This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller") and Sergejs Makarovs, trading as LicenseFort ("Processor"), and applies to LicenseFort's processing of your End Users' personal data as described in the Privacy Policy, Part B. Where this DPA conflicts with the Terms on this specific subject, this DPA controls.
1. Subject matter & duration
Processing of End User activation data for the duration of your LicenseFort account, plus any post-termination period described in §10.
2. Nature & purpose of processing
Automated processing of licence-validation requests: checking a Licence Key's status, enforcing device/account binding, and recording Activations — solely to provide the Service to you.
3. Categories of data subject and personal data
Data subjects: your End Users. Data: hardware/device identifier, IP address, MetaTrader account number (where account binding is enabled), Activation timestamps. No special-category data is intentionally processed.
4. Obligations of the parties
- Processor processes personal data only on the Controller's documented instructions — in practice, the Plan configuration, revocation, and expiry settings the Controller sets in the dashboard.
- Processor ensures personnel with access are bound by confidentiality obligations.
- Controller warrants it has a lawful basis for the processing it instructs.
5. Confidentiality
Processor keeps personal data confidential and does not disclose it except as instructed by the Controller or required by law.
6. Security measures
See Privacy Policy §C2 for the current security measures in place — encryption in transit and at rest, access controls, and rate limiting on the relevant endpoints.
7. Subprocessors
Processor may engage the subprocessors listed at /subprocessors, and will give notice there before adding a new one. Continued use of the Service after such notice constitutes authorisation, unless the Controller objects in writing within a reasonable time.
8. Assistance with data subject requests, DPIAs and breach notification
Processor will provide reasonable assistance to the Controller in responding to End User data subject requests, and in the Controller's own data protection impact assessments and breach notifications, to the extent the relevant information is available to Processor.
9. Breach notification
Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's End Users' data.
10. Deletion or return on termination
On termination of the Controller's account, Processor deletes End User activation data within the timeframe described in the Privacy Policy, except where retention is required by law.
11. Audit rights
Controller may request reasonable information demonstrating Processor's compliance with this DPA. [[AUDIT_MECHANISM_DETAIL — e.g. written information request vs. on-site audit rights and notice period]].
12. International transfers
Where a subprocessor is located outside the Controller's or data subject's jurisdiction, Processor relies on [[TRANSFER_MECHANISM (e.g. Standard Contractual Clauses, Module 3/4 as applicable)]] as the transfer mechanism.
Changelog
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-12 | Initial draft. |
