Privacy Policy
Last updated: March 28, 2026
1. Introduction and Commitment to Privacy
At MiVPN we are committed to protecting the privacy of our users and customers. This Privacy Policy explains what personal data we collect, the purposes for which we process it, the legal basis, who we share it with, how long we retain it and what rights the user has.
Personal data is processed in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (GDPR), Spanish Organic Law 3/2018 of December 5 on Personal Data Protection and Digital Rights Guarantee (LOPDGDD) and any other applicable data protection legislation.
Accessing and using MiVPN's website and services implies reading and accepting this Privacy Policy. If the user disagrees with its content, they must refrain from using the services.
2. Data Controller
The data controller for personal data collected through the websites mivpn.net and mivpn.es is:
- Controller: Rabi Ouallam Jamladi
- Tax ID (NIF): 77681099W
- Business address: Rúa A Pomba 13 1º, 36162 Pontevedra (Pontevedra), Spain
- Phone: +34 623 947 143
- Privacy email: privacy@mivpn.net
- Support email: soporte@mivpn.net
For any queries regarding the processing of personal data or the exercise of rights, the user may contact privacy@mivpn.net.
3. Personal Data We Process
MiVPN applies the principle of data minimisation and only collects the data strictly necessary for each purpose. The categories of data we may process are:
- Identification and contact data: first name, surname(s), email address and phone number.
- Shipping address: street, number, floor, postcode, city and province, necessary for the management of shipping and delivery of the physical products MiVPN and WiVPN in Spain. This data is only collected when the user contracts a product requiring physical delivery.
- Country of residence or billing: necessary for the correct issuance of invoices, the application of the applicable VAT rate under the tax regulations in force in each country, and compliance with tax obligations arising from international contracting.
- Account and authentication data: username, encrypted password, session identifiers and account access logs.
- Service configuration data: VPN name, network configuration, country or location selected for the VPN connection, necessary for the technical provision of the service.
- Payment and billing data: data necessary for the management of charges, subscriptions and invoice issuance. Full card data is managed entirely by Stripe and is not stored by MiVPN (see Section 7).
- Technical and usage data: IP address used to connect to the panel or website, device type, operating system, browser, technical logs strictly necessary to operate, protect and maintain the services.
- Communications data: content of messages exchanged with the support team, incidents and complaints.
- Preferences and consents: language settings, notification preferences, privacy settings and records of consents granted.
- Cookie and similar technology data: as described in the Cookie Policy.
MiVPN does not process special categories of data (health data, ethnic origin, ideology, religion, sexual life or other data referred to in Article 9 of the GDPR), nor data of persons under 14 years of age. If we detect that a minor has provided data without the consent of their legal representatives, we will proceed to delete it immediately.
4. Data We Do Not Process as Ordinary Usage Content
MiVPN applies a principle of enhanced data minimisation in the context of VPN services. In services where a "no-logs" policy is expressly stated, MiVPN does not record the content of user traffic or browsing history as part of the ordinary operation of the service.
However, limited and proportionate processing of minimum technical data may be carried out where strictly necessary to:
- resolve serious technical incidents affecting service availability or security;
- detect and prevent fraud, abuse or malicious activity in accordance with the General Terms;
- comply with a legal obligation or request from a competent authority.
In such cases, processing will always be carried out in accordance with the GDPR, LOPDGDD and applicable regulations, limited to the minimum necessary and for the strictly required time.
5. Purposes of Processing
MiVPN processes users' personal data for the following purposes:
- Creating, managing and maintaining the user's account.
- Providing the contracted services: MiVPN, WiVPN and SiVPN.
- Managing payments, recurring subscriptions, billing and refunds through Stripe.
- Providing technical support, customer service and handling incidents and complaints.
- Detecting, preventing and investigating fraud, abuse, unauthorised access and security incidents.
- Complying with applicable legal, tax, accounting and regulatory obligations.
- Sending service communications necessary for the performance of the contract (renewal notices, service changes, incidents, etc.).
- Sending commercial and promotional communications, only where the user has given express consent or where there is sufficient legal basis, with the possibility of withdrawal at any time.
- Improving the features, performance, stability and user experience of the services.
- Managing the shipment and delivery of physical products (MiVPN and WiVPN) in Spain.
6. Legal Bases for Processing
Each data processing activity is based on one of the following legal grounds set out in Article 6 of the GDPR:
- Performance of a contract (Art. 6.1.b GDPR): processing necessary for the provision of contracted services, account management, billing and support.
- Compliance with a legal obligation (Art. 6.1.c GDPR): retention of invoices and accounting records, responding to requests from competent authorities, compliance with tax and international sanctions regulations.
- Consent of the data subject (Art. 6.1.a GDPR): sending commercial communications, use of non-essential cookies and other optional processing. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
- Legitimate interest (Art. 6.1.f GDPR): fraud prevention, system security, service improvement, legal defence and internal management, subject to a balancing of interests where applicable.
7. Recipients and Data Processors
MiVPN does not sell personal data to third parties. Data may be accessible to or shared with the following recipients where necessary for the provision of the service or by legal obligation:
- Stripe Payments Europe, Ltd. — payment service provider based in Ireland and regulated by the Central Bank of Ireland. Stripe acts as a data processor for the management of charges, subscriptions and card data under PCI-DSS standards. MiVPN does not store full card data. Stripe's privacy policy: https://stripe.com/en/privacy.
- Infrastructure and hosting providers: companies that host MiVPN's servers, databases and systems, with whom the corresponding data processing agreements have been signed.
- Transactional messaging and support providers: platforms used for sending service emails, notifications and managing support tickets.
- Monitoring and security providers: tools used to detect technical incidents, unauthorised access attempts or abusive behaviour.
- Advisors and financial institutions: where necessary to comply with accounting, tax or commercial obligations.
- Public authorities, courts and tribunals: where there is a legal obligation or formal request requiring it.
All data processors have signed or are subject to contractual commitments of confidentiality and security in accordance with the GDPR.
8. International Data Transfers
As MiVPN provides services to users worldwide and uses infrastructure and technology providers that may be established outside the European Economic Area (EEA), international transfers of personal data may occur.
Such transfers will only take place where one of the following safeguards provided for in Chapter V of the GDPR is in place:
- European Commission adequacy decision: where the destination country has a recognised adequate level of protection (for example, the United Kingdom, Switzerland, Japan or countries covered by the EU-US adequacy framework).
- Standard Contractual Clauses (SCCs): approved by the European Commission, signed with processors or controllers located in third countries without an adequacy decision.
- Binding Corporate Rules (BCRs): where the provider has approved binding corporate rules.
- Other appropriate safeguards provided for in Article 46 of the GDPR.
The user may request information about international transfers affecting their data and the applicable safeguards by writing to privacy@mivpn.net.
9. Data Retention Periods
Personal data will be retained for the time strictly necessary to fulfil the purpose for which it was collected and, in all cases, for the legally established periods:
- Account and service data: while the account is active and, following its cancellation, for a maximum period of 3 years to address potential claims, unless a longer legal retention obligation applies.
- Billing and accounting data: 6 years from the date of invoice issuance, in accordance with Article 30 of the Spanish Commercial Code and applicable tax regulations.
- Payment data managed by Stripe: in accordance with Stripe's retention policy and applicable payment services regulations.
- Support communications: up to 3 years from the closure of the incident, unless they must be retained for a longer period for legal or defence purposes.
- Commercial communications: until the user withdraws consent or exercises the right to object.
- Cookie and analytics data: as indicated in the Cookie Policy.
- Minimum technical logs: the time strictly necessary to fulfil their operational or security purpose, with a maximum of 12 months unless a different legal obligation applies.
Once retention periods have expired, data will be securely deleted or anonymised, unless it must be retained by legal obligation or for the establishment, exercise or defence of claims.
10. Data Subject Rights
The user may exercise at any time the following rights recognised by the GDPR and LOPDGDD:
- Right of access (Art. 15 GDPR): to know what personal data MiVPN processes about the user and to obtain a copy of it.
- Right to rectification (Art. 16 GDPR): to request the correction of inaccurate or incomplete data.
- Right to erasure or "right to be forgotten" (Art. 17 GDPR): to request the deletion of data when, among other reasons, it is no longer necessary for the purpose for which it was collected.
- Right to restriction of processing (Art. 18 GDPR): to request the suspension of data processing in certain circumstances provided for by the GDPR.
- Right to data portability (Art. 20 GDPR): to receive personal data provided in a structured, commonly used and machine-readable format, or to request its direct transmission to another controller where technically possible.
- Right to object (Art. 21 GDPR): to object to the processing of data based on legitimate interest or for direct marketing purposes, with immediate effect in the latter case.
- Right not to be subject to automated decisions (Art. 22 GDPR): not to be subject to decisions based solely on automated processing of data that produce significant legal effects, except in cases provided by law.
- Right to withdraw consent: at any time and without retroactive effect, where processing is based on the user's consent.
To exercise any of these rights, the user must send a written request to privacy@mivpn.net, indicating the right they wish to exercise and enclosing a copy of their identity document or other means of identity verification. MiVPN will respond within a maximum period of one month from receipt of the request, which may be extended by a further two months in cases of particular complexity, with prior notification to the data subject.
If the user considers that the processing of their data does not comply with applicable regulations, they may lodge a complaint with the Spanish Data Protection Agency (AEPD), the competent supervisory authority, through its electronic portal: https://www.aepd.es.
11. User Responsibility Regarding Data Provided
The user warrants that the personal data provided to MiVPN is truthful, accurate, complete and up to date, and undertakes to keep it current. The user also declares that they are over 18 years of age or, where applicable, that they have the consent of their legal representatives to provide their data.
The user shall be liable for any damages arising from the provision of false, inaccurate, incomplete or outdated data, or third-party data without their consent.
12. Data Security
MiVPN has implemented the necessary technical and organisational measures to ensure the security of personal data and prevent its alteration, loss, processing or unauthorised access, taking into account the state of technology, the nature of the data and the risks to which it is exposed. Such measures include, without limitation:
- Encryption of communications using secure protocols (TLS/HTTPS).
- Encryption of stored passwords using secure hashing algorithms.
- Role-based access control and authentication for staff with access to data.
- Monitoring of access and suspicious activity on systems.
- Management of card data exclusively through Stripe under PCI-DSS standards.
However, MiVPN cannot guarantee absolute security against all possible technical risks. In the event of a security breach that may pose a risk to users' rights and freedoms, MiVPN will notify the AEPD and, where applicable, the affected individuals, within the timeframes and under the conditions set out in Articles 33 and 34 of the GDPR.
13. Cookies and Similar Technologies
MiVPN's website uses first-party and third-party cookies. Details about the types of cookies used, their purpose, duration and how to manage or disable them can be found in MiVPN's Cookie Policy, available on the website, which forms an integral part of this privacy framework.
14. Commercial Communications
MiVPN may send commercial communications about its own products and services where the user has given express consent or where there is a pre-existing contractual relationship that supports it, in accordance with Article 21 of the LSSI-CE.
The user may withdraw their consent and unsubscribe from commercial communications at any time, free of charge and easily, through the unsubscribe link included in each communication or by writing to privacy@mivpn.net.
MiVPN will not disclose the user's data to third parties for the sending of third-party commercial communications without the user's express consent.
15. Changes to the Privacy Policy
MiVPN reserves the right to amend this Privacy Policy to adapt it to regulatory, case law, technical or service changes. Relevant changes will be communicated to the user by notice on the website, by email or through the account panel, with sufficient advance notice before taking effect.
The updated version will always be available on the website, with the date of the last update indicated. Continued use of the services after the changes take effect will constitute acceptance of the updated Policy.
16. Applicable Law and Supervisory Authority
This Privacy Policy is governed by the GDPR and LOPDGDD, as well as applicable Spanish and European data protection legislation.
The competent supervisory authority in Spain is the Spanish Data Protection Agency (AEPD), located at Calle Jorge Juan, 6, 28001 Madrid, with an electronic portal at https://www.aepd.es.