These Data Protection Terms form part of the Reseller Agreement between HidzoVPN, Inc. ("HidzoVPN") and the Reseller.

  1. Roles. Each party is an independent controller of the personal data it collects. The Reseller is the controller of the data of its customers that it collects when selling Activation Codes. HidzoVPN is the controller of the data of End Users that it processes when they activate a code and use the service. The parties do not jointly determine the purposes and means of any processing. Before they do so — for example through a co-branded redemption page, joint marketing or a white-label service — they shall agree terms under Article 26 of the GDPR.
  2. Data shared. The parties shall share only the following, and only for the purposes stated:
FromToDataPurpose
HidzoVPNResellerActivation Codes; aggregate counts of activated and unactivated codes per batchSupply and reconciliation
ResellerHidzoVPNBusiness contact details of the Reseller's staffAccount management; sanctions and anti-fraud screening
Either partyThe otherEnd User contact details needed to resolve a specific support or fraud case, where the End User has asked for help or fraud is suspectedResolving that case only; deleted within [OPEN] days after the case is closed
  1. Minimization. Each party shall collect and share only the data needed for the purposes in Section 2.
  2. Compliance. Each party shall comply with the data-protection laws that apply to it, give its own privacy notice to the persons whose data it collects, and have a lawful basis for any sharing.
  3. Security and breaches. Each party shall protect shared data with appropriate technical and organizational measures and shall notify the other without undue delay, and in any case within [OPEN] hours, after becoming aware of a breach affecting shared data.
  4. Requests from individuals and authorities. Each party shall handle requests relating to the data it controls. If a party receives a request that concerns the other party's data, it shall forward it promptly. The Reseller shall not represent to any person or authority that it can obtain HidzoVPN account data.
  5. International transfers. Where a transfer of personal data between the parties from the European Economic Area, the United Kingdom or Switzerland requires safeguards, the parties shall sign the Standard Contractual Clauses in Schedule 1 [COUNSEL]. The Standard Contractual Clauses prevail over the Reseller Agreement to the extent of any conflict, including on governing law. [COUNSEL]
  6. No sale; no marketing use. Neither party shall sell data received from the other or use it for marketing.
  7. Unlinkability. HidzoVPN shall not disclose to the Reseller whether, when or by which account a particular Activation Code was activated. The Reseller shall not ask End Users for their HidzoVPN account details.
  8. Return and deletion. On termination of the Reseller Agreement, each party shall delete or return personal data received from the other, unless the law requires it to be kept.
  9. Cooperation and audit. Each party shall cooperate reasonably with the other in responding to a supervisory authority and shall give the other, on reasonable notice, the information needed to show compliance with these Terms.
  10. Duration. These Terms apply for as long as either party holds data shared under the Reseller Agreement.

Schedule 1 — Standard Contractual Clauses [COUNSEL]

HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States, processes the names, business email addresses, phone numbers and job titles of people who work for our resellers, which we receive from you or from your employer, and records of our communications with you. We use this information to manage the reseller relationship, process orders and payments, carry out sanctions and anti-fraud screening, and meet our obligations. Our legal bases are the performance of the Reseller Agreement and our legitimate interests in managing our business relationships and in complying with the sanctions laws that apply to us [COUNSEL]. We keep this information for the duration of the relationship and for [OPEN] years after it ends, and sanctions-screening records for 10 years [TO COMPLETE]. We transfer it to the United States [COUNSEL] and share it with our service providers and, where required, with authorities. You may have rights to access, correct and delete your information, to object to our use of it, and to complain to a data-protection authority. Contact [OPEN].