Privacy Policy

Last updated: July 25, 2026

1. Data Controller

WireZTNA ("we", "us", "our") operates as the data controller for the personal data processed through our platform. For questions regarding this policy, contact us at:

2. Data We Collect

2.1 Account Data

DataPurposeLegal Basis
Email addressAuthentication, notifications, supportContract performance
Display nameIdentification within the platformContract performance
Password hash (bcrypt)AuthenticationContract performance
TOTP secret (if MFA enabled)Two-factor authenticationLegitimate interest (security)

2.2 Technical Data

DataPurposeRetention
WireGuard public keyTunnel authenticationUntil account deletion
Overlay IP addressNetwork routing within the platformUntil account deletion
Session timestampsAccess control, TTL enforcement30 days
Connection metadata (handshake age, bytes transferred)Health monitoring, diagnostics24 hours
Audit log entriesSecurity monitoring, compliance90 days

2.3 Data We Do NOT Collect

  • Traffic payload content (encrypted end-to-end, opaque to the broker)
  • DNS query contents (proxy routes but does not log)
  • WireGuard private keys (generated and stored only on user's device)
  • Browsing history or application usage patterns

3. How We Use Your Data

We process personal data exclusively for:

  • Providing the ZTNA service (tunnel setup, routing, access control)
  • Authenticating users and managing sessions
  • Monitoring system health and detecting anomalies
  • Communicating service updates and security notices
  • Responding to support requests

We do not sell, rent, or share personal data with third parties for marketing purposes.

4. Data Storage and Location

All data is stored and processed within the European Union:

  • Infrastructure: AWS eu-central-1 (Frankfurt, Germany)
  • Database: Encrypted at rest on the broker instance
  • Backups: Encrypted, stored in EU S3 buckets
  • CDN/Edge: Cloudflare (EU edge preferred, with data localization settings)

Your data never leaves the European Economic Area (EEA) unless you explicitly configure publishers in other regions.

5. Data Retention

Data CategoryRetention Period
Account dataUntil account deletion + 30 days grace
Session dataAutomatically purged on expiry (default 8h)
Audit logs90 days rolling
Connection metadata24 hours
Support correspondence2 years

6. Your Rights (GDPR Articles 15-22)

Under the General Data Protection Regulation, you have the right to:

  • Access — Request a copy of your personal data
  • Rectification — Correct inaccurate personal data
  • Erasure — Request deletion of your data ("right to be forgotten")
  • Restriction — Restrict processing in certain circumstances
  • Portability — Receive your data in a structured, machine-readable format
  • Object — Object to processing based on legitimate interests

To exercise any of these rights, email privacy@wireztna.com. We will respond within 30 days.

7. Sub-processors

ProviderPurposeLocation
Amazon Web Services (AWS)Infrastructure hostingEU (Frankfurt)
CloudflareCDN, DDoS protection, DNSEU edge nodes
Mailjet (Sinch)Transactional email deliveryEU
Better StackUptime monitoringEU

We will notify partners 30 days before adding new sub-processors.

8. Cookies and Tracking

Our marketing website (wireztna.com) does not use cookies or tracking scripts. The admin panel uses a single session cookie (JWT in localStorage) strictly necessary for authentication — no analytics, no third-party trackers.

9. Security Measures

See our Security page for detailed information about our technical and organizational measures, including encryption standards, access controls, and vulnerability management.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated to partners via email at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision.

11. Contact and Complaints

For privacy-related inquiries: privacy@wireztna.com

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. For EU-based complaints, you may also contact the relevant supervisory authority in the member state of our establishment.