Hugo & Friends AB · 559555-9989
How ProxyAPI processes account, connection, and billing data.
1. Controller
ProxyAPI is operated by Hugo & Friends AB, company reg. no. 559555-9989. For accounts, the website, customer relationships, billing, security, and our own operations, Hugo & Friends AB is normally the controller. Contact hello@proxyapi.se with privacy questions.
2. Data We Process
- Account and customer relationship: email address, name, company details, plan, account status, and support or business communications.
- Authentication and security: hashed API keys, key prefixes, session data, IP address, user agent, timestamps, and relevant audit logs.
- Proxy connections: customer, key, and exit identifiers; start/end time; destination host; destination port; bytes in/out; close reason; session ID; and selected targeting parameters.
- Operations: health-check results, response time, status code, observed IP, errors, and technical metrics.
- Billing: subscription, usage, invoice basis, Stripe customer reference, and payment status. Full card details are handled by Stripe and are not stored by ProxyAPI.
3. Traffic Content and CONNECT
For HTTPS over CONNECT, ProxyAPI does not terminate the TLS session between your client and the destination. The gateway relays encrypted bytes and does not store request headers, request bodies, or response bodies as application content.
A proxy must still know where to connect. Destination host and port plus other connection metadata are therefore processed as described in section 2. Unencrypted HTTP traffic lacks HTTPS protection and may technically be read by network intermediaries; always use HTTPS for sensitive data.
4. Purposes and Legal Bases
- Contract performance: create accounts, authenticate connections, route traffic, show usage, manage plans, and provide support.
- Legitimate interests: secure the service, prevent abuse, troubleshoot, measure quality, handle legal claims, and improve operations.
- Legal obligation: accounting, tax, authority orders, and other mandatory requirements.
- Consent is used only where expressly requested and may be withdrawn.
5. Roles When You Use the Proxy
You normally determine why traffic is sent and which personal data it contains. You are responsible for a legal basis, information to data subjects, and compliance with law and target-site rules. Where ProxyAPI processes personal data solely on your behalf, we act as processor or subprocessor and our standard DPA applies.
6. Recipients, Subprocessors, and Transfers
The core database and control plane are operated by Hugo & Friends AB on our own hardware in Sweden. Selected providers are used for edge, private networking, email, payments, and upstream proxy capacity. The current list, location, and role are shown on Subprocessors and providers. Where processing occurs outside the EU/EEA, we use an applicable transfer mechanism and contractual safeguards.
7. Retention
- Account data is retained while the account is active and afterward as needed for closure, security, disputes, or legal requirements.
- Detailed connection and usage metadata is normally retained for no more than 24 months; aggregated billing and usage records may be retained longer.
- Accounting and invoice records are normally retained for seven years under Swedish accounting requirements.
- Security, audit, and support data is retained for as long as proportionate to the matter and legal need.
- Backups follow rotating retention and disappear as backup generations expire.
8. Cookies and Analytics
The marketing site uses no third-party analytics or advertising tracking. The dashboard uses necessary local storage and session mechanisms for sign-in, language, and theme. We do not use them for behavioural advertising.
9. Your Rights
You may have rights of access, rectification, deletion, restriction, objection, and portability. Email hello@proxyapi.se. Where we act as processor, we may need to refer the request to the customer acting as controller. You may complain to the Swedish Authority for Privacy Protection (IMY).
10. Security and Changes
We use TLS, hashed API keys, encrypted provider secrets, restricted administrative access, private networking, logging, backups, and incident procedures. No technical solution is risk-free. Material policy changes are communicated via the website, dashboard, or email.