Privacy Policy

Last updated: 4 September 2026

This Privacy Policy explains how SV London UK collects, uses, stores and protects personal information when you use our website, contact us or use our services, including our VPN services.

1. Our Commitment to Privacy

SV London UK is committed to protecting the privacy and security of our customers.

Our services are designed around data minimisation. We collect and retain only the information reasonably necessary to provide, administer, support and secure our services.

We do not operate our VPN service for the purpose of monitoring customers’ internet activity.

2. Information We Collect Through Our Website

When you contact SV London UK through our website, by email or through another communication method, we may collect information such as:

  • your name;
  • your email address;
  • your telephone number, where provided;
  • the contents of your enquiry; and
  • any other information you choose to provide.

We use this information to respond to enquiries, provide information about our services, prepare quotations, provide customer support and take steps requested before entering into a contract.

Our website and hosting infrastructure may also process limited technical information, such as IP addresses, browser information and security logs, where necessary to operate, protect and maintain the website.

3. Information We Collect for VPN Services

When you become an SV London UK VPN customer, we may hold account and service information including:

  • your name;
  • your email address, where provided;
  • your SV London UK customer/VPN identifier;
  • your assigned internal VPN address;
  • your WireGuard public key;
  • the status of your VPN account;
  • account creation, activation, disabling and update dates;
  • limited administrative notes where necessary to manage your service; and
  • limited records of administrative actions performed on your VPN account.

This information is used to create, provide, support, secure and administer your VPN service.

We aim to collect only the information necessary for these purposes.

4. What We Do Not Log

SV London UK does not intentionally maintain historical logs of:

  • websites you visit;
  • your browsing history;
  • the contents of your internet traffic;
  • DNS query history;
  • searches performed through your VPN connection;
  • files or content downloaded through your VPN connection; or
  • historical records of your VPN traffic activity.

Our VPN customer-management system does not maintain a historical database of WireGuard connection endpoints, handshake history or customer traffic volumes.

We do not sell browsing information or create advertising profiles based on customers’ VPN activity.

5. Live WireGuard Connection Information

WireGuard requires limited technical information in order to establish and maintain VPN connections.

While the service is operating, WireGuard may hold live technical information including:

  • the current peer endpoint;
  • the most recent handshake;
  • the assigned VPN address; and
  • current transfer counters.

SV London UK’s customer-management system may display this live information to an authorised administrator for operational, troubleshooting and security purposes.

We do not intentionally copy this information into a historical customer activity database.

6. System and Security Logs

Our servers maintain limited system and security logs necessary to operate and protect our infrastructure.

These may include operating-system events, administrative authentication events, firewall and security information, and information required by security systems such as Fail2Ban.

These security records are used for infrastructure operation and protection. They are not intended to record customers’ browsing activity.

The system journal on our VPN infrastructure is configured with a maximum retention period of 30 days and a maximum storage limit.

7. Administrative Audit Records

SV London UK maintains a limited administrative audit trail for VPN accounts.

The audit system records information such as:

  • date and time;
  • SV customer/VPN identifier;
  • administrative action performed; and
  • a minimal description of that action.

Examples include a VPN client being created, assigned, enabled, disabled, having its credentials rotated or having an encrypted customer package generated.

The audit system is designed to avoid unnecessarily duplicating customer names, email addresses, VPN addresses or customer export file paths within its descriptions.

Administrative VPN audit records are subject to a 12-month retention period.

Records older than the configured retention period are removed by our automated maintenance process, unless particular information must legitimately be preserved for security, dispute resolution or legal purposes.

8. Customer VPN Configuration Packages

When required, SV London UK may generate an encrypted customer package containing the information necessary to configure the customer’s VPN connection.

Customer export packages are protected using AES-256 encryption.

The password generated for an encrypted customer package is not stored in the VPN customer database or administrative audit log.

Where an encrypted package must be delivered to a customer, the package and its password should be communicated separately where practical.

Customer export packages are subject to a 30-day retention period.

Packages older than 30 days are removed by the VPN export cleanup process when that process next runs.

Customers are responsible for keeping their VPN configuration and package password secure and should not disclose their configuration, private keys or password to unauthorised persons.

9. VPN Backups

SV London UK creates secured backups of its VPN infrastructure for disaster recovery, security and service continuity.

VPN backup archives are subject to a 30-day retention period.

Backup archives older than 30 days are removed by the VPN backup cleanup process when that process next runs.

Access to VPN infrastructure, configurations and backups is restricted to authorised administration.

10. VPN Credential Security and Reassignment

Customer VPN credentials are treated as security-sensitive information.

If an SV London UK VPN client identifier is reassigned to another customer, the previous customer’s WireGuard credentials are not intentionally reused.

Our secure reassignment process generates fresh WireGuard cryptographic credentials for the new assignment, including a new client key pair and preshared key.

Existing customer export packages associated with the reassigned client identifier are removed as part of the secure reassignment process.

The SV customer/VPN identifier and assigned internal VPN address may be reused operationally, but previous customer cryptographic credentials are replaced.

11. Why We Process Personal Information

We process personal information where necessary to:

  • set up and provide our services;
  • administer customer accounts;
  • provide customer support;
  • respond to enquiries and requests;
  • maintain the security and reliability of our services;
  • prevent or investigate attacks or misuse affecting our infrastructure;
  • maintain appropriate business and accounting records; and
  • comply with applicable legal obligations.

Where personal information is necessary to provide a service requested or purchased by a customer, processing may be necessary for the performance of our contract with that customer or to take requested steps before entering into that contract.

Where limited personal information is processed to protect our systems and network, we may rely on our legitimate interests in maintaining the security and integrity of our infrastructure, where those interests are not overridden by the individual’s rights and freedoms.

Where processing is required by law, information may be processed to comply with a legal obligation.

12. How Long We Keep Information

SV London UK does not retain personal information indefinitely simply because it might be useful in the future.

Our general retention approach is:

  • Active customer account information: retained while reasonably necessary to provide, support and administer the service.
  • VPN system and security journal: maximum 30-day retention.
  • Encrypted customer VPN export packages: subject to a 30-day retention period and removed by the export cleanup process after becoming eligible for deletion.
  • VPN infrastructure backups: subject to a 30-day retention period and removed by the backup cleanup process after becoming eligible for deletion.
  • Administrative VPN audit records: subject to a 12-month retention period.
  • Former customer VPN configurations and operational credentials: removed, replaced or anonymised when they are no longer reasonably required, taking account of account closure, security, support and applicable retention requirements.
  • Financial, transaction and accounting information: retained for the period required by applicable accounting, tax and other legal obligations.

Information may be retained for longer where reasonably necessary to establish, exercise or defend legal claims, investigate security incidents, resolve disputes or comply with a legal requirement.

13. Sharing Personal Information

SV London UK does not sell customers’ personal information.

We may use trusted service providers where reasonably necessary to operate our business and provide our services, including providers of hosting infrastructure, payment processing, email and other essential business services.

Where another organisation processes personal information on our behalf, we take appropriate steps to ensure that information is handled securely and in accordance with applicable data-protection requirements.

We may also disclose information where required by applicable law or a valid legal requirement.

14. International Processing

Some providers used to operate SV London UK’s business or supporting services may process information outside the United Kingdom.

Where personal information is transferred internationally, we will take appropriate measures required under applicable UK data-protection law.

15. Your Data Protection Rights

Depending on the circumstances, UK data-protection law provides individuals with rights relating to their personal information.

These may include the right to:

  • be informed about how personal information is used;
  • request access to personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion of information in certain circumstances;
  • request restriction of processing in certain circumstances;
  • object to certain processing;
  • request portability of certain information where applicable; and
  • raise concerns about how personal information is being handled.

These rights are subject to the conditions and exemptions contained in applicable data-protection law and therefore do not apply in every situation.

16. Access, Correction and Deletion Requests

Customers may contact SV London UK to ask what personal information we hold about them or to request its correction or deletion where applicable.

We may need to verify the identity of the person making the request before disclosing, changing or deleting account information. This helps protect customers against unauthorised access to their information.

Requests concerning data-protection rights will be handled without undue delay and normally within one month, subject to the circumstances of the request and any lawful extension permitted under UK data-protection law.

The right to deletion is not absolute. Some information may need to be retained where there is a lawful reason or legal obligation to do so.

17. Security

SV London UK uses technical and organisational measures intended to protect customer information and our infrastructure.

These measures include, where appropriate:

  • restricted administrative access;
  • firewall protection;
  • encrypted WireGuard VPN connections;
  • server security monitoring;
  • intrusion and authentication protection;
  • encrypted customer VPN packages;
  • restricted server administration;
  • secure credential generation and rotation;
  • controlled backup access; and
  • limited data-retention periods.

No internet-connected system can be guaranteed to be completely secure. We therefore seek to minimise the information we retain while protecting the information necessary to provide our services.

18. Personal Data Breaches

If SV London UK becomes aware of a personal-data breach, we will investigate the incident and take appropriate steps to contain and remedy it.

Where a personal-data breach is required to be reported to the Information Commissioner’s Office under applicable data-protection law, we will report it without undue delay and, where feasible, within 72 hours of becoming aware of it.

Where applicable law requires affected individuals to be informed, we will take appropriate steps to notify them.

19. Complaints

If you have concerns about how SV London UK handles your personal information, please contact us first so that we have an opportunity to investigate and respond.

You also have the right to raise a data-protection complaint with the Information Commissioner’s Office (ICO), the UK’s independent data-protection regulator.

20. Changes to This Privacy Policy

We may update this Privacy Policy when our services, infrastructure, legal obligations or data-processing practices change.

The current version will display its most recent revision date.

If we introduce a materially different use of customers’ personal information, we will update our privacy information and provide further information to affected customers where required.

21. Contact SV London UK

SV London UK
Website: svlondonuk.com
Email: support@svlondonuk.com

For privacy, data-protection, access, correction or deletion enquiries, please contact us using the details above.

Scroll to Top