Last updated: August 2026
This Privacy Policy describes how Hunt-Benito Ltd. ("Company", "we", "us", "our") collects, uses, and protects your personal data when you use the Simply Proxies service ("Service").
We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The data controller responsible for your personal data is Hunt-Benito Ltd., a company registered in Scotland, United Kingdom (company No. SC728400, VAT No. GB435392292).
Registered office: Newseat of Gowanwell, Ellon, Aberdeenshire, AB41 7JQ, United Kingdom.
Privacy contact: privacy@simplyproxies.com (general enquiries: support@simplyproxies.com).
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account identification, email verification, support | Contract performance (Art. 6(1)(b) UK GDPR) |
| Password (hashed) | Account security | Contract performance (Art. 6(1)(b) UK GDPR) |
| Billing details (name, company, address, city, postcode, country, VAT number) | VAT-compliant invoicing where you provide them | Contract performance and legal obligation — VAT (Art. 6(1)(c) UK GDPR) |
| Proxy credential labels | Organising your credentials | Contract performance (Art. 6(1)(b) UK GDPR) |
| Data | Purpose | Legal Basis |
|---|---|---|
| Credit balance and history | Service delivery, billing records | Contract performance (Art. 6(1)(b) UK GDPR) |
| Proxy credential pairs | Service delivery | Contract performance (Art. 6(1)(b) UK GDPR) |
| Traffic volume per credential | Usage tracking, credit deduction | Contract performance (Art. 6(1)(b) UK GDPR) |
| Data | Purpose | Legal Basis |
|---|---|---|
| Session cookies | Maintain login state across page loads | Legitimate interest (Art. 6(1)(f) UK GDPR) |
| Server logs (IP address, timestamps) | Security, fraud prevention, abuse defence | Legitimate interest (Art. 6(1)(f) UK GDPR) |
| Website analytics (self-hosted, cookieless) | Aggregate audience measurement (page views, referrer). No cookies, no cross-site tracking, no advertising. | Legitimate interest (Art. 6(1)(f) UK GDPR) |
| Anti-bot challenge (Cloudflare Turnstile) | Confirming a human created the account, preventing automated abuse | Legitimate interest (Art. 6(1)(f) UK GDPR) |
| Data | Processor | Purpose |
|---|---|---|
| Payment card details | Stripe (PCI Level 1) | Payment processing (card never touches our servers) |
| Payment transactions & billing | Stripe | Billing and invoicing |
| Payment transactions (PayPal account email, country, amount) | PayPal | Payment processing for PayPal checkout |
| Content delivery, DDoS protection, TLS termination | Cloudflare | Serving and securing simplyproxies.com and the customer portal |
| Anti-bot challenge token | Cloudflare Turnstile | Confirming a human at account activation (bot/abuse prevention) |
We never see, store, or have access to your card details. All card data is handled directly by Stripe. PayPal processes its own checkout; we receive only the confirmed payment and your PayPal account's country (for VAT allocation).
We use your personal data to:
We do not sell, rent, or trade your personal data.
We share data only with:
| Data Type | Retention Period |
|---|---|
| Account data (email, hashed password) | Until account deletion + 30 days |
| Credit, billing and invoice history | 6 years (HMRC / VAT Act 1994 requirement for tax records). On account deletion, your personal data is erased but invoice financial records are retained and anonymised so they can no longer be linked to you. |
| Proxy credentials | Until account deletion |
| Usage history (aggregated daily volume) | 24 months |
| Server / connection logs (raw metadata, IP) | Up to 30 days |
| Login-attempt records (email, IP) | Up to 30 days (security / abuse defence) |
| Audit log (security events) | Up to 12 months |
| Session cookies | 24 hours (browser-side) |
| Email verification tokens | Until verified or re-sent (max 72 hours) |
You have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate data |
| Erasure | Request deletion of your data. Note: invoice financial records are retained for 6 years as required by UK tax law (UK GDPR Art. 17(3)(b)); all personal data is removed and the records anonymised. |
| Data portability | Receive your data in a structured, machine-readable format (a one-click export is available in your Account settings) |
| Restriction | Request that we limit how we process your data |
| Objection | Object to processing based on legitimate interests |
| Withdraw consent | Withdraw consent where processing is based on consent (our processing is primarily on contract / legal-obligation / legitimate-interest bases, so this right has limited application) |
To exercise any of these rights, email privacy@simplyproxies.com. You can also export or delete your data directly from the Account page in the customer portal.
We implement appropriate technical and organisational measures to protect your data:
The Service uses the following essential cookies:
We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Our website analytics are cookieless and self-hosted (no data is shared with third-party advertising or analytics networks).
Cloudflare, which provides our content delivery network and security, may set essential technical cookies to protect the site (e.g. bot defence). Cloudflare Turnstile, used only on the account-activation page to confirm you are human, may set a temporary, privacy-preserving token. These do not track you across websites and are not used for advertising.
Your primary account and billing data is stored and processed on servers located in the United Kingdom (our database and application servers are UK/EU-hosted). Some processors we rely on may transfer data outside the UK:
Where your data is transferred outside the UK, we ensure appropriate safeguards are in place as required by UK GDPR Chapter V, including the International Data Transfer Agreement (IDTA) or Addendum to the EU Standard Contractual Clauses adopted by the processors concerned. We do not rely on the UK to process data in jurisdictions without such safeguards.
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you (UK GDPR Art. 22). Rate-limiting, anti-bot challenges, and fraud-prevention rules may automatically restrict access in clearly abusive cases, but these do not evaluate personal characteristics and you can request human review by contacting privacy@simplyproxies.com.
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
For privacy-related inquiries or to exercise your data rights:
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):