Privacy Policy

Updated: July 13, 2026

1. Introduction

This Privacy Policy explains how Borderless AS (“Company,” “we,” “our,” or “us”) collects, uses, stores, and protects personal and organizational data when you access or use the Borderless AS corporate virtual private network platform (“BVPN” or the “Service”). By using the Service, you agree to the practices described in this Privacy Policy. This Policy applies to all Users, including Owners, Administrators, and Members within an Organization.

2. Information We Collect

2.1. Account & Organization Information

We collect information provided during registration and account setup, including Organization name, contact details, Owner and Administrator information, billing details, and subscription data.

2.2. Subscription Data

To provide and manage your subscription, we process information related to your chosen plan, billing cycle, renewal dates, and payment status. This data is linked to your account and stored securely for the duration of your business relationship. Your subscription will automatically renew unless you cancel it through your account settings or the platform where you purchased the Service. If you cancel, we may retain limited subscription data (such as plan type, transaction history, and renewal status) for a period necessary to comply with legal and accounting obligations, resolve disputes, and facilitate potential re-subscriptions.

2.3. User Information

We may collect user identifiers such as name, email address, role, and authentication data (e.g., MFA status).

2.4. Technical & Device Information

We may collect device type, OS, app version, connection timestamps, and servers region. We do NOT collect or store browsing activity, DNS queries, traffic content, destination IPs, or application usage data. BVPN is a zero-traffic-logging service.

2.5. Payment Information

Payments are processed by PCI-compliant third-party providers. We do not store full credit card numbers.

2.6. Support Interactions

We may collect support communications, diagnostic logs, and troubleshooting data voluntarily shared by the Organization.

3. How We Use Information

We use collected information to provide and improve the Service, authenticate users, manage billing, deliver support, monitor performance, prevent abuse, and comply with legal obligations. We do not sell or rent personal information.

4. Legal Basis for Processing (GDPR)

For EU/EEA Organizations, processing is based on contractual necessity, legitimate interests, legal compliance, or explicit consent where required.

5. Data Retention

We retain data only as long as necessary for service delivery, legal compliance, dispute resolution, and enforcement. Upon account termination, account data may be deleted within 30–90 days. No VPN traffic logs exist to delete.

6. Data Sharing & Disclosure

We may share limited data with service providers, compliance partners, or law enforcement when legally required. We do not share VPN traffic data because we do not collect it.

7. International Data Transfers

Data may be processed in countries where we or our providers operate. Safeguards include SCCs, DPAs, and encryption.

8. Security Measures

We implement AES-256 encryption, secure tunnels, MFA, RBAC, zero-traffic-logging architecture, and regular audits. Organizations are responsible for internal access policies.

9. Organization Responsibilities

Organizations must ensure user compliance, configure security settings, manage roles, and maintain legal compliance.

10. Children’s Privacy

The Service is not intended for individuals under 18. We do not knowingly collect information from minors.

11. Your Rights

Depending on jurisdiction, users may request access, correction, deletion, restriction, export, or objection. Requests must be submitted through the Organization’s Owner.

12. Changes to This Policy

We may update this Policy periodically. Continued use of the Service constitutes acceptance of the updated Policy.

13. Contact Us

For privacy inquiries: support@borderlessvpn.freshdesk.com