Legal

Privacy Policy

GDPR-compliant. We collect the minimum data needed to deliver your order. No ad trackers, no data brokers, no surprises.

LicenseVault is the data controller for personal data collected through this website. This policy explains what we collect, why, what we share with whom, and what your rights are under the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the UK GDPR.

Last updated: 1 January 2026. Material changes are announced by email to active customers at least 30 days before they take effect.

1. What we collect

  • Order data: email address, billing name, country, the products you bought, the IP address used at checkout (fraud prevention), and the language of the browser (localised invoice + delivery).
  • Payment data: processed by our payment partner (Stripe Payments Europe Ltd, Ireland, or Paddle.com Market Ltd, UK, depending on region). We never see or store your card number — only the last 4 digits and the card brand for receipt purposes.
  • Support data: any information you include in support emails, plus message metadata (timestamps, mailbox).
  • Analytics: aggregate, cookie-less page analytics with no cross-site tracking, no fingerprinting, no IP storage beyond the first /24 truncation.
  • Server logs: standard HTTP logs (IP, path, status, latency) retained for 14 days for security and abuse investigation.

2. Why we collect it (legal basis under GDPR Art. 6)

  • Art. 6(1)(b) — Contract performance: for order processing, license delivery and support.
  • Art. 6(1)(c) — Legal obligation: for VAT invoicing and 10-year accounting retention required by EU and member-state tax law.
  • Art. 6(1)(f) — Legitimate interest: for fraud prevention (IP at checkout), security logging, and aggregate analytics. We do not rely on legitimate interest for any marketing.

3. Subprocessors

The complete list of third parties that may process personal data on our behalf:

  • Payment processing: Stripe Payments Europe Ltd (Ireland) or Paddle.com Market Ltd (UK).
  • Transactional email: Postmark / ActiveCampaign Postmark (EU region).
  • Infrastructure: Cloudflare Inc. (CDN, with EU Data Boundary enabled) and Supabase / Hetzner Online GmbH (Frankfurt, primary database).
  • Error monitoring: Sentry GmbH (EU region) with PII scrubbing enabled.
  • Activation escalation: Microsoft Ireland Operations Ltd, only on a per-ticket basis when required to resolve a customer escalation.

4. Retention

Order records are kept for 10 years to comply with EU accounting and tax retention laws. Support tickets are deleted 24 months after resolution. Analytics data is aggregated daily and the raw events discarded after 30 days. Server logs roll off after 14 days.

5. Your rights

Under GDPR you have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). You also have the right to withdraw consent at any time where consent was the legal basis, and the right to lodge a complaint with your national data protection authority (the lead authority for LicenseVault is the Czech ÚOOÚ).

To exercise any right, email privacy@licensevault.netfrom the address on your order. We respond within 30 days and never charge a fee.

6. International transfers

All personal data is stored on EU-located servers. The limited transfers that occur (Microsoft activation escalations) rely on the EU Standard Contractual Clauses (2021/914) as adopted by the European Commission, plus Microsoft's published EU Data Boundary commitments.

7. Cookies

We use one essential first-party cookie to remember the contents of your cart. It contains no personal data and expires after 30 days. No advertising, retargeting, fingerprinting or third-party cookies are set, so we do not show a cookie banner — under ePrivacy Directive Article 5(3) consent is not required for strictly necessary cookies.

8. Security

TLS 1.3 in transit. AES-256 at rest. Role-based access on a need-to-know basis. Two-factor authentication enforced on all admin accounts. Quarterly third-party penetration tests. Vulnerability reports to security@licensevault.net are acknowledged within 24 hours.

9. Children

The site is not directed at children under 16 and we do not knowingly collect their personal data. If you believe we have, email privacy@licensevault.net and we will delete it.

10. Contact

Data controller: LicenseVault s.r.o., Prague, Czech Republic.
Email: privacy@licensevault.net
Supervisory authority: Úřad pro ochranu osobních údajů (uoou.cz).

See also our Terms of Service and Refund Policy.

Frequently asked

Do you sell my personal data?
No. We never sell, rent or trade personal data with anyone. Data is only shared with the subprocessors strictly needed to deliver your order (payment processor, email delivery, license fulfillment).
Do you use advertising or tracking cookies?
No. There are no advertising, retargeting, fingerprinting or third-party tracking cookies on this site. We use one essential cookie to remember your cart contents.
How can I delete my data?
Email privacy@licensevault.net from the address on your order. We delete personal data within 30 days, except where EU tax law requires us to retain order records for 10 years.
Where is data stored?
All personal data is stored on EU-located servers (Frankfurt, Germany). Backups are encrypted at rest and never leave the EU/EEA.
Do you transfer data outside the EU?
Only to Microsoft when strictly required for license activation support, and only when you've asked us to escalate. These transfers rely on Microsoft's EU Data Boundary commitments and Standard Contractual Clauses.