Privacy Policy
Updated: July 13, 2026
1. Introduction
This Privacy Policy explains how Borderless AS (“Company,” “we,” “our,” or “us”) collects, uses, stores, and protects personal and organizational data when you access or use the Borderless AS corporate virtual private network platform (“BVPN” or the “Service”). By using the Service, you agree to the practices described in this Privacy Policy. This Policy applies to all Users, including Owners, Administrators, and Members within an Organization.
2. Information We Collect
2.1. Account & Organization Information
We collect information provided during registration and account setup, including Organization name, contact details, Owner and Administrator information, billing details, and subscription data.
2.2. Subscription Data
To provide and manage your subscription, we process information related to your chosen plan, billing cycle, renewal dates, and payment status. This data is linked to your account and stored securely for the duration of your business relationship. Your subscription will automatically renew unless you cancel it through your account settings or the platform where you purchased the Service. If you cancel, we may retain limited subscription data (such as plan type, transaction history, and renewal status) for a period necessary to comply with legal and accounting obligations, resolve disputes, and facilitate potential re-subscriptions.
2.3. User Information
We may collect user identifiers such as name, email address, role, and authentication data (e.g., MFA status).
2.4. Technical & Device Information
We may collect device type, OS, app version, connection timestamps, and servers region. We do NOT collect or store browsing activity, DNS queries, traffic content, destination IPs, or application usage data. BVPN is a zero-traffic-logging service.
2.5. Payment Information
Payments are processed by PCI-compliant third-party providers. We do not store full credit card numbers.
2.6. Support Interactions
We may collect support communications, diagnostic logs, and troubleshooting data voluntarily shared by the Organization.
3. How We Use Information
We use collected information to provide and improve the Service, authenticate users, manage billing, deliver support, monitor performance, prevent abuse, and comply with legal obligations. We do not sell or rent personal information.
4. Legal Basis for Processing (GDPR)
For EU/EEA Organizations, processing is based on contractual necessity, legitimate interests, legal compliance, or explicit consent where required.
5. Data Retention
We retain data only as long as necessary for service delivery, legal compliance, dispute resolution, and enforcement. Upon account termination, account data may be deleted within 30–90 days. No VPN traffic logs exist to delete.
6. Data Sharing & Disclosure
We may share limited data with service providers, compliance partners, or law enforcement when legally required. We do not share VPN traffic data because we do not collect it.
7. International Data Transfers
Data may be processed in countries where we or our providers operate. Safeguards include SCCs, DPAs, and encryption.
8. Security Measures
We implement AES-256 encryption, secure tunnels, MFA, RBAC, zero-traffic-logging architecture, and regular audits. Organizations are responsible for internal access policies.
9. Organization Responsibilities
Organizations must ensure user compliance, configure security settings, manage roles, and maintain legal compliance.
10. Children’s Privacy
The Service is not intended for individuals under 18. We do not knowingly collect information from minors.
11. Your Rights
Depending on jurisdiction, users may request access, correction, deletion, restriction, export, or objection. Requests must be submitted through the Organization’s Owner.
12. Changes to This Policy
We may update this Policy periodically. Continued use of the Service constitutes acceptance of the updated Policy.
13. Contact Us
For privacy inquiries: support@borderlessvpn.freshdesk.com