Privacy Policy
Last updated: October 2026
1. Introduction & Data Controller
Wyming Digital ("we", "us", or "our") operates the wydProxy secure tunneling infrastructure. This Privacy Policy explains how we collect, use, and safeguard your information in strict compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Data Controller: Wyming Digital
Contact Email: [email protected]
2. Data We Collect
Based on our service architecture, we collect and process the following specific categories of data:
- Account & Identity Data: Email address, securely hashed password (using bcrypt), account role, and email verification status.
- Security & Session Data: Two-factor authentication (2FA) secrets, active session tokens, IP addresses, User-Agent strings, and device fingerprint hashes (used strictly for fraud prevention).
- Technical & Infrastructure Data: Client server hostnames, operating system information, and WireGuard cryptographic keys (public, private, and pre-shared) necessary to establish secure mesh network tunnels.
- Billing & Transaction Data: Subscription plan, billing status, transaction amounts, and payment processor reference IDs. (We do not store raw credit card details).
- Activity Logs: Timestamps of significant account actions (e.g., logins, tunnel creations) and associated IP addresses for security auditing.
- Custom Domain Data: The custom domain names you choose to link to your tunnels, along with the DNS verification tokens used to prove you own them. We also perform standard DNS TXT record lookups to verify this ownership.
3. Use of Information & Legal Basis
Under UK GDPR, we process your personal data based on the following lawful grounds:
- Performance of a Contract: To create your account, provide the tunneling service, manage subscriptions, and deliver service-related notifications.
- Legitimate Interests: To maintain network security, prevent abuse, monitor system performance, and keep our infrastructure operational.
- Consent: For optional marketing or product update communications. You can withdraw this consent at any time via your Account Settings.
4. Data Sharing & Third Parties
We do not sell your personal data. We only share data with trusted third-party processors strictly necessary to operate the service:
- Oracle Cloud Infrastructure (OCI): Hosts our email delivery services (SMTP) for account verification and system notifications.
- Payment Processors: Processes billing transactions securely. We only share the minimum data required to process your subscription.
- Proxy "Doer" Nodes: Technical configuration data (such as WireGuard public keys and assigned internal IPs) is shared with our proxy nodes strictly to route your traffic. No personally identifiable information (PII) like your email or name is ever sent to these nodes.
5. Data Retention
- Active Accounts: Retained indefinitely while your account remains active.
- Deleted Accounts: Upon account deletion, all associated personal data, tunnels, cryptographic keys, and logs are permanently purged from our active systems within 30 days.
- Financial Records: In accordance with HMRC regulations, basic transaction records may be retained for up to 6 years.
- Session Data: Automatically expired and deleted from our database after 7 days of inactivity.
6. Your Rights Under UK GDPR
You have the right to access, rectify, or request the erasure ("right to be forgotten") of your personal data. You can delete your account and data directly via the "Danger Zone" in your Account Settings. To exercise other rights, please contact us at [email protected].
7. Data Security
We implement robust technical measures to protect your data, including passwords hashed using industry-standard bcrypt algorithms, secure HTTP-only cookies for session management, and end-to-end encrypted WireGuard tunnels for all proxied traffic.
8. Contact & Complaints
If you have any questions regarding privacy or data handling on this network, reach out directly at [email protected]. If you believe we have not handled your data in accordance with UK law, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).