Privacy Policy
Last updated: June 17, 2026
1. Who we are
DSoftStudio ("we", "us", "our") develops and distributes DSoftStudio Mediator, a .NET mediator library and commercial developer tooling. Our billing is processed by Paddle.com Market Ltd ("Paddle"), who acts as the Merchant of Record for all transactions.
2. What we collect
- Account data — email address and optional display name when you sign up for the customer portal.
- License data — license key, seat count, activation timestamps, machine fingerprints (one-way hashed, non-reversible identifiers), machine name, IDE/editor version, a platform identifier (operating system and architecture), and a build identifier. Sent only during license activation and periodic check-ins, and used solely for license validation, seat management, and anti-piracy.
- Billing data — handled entirely by Paddle. We do not store credit card numbers, bank details, or payment tokens.
We do not collect usage telemetry, analytics, or source code from your applications. Authentication is performed using email-based magic links. We do not require or store passwords.
3. Why we collect it
- To issue, activate, and validate your commercial license.
- To enforce seat limits per your subscription tier.
- To communicate product updates and security notices.
4. Legal basis (GDPR)
We process your data based on:
- Contractual necessity — license activation, seat enforcement, and billing.
- Legitimate interest — communicating product updates and security notices to registered users.
- Legitimate interest — preventing fraud and repeated free-trial abuse.
5. How we store it
All data is stored in Microsoft Azure using encrypted-at-rest storage. Machine fingerprints are one-way hashed before transmission. License payloads are signed with Ed25519 and verified offline — no sensitive data leaves your machine during routine validation.
6. Third parties
- Paddle — payment processing, invoicing, tax compliance (Merchant of Record).
- Microsoft Azure — infrastructure hosting.
We do not sell, rent, or share your data with advertisers or data brokers. We do not use your data for advertising or marketing targeting. All third-party providers are subject to appropriate data protection agreements.
7. Cookies
The customer portal uses a single session cookie for authentication. The marketing site does not use tracking or analytics cookies. Paddle may set cookies during checkout — see Paddle's Privacy Policy.
8. Your rights
You can request access to, correction of, or deletion of your personal data at any time. For any privacy-related questions, contact us at privacy@dsoftstudio.com. We will respond within 30 days. We honor erasure requests except where we must retain certain data by law (for example, tax records held by Paddle) or to prevent fraud, in which case we keep only the minimum necessary. If you are in the EU/EEA, you have additional rights under GDPR including data portability and the right to lodge a complaint with your local supervisory authority.
9. Data retention
We keep personal data only as long as needed for the purpose it was collected:
- Account & license data — for the life of your subscription and up to 24 months after your last license ends (to support renewals, reactivation, and dispute resolution). After that the account is anonymized: your email and name are irreversibly removed and the account can no longer be accessed.
- Authentication links — magic-link and trial-verification tokens are deleted within 90 days.
- Security & activation records — license check-in logs are kept up to 30 days; activation history is de-identified after 14 months; security audit records are kept up to 14 months.
- Fraud-prevention signal — a one-way, non-reversible value derived from your email is retained even after anonymization, solely to prevent repeated free-trial abuse, on the basis of our legitimate interest.
- Billing & tax records — retained by Paddle (our Merchant of Record) under their legal obligations; see Paddle's privacy policy.
Data collected during a free trial is subject to the same retention and protection standards as paid subscriptions.
10. Security
We implement industry-standard security practices including encrypted storage, signed license validation, and secure authentication flows. Authentication is passwordless and performed using secure, time-limited email links. Sensitive payment data is never handled directly by us and is processed entirely by Paddle.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to registered users. The "Last updated" date at the top reflects the most recent revision.