Document libraryکتابخانه‌ی اسناد

Resellers and user dataنماینده‌ها و اطلاعات کاربر

What resellers may do with user data.نماینده‌ی فروش با اطلاعات کاربر چه کند.Reseller Privacy Policy (Reseller Data Protection Terms)

Draft — not final. Do not publish until our lawyer approves it.پیش‌نویس است و هنوز نهایی نیست؛ تا تأیید وکیل منتشر نشود.

It still has 14 gaps, shown in yellowهنوز ۱۴ جای خالی دارد که زرد نشان داده شده [OPEN: …] · What to fill inچه چیزی پر شود

The text below is in English — the official text.متن زیر انگلیسی است؛ متن رسمی همین است.
Technical detailsجزئیات فنی
draftپیش‌نویس
IDشناسهPOL-RPRIV-001
Versionنسخه0.2
OwnerمسئولLegal Lead (named person TBD) with Founder
Counsel reviewبررسی وکیلnone
Next reviewبررسی بعدی2026-10-23
Fileفایلknowledge-base/05-Policies-Public/drafts/POL-RPRIV-001_RESELLER_DATA_PROTECTION_TERMS_v0.2-draft.md

Reseller Data Protection Terms — framework draft

Prepared for review by licensed counsel. Not legal advice. Part B contains the data-protection terms between HidzoVPN and a Reseller; Part C is a privacy notice for reseller business contacts. Data roles follow the facts, not the contract; the default here (independent controllers, minimal sharing, no per-user data to resellers) must be re-assessed once the reseller model is chosen (POL-RTOS-001 §0). Design constraint: Apple Guideline 5.4 — VPN apps "may not sell, use, or disclose to third parties any data for any purpose" (EV-106, Verified) — so HidzoVPN shares no End User data with Resellers, except as Section 2 allows for a specific support or fraud case [COUNSEL: Apple 5.4 reading].

Part A — Drafting brief (internal)

ItemValue
Question presentedHow do HidzoVPN and a Reseller allocate data-protection responsibilities, while keeping End Users' activations unlinkable to their purchase from a Reseller?
Role testWho determines purposes and means (GDPR Arts. 4(7), 4(8), 26, 28; EDPB Guidelines 07/2020) [VERIFY: EV-235]
Safety pointA reseller in a restrictive country could be compelled to disclose buyer identities; if it could also learn which codes were activated, users could be identified. Section 9 prevents this

Part B — Reseller Data Protection Terms

These Data Protection Terms form part of the Reseller Agreement between HidzoVPN, Inc. ("HidzoVPN") and the Reseller.

  1. Roles. Each party is an independent controller of the personal data it collects. The Reseller is the controller of the data of its customers that it collects when selling Activation Codes. HidzoVPN is the controller of the data of End Users that it processes when they activate a code and use the service. The parties do not jointly determine the purposes and means of any processing. Before they do so — for example through a co-branded redemption page, joint marketing or a white-label service — they shall agree terms under Article 26 of the GDPR.
  2. Data shared. The parties shall share only the following, and only for the purposes stated:
FromToDataPurpose
HidzoVPNResellerActivation Codes; aggregate counts of activated and unactivated codes per batchSupply and reconciliation
ResellerHidzoVPNBusiness contact details of the Reseller's staffAccount management; sanctions and anti-fraud screening
Either partyThe otherEnd User contact details needed to resolve a specific support or fraud case, where the End User has asked for help or fraud is suspectedResolving that case only; deleted within [OPEN: 30] days after the case is closed
  1. Minimization. Each party shall collect and share only the data needed for the purposes in Section 2.
  2. Compliance. Each party shall comply with the data-protection laws that apply to it, give its own privacy notice to the persons whose data it collects, and have a lawful basis for any sharing.
  3. Security and breaches. Each party shall protect shared data with appropriate technical and organizational measures and shall notify the other without undue delay, and in any case within [OPEN: 72] hours, after becoming aware of a breach affecting shared data.
  4. Requests from individuals and authorities. Each party shall handle requests relating to the data it controls. If a party receives a request that concerns the other party's data, it shall forward it promptly. The Reseller shall not represent to any person or authority that it can obtain HidzoVPN account data.
  5. International transfers. Where a transfer of personal data between the parties from the European Economic Area, the United Kingdom or Switzerland requires safeguards, the parties shall sign the Standard Contractual Clauses in Schedule 1 [COUNSEL: Module 1 of Decision (EU) 2021/914, with Annexes I–III completed; Clause 17 governing law and Clause 18 forum of an EU Member State; UK Addendum or IDTA; Swiss adaptation; HidzoVPN's status under GDPR Art. 3(2)]. The Standard Contractual Clauses prevail over the Reseller Agreement to the extent of any conflict, including on governing law. [COUNSEL: local transfer instruments for the Reseller's country — e.g. Turkey, UAE, Indonesia, Brazil, Saudi Arabia]
  6. No sale; no marketing use. Neither party shall sell data received from the other or use it for marketing.
  7. Unlinkability. HidzoVPN shall not disclose to the Reseller whether, when or by which account a particular Activation Code was activated. The Reseller shall not ask End Users for their HidzoVPN account details.
  8. Return and deletion. On termination of the Reseller Agreement, each party shall delete or return personal data received from the other, unless the law requires it to be kept.
  9. Cooperation and audit. Each party shall cooperate reasonably with the other in responding to a supervisory authority and shall give the other, on reasonable notice, the information needed to show compliance with these Terms.
  10. Duration. These Terms apply for as long as either party holds data shared under the Reseller Agreement.

Schedule 1 — Standard Contractual Clauses [COUNSEL: to be completed]

Part C — Privacy notice for reseller business contacts

HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States, processes the names, business email addresses, phone numbers and job titles of people who work for our resellers, which we receive from you or from your employer, and records of our communications with you. We use this information to manage the reseller relationship, process orders and payments, carry out sanctions and anti-fraud screening, and meet our obligations. Our legal bases are the performance of the Reseller Agreement and our legitimate interests in managing our business relationships and in complying with the sanctions laws that apply to us [COUNSEL: GDPR Art. 10 and member-state law for screening data]. We keep this information for the duration of the relationship and for [OPEN: 7] years after it ends, and sanctions-screening records for 10 years [31 C.F.R. §501.601 — Reported]. We transfer it to the United States [COUNSEL: safeguard] and share it with our service providers and, where required, with authorities. You may have rights to access, correct and delete your information, to object to our use of it, and to complain to a data-protection authority. Contact [OPEN: [email protected]].

Part D — Drafting notes (internal)

D.1 Sources

ElementBasisLabel
No third-party disclosure by VPN appsApple Guideline 5.4Verified (EV-106)
Role testGDPR Arts. 4(7), 4(8), 26, 28; EDPB Guidelines 07/2020[VERIFY: EV-235]
Controller-to-controller transfersDecision (EU) 2021/914 (Module 1; Clauses 17–18); UK Addendum/IDTA[VERIFY: EV-234]
Screening dataGDPR Arts. 6(1)(c), 6(3), 10[VERIFY]
Recordkeeping31 C.F.R. §501.601Reported

D.2 Limits of this analysis

Verified first-hand: Apple Guideline 5.4 only. Not opened: EUR-Lex (SCCs), EDPB guidelines. Not reviewed: data-protection laws of reseller countries; CCPA third-party contract terms (Cal. Civ. Code §1798.100(d)), applicability open (EV-233). Facts unknown: the reseller model and data flows. Counsel required: EU/UK privacy; U.S. privacy.

D.3 Review log

DateReviewerVerdictNotes
2026-09-25Drafted—v0.1 framework
2026-09-25hidzo-counsel-reviewer (AI)REVISE (1 Blocker; 5 Majors)v0.2: per-code activation status removed (Apple 5.4 Blocker); unlinkability clause; SCC schedule and governing-law priority; Privacy Policy disclosure required (POL-PRIV-002); self-standing contact notice; screening legal basis; roles triggers; minimization, deletion, cooperation; retention aligned (7 years; 10 years for screening)