Privacy Policy
vploq · Effective date: 17 September 2026 · Version 1.2
1. Introduction
This Privacy Policy describes how InTallyCon Development - FZCO, DDP, Building A1, Dubai, United Arab Emirates ("vploq", "we", "us") processes personal data in connection with the vploq service. The service comprises the vploq applications for iOS, macOS, Android and Windows (the "App"), the vploq hardware device (the "Device"), our coordination service and programming interfaces, our team-invitation web pages, and related transactional communications (together, the "Service").
We are the controller of the personal data described in this Policy within the meaning of Regulation (EU) 2016/679 ("GDPR"). References to the GDPR include, where applicable, the retained EU law version of the GDPR applicable in the United Kingdom. We are established outside the European Union.
This Policy does not apply to third-party websites, applications or services that you access through a network connection established by the Service. We do not observe or control their content.
Nor does it apply to our online store at shop.vploq.com, which is hosted by Shopify. Devices are bought and paid for there rather than through the Service: payment is handled by Shopify and its payment providers, and no payment-card details reach any system described in this Policy. Order data — such as your name, delivery address, email address and purchase history — is processed in the store, where InTallyCon Development - FZCO is likewise the controller, under the store's own privacy policy at vploq.com/policies/privacy-policy. Buying a Device and holding an account are separate: neither requires the other, and we do not link store orders to accounts.
Questions and requests concerning this Policy or your personal data may be directed to info@vploq.com (Section 13).
2. Summary of key points
- We process the personal data necessary to operate the Service: your account details, your registered devices, and limited connection metadata required to establish and maintain encrypted tunnels.
- We do not inspect, record or store the content of your network traffic. Traffic between your devices travels inside WireGuard® tunnels. Where your devices reach one another directly, that tunnel runs end to end between them. Where they cannot and a relay server carries the traffic instead, the relay is itself an end of the tunnel: it decrypts each packet in order to route it and re-encrypts it for the onward hop (Section 4.1). It performs no packet capture, no payload inspection and no per-user traffic accounting. Traffic leaving an exit Device to the open internet is protected by whatever encryption the visited service itself uses.
- We do not record DNS queries. Resolvers operated as part of the Service are configured with query logging disabled and forward queries upstream over encrypted transport (DNS over TLS), with one narrow exception for local names, described in Section 4.2.
- We do not serve advertising, do not use advertising or product-analytics software development kits, do not build behavioural profiles, and do not sell personal data. The App sends diagnostic reports and connection statistics under a single setting; that setting is on when you install the App, and you may turn it off at any time. Turning it off stops everything the App itself sends, but two streams produced by the error-monitoring component embedded in it continue regardless — we describe both, and why, in Section 3.7.
- Devices are sold through our Shopify-hosted store, not through the Service. We receive no payment-card details, and order data is governed by the store's own privacy policy (Section 1).
- Connection metadata that we do process is described in Section 4, together with its retention: most records expire within one hour to seven days; activation records are kept for ninety days and team and administrative activity logs for one hundred and twenty days; the current public IP address of a registered device is held while it remains registered.
- Service data is stored in the European Union. A limited number of processors are located in the United States; the safeguards applied to those transfers are described in Section 6.
- You may obtain a machine-readable export of your personal data and delete your account directly in the App (Section 9).
3. Personal data we process
This Section lists each category of personal data, its source, the purposes of processing, the legal basis under Article 6 GDPR for each purpose, and the retention period. Retention is summarised again in Section 7.
3.1 Account data
| Category | Details |
|---|---|
| Data | Email address; display name; internal account identifier; authentication identifier issued by our authentication provider |
| Source | Provided by you at registration (email and password, or Google Sign-In) |
| Purposes and legal bases | Creating and operating your account, authentication, and service communications — performance of a contract (Art. 6(1)(b)) |
| Retention | For the life of the account; erased upon account deletion following a thirty (30) day grace period (Section 7) |
Authentication is performed by Google Firebase Authentication. We do not receive or store your password. Where you use Google Sign-In, we receive your email address and name from your Google account; we receive no other Google account data.
3.2 Device and installation data
| Category | Details |
|---|---|
| Data | Device model designation and operating system version; a randomly generated installation identifier; the WireGuard public key of each installation or Device; for hardware Devices additionally: serial number, hardware revision, firmware version and device certificate fingerprint; operational status of hardware Devices (firmware update state, uptime, reboot counters, crash signatures of on-device system services) |
| Source | Generated by, or read from, your device upon registration and during operation |
| Purposes and legal bases | Registering and identifying devices, provisioning encrypted tunnels, and delivering and monitoring firmware updates — performance of a contract (Art. 6(1)(b)). Preventing the activation of counterfeit or cloned hardware — our legitimate interest in the security and integrity of the Service (Art. 6(1)(f)) |
| Retention | For as long as the device remains registered. An App installation whose record has been inactive for ninety (90) days is deleted automatically. A hardware Device, and a software node you have enrolled, are not removed on a timer — their records last as long as the registration, and end when you delete the device, when you are removed from the team it belongs to, or when you delete your account. A deleted Device may be registered again at any time. Personal data on device records is scrubbed upon account deletion |
The WireGuard private key corresponding to each public key is generated on your device and is never transmitted to us. That key authenticates your device and protects the tunnel between your device and whatever is at the other end of it. Where the other end is one of our relay servers rather than another of your devices, the relay holds a key of its own; Section 4.1 sets out what that means and what a relay does and does not do with the traffic.
3.3 Connection metadata
| Category | Details |
|---|---|
| Data | The public IP address and port of a device as observed by our infrastructure; local network parameters reported by hardware Devices (interface IP address, gateway address, configured DNS server addresses); timestamp of the most recent WireGuard handshake; network address translation behaviour statistics; a current aggregate throughput figure reported by hardware Devices (total bytes over the preceding sixty seconds, as two numbers, with no information as to destinations, connections or content — processed transiently for status display and not stored) |
| Source | Observed by our coordination service and relay servers in the course of operating the Service; reported by hardware Devices |
| Purposes and legal bases | Establishing connectivity between devices (including traversal of network address translation), device status display, and connection recovery — performance of a contract (Art. 6(1)(b)). Abuse prevention — our legitimate interest in the security of the Service (Art. 6(1)(f)) |
| Retention | One (1) hour to seven (7) days per record, as set out in Section 4.3, with two exceptions stated there: device activation events (ninety (90) days) and the current public IP address on the device record (retained while the device remains registered; scrubbed on removal or account deletion) |
3.4 Approximate location (country level)
We derive the country in which a device is located from its public IP address, using a commercial IP-geolocation database (MaxMind GeoLite2) operated as an embedded, offline copy on our own servers. No geolocation query is transmitted to any third party. We store the country code and country name only. We do not store city-level data, coordinates or any location history, and we never access device GPS or other location sensors; the App requests no location permission. The stored country value follows the device record: it is overwritten on change and scrubbed with the device record (Section 3.2). Legal basis: performance of a contract (Art. 6(1)(b)) — the location is displayed to you in the App and used to select the nearest relay server.
3.5 Team and invitation data
Where you create or join a team, we process: the team name; membership and role; and a team activity log recording membership and administrative actions together with the acting user's anonymised IP address and user agent. IP addresses in team activity logs are anonymised before storage by truncation (final octet for IPv4; equivalent for IPv6). Legal bases: operating the team — performance of a contract (Art. 6(1)(b)); the activity log — our legitimate interest in the accountability of team administration (Art. 6(1)(f)). Retention: team data for the life of the team. Activity logs remain queryable in our database for ninety (90) days; they are then moved to encrypted object storage and deleted thirty (30) days after that, so that the total retention of an activity log entry is one hundred and twenty (120) days from the day it was written.
If you have received a team invitation: we obtained your email address from the team member who invited you, and we process it solely to deliver and administer the invitation — our legitimate interest, and that of the inviting team, in enabling team collaboration (Art. 6(1)(f)). The invitation email contains a link to this Policy. If you do not accept, the invitation expires, and the invitation record, including your email address, is deleted ninety (90) days after expiry. You may object to further invitations at info@vploq.com.
3.6 Push notification tokens
A push-notification registration token (Firebase Cloud Messaging) enabling us to deliver service notifications, such as security events and update outcomes. On Apple platforms, delivery additionally transits the Apple Push Notification service (Section 5.1). The token is deleted upon sign-out or account deletion; tokens that are no longer refreshed by an active installation are deleted automatically. Legal basis: performance of a contract (Art. 6(1)(b)).
3.7 Diagnostic reports and connection statistics
A single setting in the App — Profile → My information → Privacy → Diagnostics — governs what is described in this subsection. That setting is on when you install the App. You are not asked about it at first launch. You may turn it off at any time, and what turning it off does and does not stop is stated below. It covers three things:
- Error and crash reports, sent to our error-monitoring processor.
- A sample of performance measurements — timings of screens and network calls, taken from a minority of sessions — sent to the same processor.
- Connection statistics: for each attempt to establish a direct connection between your devices, whether it succeeded, the reason if it did not, a classification of your network's address translation, and the App version and platform. Durations and counts are placed into ranges before they are sent, and no address, destination or identifier of the visited service is included. These are sent to our own systems, not to the error-monitoring processor.
Reports are minimised before transmission: request bodies, cookies, authentication headers and IP-carrying headers are removed; the sole user identifier attached is the internal account identifier; values resembling IP addresses are redacted from connection metadata. Our server software transmits equivalently minimised error reports; where a transactional email fails to reach its recipient, the report identifies that recipient by a pseudonymous reference derived from their address, never by the address itself.
What turning the setting off stops, and what it does not. With the setting off, the App sends no error report, no performance measurement and no connection statistic. Two things continue regardless, because they are produced by the error-monitoring component embedded in the App rather than by the App's own code, and that component is not told about your choice: a report of a crash that terminates the App itself, and a record that the App was started and brought to and from the foreground. Both go to the error-monitoring processor, and both carry the internal account identifier. We regard this as a defect rather than a design. It is stated here because it is what happens today.
Legal basis: our legitimate interest in the reliability and security of the Service (Art. 6(1)(f)), for both App and server-side reports. You may object to this processing at any time by turning the setting off, and, in respect of the two streams named above, by writing to us (Section 9). Retention: error reports are retained by the error-monitoring processor for ninety (90) days.
3.8 Device diagnostics
Where a firmware update fails, the hardware Device transmits a diagnostic bundle so that the failure can be diagnosed and the update repaired. The bundle is limited to logs of the Device's own system services, kernel messages and storage utilisation relating to the update process; it does not contain user traffic. Legal basis: our legitimate interest in the reliability of the update mechanism you have enabled (Art. 6(1)(f)); you may object as described in Section 9. Retention: thirty (30) days.
3.9 Infrastructure and security logs
Our cloud entry points maintain standard technical logs: load-balancer access logs recording the connecting IP address, requested API path and user agent (retained thirty (30) days); network flow logs (fourteen (14) days); and application logs (fourteen (14) days). These logs concern connections to our coordination APIs only. They are not, and by design cannot be, records of tunnel traffic, which does not terminate at those systems. Device activation events, including the connecting IP address, are retained for ninety (90) days to detect cloned or counterfeit hardware. Relay servers additionally maintain operational logs concerning their own service health, which are processed by our monitoring processor (Section 5.1) and retained by that processor for no longer than thirty (30) days.
Legal basis: our legitimate interest in network security, abuse prevention and service operation (Art. 6(1)(f)).
3.10 Data and practices we do not employ
We do not record, store or examine: the content of your network traffic (Section 4.1 describes what a relay must do with a packet in order to route it, and what it does not do); browsing history; per-connection or per-destination records; DNS query logs; advertising identifiers; analytics or behavioural profiles; device GPS or location-sensor data; contacts, photographs, camera or microphone data (the App requests no such permissions); payment-card numbers or other payment details (Section 1); your passwords; or your WireGuard private keys.
Automated checks may refuse the activation of hardware that fails authenticity verification (Section 3.2). You may contest such a refusal and obtain human review by contacting info@vploq.com. We carry out no other automated decision-making producing legal or similarly significant effects, and no profiling, within the meaning of Article 22 GDPR.
Our web pages do not use cookies or similar technologies for tracking, advertising or analytics. Strictly necessary security cookies may be set by our infrastructure providers.
3.11 Whether you are required to provide personal data
Providing an email address is a contractual requirement: without it we cannot create or operate your account. The device data described in Section 3.2 is necessary to register a device. You are under no statutory obligation to provide any personal data. All other data described in this Policy arises from your use of the Service.
4. Traffic and logging
We consider generalised "no-logs" statements insufficiently precise. This Section describes in detail what the Service records in connection with tunnel traffic and connectivity; all other records are described in Section 3.
4.1 Traffic content
Your devices reach one another in one of two ways, and the answer to "what can see this traffic" differs between them.
Directly. Where a direct connection between two of your devices can be established, the WireGuard tunnel runs end to end between those two devices. No relay server is in the path, and no system we operate can read that traffic.
Through a relay server. Where a direct connection cannot be established, a relay server carries the traffic — and that relay is itself an end of the tunnel, not a forwarder of somebody else's. It holds a WireGuard key of its own for your team, decrypts each packet in order to route it, and re-encrypts it for the onward hop. It has to: choosing where a packet goes means reading the packet's network and transport headers. We state this rather than leave it to be inferred from a phrase like "end-to-end encrypted", because on a relayed connection that phrase would not be accurate.
What a relay does not do is a matter of what is built rather than what is promised. There is no packet capture, no payload inspection, no flow export, no per-user or per-destination byte accounting, and no connection log. The traffic figures a relay measures are whole-server aggregates — total throughput, number of active peers, bytes transmitted this month — and those are what it reports. Translating addresses does require the operating-system kernel to hold per-connection state for as long as each connection lasts, as it does on an exit Device (below); that state lives in memory, is not written down, and no record of a connection outlives it.
Two things a relay reports are not whole-server figures, and we would rather name them than let "aggregates" imply more than it should. It reports the public address and port from which each device connects, because establishing a direct connection needs them; those are retained as stated in Section 4.3, and in a relay's own logs an address of this kind appears only at a diagnostic level which is discarded before the logs leave the machine. It also reports operational health figures per tunnel rather than per server — how many peers a tunnel carries and whether it is faulted — to the monitoring processor named in Section 5. A tunnel corresponds to one team, and is identified in those figures by a fragment of the team's internal identifier: no name, no email address, no network address, and nothing about the traffic itself.
Hardware Devices report a single current sixty-second aggregate byte counter for health display (Section 3.3); it is not stored, and no history exists. Rate-limiting rules applied against flooding discard excess packets without logging. Devices configured as exit points translate network addresses in the operating-system kernel, which requires per-connection state held in memory for as long as each connection lasts; there are no logging rules, no flow export and no per-destination counters, and no record of a connection outlives it.
4.2 DNS
Resolvers operated on exit Devices are configured with query logging disabled and respond from memory-resident caches only. Queries that cannot be answered from cache are forwarded over DNS over TLS (encrypted transport) to resolver services operated by Mullvad and by Quad9, each of which publishes a no-logging commitment for its resolver service. Such upstream resolvers observe queries as originating from the network address of the exit Device and receive no account identifier or other information from us.
One exception, and it is deliberate. Names that exist only on the local network the exit Device is plugged into — a printer, a network drive, another machine in the house — are unknown to any upstream resolver. So where an upstream resolver answers a request for an address record by saying the name does not exist, the exit Device retries that one request against the default gateway of its own local network, that is, against the router it is connected to. That retry is sent in clear over the local network and carries the name that was looked up. The answer is used only if it consists entirely of private network addresses; anything else is discarded and the original "does not exist" answer stands. Apart from this retry, queries forwarded by an exit Device on behalf of your devices leave it only over DNS over TLS.
No DNS query is written to persistent storage at any layer of the Service.
4.3 Connection metadata retained
| Record | Purpose | Retention |
|---|---|---|
| Device public IP address and port observed by a relay server | Establishment of direct peer-to-peer connections (NAT traversal) | One (1) hour from last observation |
| Connection candidates reported by a device (local and public addresses) | NAT traversal | Seven (7) days from last refresh |
| Most recent WireGuard handshake timestamp | Device status display; connection recovery | Current value only; overwritten upon each report |
| Public IP address on the device record | Routing; country display (Section 3.4); abuse prevention | While the device remains registered; deleted with the device. An inactive App installation is deleted automatically after ninety (90) days; a hardware Device or software node is deleted when you delete it or your account, not on a timer (Section 3.2) |
| Device activation events, including connecting IP address | Detection of cloned or counterfeit hardware | Ninety (90) days |
| Team and administrative activity logs (anonymised IP address; user agent) | Accountability of team and support actions | Ninety (90) days in the database, then thirty (30) days in an archive — one hundred and twenty (120) days in total |
| Load-balancer access logs (IP address; API path; user agent) | Security; abuse prevention; fault diagnosis | Thirty (30) days |
No component of the Service creates records associating your identity with the destinations of your traffic, because no component observes those destinations in unencrypted form or logs them.
4.4 Exit Devices and your IP address
If you enable a Device as an exit point, traffic of other members of your team exits to the internet through your network connection. The operators of visited services, and the upstream DNS resolvers named in Section 4.2, will observe your public IP address as the apparent origin of that traffic. You enable this function yourself and may disable it at any time in the App.
5. Recipients of personal data
5.1 Processors
We disclose personal data only to the processors listed below, solely to the extent necessary to operate the Service, and subject to data-processing agreements pursuant to Article 28 GDPR. The transfer mechanism column is explained in Section 6.
| Processor | Processing | Location of processing | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting of the Service: databases, computing, storage and logging; encrypted at rest | Frankfurt am Main, Germany (eu-central-1) | Not applicable (EU) |
| Hetzner Online GmbH | Operation of relay servers through which encrypted tunnel traffic transits; no traffic data is stored (Section 4.1) | Falkenstein, Germany; Helsinki, Finland | Not applicable (EU) |
| Google Ireland Limited, with Google LLC as sub-processor (Firebase Authentication and Cloud Messaging) | Sign-in identities (email address, authentication identifier); push-notification tokens and payloads | United States | SCCs; EU–U.S. DPF |
| Apple Inc. (Apple Push Notification service) | Delivery of push notifications on Apple platforms (device push token; notification payload) | United States | SCCs |
| Resend, Inc. | Delivery of transactional email (recipient address; message content, including invitation links) | United States | SCCs; EU–U.S. DPF |
| Cloudflare, Inc. | Object storage and delivery: firmware updates; time-limited data-export archives; device diagnostic bundles; service-status page; and the archive of team and administrative activity logs described in Section 4.3. Each archived entry is the complete log record as our database holds it, so it carries email addresses, truncated IP addresses, user-agent strings, our internal account, team and device identifiers, the account identifier held by our sign-in provider, and a free-form field describing the action — which, for a support look-up, includes the value that was looked up. The archive is written from the whole record deliberately, so that a field added to the log in future is carried into it rather than silently dropped | Global network (United States and other countries) | SCCs; EU–U.S. DPF |
| Functional Software, Inc. (Sentry) | Error and crash reports, minimised as described in Section 3.7 | United States | SCCs; EU–U.S. DPF |
| Grafana Labs | Operational logs and metrics of relay servers (service health telemetry) | United Kingdom (London); remote access by Grafana Labs personnel may occur from the United States | UK: adequacy decision; US access: SCCs |
Each Data Privacy Framework certification stated above was verified as active against the public list maintained by the United States Department of Commerce (dataprivacyframework.gov) on 4 August 2026. Apple Inc. does not participate in the Framework; transfers to Apple therefore rely on the Standard Contractual Clauses alone. Should a certification lapse, the Standard Contractual Clauses concluded with that processor continue to apply.
5.2 Other disclosures
We may disclose personal data where required by a legal obligation to which we are subject (Art. 6(1)(c)), or by a binding order of a court or competent authority. We can only disclose what we hold, and we hold no record of traffic content and no record of DNS activity (Section 4). We do not sell personal data and have never done so.
6. International data transfers
Personal data is stored within the European Union. Transfers to Grafana Labs' United Kingdom facilities are covered by the European Commission's adequacy decision in respect of the United Kingdom. Where a processor listed in Section 5.1 processes personal data in the United States or from other third countries, the transfer is performed on the basis of the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where the processor holds a valid certification, the EU–U.S. Data Privacy Framework adequacy decision. Access to personal data by us as controller from the United Arab Emirates is likewise performed on the basis of the Standard Contractual Clauses. These safeguards are supplemented by the technical measures described in this Policy, including transport encryption and data minimisation.
You may obtain a copy of the Standard Contractual Clauses we have concluded (redacted for commercial terms) by writing to info@vploq.com. The Commission's standard text is published on EUR-Lex (eur-lex.europa.eu).
7. Retention and deletion
Retention periods are stated per category in Sections 3 and 4.3. In summary: connection metadata, one hour to seven days, except device activation events (ninety days) and the current public IP address on the device record (life of the registration); infrastructure logs, fourteen to thirty days; activation logs, ninety days; team and administrative activity logs, one hundred and twenty days (ninety in the database and thirty in the archive); error reports, ninety days; device diagnostics, thirty days; inactive device records, ninety days; expired invitations, ninety days; data-export archives, forty-eight hours; account data, for the life of the account. Database backups are retained for no longer than thirty-five (35) days and expire automatically; backups are not used to restore deleted accounts, and personal data may persist in encrypted backups until the corresponding backup expires.
Upon account deletion, we immediately: deactivate the account; scrub personal data from device records and application-level activity records (names, addresses, IP addresses, location data); revoke the certificates of associated Devices; delete push-notification tokens and any data-export archives; and terminate all sessions. Infrastructure logs (Section 3.9) are not retroactively edited; they expire on their fixed schedules of fourteen to thirty days. Residual account data is permanently erased upon expiry of a thirty (30) day grace period, which exists solely to permit reversal of accidental deletion. Records retained beyond deletion in our live systems are limited to entries necessary for security purposes — such as the revocation record of a device certificate and the deletion event itself — and may include a pseudonymous internal identifier.
Erasure does not clear every field of the activity logs in Section 4.3, and we state what survives rather than leave it to be discovered. In each case the entry expires on the schedule given there — ninety (90) days in the database and thirty (30) days in the archive — and nothing renews it.
- Team activity logs. Your email address is replaced with a marker wherever it appears as the person who acted or the person acted upon. The truncated IP address and the user-agent string on those same entries are not removed.
- Administrative activity logs. These record actions our support staff took. Where an action involved looking you up, the record of what was done includes the value that was looked up — and where that value was your email address, the entry still contains it. These entries are not amended on erasure.
- Anything already archived. Entries of either kind that had been moved to the archive before your request cannot be amended at all: an archived object is written once and expires as a whole, and the scrub that clears the database cannot reach inside it.
Activation records are treated differently: the link to your account and the connecting IP address are cleared, leaving only the serial number and certificate fingerprint the record exists to preserve (Section 4.3).
8. Security
We apply technical and organisational measures appropriate to the risk, including: encryption of all tunnel traffic using the WireGuard protocol (ChaCha20-Poly1305; Curve25519) — end to end between your devices on a direct connection, and hop by hop where a relay server carries it (Section 4.1) — with each device's private key generated on, and never leaving, that device; mutual TLS authentication of Devices against our services using per-device certificates issued at activation; TLS for all connections to our APIs and for email delivery; encryption at rest of databases, secrets and logs using managed keys with automatic rotation; cryptographic signing of firmware updates, verified by the Device before installation; and restricted access to production systems using short-lived credentials.
No system is perfectly secure. In the event of a personal data breach we will notify the competent supervisory authority and, where required, affected data subjects in accordance with Articles 33 and 34 GDPR.
If you believe you have found a security vulnerability in the App, the Device or our services, please tell us. How to do that, and what we undertake to do in return, is set out in our vulnerability disclosure policy. The same contact is published in machine-readable form at /.well-known/security.txt.
9. Your rights
9.1 Rights under the GDPR
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), the right, where processing is based on your consent, to withdraw that consent at any time with effect for the future (Art. 7(3)), and the right to lodge a complaint with a supervisory authority (Art. 77). You may also request further information on the balancing assessments underlying our legitimate-interest processing.
Right to object (Art. 21). Where we process your personal data on the basis of legitimate interests (identified per category in Section 3), you have the right to object at any time, on grounds relating to your particular situation. We will then cease the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
9.2 Self-service means
The following may be exercised directly in the App:
- Access and portability. Profile → My information → Request data export: a machine-readable archive of your personal data, accompanied by a disclosure statement listing recipients and retention periods; available for forty-eight (48) hours following generation; limited to one request per twenty-four (24) hours; subject to re-authentication.
- Erasure. Profile → My information → Delete account, with the effects described in Section 7.
- Rectification. Account details in the Profile screen; devices may be renamed or removed at any time.
- Objection to diagnostics. The Diagnostics setting (Section 3.7) may be turned off at any time, subject to the limits stated there.
9.3 Requests
Requests may also be made to info@vploq.com. We respond within one month of receipt; this period may be extended by two further months for complex or numerous requests, in which case we will inform you within the first month (Art. 12(3) GDPR). We will verify the identity of the requester before acting on a request and may ask for further information for that purpose.
9.4 Complaints
You may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of an alleged infringement. A directory of EU supervisory authorities is maintained by the European Data Protection Board (edpb.europa.eu).
10. Children
The Service is not directed at children below the age of sixteen (16), and we do not knowingly process the personal data of such children. Where we become aware that such data has been collected, we will delete it. Reports may be made to info@vploq.com.
11. Additional information for certain jurisdictions
This Policy is written to the standard of the GDPR, which we apply to all users worldwide as our baseline. The following subsections state additional disclosures required by particular jurisdictions. Where the law of your jurisdiction grants you further rights, we will honour them; contact info@vploq.com.
11.1 California
In the preceding twelve months we have collected the following categories of personal information as defined by the California Consumer Privacy Act: identifiers (email address, name, account and device identifiers, IP address) — retained for the life of the account or of the device registration (Sections 3 and 7); internet or other electronic network activity information (limited to the API access logs and connection metadata described in Sections 3.9 and 4.3; we do not collect browsing history) — retained between one hour and ninety days; coarse geolocation data (country, derived from IP address) — retained while the device remains registered; and sensitive personal information limited to account log-in credentials, which are processed by our authentication provider (we never receive your password) and used solely to authenticate you.
We collect this information from you and your devices and, in the case of invitation email addresses, from the team member who invites you. We use it for the purposes stated in Section 3 and disclose it only to the service providers listed in Section 5.1. We do not sell personal information and do not share personal information for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We have no actual knowledge of selling or sharing the personal information of consumers under sixteen (16) years of age. We do not use or disclose sensitive personal information for purposes other than providing the Service.
California residents have the rights to know, to delete, to correct, and to non-discrimination, exercisable in the App (Section 9.2) or at info@vploq.com. An authorized agent may submit a request on your behalf at the same address; we will require proof of authorization and verify your identity. Because we do not sell or share personal information, there is no opt-out to be exercised through opt-out preference signals such as Global Privacy Control; we honour the substance of such signals by not engaging in the practices they are designed to prevent.
12. Changes to this Policy
We may amend this Policy from time to time. Amendments will be published at this address with an updated effective date; previous versions are available on request. In the case of material changes — including new categories of personal data, new purposes of processing or new categories of recipients — we will provide prior notice through the App or by email.
13. Contact
InTallyCon Development - FZCO DDP, Building A1 Dubai, United Arab Emirates
We have not appointed a data protection officer, as we are not required to do so under Article 37 GDPR; the contact above handles all data-protection matters.
WireGuard is a registered trademark of Jason A. Donenfeld.