
Privacy Policy
This Privacy Policy explains what information (including personal data) we collect when you use iguard.one's website, apps, and VPN services (the "Services"); for what purposes we collect it; how we use, store, and protect it; with whom it may be shared; and how you can exercise your rights.
This Policy applies to all users of the Services worldwide. It is designed to comply with the EU General Data Protection Regulation ("GDPR"), the UK General Data Protection Regulation ("UK GDPR"), and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"). Additional provisions applicable to users in specific regions are set out in Section 15 (Region-Specific Provisions).
Who We Are (Controller)
VAIZEN, OSOO (doing business as "iguard.one"). Registration number 225289-3301-OOO, TIN 01412202310122, Tynystanova St., Office 38, Pervomaisky District, Bishkek, Kyrgyzstan, is the controller of your personal data.
Privacy contact: privacy@iguard.one
Legal contact: legal@iguard.one
Key Principles & No-Logs Policy
iguard.one is built on data minimisation. While you are connected to our Services, we do not log:
- •browsing history or traffic contents;
- •traffic destinations or DNS queries;
- •your source IP address or the assigned exit IP address;
- •connection timestamps or session duration.
Our VPN servers are configured so that they do not write activity or connection logs. Because we do not hold such logs, we cannot disclose them to any person or authority. Where we receive a valid legal order, we can produce only the limited data we actually hold, as described in Section 3.
Personal Data We Collect and Legal Bases
3.1 Account and Subscription Data
Email address (required to create and manage your account); payment metadata only (transaction outcome, country, and, where provided by the payment processor, the last four digits of the card) — we do not store full payment card data; optional profile fields you choose to provide.
Legal bases: performance of a contract (Art. 6(1)(b) GDPR); compliance with a legal obligation including tax and accounting obligations (Art. 6(1)(c)); legitimate interests in preventing fraud and abuse (Art. 6(1)(f)).
3.2 Support and Communications
When you contact us, we process the content of your message and the necessary metadata (email address, timestamps) in order to respond to you and to improve our support.
Legal bases: performance of a contract (Art. 6(1)(b)); legitimate interests in providing and improving customer support (Art. 6(1)(f)).
3.3 Minimal Service Telemetry
To maintain service quality, we may process minimal telemetry: whether a connection succeeded on a given day (not the time), the server location selected (not the exit IP address), and country or ISP-level information (not your source IP address). This never includes content, destinations, DNS queries, or per-site activity, and is never combined with VPN traffic data.
Legal basis: legitimate interests in maintaining the availability, capacity, and quality of the Services (Art. 6(1)(f)).
3.4 Technical and Device Information
When you visit our website or use our apps, we process: your IP address (transiently, for security and anti-DDoS purposes); User-Agent string; device identifiers and settings; time zone and non-precise location derived from IP address; and performance and diagnostics data. This information is never combined with VPN traffic data.
On our website we also determine your IP address and approximate location (country and city) on the fly to display whether your current connection runs through iGuard. This lookup is performed locally on our servers, the result is shown only to you, is not stored beyond standard technical server logs, does not use cookies, and is not shared with third parties.
Legal basis: legitimate interests in the security and integrity of our website and infrastructure (Art. 6(1)(f)); where required, your consent (Art. 6(1)(a)).
Purposes of Processing
We process personal data in order to: create and administer your account; provide, maintain, and secure the Services; process payments and issue refunds; respond to your enquiries; detect, prevent, and investigate fraud, abuse, and security incidents; comply with legal, tax, and accounting obligations; and, where you have consented, send you service-related marketing communications.
Cookies and Analytics
We use cookies and similar technologies for website functionality, analytics, and marketing. Please refer to our Cookie Policy for full details. Strictly necessary cookies are set on the basis of our legitimate interests; analytics and advertising cookies are placed only with your prior consent, which you may withdraw at any time through the cookie settings on our website.
Sharing and Recipients
We do not sell your personal data. We share personal data only as necessary with the following categories of recipients:
- •Payment processing. Purchases made directly on our website are processed by Paddle.com Market Limited, which acts as merchant of record and as an independent controller in respect of the payment transaction. Paddle's own privacy notice governs that processing.
- •Service providers and processors acting under our instructions (hosting and infrastructure, customer support tooling, analytics, anti-fraud, and content delivery networks), each bound by a written data processing agreement.
- •Legal and compliance recipients, where necessary to comply with law, to respond to valid legal process from competent authorities, to enforce our terms, or to protect rights, property, or safety.
- •Business successors, in the event of a reorganisation, merger, or sale of assets.
We never share — and do not possess — VPN activity logs.
International Transfers
We are established in the Kyrgyz Republic and our infrastructure providers operate in a number of countries, so your personal data may be transferred outside your country of residence.
Kyrgyzstan is not the subject of an adequacy decision of the European Commission or of the United Kingdom. Transfers from the EEA or the UK to us, and onward transfers to our processors in third countries, are made on the basis of Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organisational measures including encryption in transit and at rest and the absence of VPN activity logs.
Where transfers are made from the United Arab Emirates to countries that do not provide an adequate level of protection, we implement appropriate safeguards as required under the UAE PDPL. Copies of the relevant transfer mechanisms are available on request from privacy@iguard.one.
Retention
We retain personal data only for as long as necessary for the purposes described in this Policy:
- •Account data: retained for the duration of your account. When you request deletion, your account is deactivated immediately and the associated account data is erased within 30 days.
- •Payment and transaction records: retained for the period required by applicable tax and accounting legislation, which may exceed the period above.
- •Support correspondence: retained for up to 24 months from the date of the last communication.
- •Website and infrastructure security logs: retained for up to 30 days, unless a longer period is necessary to investigate a specific security incident.
We do not retain VPN activity data, because we do not collect it.
Security
We implement administrative, technical, and organisational measures appropriate to the risk: access controls, encryption in transit and at rest, network segmentation, least-privilege principles, vulnerability management, and confidentiality obligations for staff and contractors. Our VPN servers are configured so that they do not write activity or connection logs.
Your Rights
Subject to applicable law, you have the right to: obtain access to your personal data; have inaccurate data rectified; have your data erased; restrict or object to processing; receive your data in a portable format; and withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact privacy@iguard.one. We will respond within one month, or within such shorter period as applicable law requires. We may ask you for information necessary to verify your identity before acting on a request. Exercising your rights is free of charge, save for manifestly unfounded or excessive requests.
Automated Decision-Making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you. Automated fraud screening applied to payments is carried out by our payment processor in accordance with its own privacy notice; you may contact us to request human review of any resulting decision affecting your access to the Services.
Children
Our Services are not offered to individuals under 18 years of age, and we do not knowingly collect personal data from them. If you believe that a child has provided us with personal data, please contact privacy@iguard.one and we will delete it without undue delay.
Personal Data Breaches
We assess and respond to security incidents promptly. Where required under applicable law, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, and we will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date indicates the latest version. Material changes will be highlighted on our website and, where legally required, communicated to you directly.
Region-Specific Provisions
The provisions in this Section apply to users in the regions specified and prevail over conflicting provisions elsewhere in this Policy in respect of such users. In all other respects, the remainder of this Policy continues to apply.
15.1 European Economic Area and United Kingdom
Where you are located in the European Economic Area or the United Kingdom, the GDPR or the UK GDPR applies to the processing described in this Policy.
Our representative for the purposes of Article 27 GDPR and Article 27 UK GDPR is identified in Section 1, and you may contact that representative on all matters relating to the processing of your personal data.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, or — in the United Kingdom — with the Information Commissioner's Office. Where we rely on legitimate interests, you have the right to object to that processing at any time on grounds relating to your particular situation, and an unconditional right to object to processing for direct marketing purposes.
15.2 United Arab Emirates
The following provisions apply to users in the United Arab Emirates under Federal Decree-Law No. 45 of 2021:
- •we process your personal data on the basis of contractual necessity, our legitimate interests, and your consent where required;
- •we will not transfer your personal data outside the UAE to countries that do not provide an adequate level of protection without implementing appropriate safeguards, such as Standard Contractual Clauses or equivalent;
- •you have the right to access, correct, and delete your personal data and to object to its processing. To exercise these rights, contact privacy@iguard.one;
- •we will respond to verified data subject requests within 30 days as required under the UAE PDPL;
- •in the event of a personal data breach that is likely to result in harm to you, we will notify the UAE Data Office and affected individuals as required by law.
Contact Us
📧Privacy: privacy@iguard.one
📧Legal: legal@iguard.one
📍VAIZEN, OSOO. Registration number 225289-3301-OOO, TIN 01412202310122, Tynystanova St., Office 38, Pervomaisky District, Bishkek, Kyrgyzstan