Legal¶
All legal documentation, operator details, liability, data policy, and architectural disclosures — in one place.
Service Operator¶
| Field | Value |
|---|---|
| Legal form | Individual Entrepreneur (ИП / sole proprietor) |
| Name | IP Sakhno Roman Alexandrovich |
| INN (Tax ID) | 614104707933 |
| OGRNIP (Business ID) | 323237500434312 |
| Website | dix.su |
| General email | admin@dix.su |
| Data / privacy email | dixsu@itdid.ru |
| Abuse email | abuse@dix.su |
MCC Code¶
MCC 4816 — "Computer Network Services" — the same code used by ngrok and Cloudflare Tunnel. No telecommunications license is required.
Jurisdiction¶
Russian Federation. Disputes are handled by courts at the Operator's location.
| Law | Subject |
|---|---|
| 152-FZ | Personal Data (primary) |
| 149-FZ | Information, IT and Information Protection |
| 436-FZ | Protection of Children from Harmful Information |
| 187-FZ | Anti-piracy law |
| Criminal Code Art. 242, 242.1, 242.2 | CSAM |
| Criminal Code Art. 280, 205.2 | Extremism |
| Criminal Code Art. 159 | Fraud |
| Criminal Code Art. 273 | Malware |
Data protection supervisory authority: Roskomnadzor (rkn.gov.ru).
Legal Documents¶
| Document | RU | EN |
|---|---|---|
| Terms of Service | dix.su/terms | dix.su/en/terms |
| Privacy Policy | dix.su/privacy | dix.su/en/privacy |
| Acceptable Use Policy | dix.su/aup | dix.su/en/aup |
| Data Deletion | dix.su/data-deletion | — |
Document hierarchy
The Terms of Service is the primary document. The Privacy Policy and AUP are integral parts of it. In case of conflict, the latest version of the respective document takes precedence.
Technical Intermediary Position¶
dix.su acts as a technical intermediary (similar to a hosting provider or CDN). The Operator provides network infrastructure and has no access to the content of resources published through the tunnel. Full responsibility for content rests with the user (ToS §3.2).
Liability and Refunds¶
Liability Caps by Plan¶
| Plan | Operator liability cap |
|---|---|
| SIMPLE (free) | 0 ₽ — access is provided free of charge |
| VIP | ≤ amount paid for the current 30-day billing period |
| PRO | ≤ amount paid for the current 30-day billing period |
| PERS | ≤ amount paid for the current 30-day billing period |
| GLAVA | ≤ amount paid for the current 30-day billing period |
Refund Policy¶
| Situation | Resolution |
|---|---|
| Voluntary cancellation mid-period | No refund. Plan remains active until end of paid period. |
| Account blocked for ToS / AUP violation | No refund. |
| Service outage caused by Operator > 24 consecutive hours | On request to admin@dix.su — proportional plan extension. |
| Full service shutdown | Refund for unused portion of period — within 30 days of notice. |
Resale prohibition
Resale, sublease, or commercial transfer of access to the infrastructure to third parties without the Operator's written consent is prohibited (AUP §4.2). For B2B integration or white-label enquiries, contact admin@dix.su.
Personal Data¶
What We Collect¶
| Data | Required | Source |
|---|---|---|
| Required | Form / OAuth providers | |
| Name, avatar, bio | Optional | Profile / OAuth |
| Phone number | Optional | Profile |
| Ethereum wallet address | Optional | MetaMask in profile |
| OAuth identifiers | When signing in via social account | Google, GitHub, VK, Facebook, Yandex, Telegram |
| IP address, User-Agent | Automatically | Server logs |
| Tunnel data (IP, timestamps) | Automatically when using tunnels | Proxy service |
Retention Periods¶
| Data | Retention |
|---|---|
| Account data (email, profile) | Until deletion or 3 years of inactivity |
| IP addresses and tunnel logs | 30 days, then auto-deleted |
| Deleted account data | 30-day recovery buffer, then destroyed |
Cross-border Data Transfer¶
User data is stored on servers in the Russian Federation. When signing in through a foreign OAuth provider, cross-border transfer occurs with the user's consent (152-FZ Art. 12):
| Provider | Data transferred | Country |
|---|---|---|
| Google (Google LLC) | Email, name, avatar | USA |
| GitHub (Microsoft) | Email, login, avatar | USA |
| Facebook (Meta) | Email, name, avatar | USA |
| VK (VK Online Technologies) | Name, avatar, VK ID | Russia |
| Yandex ID | Email, login, avatar | Russia |
| Telegram (Telegram Messenger) | Name, avatar, Telegram ID | UAE |
GDPR / International Users¶
For users from EU/EEA: the service complies with core GDPR requirements — cookie consent banner, English versions of all legal documents, rights to access, rectify, and delete data. Users are notified by email of material policy changes.
Data Subject Rights¶
- Access — request at dixsu@itdid.ru
- Rectification — via profile settings
- Deletion — via dix.su/data-deletion or dixsu@itdid.ru
- Withdrawal of consent — dixsu@itdid.ru (results in loss of service access)
- Unlink OAuth / wallet — in the "Account" section of your profile
- Lodge complaint — rkn.gov.ru
Tunnel Architecture and Data Security¶
dix.su is a centralised reverse-proxy tunnel (like ngrok or frp). The user's device establishes an outbound WebSocket connection to the server. There is no P2P connection between visitor and device.
Two Tunnel Modes¶
| Mode | Address | Where TLS terminates | What the Operator sees |
|---|---|---|---|
| Public | slug.dix.su |
On dix.su server (wildcard certificate) | Technically — decrypted traffic (like any reverse proxy / CDN). The Operator does not monitor content. |
| Private E2E | e2e-<token>.dix.su |
On the user's device (Let's Encrypt via DNS-01/ACME) | Encrypted bytes only — blind relay. Private key never leaves the device. |
Private E2E tunnel
When using private_mode, the Operator is technically unable to read the tunnel traffic.
See Security for details.
Billing¶
Payment Methods¶
| Method | Status | Notes |
|---|---|---|
| T-Bank (Tinkoff) — Russian cards | ✅ Active | Russian acquiring, Visa/MC/Mir |
| Lemon Squeezy — international cards | 🔧 In progress | Code ready; activation blocked by IBAN/routing requirement (Stripe Connect). Planned via Payoneer. |
Billing period: 30 days. For payment questions, contact admin@dix.su within 14 days of the transaction.
Acceptable Use — Summary¶
Full text: dix.su/aup · dix.su/en/aup
Allowed Use Cases¶
Smart home, IP cameras, personal cloud (Nextcloud), media server (Jellyfin, Plex), personal website, Git repository, messengers, monitoring, password manager, development and testing, databases and APIs — anything running on your own hardware.
Absolute Prohibitions¶
- CSAM — immediate block + report to law enforcement and NCMEC
- Terrorism and extremism (as defined under Russian law)
- Illegal content: drugs, illegal weapons, counterfeit goods, personal data leaks
- Phishing, malware, DDoS, C2 servers
- Spam and unsolicited mass mailings
Response Times for Complaints¶
| Violation type | Response time |
|---|---|
| CSAM, terrorism | Immediately, 24/7 |
| Phishing, malware | Within 24 hours |
| Fraud, scam | Within 48 hours |
| Other violations | Within 72 hours |
Violation of the rules is grounds for immediate account termination without prior notice and without a refund.
Contacts¶
| Topic | Contact |
|---|---|
| General questions, billing, technical issues | admin@dix.su |
| Personal data, deletion requests, consent withdrawal | dixsu@itdid.ru |
| Abuse complaints, harmful content | abuse@dix.su |
| B2B, white-label, partnerships | admin@dix.su |
Frequently Asked Questions¶
Is dix.su liable for the content of tunnels?¶
No. dix.su is a technical intermediary: it provides network infrastructure but has no access to the content of resources published through the tunnel. All responsibility for content rests with the user (ToS §3.2). The position is equivalent to a hosting provider or CDN.
Can I resell tunnel access?¶
No. Resale, sublease, or commercial transfer of access without the Operator's written consent is prohibited (AUP §4.2). For B2B integration — admin@dix.su.
Is the service GDPR-compliant?¶
For EU/EEA users, core GDPR requirements are implemented: cookie consent banner, English versions of all documents, right to access and delete data, notification of policy changes. Primary regulator: 152-FZ (Russia). Supervisory authority: Roskomnadzor (rkn.gov.ru).
How do I delete my data?¶
Via dix.su/data-deletion or by request to dixsu@itdid.ru. After account deletion, data is retained for 30 days (recovery buffer), then destroyed.
Which court handles disputes?¶
Court at the Operator's location (Russia). Governing law: Russian Federation.
Where are the current versions of all legal documents?¶
At dix.su/terms, dix.su/privacy, dix.su/aup and dix.su/data-deletion. English versions at /en/ prefix paths.