Privacy Policy
What data Blik VPN processes at sign-up, when the balance is topped up and when it is debited, why it is needed and how to delete it.
The short version
01Seller and data operator
"WAVERISE" LIMITED LIABILITY COMPANY; jurisdiction of registration: Republic of Armenia; registration ID: 290.110.1467373; tax ID: 01365166; registered address: 73 Andranik Street, Malatia-Sebastia, Yerevan 0064, Armenia. Working hours: Online service: 24/7; support upon request. Contract contact: https://t.me/blik_vpn_bot. Data operator: "WAVERISE" LIMITED LIABILITY COMPANY; privacy contact: https://t.me/blik_vpn_bot.
02Approved document text
PRIVACY POLICY OF THE BLIK VPN SERVICE Revision 2026-08-08.1 · effective 8 August 2026 1. WHO PROCESSES THE DATA 1.1. The data operator is "WAVERISE" LIMITED LIABILITY COMPANY (short form: "WAVERISE" LLC), registered in the Republic of Armenia: registration number 290.110.1467373, taxpayer number 01365166, registered address: 73 Andranik Street, Malatia-Sebastia, Yerevan 0064, Armenia. 1.2. Any question about data processing is accepted through the Telegram bot https://t.me/blik_vpn_bot. 2. WHAT WE PROCESS TO PROVIDE THE SERVICE 2.1. Telegram account: the numeric identifier, first name, last name and username exactly as Telegram supplies them, plus the chosen language. This is the only way we identify you; we ask for no email address and no phone number. 2.2. Devices: the hardware identifier reported by the application, the platform, the model, the application version and the time of the last request — so that the simultaneous-device limit can be enforced and credentials issued. 2.3. Payments and balance: amount, currency, status, the provider's own payment identifier and the balance ledger entries. We neither receive nor store card details; the payment provider processes them. 2.4. For billing we process hourly per-account totals of bytes carried: they are what decides which days carried traffic, and they are kept for no more than 31 days. 3. THE NETWORK ACTIVITY RECORD: WHAT IS ACTUALLY RECORDED 3.1. To operate the network, investigate abuse and support users we record, against the credential that carried the connection, the client IP address and the observed destination hostname or domain. 3.2. We do not store the URL or path, the query string, request or response headers, packet payloads, or the answer to a DNS lookup, and we never decrypt or intercept TLS: there is no certificate substitution and no interception of a secured connection anywhere in the service. 3.3. Where a connection cannot be attributed to a credential, the corresponding field is left unknown. We do not put a guess in its place. 3.4. A failure to record never interrupts the carriage of traffic: if activity cannot be recorded, the VPN keeps working and the record simply does not appear. 4. HOW LONG IT IS KEPT AND WHERE IT GOES 4.1. On the control plane the network activity record is kept for exactly seven completed UTC days. The day currently in progress is not one of those seven. 4.2. Completed days older than that window are moved to an encrypted archive held on the operator's private machine. The archive exists for abuse investigation and incident analysis. 4.3. Data is removed from the control plane only after a deterministic export has run, a manifest, a digest and a row count have been recorded, the copy has been restored from the remote snapshot and verified, and the source has been re-read under lock. If archiving fails, the data stays on the control plane. 4.4. The archive performs no automatic deletion and no automatic pruning of older copies. Under the operator's internal rule data is not destroyed but moved: a record leaves the working table and lands in the archive. 4.5. Payment records and the balance ledger are retained for the period required by applicable accounting and tax law, independently of the deletion of an account's working copy. 5. WHO HAS ACCESS 5.1. The network activity record and the archive are accessible only to the operator's authorised administration, and only for network security, abuse investigation, reliability and user support. 5.2. We do not sell data, do not pass it to advertising networks and do not use it for profiling or ad targeting. 5.3. Data is passed to the payment provider strictly to the extent needed to carry out a payment and issue a fiscal document, and to a competent authority where a demand is made in the manner prescribed by law. 6. THE WEBSITE AND COOKIES 6.1. The website sets a cookie holding the chosen language. A session cookie appears only when web account sign-in is enabled. The colour theme is stored in the browser's local storage. 6.2. The website sets no analytics and no advertising cookies. 7. YOUR RIGHTS 7.1. Through the Telegram bot you may request information about the data processed, its correction, and deletion of the working copy of your account. 7.2. Deletion of the working copy does not affect records the operator is required by law to keep (payments and fiscal documents) and does not undo archive copies already made. 7.3. Withdrawing consent to the processing of the data required to provide the service means the service stops being provided. 8. WHAT WE DO NOT CLAIM 8.1. We publish no independent audit report and claim no no-logs policy. This document describes what is actually recorded. 9. CHANGES TO THIS DOCUMENT 9.1. A new revision is published with its version number, effective date and the SHA-256 checksum of its text; previous revisions remain reachable at their own immutable archive addresses.
03Revision and archive evidence
2026-08-08.1 · SHA-256 1ec4754c3c93af9149d39bb2fba7195d7669348bfdf015b3723b53a81dadc923 · 2026-08-08T00:00:00Z · https://blik.waverise.org/en/legal/archive/privacy/2026-08-08.1