Who we are and how to contact us
1.1. The data controller of the personal data of Users of the Maximum VPN service (hereinafter — the "Service") is Sirius LTD (registration number 515230530, hereinafter — the "Company", "we", "us"), registered at: גרוב יוסף 90, דירה 6, באר שבע, ישראל.
1.2. This Policy constitutes mandatory disclosure in accordance with applicable personal data protection legislation.
1.3. All questions and requests should be directed to support@maximum-vpn.com.
1.4. The Terms of Service are published separately at maximum-vpn.com/terms-of-service.
No-Logs Policy What we do NOT store
2.1. The Company does not store, aggregate or disclose to third parties the following categories of data:
- the history of visited websites and domains;
- the contents of traffic transmitted through the VPN tunnel;
- the User's DNS queries;
- the User's originating IP address (source IP) during an active VPN session;
- the assigned VPN IP address following connection;
- detailed session timestamp logs that would allow the activity of a specific User to be reconstructed; the transient technical markers required to establish and maintain a connection are not retained after the session ends;
- the volume of data transferred during a particular session;
- information about the applications or protocols used by the User through the VPN tunnel.
2.2. The Company does not operate a data-monetisation model: Users' personal data is not disclosed to third parties for commercial purposes and is not used to build advertising profiles.
What we collect and on what basis
3.1. In order to provide the Service, the Company processes the following categories of data:
| Data category | Legal basis | Purpose of processing |
|---|---|---|
| Account email | Contract | Authentication, account recovery, Service notifications |
| Hashed password (Argon2id) | Contract | Authentication |
| Telegram account identifier and public profile fields transmitted by the Telegram platform when the bot is connected (including user ID, username, name, language code, premium status — the scope is determined by the Telegram platform) | Contract | Authentication and identification of the User when using the Telegram bot |
| Device model, OS version, application version, interface language | Legitimate interest | Compatibility, debugging, development statistics |
| Crash reports and application diagnostics (pseudonymised, without traffic contents) | Legitimate interest | Fixing application errors; the user may disable submission in the application settings where such an option is available |
| Date of the account's last activity (without exact time) | Contract | Management of inactive accounts |
| Support tickets and correspondence | Contract and legitimate interest | Resolving requests, protecting the Company's rights in disputes |
| Marketing communications | Consent (opt-in) | Informing about new features and offers |
3.2. The Company does NOT collect: first name, last name, date of birth, phone number, home address, government identifiers (passport, tax ID, SSN), or biometric data.
3.3. Infrastructure management. The Company uses automated systems (including AI load balancers) running on on-premises servers within the jurisdiction of the State of Israel and the European Union. No operational data is transferred to external AI providers. These systems operate solely on technical parameters and do not analyse traffic contents, DNS queries or Users' personal data for commercial purposes.
3.4. Decisions with legal or similarly significant effects. With respect to the blocking, suspension or other restriction of an account (including cases of reasonable suspicion of abuse, fraud or breach of the ToS), a mixed procedure applies:
- the automated anti-abuse system may flag an account and apply a temporary technical restriction of access in order to protect the Service and other Users;
- the final decision on restricting or restoring access is taken by an authorised member of staff on the basis of a review of the available technical data and context.
3.5. The Company does not make solely automated decisions concerning Users. A User in respect of whom a decision to restrict access has been taken has the right to:
- obtain an explanation of the reasons for the decision;
- contest the decision and present their own explanations;
- request a review of the decision by another authorised member of staff who was not involved in the initial assessment.
Retention periods
4.1. The Company retains personal data only for as long as is necessary for the processing purposes set out in §3. The specific retention period is determined by reference to the following combined criteria:
- the period of the User's active use of the Service;
- a reasonably necessary period after use ends to complete settlements and close open requests;
- the operational security requirements of the infrastructure (including backup rotation);
- the applicable limitation periods and the need to protect the rights of the Company and the User in disputes.
4.2. Account deletion. Upon a User's request submitted through the personal account or to support@maximum-vpn.com, the Company deletes the account and the associated personal data without undue delay, except for data that must be retained under mandatory requirements of applicable law.
Disclosure to third parties
5.1. In order to provide the Service, the Company engages processors in the following categories: payment providers, hosting infrastructure, transactional email delivery services, and support request handling. Transfers to processors are carried out on the basis of data processing agreements. An up-to-date list of processors, indicating the jurisdiction and the category of data transferred, is available on request via support@maximum-vpn.com.
5.2. The Company does not sell, rent or transfer Users' personal data for the marketing purposes of third parties. Monetisation of Users' data is not carried out.
5.3. Telegram as an independent controller: when registering for and using the Service through the Telegram bot, Telegram FZ-LLC (Dubai, UAE) acts as an independent data controller for its platform and processes the User's data in accordance with its own privacy policy (telegram.org/privacy). The Company is not responsible for the processing of data on Telegram's side. A User wishing to minimise the transfer of data may register through the web interface at app.maximum-vpn.com.
5.4. Disclosure of data to government authorities is made only on the basis of a valid court order or other legally binding directive of a competent authority of the State of Israel or another jurisdiction, in the manner provided for by international treaties. By virtue of the No-Logs Policy (§2), the Company technically does not hold logs of traffic, DNS queries or session-IP correlation and cannot provide such data.
Jurisdiction of data processing
6.1. Control plane — processing of personal data. The account database, billing, support request logs, crash reports and backups are hosted exclusively on servers within the jurisdiction of the State of Israel and the European Union. The Company does not use any other geographic regions for storing personal data.
6.2. The State of Israel is covered by an adequacy decision of the European Commission on the level of data protection, reaffirmed in January 2024. The transfer of personal data from the European Economic Area (EEA) to Israel does not require additional safeguards.
6.3. Data plane — VPN exit nodes. To operate the Service, the Company maintains a network of VPN nodes (exit nodes) in various countries around the world. These nodes perform solely the function of transit routing of encrypted traffic and, by virtue of the No-Logs Policy (§2), do not store the User's personal data — neither IP addresses, nor DNS queries, nor traffic contents, nor activity logs. Accordingly, the exit nodes are not a place of personal data processing, and their geographic location gives rise to no obligations regarding international data transfers.
6.4. Technical and organisational security measures. The Company employs cryptographic protection both when transmitting the User's traffic (end-to-end encryption of the VPN tunnel) and when storing personal data (encryption of databases and backups), as well as organisational measures (least-privilege access control, logging of administrative actions, regular security updates, and pseudonymisation of diagnostic data). The specific cryptographic algorithms, protocol versions and implementation details constitute the Company's trade secret and are not subject to public disclosure for security reasons; such information is provided to the competent supervisory authority upon a justified request.
Your rights as a data subject
7.1. The User has the right to request access to the personal data being processed, as well as its rectification, erasure, restriction of processing, portability, objection to processing, and the withdrawal of consent previously given. Requests should be sent to support@maximum-vpn.com and are handled within a reasonable time.
7.2. The User also has the right to lodge a complaint with the national data protection supervisory authority in their place of residence.
Security incident notifications
8.1. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of Users, the Company will notify the competent supervisory authority within 72 hours of becoming aware of the incident.
8.2. Where an incident is likely to result in a high risk to the rights and freedoms of Users, the Company will additionally, without undue delay, notify the affected Users by email and in-app notification.
Changes to this Policy
9.1. The Company reserves the right to make changes to this Policy. The updated version is published at maximum-vpn.com/privacy-policy, indicating the date of the last update.
9.2. The Company will notify Users of material changes (affecting the categories of data processed, retention periods, disclosure to third parties or the scope of the User's rights) at least 14 calendar days in advance by email or in-app notification. Such changes take effect for a particular User only after explicit confirmation via an in-app modal window. A User who does not agree with the updated version may discontinue use of the Service and request deletion of their account via support@maximum-vpn.com; until confirmation is received, the functionality of the Service may be restricted insofar as it requires the updated processing basis.
9.3. Non-material changes (typographical corrections, restructuring, updates to contact details) take effect upon publication and do not require separate confirmation.
Cookies and tracking technologies
10.1. The maximum-vpn.com website uses cookies to ensure the operation of the site and for anonymous traffic analytics. Non-essential cookies are set only after the User's consent via the cookie banner; consent can be withdrawn at any time through the browser settings.