Legal & Compliance
Privacy Policy
Compliant with DPDP Act, 2023, CERT-In Directives (2022) & IT Act, 2000 (India) • Last updated: July 2026
Data Retention — India-Based Infrastructure Notice
If you are routed through our India-based server infrastructure, applicable Indian regulations (CERT-In Cyber Security Directions, 2022) require us to retain session timestamps (login/logout) and the IP address assigned to you for the period mandated by law.
What we NEVER log: We do NOT log, monitor, or retain the specific websites you visit, the content of your network traffic, DNS queries, or your browsing activity. Only connection metadata (when you connected and disconnected) is retained for India-based servers as required by law.
ZionVPN ("we", "us", or "our") is committed to respecting your privacy and fulfilling all requirements under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 of India. This Privacy Policy governs the processing of personal data when you access or use ZionVPN.
1. Data Fiduciary & Scope
Under Indian law (DPDP Act 2023), ZionVPN operates as the Data Fiduciary responsible for processing personal data provided directly by Data Principals (users). We operate under a strict data minimization principle, collecting only data strictly necessary to provide secure VPN proxy services.
2. Personal Data We Collect
We process only the minimum necessary data: • Account Authentication: Email address and account profile obtained via OAuth (such as Google OAuth). • Device Access Tokens: Randomly generated device tokens (ZVN-xxxx) created on your dashboard to manage your connected hardware slots. • Billing & Usage Metrics: Total bandwidth consumed (upload/download bytes) and active subscription status.
3. Strict Zero Activity-Log Policy
ZionVPN enforces a zero activity-log infrastructure. We DO NOT monitor, record, log, store, or profile: • Browsing history, visited URLs, or DNS queries. • Transferred payload contents or unencrypted data packets. • Behavioral, advertising, or third-party tracking analytics.
4. Your Rights under the DPDP Act, 2023 (Data Principal Rights)
As a Data Principal residing in India, you are entitled to the following legal rights: • Right to Information: Seek confirmation on data processing activities. • Right to Correction & Erasure: Request immediate update or complete deletion of your account and personal data. • Right of Grievance Redressal: Access a dedicated Grievance Officer to resolve any privacy concerns within statutory timeframes. • Right to Nominate: Nominate any individual to exercise data rights in the event of incapacity.
5. Data Security & Encryption
All personal data and Hysteria 2 connection credentials are encrypted both in transit (TLS 1.3) and at rest. Technical and organizational measures are routinely audited to prevent unauthorized access, loss, or disclosure.
6. Grievance Officer & Legal Jurisdiction
In accordance with Rule 5(9) of the Information Technology Rules, 2011 & DPDP Act 2023, you may contact our Grievance Officer at: Email: privacy@zionvpn.app Jurisdiction: Courts of New Delhi, India.