Data handling policy
This Data Handling Policy explains what happens to data on the CyberYozh Data platform: what we store, where, how we protect it, how long we keep it, and how you have it deleted. It applies to the hosted services operated by WebGears Services d.o.o. (registration number 22038745), registered under Serbian law at Jurija Gagarina 231/329, Novi Beograd, Beograd, Serbia (the “Company“, “we“, operating the brand “CyberYozh Data“). These are the standards we follow in practice, not aspirations, and they are binding on us. For how we handle the personal data of website visitors and account holders, read this policy alongside our Privacy Policy.
1. Scope and what this policy governs
1.1 This policy covers two kinds of data: Scraped Output and proxy traffic routed through our hosted platform, and Account Data we hold to run the Services, bill the Client and provide support.
1.2 CyberYozh Data is an open-source platform. The yozh-scraper engine and the Yozh Crawler (which walks a site from a start URL, streams discovered pages, and fetches each through the Scraper over HTTP) are self-hostable. When the Client runs these tools on their own infrastructure, the Client controls storage, retention and deletion, and this policy does not govern that deployment. This policy governs the hosted Proxy Network and any managed scraping we operate for the Client.
1.3 This policy sits alongside our Terms of Service, Cookie Policy and Payment and Refund policy, and complements our Use Policy, Restricted Targets Policy, Network Sourcing Standards, Customer Verification Policy and Abuse Response Policy, all available at /legal/.
2. Our data-handling principles
2.1 Data minimisation. We collect and keep only what is necessary to run the Services, provide support, take payment and meet our legal obligations. We do not accumulate data we do not need.
2.2 Purpose limitation. Data collected for one purpose is not repurposed for unrelated ones. We do not sell the Client’s data.
2.3 Ethics in practice. Ethical data collection, a transparent Proxy Network and fast abuse response are operational commitments described in this policy, not marketing claims.
3. Roles under data-protection law
3.1 For Scraped Output and proxy traffic, the Client is the controller: the Client chooses the targets, the data and the purposes. We act as a processor, handling that data only on the Client’s instructions and only to route requests and deliver results. These controller/processor roles are consistent with, and should be read together with, our Privacy Policy.
3.2 For the Client’s Account Data (registration, billing and support records), we act as the controller, as described in our Privacy Policy.
3.3 We are designed to align with GDPR and CCPA expectations for our EU and California Clients as a voluntary commitment. Serbia sits outside the EU/EEA and has its own Law on Personal Data Protection modelled on the GDPR; we apply GDPR-level safeguards regardless.
4. Pass-through of scraped content
4.1 This is the clause that defines us. The Yozh Crawler streams discovered pages and the Proxy Network routes requests; scraped content is not retained on Company servers by default. We are a conduit, not a dataset seller.
4.2 Where we run managed scraping for the Client, results are delivered to the Client and are not retained beyond the minimal technical buffer needed to complete delivery. We do not build a persistent store of the Client’s scraped content.
5. Storage, encryption and access
5.1 In transit. All traffic between the Client, the platform and Target Sites is protected with TLS encryption.
5.2 At rest. Account and configuration data is encrypted at rest, with logical isolation between Client environments.
5.3 Access control. Access is least-privilege: limited to personnel who need it, bound by confidentiality obligations, and logged.
6. Retention
6.1 Scraped Output: not retained beyond delivery (see Section 4). Retention windows in this section are aligned with those in our Privacy Policy and should be read as identical to, or derived from, the periods stated there.
6.2 Request logs and proxy metadata: kept for a short operational window (currently up to 30 days) for security, abuse prevention and troubleshooting, then deleted or aggregated.
6.3 Account and billing data: kept for the life of the Client’s account and for up to 24 months after closure, then deleted, subject to legal, tax and accounting obligations that may require longer retention.
6.4 Support data: kept only as long as needed to resolve the Client’s request and maintain a reasonable support history.
7. Deletion and data return
7.1 On account closure, or earlier on request, we will delete or return the personal data we process on the Client’s behalf, at the Client’s choice, within 30 days, except where we are legally required to retain it under a legal hold.
7.2 To make a request, email support@cyberyozh.com. We confirm receipt within 72 hours and act without undue delay, as described in our Privacy Policy.
8. Sub-processors and international transfers
8.1 We use a limited set of sub-processors to run the Services, currently including Cloudflare (DDoS protection), DigitalOcean and Inferno Solutions (hosting), Mailgun (transactional and notification email), xproxy, iproxy and proxysmart (proxy and SMS infrastructure), IPQualityScore (IP and resource checks) and UseGateway.net (payments). We share only what each provider needs to perform its function. This sub-processor list is maintained to be identical to the one published in our Privacy Policy; where the two differ, the Privacy Policy governs.
8.2 Because we operate from Serbia, the Client’s data may be processed outside the Client’s own country. Where personal data is transferred internationally, we rely on Standard Contractual Clauses or adequacy mechanisms as appropriate, on the same basis set out in our Privacy Policy.
9. Security measures and breach notification
9.1 We maintain technical and organisational measures aligned with ISO 27001 and GDPR expectations, including encryption, access controls, network protection and staff confidentiality obligations. We do not currently claim ISO 27001 or SOC 2 certification, and we will not imply one we do not hold.
9.2 In the event of a personal data breach, we will notify affected controllers without undue delay and, where feasible, within 72 hours of becoming aware, with the information needed to assess and respond.
10. Ethical sourcing, vetting and abuse response
10.1 Transparent Proxy Network. Our Proxy Network is built only from informed, consenting and fairly-treated peers and ISP sources, as detailed in our Network Sourcing Standards. We do not use deceptively acquired or exploited endpoints.
10.2 Ethical data collection. We apply KYC-style customer vetting and acceptable-use restrictions to keep the platform from being used for unlawful data collection. Client verification is authoritatively defined in our Customer Verification Policy, and permitted and prohibited uses are set out in our Use Policy and Restricted Targets Policy.
10.3 Fast abuse response. Report abuse or misuse to abuse@cyberyozh.com, in line with our Abuse Response Policy. We acknowledge reports within one business day and act on validated reports, including takedown of offending activity, without undue delay.
11. Your rights and changes to this policy
11.1 The Client may request access to, correction of, export of, or deletion of their personal data. How to exercise these rights, including under the GDPR and CCPA, is set out in our Privacy Policy.
11.2 We may update this policy. When we do, material changes take effect on publication.
12. Contact
12.1 For questions about this policy or a data-handling request, email support@cyberyozh.com or help@cyberyozh.com, or message us on Telegram at @CyberYozh_support_bot. For abuse or misuse reports, use abuse@cyberyozh.com. For formal data-protection and breach correspondence, contact support@cyberyozh.com. Our website is cyberyozh.com and your dashboard is at app.cyberyozh.com.
13. Related policies
This Policy works together with the other documents in our Legal Center: