Overview — two different roles
LicenseFort handles personal data in two distinct roles, and this policy is split accordingly. Getting this distinction right is the point of this document, not an afterthought:
- Part A — we are the Controller for data about you, the Customer: your account, billing, and how you use the dashboard.
- Part B — we are a Processor, acting for you, for data about your End Users that passes through the licence-validation API when their copy of your Protected Software checks in — things like a hardware ID, an IP address, or a MetaTrader account number. That data belongs to your business relationship with your End Users, not ours; we handle it only on your instructions.
- Part C covers what's common to both: subprocessors, security, cookies, and how we handle changes to this policy.
Part A — LicenseFort as Controller
A1. Who we are
The data controller is Sergejs Makarovs, a sole trader trading as LicenseFort, registered address 71-75 Shelton St, London WC2H 9JQ, United Kingdom. Contact for any privacy matter, including exercising your rights below: support@licensefort.com.
Whether a separate EU representative (GDPR Article 27) is required or appointed: [[EU_REPRESENTATIVE_STATUS]] — LicenseFort serves customers worldwide, including in the EU, which is why this needs a definite answer rather than being left open; see the build report for why it's flagged rather than answered here.
A2. Data we collect about account holders
- Account: name, email address, hashed password (never stored in plain text — see §C2), company name if provided.
- Billing: handled by Paddle for card payments — LicenseFort does not receive or store full card numbers. For crypto payments, handled by NowPayments — LicenseFort receives the payment amount, cryptocurrency used, and transaction status, not wallet private keys.
- Usage data: products, Licence Keys, and Activations you create; API usage; support correspondence.
- Technical data: IP address and device/browser information from your own requests to the dashboard and API, for security and fraud prevention.
A3. Lawful bases
| Purpose | Lawful basis |
|---|---|
| Providing the Service, billing | Performance of a contract with you |
| Security, fraud prevention, abuse detection | Legitimate interest — protecting the Service and other Customers from misuse |
| Product analytics on your own account usage | Legitimate interest — understanding and improving the Service |
| Marketing communications | Consent, where required — you can withdraw it at any time |
| Tax and accounting records | Legal obligation |
A4. Retention
- Account data: for as long as your account is active, plus a reasonable period afterward for legal/tax records, then deleted.
- Support correspondence: retained for as long as reasonably needed to resolve related issues, typically no more than 24 months.
- Billing/tax records: retained as required by applicable tax law.
A5. Your rights
Subject to the law that applies to you, you may have the right to: access the personal data we hold about you; correct it; request deletion; object to or restrict certain processing; receive your data in a portable format; and withdraw consent where processing is based on it. Exercise any of these at support@licensefort.com. You also have the right to complain to your local data protection supervisory authority.
A6. International transfers
Where personal data is transferred outside the country it was collected in (for example, to a subprocessor located elsewhere — see Part C), we rely on [[TRANSFER_MECHANISM (e.g. Standard Contractual Clauses / UK IDTA / adequacy)]] as the transfer mechanism.
Part B — LicenseFort as Processor (your End Users' data)
B1. What this is
When someone using your Protected Software activates or checks a Licence Key, their copy of the software calls LicenseFort's validation API. That call carries identifiers about your End User — not you. These identifiers are personal data under GDPR (and equivalent laws elsewhere), and we're stating that plainly rather than leaving it implicit.
B2. What we process, on your behalf
- A hardware/device identifier generated by the Protected Software.
- The IP address the validation request came from.
- Where account binding is enabled: the End User's MetaTrader account number.
- Timestamp of each check, and coarse geolocation derivable from the IP address.
For this data, you are the controller and LicenseFort is the processor, acting only on your documented instructions (in practice: the Plan Limits, revocation, and expiry settings you configure). The terms of that processing are set out in the Data Processing Agreement, which forms part of your agreement with us. Activation logs are retained for [[ACTIVATION_LOG_RETENTION_PERIOD]].
LicenseFort does not use End User data for its own purposes, does not sell it, and does not use it for marketing, under any circumstances.
B3. Your obligations as controller
As the controller for your End Users' data, you're responsible for having your own lawful basis for processing it and for telling your End Users, in your own terms/privacy policy, that licence validation is performed by a third-party service (LicenseFort) and what that involves — see Terms §9.
Part C — shared
C1. Subprocessors
The subprocessors below actually handle data on our behalf today — see the maintained list at /subprocessors for the current, dated version. We'll give notice there before adding a new one.
C2. Security measures
Encryption in transit (TLS) and at rest for stored data; passwords hashed with Argon2id, never stored in plain text; sensitive identifiers such as Licence Keys stored hashed/encrypted, not in plain text; per-tenant data isolation enforced at the application layer; role-based access controls for administrative functions; and rate limiting on authentication and public endpoints. We do not hold, and do not claim, any third-party security certification (e.g. SOC 2, ISO 27001) — if that changes, this section will say so with the actual certificate.
C3. Cookies
LicenseFort sets exactly one cookie, and it's strictly necessary — there is no analytics, advertising, or marketing cookie on this site, so no cookie consent banner is shown.
| Name | Purpose | Duration | Category |
|---|---|---|---|
session | Keeps you signed in to the dashboard | 7 days | Strictly necessary |
C4. Children
The Service is not directed at, and is not intended for use by, anyone under 18.
C5. Breach notification
If a personal data breach occurs that's likely to affect you, we'll notify you without undue delay and, where legally required, notify the relevant supervisory authority within the applicable statutory window.
C6. Changes to this policy
Material changes are notified by email with at least 14 days' notice, matching the process in the Terms.
Changelog
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-12 | Initial draft. |
