Document

Privacy Policy

This document explains in plain language what data the HamikVPN service processes, why, who we share it with and how you can manage it. Our core principle: we do not keep a log of your internet activity and collect only the minimum the service cannot work without.

1. Who processes your data

The HamikVPN service (the "service", "we") provides access to a VPN — encryption of internet traffic between your device and our servers. This policy applies to the hamik.site website, the user dashboard, the HamikVPN mobile app and the Telegram bot. For any question about your data, contact support: @HamikVPNSupportBot on Telegram.

2. What data we process

We try to collect as little data as possible and do not require any ID or proof of identity — an email or a Telegram account is enough to register. Depending on how you use the service, we process:

  • Account data. If you sign up with an email, your email address and password. The password is stored only as a cryptographic hash: we neither see nor store it in plain text. If you sign in with Telegram — your Telegram ID, name and username. We do not require a phone number: you may provide it optionally, only if you share it via the bot, for example to be reached by support. In addition: your chosen language, referral code, and the dates of registration and last sign-in.
  • Technical connection metadata. To operate the tunnel and prevent abuse we process: the internal IP address assigned to you inside the VPN network, which server you are connected to, the time the connection was established and the volume of data transferred (in bytes). This is needed for the service to work, to enforce plan limits and to help you via support.
  • Payment data. Payments are handled by the payment provider Platega. From them we receive the payment status, amount, currency, chosen plan and transaction ID. Your bank card details are handled by the provider — we do not receive or store them.
  • Support requests. The messages you exchange with us through the Telegram support bot, in order to resolve your issue.

3. What we do NOT collect or log

The service does not keep a log of your internet activity. In particular, we do not store:

  • a history of the websites and apps you visit;
  • your DNS queries;
  • the contents of the traffic that passes through the tunnel.

In other words, by "no logs" we mean exactly this: what you do online through the VPN remains unknown to us. At the same time, as described above, a minimal set of technical connection metadata (connection time, data volume, internal address) is processed so the service can function.

4. Cookies and analytics

We do not use advertising trackers and do not build advertising profiles. The website uses Cloudflare Web Analytics — a web analytics service that works without cookies and does not tie statistics to your identity. For the dashboard to work, session tokens and your chosen interface language are stored in your browser's local storage (localStorage) — without them you could not stay signed in.

5. Who we share data with

We do not sell your data. Certain data is processed by our contractors (processors) — strictly to the extent needed for their function:

  • Platega — payment processing;
  • Telegram — bot operation, sign-in via Telegram and notifications;
  • Cloudflare — website protection, content delivery (CDN/DNS) and cookieless web analytics;
  • Hosting provider — the servers the service runs on (located in the EU);
  • Email delivery service — to send emails, e.g. for password resets.

We may also disclose data where required by applicable law.

6. Where data is stored

Accounts and operational data are stored on servers in the European Union (Finland). The VPN nodes that carry the encrypted traffic may be located in different countries — you can see them when choosing a server.

7. How long we keep data

Account data is kept for as long as your account exists. Technical connection metadata is kept for the limited time needed to run and diagnose the service, after which it is deleted or anonymised. Payment data may be kept for the period required by law (for example, for accounting and tax purposes). After you delete your account we delete or anonymise the data associated with it, except where we are required by law to keep it.

8. Your rights

You can:

  • ask what data of yours we process and receive a copy;
  • correct inaccurate data;
  • delete your account and the data associated with it;
  • withdraw consent you previously gave.

To exercise your rights, contact support at @HamikVPNSupportBot. We will respond within a reasonable time.

9. Security

The connection to the website and the dashboard is protected with HTTPS/TLS, passwords are stored as hashes, and traffic between your device and the server is encrypted. No service can guarantee absolute protection, but we apply reasonable technical and organisational measures.

10. Children

The service is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has provided us with their data, contact support and we will delete it.

11. Changes to this policy

We may update this policy — for example, if the set of processed data or the list of contractors changes. The current version is always available on this page; the last-updated date is shown at the top. We will try to announce material changes separately.

12. Contact

Questions about privacy and data processing: @HamikVPNSupportBot on Telegram.