1. Controller
The data controller is EoF Software Lab (see Imprint for full contact details). For privacy enquiries contact us at privacy@eofsl.com.
2. Data We Collect
We collect only the data necessary to provide our service:
-
Purchase data: name, email address, billing country, VAT ID (if supplied), transaction ID — to fulfil the contract and issue invoices.
-
License activation data: license key, device fingerprint hash (anonymised) — to enforce seat limits.
-
Support data: content of support emails — to respond to enquiries.
-
Website analytics: anonymised page-view data (no cookies, no cross-site tracking).
We do not collect payment card details. Card processing is handled entirely by Stripe and PayPal on their infrastructure.
3. Legal Basis (GDPR)
- Art. 6(1)(b) – contract performance: purchase, delivery, license management.
- Art. 6(1)(c) – legal obligation: VAT record-keeping (10 years, § 257 HGB).
- Art. 6(1)(f) – legitimate interest: fraud prevention, service security.
4. Third-Party Processors
-
Stripe Payments Europe, Ltd. (Ireland) – card payment processing. Privacy policy
-
PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) – PayPal payment processing. Privacy policy
All processors are bound by GDPR-compliant Data Processing Agreements.
5. Data Retention
- Transaction and invoice data: 10 years (legal obligation).
- License activation hashes: duration of active license + 1 year.
- Support correspondence: 3 years after last interaction.
6. International Transfers
Data may be processed on servers within the EEA. Where data is transferred outside the EEA (e.g. by Stripe to the USA), adequate safeguards under Art. 46 GDPR (Standard Contractual Clauses) are in place.
7. Your Rights
Access
Receive a copy of your personal data (Art. 15 GDPR).
Rectification
Correct inaccurate data (Art. 16 GDPR).
Erasure
Request deletion where no legal obligation applies (Art. 17 GDPR).
Portability
Receive data in a machine-readable format (Art. 20 GDPR).
Objection
Object to processing based on legitimate interest (Art. 21 GDPR).
Complaint
Lodge a complaint with your supervisory authority.
To exercise any right contact privacy@eofsl.com. We will respond within 30 days.
8. California Privacy Rights (CCPA)
California residents have the right to know what personal information is collected, to delete personal information, and to opt out of the sale of personal information. We do not sell personal information. To submit a request, email privacy@eofsl.com with subject "CCPA Request".
9. Cookies
Our website does not use tracking or advertising cookies. We use a single session cookie strictly necessary for checkout functionality. No consent banner is therefore required.
10. Changes
Material changes will be announced via our website or email at least 30 days in advance.