Privacy Policy
Archived release: v1. Updated: September 17, 2026.
Use your browser’s print command to print or save this complete document as a PDF.
WATTENNE INTERNATIONAL LLC (“Company,” “we,” “us,” or “our”) is committed to protecting the privacy and security of our customers (“Customer,” “you,” or “your”).
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit databay.com and app.databay.com (together, the “Site”) and use our proxy services, APIs, and dashboard (collectively, the “Services”).
Our data-minimization policy is to limit personal data to what is needed for the purposes described here, including service delivery, payments, account security, abuse review, and legal compliance. The categories and retention rules below explain the scope of that policy.
1. Information We Do NOT Collect (Zero Payload Logging)
WE DO NOT INSPECT, LOG, STORE, OR MONITOR THE PAYLOAD DATA OF CUSTOMER TRAFFIC.
When you use our Proxy Services, on the systems we operate we do not inspect, log, or store:
The content of the websites you visit.
The data you transmit (POST data, form bodies, files, messages).
Your usernames, passwords, or API keys sent to third-party destinations.
The specific URLs (paths, query parameters) beyond the destination hostname.
These statements describe systems Databay operates; Customer Traffic also transits third-party network infrastructure that Databay does not operate. For proxy traffic, we provide routing infrastructure at your direction. We separately process account, authentication, billing, security, abuse-prevention, support, analytics, and legal-compliance data as described below. We are therefore not acting only as a passive conduit for every category of personal data.
2. Information We Collect
We distinguish account and dashboard information, proxy Operational Logs, and information supplied in support, abuse, and legal matters. Website analytics and third-party processing are described separately below.
2.1. Account & Dashboard Information
When you register for an account, purchase services, or interact with our dashboard, we collect:
Identity Data: First name and last name.
Contact Data: Email address.
Technical Access Data: The IP address used to log in to the dashboard and your User-Agent string.
Activity Logs: Account identifiers, actions performed within the dashboard and via the API (e.g., API key generation and settings changes), and associated times, access IP addresses, and User-Agent information for security auditing.
Billing Information: Billing address, payment history, payment-processor customer and payment-method reference IDs, subscription preferences and settings, and records of checkout requests and authorizations, including their wording version and time. We use these records to process payments, operate automatic top-ups, send transactional notices and resolve disputes. Note: We do not store full credit card numbers or card security codes on our servers.
2.2. Proxy Service Operational Logs (Metadata)
Our proxy Operational Logs record metadata for operating the network, metering bandwidth, and reviewing security or abuse issues:
Source IP Address: The IP address from which you initiate the connection to our proxy servers.
Connection Counters: Counts associated with destination domains or directly addressed destination IPs (e.g., 50 connections to
example.com).Bandwidth Usage: Uploaded and downloaded byte totals for metering and billing.
These records are associated with an account and reporting period. Metering and connection-count records also use account or proxy-user identifiers, service/network categories, and Company gateway identifiers. Our gateway request logs do not record the final proxy exit IP used for your connection, and we do not have a mapping from that exit IP to your account. Source IPs, destination IPs, and Company gateway identifiers are distinct from the final exit IP seen by a destination.
We can review available destination-domain records and other relevant information. Because we do not hold a final-exit-IP mapping, an exit IP and incident timestamp alone do not identify an account in our gateway request logs. Available information may be insufficient to attribute an incident to an account or downstream user.
2.3. Support, Abuse Reports, and Legal Matters
We process the contact details, correspondence, incident details, and evidence supplied when someone contacts us or reports suspected abuse. Abuse-report submissions also include a case reference, submission time, and reporter source IP. Submitted evidence can contain URLs, screenshots, or other information supplied by the reporter; it is separate from our proxy Operational Logs and is not collected by inspecting proxy payloads. Please omit passwords, API keys, unrelated personal information, and unnecessary sensitive material.
3. How We Use Your Information
We use the collected information for the following specific purposes:
Service Provision: To authenticate your access, route your traffic, and manage your account.
Billing: To calculate bandwidth consumption and process payments.
Security & Abuse Prevention: To detect and mitigate fraudulent activity, botnets, DDoS attacks, and violations of our Terms of Use.
Legal Compliance: To comply with applicable legal obligations, tax laws, and regulatory requirements.
Communication: To send you transactional emails (receipts, password resets) or critical service updates.
Analytics & Site Improvement: To measure audience, performance, and interactions on the public marketing Site, as described in Section 8.
Abuse & Trust and Safety: To receive, investigate, and respond to abuse reports and related legal or safety inquiries.
4. Third-Party Data Processors
We use third-party providers for payments, identity verification, analytics, and infrastructure. We transmit information needed for those services. We do not store full payment-card numbers or card security codes on our servers. Identity-verification processing is described below; a provider's own processing is also governed by its applicable terms and privacy information.
A. Payment Processors
Stripe performs transaction monitoring for credit card payments and Confirmo for cryptocurrency payments under their respective services and policies. We may receive payment status, risk alerts, and related information made available by these providers and use that information to review payments, resolve disputes, or respond to suspected abuse. Provider checks do not replace our own obligations under applicable law.
Stripe (Credit/Debit Card)
Address: 185 Berry Street, Suite 550, San Francisco, CA 94107, USA
Data Shared: Name, Email, Billing Address, Payment Amount.
Privacy PolicyConfirmo (Cryptocurrency)
Address: 33 Sir John Rogerson's Quay, Dublin, D02 XK09, Ireland
Data Shared: Invoice and transaction information, email, and individual or company name and billing details supplied for the payment.
Privacy Policy
B. Identity Verification (KYC)
Persona Identities, Inc. (withpersona.com), United States
Data Shared: Account/contact and identity information needed to initiate verification. ID documents, photos, and biometric information requested in the verification flow are submitted directly to Persona under the notices and consent presented there. Persona sends verification responses that we process to assess the outcome and identity match. Our verification records contain status and reference identifiers, verification times, identity-match information, and verification-session IP and User-Agent information. We do not retain copies of raw ID-document images in those verification records.
Privacy Policy
C. Analytics
Google LLC (Google Analytics 4)
Data Shared: device, browser, page, interaction, network, and approximate-location data for the public marketing Site.
Privacy PolicyMicrosoft Corporation (Clarity)
Data Shared: device, browser, page, and interaction data (session replays, heatmaps) for the public marketing Site.
Privacy StatementCloudflare, Inc. (Cloudflare Web Analytics)
Data Shared: page and referrer, browser/device, network and approximate-location, and performance/timing data from the public marketing Site. This consent-controlled client beacon is separate from Cloudflare's infrastructure-level delivery, security, and request analytics.
Privacy Policy
D. Infrastructure and Communications
Hosting, content-delivery, and security providers that operate the servers and networks behind the Site and dashboard (data processed: technical access data and service logs).
Transactional email delivery providers (data processed: email address and the content of service emails).
E. Network Partners
Third-party network infrastructure used to route Customer Traffic (data processed: traffic routing data necessary to carry connections).
5. Disclosure of Information to Law Enforcement
We handle law-enforcement requests subject to applicable law, including rules governing disclosure, confidentiality, and international transfers. An official request does not, by itself, authorize unrestricted access to customer information.
Standard for Disclosure: We disclose customer information when required by valid and applicable legal process binding on us, or when disclosure is otherwise permitted by applicable law. We assess the authority's identity, jurisdiction, requested records, and legal basis. Different requirements can apply to communications content and non-content records; a subpoena or an official email does not authorize every category of disclosure. A general interest in preventing fraud or enforcing our Terms, or acceptance of this policy, does not override communications-privacy or international-transfer restrictions. We make reports required by applicable law. Disclosures to payment providers for payment review remain subject to applicable law and the purposes described in this policy.
Emergencies and Scope Review: We may disclose relevant information without ordinary compulsory process only when an applicable legal exception permits it and its conditions are met. For example, where the applicable US communications-privacy exception applies, it requires a good-faith belief that an emergency involving danger of death or serious physical injury requires disclosure without delay. Where legally permitted and appropriate, we may request clarification or narrowing of a request or seek legal review; we do not promise to challenge every request.
Scope of Disclosure: Disclosures are limited to records in our possession that are relevant to the request or other lawful purpose and that we may or must disclose. These may include account, access, billing, and limited proxy metadata described in Section 2. We do not store proxy payload content as part of ordinary service operation. Records may be preserved for a specific investigation, dispute, or legal obligation as described in Section 9.
User Notification: We do not routinely notify users of official inquiries or related disclosures. We provide notice when required by applicable law, subject to any lawful exception or restriction. Where legally permitted, notice may be withheld or delayed to comply with confidentiality requirements or avoid prejudicing an investigation. This provision does not waive any mandatory user rights or retroactively change the privacy commitments applicable to previously collected data.
Receipt of an official inquiry does not automatically suspend or terminate an account. Account restrictions and preservation requests are handled subject to applicable law and the enforcement provisions of the Terms of Use.
Preservation concerns relevant records already held and does not itself authorize disclosure. This policy does not authorize new payload monitoring or promise to create records that we do not maintain. See our Law Enforcement Guidelines for request information.
6. International Data Transfers
WATTENNE INTERNATIONAL LLC is a Wyoming, United States limited liability company. The business is managed from Thailand and uses global infrastructure and service providers. US incorporation does not mean that all access to or processing of personal information occurs in the United States. Your information may be transferred to, stored, accessed, or processed in countries other than your country of residence.
International processing is subject to applicable data-protection and transfer requirements. Where a transfer requires a legal basis and a separate transfer mechanism or safeguard, both must be satisfied; a request from a foreign authority or a general reference to legitimate interests does not by itself satisfy those requirements. Contact privacy@databay.com for information about the locations and safeguards applicable to your data. This policy does not represent that a particular certification, adequacy decision, or contractual transfer mechanism covers every recipient or transfer.
7. Your Data Rights (GDPR & CCPA)
Depending on your location, you have specific rights regarding your personal data. We extend these rights to all our users globally where technically feasible.
Right to Access: You may request a copy of the personal data we hold about you.
Right to Rectification: You may request that we correct inaccurate or incomplete data.
Right to Deletion (Right to be Forgotten): You may request that we delete your account and personal data, subject to our legal obligations to retain certain financial/transaction records for tax and legal compliance.
Right to Portability: You may request a copy of your data in a structured, machine-readable format.
Right to Object and to Restrict Processing: You may object to processing based on our legitimate interests and request restriction while we assess your objection.
Right to Withdraw Consent: Where processing is based on consent (for example, analytics cookies), you may withdraw it at any time without affecting prior processing.
Right to Complain: If you are in the EEA or the UK, you may lodge a complaint with your local data protection supervisory authority.
Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
We do not sell personal information as “sell” is defined by applicable law, and we do not use it for cross-context behavioral advertising.
Automated decisions: Some account risk controls (for example, verification triggers and payment-risk checks) run automatically. Where an automated control materially affects your account, you may contact us to request human review.
Legal bases (EEA/UK): We process personal data (i) to perform our contract with you (service provision, billing, support); (ii) for our legitimate interests (security, abuse prevention, fraud prevention, service improvement); (iii) with your consent (analytics cookies where consent is required, marketing); and (iv) to comply with legal obligations (tax, accounting, sanctions, lawful requests).
To exercise these rights, please contact us at support@databay.com. We will respond to verifiable requests within 30 days (or any shorter period required by law).
8. Cookies and Tracking Technologies
The Dashboard uses cookies or similar storage necessary for authentication, security, preferences, and service operation. The public marketing Site uses Google Analytics 4, Microsoft Clarity, Cloudflare Web Analytics, and a first-party Core Web Vitals reporter for audience, performance, and interaction analytics, as described in Section 4. Those services may use cookies or similar storage under their respective terms.
Essential Technologies: These support login, security, navigation, preferences, and requested functionality, and do not require consent.
Analytics Technologies: Where applicable law requires prior consent (including the EEA, the United Kingdom, and Switzerland), analytics technologies load only after you consent through the cookie banner, and you can change or withdraw your choice at any time through the banner settings.
Advertising: We do not operate behavioral-advertising pixels on the Site.
The analytics choice controls the client-side Cloudflare Web Analytics beacon. It does not disable Cloudflare's infrastructure-level content delivery, security, traffic measurement, or request logs that are necessary to operate and protect the Site.
You can also use browser controls to delete or block cookies, although blocking necessary storage may prevent login or Dashboard functions.
9. Data Retention
Our retention policy distinguishes ordinary service records from financial records and records needed for a specific incident or legal obligation:
Account, Access, and Verification Records: Used during the account relationship and for applicable security, verification, dispute, or legal needs afterward. A financial-record requirement does not automatically apply to every item of account or access data.
Billing and Financial Records: Retained for the tax, accounting, payment-dispute, and other legal periods applicable to the particular record. Necessary transaction records may remain after account closure.
Operational Logs: The ordinary retention policy is 180 days, subject to scoped preservation below. This period does not guarantee that every type of record exists or remains available for attribution throughout that period.
Abuse Cases, Disputes, and Legal Holds: Relevant existing records may be preserved for as long as needed for the identified matter or required by applicable law. Preservation is limited to the relevant records and purpose; receiving an inquiry does not by itself justify indefinite retention of all account data. When the preservation basis ends, ordinary retention and applicable deletion requirements apply.
Deletion requests are subject to applicable preservation duties and the handling of copies in backups. We do not promise immediate erasure of every backup copy or irreversible aggregation. Backups are not a basis for unrelated uses or indefinite retention. Third-party providers' retention is governed by their applicable obligations and arrangements; the 180-day policy does not represent a verified retention period for every provider.
10. Security
We state that we use administrative, technical, and physical measures intended to protect personal information, including TLS for supported data in transit and access controls. This public page does not provide an independent certification, audit report, or guarantee of security. No internet transmission or storage system is risk-free. If a security incident affects your personal data, we will notify affected users and the relevant authorities as required by applicable law.
11. Children's Privacy
Our Services are not intended for individuals under the age of 18. We do not knowingly seek personal information from children. If we learn that we processed a child's data in a way not permitted by applicable law, we will take reasonable steps to delete or otherwise address it, subject to legal preservation duties.
12. Changes to This Policy
We publish updates on this page and revise the date shown above. Please review this page periodically. Material changes are subject to the notice and effective-date requirements in Section 3 of the Terms of Use, including at least fourteen (14) days' advance notice to affected existing customers by email; we may also provide a prominent account/dashboard notice. Additional requirements under applicable law or the agreement then in force remain applicable. Publication or dashboard acceptance alone does not replace required notice or consent, and the page's revision date is not, by itself, the date a material change takes effect for an existing customer.
Where applicable law requires consent to a new data practice, we will obtain that consent before applying it. Continued use of the Services is not a substitute for any required consent. An update does not retroactively authorize new uses or disclosures of previously collected data contrary to the privacy commitments applicable to that data.
13. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
WATTENNE INTERNATIONAL LLC
30 N Gould St Ste N
Sheridan, WY 82801
USA
Email: support@databay.com