – Email address, username, and password (hashed and salted).
- Payment information – One‑time payment details. We do not store full credit card numbers (raw cardholder data). Payments are processed via a third‑party payment processor. We retain only: payment reference, date, amount, currency, and the last four digits of a card (if applicable).
- Communications – Any information you send us via email or through support forms (including LiveChat, if used).
1.2 Data collected automatically (including cookies)
- Service operation metadata – Originating IP address at connection time, connection timestamps, traffic volume (GB). We do NOT log the content of your traffic, websites visited, or destinations reached through the proxy. This data is retained for 30 days.
- Website usage (server logs) – IP address, browser type, referrer, pages visited, date and time. This data is retained for 14 days.
- Cookies and similar technologies – Session cookies (necessary for authentication), preference cookies, analytics cookies (if enabled via consent). No tracking cookies are placed without explicit consent. Retention varies – see Section 9 (Cookies and Consent Mechanism).
1.3 No sensitive data
We do not intentionally collect special categories of personal data (e.g., health, political opinions, biometric data, sexual orientation). Please do not share such information with us.
2. Purposes and Legal Bases for Processing (GDPR Art. 6)
We process your personal data only when we have a legal basis under GDPR:
- Providing the proxy Service – Legal basis: Contract performance (Art. 6(1)(b)). Examples include account creation, authentication, and traffic routing.
- Processing one‑time payments – Legal basis: Contract performance (Art. 6(1)(b)). Examples include payment verification and fraud checks.
- Preventing fraud, abuse, DDoS attacks – Legal basis: Legitimate interests (Art. 6(1)(f)). This protects our network and users.
- Responding to support requests – Legal basis: Legitimate interests (Art. 6(1)(f)). This includes troubleshooting and answering questions.
- Complying with legal obligations (tax, court orders) – Legal basis: Legal obligation (Art. 6(1)(c)). This includes retention of accounting records for the period required by Spanish law (typically 6 years under the Spanish Commercial Code).
- Sending service‑related notices (e.g., Terms updates) – Legal basis: Legitimate interests (Art. 6(1)(f)). We notify you about material changes.
- Website analytics (with consent) – Legal basis: Consent (Art. 6(1)(a)). This helps improve user experience and is optional.
We do not sell your personal data to third parties. We do not use automated decision‑making or profiling that produces legal effects.
3. Third‑Party Disclosures (Recipients)
We share your personal data only in the following limited circumstances:
- Payment processor(s) – Used for one‑time payment processing. Data shared includes payment reference, amount, and last four digits of a card (no full PAN). The processor is located in the EEA or a third country with EU Standard Contractual Clauses (SCCs). Contractual Data Processing Agreements (DPAs) and PCI DSS compliance are in place.
- Hosting / infrastructure provider – Used for server and database hosting. Data shared includes account data and metadata (limited). The provider is located in the EEA under a DPA.
- Legal authorities – Used to comply with law. Data shared is as required by court order or lawful request. The legal basis is legal obligation.
- Abuse prevention (upstream providers, law enforcement) – Used to stop DDoS, spam, and illegal content. Data shared includes connection metadata (source IP, timestamps). The legal basis is legitimate interest.
We never sell, rent, or trade your personal data.
4. Raw Cardholder Data and PCI DSS Compliance
MELTRIX SL does not store raw cardholder data (full Primary Account Number / PAN, expiration date, CVV/CVC, or magnetic stripe data). All payment transactions are processed by a PCI DSS‑compliant third‑party payment processor. The merchant website uses 3D Secure authentication (when supported by the card issuer) to reduce fraud and unauthorised transactions. We receive only transaction confirmation, payment reference, amount, and the last four digits of the card (if applicable).
5. Data Retention Periods
We retain personal data only as long as necessary for the purposes set out in this policy.
- Account information (email, hashed password) – Retained for the duration of your account plus 2 years after last activity (unless you request earlier deletion). Reason: user convenience and potential reactivation.
- Connection metadata (source IP, timestamps, traffic volume) – Retained for 30 days, then automatically anonymised or deleted. Reason: security and anti‑abuse.
- Payment records – Retained for 6 years. Reason: Spanish accounting and tax laws (Spanish Commercial Code).
- Support emails and chat transcripts – Retained for 3 years after resolution. Reason: customer service and legal defence.
- Website server logs (raw) – Retained for 14 days. Reason: security analysis.
- Cookie consent preferences – Retained for 6 months. Reason: legal requirement (ePrivacy / GDPR).
- Analytics data (with consent) – Retained for 14 months (rolling). Reason: performance improvement.
After these periods, data is deleted or irreversibly anonymised.
6. International Data Transfers (Outside the EEA)
Our primary servers are located within the European Economic Area (EEA). However, some third‑party processors (e.g., payment gateways, LiveChat providers, analytics services) may operate outside the EEA.
When we transfer personal data to a country not recognised by the European Commission as providing adequate protection, we implement at least one of the following safeguards:
- EU Standard Contractual Clauses (SCCs) as adopted by the European Commission;
- Binding Corporate Rules (BCRs) where applicable;
- Derogations for specific situations (e.g., with your explicit consent, or for contract performance).
You may request a copy of the SCCs by contacting us at hello@proxynode.app.
7. Your Rights Under GDPR (Arts. 15–22)
You have the following rights regarding your personal data:
- Right to access (Art. 15) – You have the right to receive a copy of the data we hold about you.
- Right to rectification (Art. 16) – You have the right to correct inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) – You have the right to request deletion of your data, subject to legal retention obligations (e.g., tax records).
- Right to restriction of processing (Art. 18) – You have the right to limit how we use your data while a request is being resolved.
- Right to data portability (Art. 20) – You have the right to receive your data in a structured, machine‑readable format (JSON, CSV).
- Right to object (Art. 21) – You have the right to object to processing based on legitimate interests (e.g., direct marketing – we do not send marketing emails).
- Right not to be subject to automated decision‑making (Art. 22) – We do not use automated decisions with legal effects.
How to exercise your rights
Contact us at: hello@proxynode.app
We will respond within 30 days (GDPR Art. 12). Requests may be extended by 60 days for complex cases, with notice.
Right to lodge a complaint
You have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos - AEPD):
8. Security Measures
We implement appropriate technical and organisational measures to protect your data:
- Encryption in transit – TLS 1.2+ for our website; SSH‑encrypted proxy control channels.
- Hashed and salted passwords – No plaintext storage.
- Access control – Restricted access to logs and internal systems (need‑to‑know basis).
- Regular audits – Security updates and vulnerability scanning.
- Data minimisation – We collect only what is necessary.
No method of transmission over the Internet is 100% secure. You use the Services at your own risk.
9. Cookies and Consent Mechanism
Our website uses cookies and similar technologies. We obtain explicit, informed consent before placing non‑essential cookies, in compliance with the ePrivacy Directive and GDPR.
9.1 Types of cookies
- Strictly necessary cookies – Used for authentication, security, and session management. Legal basis: Legitimate interest (Art. 6(1)(f)). Consent is not required for these.
- Preference / functionality cookies – Used for language and interface settings. Legal basis: Consent (Art. 6(1)(a)). Consent is required for these.
- Analytics (statistical) cookies – Used for Matomo, Plausible, or similar (anonymised or pseudonymised). Legal basis: Consent (Art. 6(1)(a)). Consent is required for these.
- Marketing / tracking cookies – None are used by the Provider.
9.2 Consent mechanism
- A cookie banner is displayed on first visit.
- You can accept all non‑essential cookies, reject all non‑essential cookies, or customise your preferences.
- Consent is stored for 6 months.
- You may withdraw consent at any time via the cookie preferences link (in the footer).
9.3 No third‑party tracking without consent
We do not load Google Analytics, Facebook Pixel, or any tracking script unless you have given explicit consent.
10. No Recurring Payments – Impact on Data
We do not operate recurring billing or subscriptions. Therefore:
- We do not store continuous payment authorisation tokens.
- We do not automatically renew your service.
- Your payment data is used only for the specific one‑time transaction and retained solely for legal accounting purposes, not for future charges.
11. Children's Privacy
Our Services are not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected personal data from a person under 18, we will delete it immediately.
12. Data Protection Officer (DPO) / GDPR Contact
We have appointed a GDPR contact person (a DPO is not required by law for our size, but we provide a dedicated contact):
GDPR Contact: Patryk Damian Ginowicz (Administrator)
Email: hello@proxynode.app
Address: Calle Caballero de Rodas, Número 120, Escalera PBJ, 03182 Torrevieja, Alicante, Spain
For all data protection matters, including exercising your rights, please use this contact.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated:
- By email to the address associated with your account; and/or
- By a notice on our website at least 15 days in advance.
The "Last updated" date at the top indicates the latest revision. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
14. Contact Information (Summary)
MELTRIX SL
NIF: B27641562
Registered Office: Calle Caballero de Rodas, Número 120, Escalera PBJ, 03182 Torrevieja, Alicante, Spain
Email (general & GDPR): hello@proxynode.app
By using our Services, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy was last updated on 18 June 2026 and is effective as of 18 June 2026.