Reseller Data Protection Terms — framework draft
Prepared for review by licensed counsel. Not legal advice. Part B contains the data-protection terms between HidzoVPN and a Reseller; Part C is a privacy notice for reseller business contacts. Data roles follow the facts, not the contract; the default here (independent controllers, minimal sharing, no per-user data to resellers) must be re-assessed once the reseller model is chosen (POL-RTOS-001 §0). Design constraint: Apple Guideline 5.4 — VPN apps "may not sell, use, or disclose to third parties any data for any purpose" (EV-106, Verified) — so HidzoVPN shares no End User data with Resellers, except as Section 2 allows for a specific support or fraud case [COUNSEL: Apple 5.4 reading].
Part A — Drafting brief (internal)
| Item | Value |
|---|---|
| Question presented | How do HidzoVPN and a Reseller allocate data-protection responsibilities, while keeping End Users' activations unlinkable to their purchase from a Reseller? |
| Role test | Who determines purposes and means (GDPR Arts. 4(7), 4(8), 26, 28; EDPB Guidelines 07/2020) [VERIFY: EV-235] |
| Safety point | A reseller in a restrictive country could be compelled to disclose buyer identities; if it could also learn which codes were activated, users could be identified. Section 9 prevents this |
Part B — Reseller Data Protection Terms
These Data Protection Terms form part of the Reseller Agreement between HidzoVPN, Inc. ("HidzoVPN") and the Reseller.
- Roles. Each party is an independent controller of the personal data it collects. The Reseller is the controller of the data of its customers that it collects when selling Activation Codes. HidzoVPN is the controller of the data of End Users that it processes when they activate a code and use the service. The parties do not jointly determine the purposes and means of any processing. Before they do so — for example through a co-branded redemption page, joint marketing or a white-label service — they shall agree terms under Article 26 of the GDPR.
- Data shared. The parties shall share only the following, and only for the purposes stated:
| From | To | Data | Purpose |
|---|---|---|---|
| HidzoVPN | Reseller | Activation Codes; aggregate counts of activated and unactivated codes per batch | Supply and reconciliation |
| Reseller | HidzoVPN | Business contact details of the Reseller's staff | Account management; sanctions and anti-fraud screening |
| Either party | The other | End User contact details needed to resolve a specific support or fraud case, where the End User has asked for help or fraud is suspected | Resolving that case only; deleted within [OPEN: 30] days after the case is closed |
- Minimization. Each party shall collect and share only the data needed for the purposes in Section 2.
- Compliance. Each party shall comply with the data-protection laws that apply to it, give its own privacy notice to the persons whose data it collects, and have a lawful basis for any sharing.
- Security and breaches. Each party shall protect shared data with appropriate technical and organizational measures and shall notify the other without undue delay, and in any case within [OPEN: 72] hours, after becoming aware of a breach affecting shared data.
- Requests from individuals and authorities. Each party shall handle requests relating to the data it controls. If a party receives a request that concerns the other party's data, it shall forward it promptly. The Reseller shall not represent to any person or authority that it can obtain HidzoVPN account data.
- International transfers. Where a transfer of personal data between the parties from the European Economic Area, the United Kingdom or Switzerland requires safeguards, the parties shall sign the Standard Contractual Clauses in Schedule 1 [COUNSEL: Module 1 of Decision (EU) 2021/914, with Annexes I–III completed; Clause 17 governing law and Clause 18 forum of an EU Member State; UK Addendum or IDTA; Swiss adaptation; HidzoVPN's status under GDPR Art. 3(2)]. The Standard Contractual Clauses prevail over the Reseller Agreement to the extent of any conflict, including on governing law. [COUNSEL: local transfer instruments for the Reseller's country — e.g. Turkey, UAE, Indonesia, Brazil, Saudi Arabia]
- No sale; no marketing use. Neither party shall sell data received from the other or use it for marketing.
- Unlinkability. HidzoVPN shall not disclose to the Reseller whether, when or by which account a particular Activation Code was activated. The Reseller shall not ask End Users for their HidzoVPN account details.
- Return and deletion. On termination of the Reseller Agreement, each party shall delete or return personal data received from the other, unless the law requires it to be kept.
- Cooperation and audit. Each party shall cooperate reasonably with the other in responding to a supervisory authority and shall give the other, on reasonable notice, the information needed to show compliance with these Terms.
- Duration. These Terms apply for as long as either party holds data shared under the Reseller Agreement.
Schedule 1 — Standard Contractual Clauses [COUNSEL: to be completed]
Part C — Privacy notice for reseller business contacts
HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States, processes the names, business email addresses, phone numbers and job titles of people who work for our resellers, which we receive from you or from your employer, and records of our communications with you. We use this information to manage the reseller relationship, process orders and payments, carry out sanctions and anti-fraud screening, and meet our obligations. Our legal bases are the performance of the Reseller Agreement and our legitimate interests in managing our business relationships and in complying with the sanctions laws that apply to us [COUNSEL: GDPR Art. 10 and member-state law for screening data]. We keep this information for the duration of the relationship and for [OPEN: 7] years after it ends, and sanctions-screening records for 10 years [31 C.F.R. §501.601 — Reported]. We transfer it to the United States [COUNSEL: safeguard] and share it with our service providers and, where required, with authorities. You may have rights to access, correct and delete your information, to object to our use of it, and to complain to a data-protection authority. Contact [OPEN: [email protected]].
Part D — Drafting notes (internal)
D.1 Sources
| Element | Basis | Label |
|---|---|---|
| No third-party disclosure by VPN apps | Apple Guideline 5.4 | Verified (EV-106) |
| Role test | GDPR Arts. 4(7), 4(8), 26, 28; EDPB Guidelines 07/2020 | [VERIFY: EV-235] |
| Controller-to-controller transfers | Decision (EU) 2021/914 (Module 1; Clauses 17–18); UK Addendum/IDTA | [VERIFY: EV-234] |
| Screening data | GDPR Arts. 6(1)(c), 6(3), 10 | [VERIFY] |
| Recordkeeping | 31 C.F.R. §501.601 | Reported |
D.2 Limits of this analysis
Verified first-hand: Apple Guideline 5.4 only. Not opened: EUR-Lex (SCCs), EDPB guidelines. Not reviewed: data-protection laws of reseller countries; CCPA third-party contract terms (Cal. Civ. Code §1798.100(d)), applicability open (EV-233). Facts unknown: the reseller model and data flows. Counsel required: EU/UK privacy; U.S. privacy.
D.3 Review log
| Date | Reviewer | Verdict | Notes |
|---|---|---|---|
| 2026-09-25 | Drafted | — | v0.1 framework |
| 2026-09-25 | hidzo-counsel-reviewer (AI) | REVISE (1 Blocker; 5 Majors) | v0.2: per-code activation status removed (Apple 5.4 Blocker); unlinkability clause; SCC schedule and governing-law priority; Privacy Policy disclosure required (POL-PRIV-002); self-standing contact notice; screening legal basis; roles triggers; minimization, deletion, cooperation; retention aligned (7 years; 10 years for screening) |