Softy logo Softy Back to site
Privacy

Privacy Policy

This policy explains what personal data Softy processes, why, on what legal basis, who receives it, how long we keep it, and the rights you can exercise. It is written to satisfy Articles 13 and 14 of the GDPR (Regulation (EU) 2016/679).

GDPR Controller: Softy CNIL supervision
01

Controller

1.1

The controller is Softy. For any question about this policy, or to exercise the rights described in section 7, write to softy.managment@gmail.com.

1.2

We have not appointed a Data Protection Officer, as none of the cases in Article 37 of the GDPR applies to our activity. The contact above handles all requests.

02

What we collect and why

We collect only what each purpose needs.

PurposeDataLegal basis
Processing your order and delivering your licence E-mail address, order reference, product and duration, amount, payment method, invoice Performance of the contract (Art. 6(1)(b))
Linking your purchases to your account and granting your customer role Discord ID, username, avatar, e-mail; OAuth tokens Performance of the contract (Art. 6(1)(b))
Licence activation and preventing key sharing Hardware identifier, activation dates, IP address (see section 3) Legitimate interest in protecting our product (Art. 6(1)(f))
Preventing fraud, chargeback abuse and abusive resale IP address, country, user agent, payment signals, blacklist entries Legitimate interest in security (Art. 6(1)(f))
Customer support and ticket history Messages you send us, ticket transcripts, order reference Performance of the contract (Art. 6(1)(b))
Publishing reviews you choose to leave Discord username or masked e-mail, rating, review text, any image you attach Consent (Art. 6(1)(a))
Affiliate and referral attribution Referral code, order amount, first-party sa_aff cookie Consent for the cookie; contract for the payout. See Cookies
Accounting and tax obligations Invoices and transaction records Legal obligation (Art. 6(1)(c))
2.1

Where we rely on legitimate interest, we have weighed that interest against your rights and you may object at any time under section 7.

2.2

We do not process special categories of data, we do not sell your data, and we do not use it for advertising profiling.

2.3

Providing the data marked as necessary for an order is a contractual requirement: without an e-mail address we cannot deliver your licence.

03

Hardware identifiers

3.1

Some products bind a licence to your machine using a hardware identifier derived from characteristics of your computer. We store it as a one-way fingerprint, not as a readable inventory of your components.

3.2

This identifier is personal data because it singles out a device linked to you. We use it only to check that a licence is used on the number of machines it covers, and to allow support to reset a binding when you change hardware.

3.3

Our software may record technical events indicating tampering or an attempt to run the licence outside its terms. These records are limited to what is needed to establish the abuse and are never used to observe what you do on your computer generally.

3.4

Decisions to block a licence are reviewed by a person before becoming permanent. You may contest one under Article 22(3) of the GDPR by contacting support.

04

Who receives your data

We use the following processors and partners.

RecipientRoleWhat it receives
SellAuthStorefront and order platformE-mail, order, payment status, invoice
SupabaseDatabase hostingAccount, licence and order records
VercelWebsite and API hostingTechnical logs, IP address
DiscordAuthentication, community, support ticketsDiscord identifiers, messages, roles
GitHubPrivate storage of the review archiveReviews you chose to publish
4.1

Each of these acts on our instructions under a contract meeting Article 28 of the GDPR.

4.2

Payment providers. Card and cryptocurrency payments are handled on the provider's own pages. Your card number never reaches our systems, and we do not receive or store your banking details. The provider processes that information under its own responsibility and its own privacy policy.

4.3

Reviews. A review you submit is displayed publicly on our site and on our Discord, under the name you chose. A copy is kept in a private archive for backup, not for publication. Do not include anything in a review that you would not want other customers to see. You may ask us to remove yours at any time.

4.4

We disclose data to a public authority only where the law obliges us to.

05

Transfers outside the EU

5.1

Several of our providers are established in the United States. Transfers there rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the European Commission, together with the additional measures required by Chapter V of the GDPR.

5.2

You may ask us for a copy of the safeguards applying to a given transfer.

06

How long we keep it

DataRetention
Account and licence recordsFor as long as your account exists, then 12 months
Invoices and accounting records10 years, as required by Article L123-22 of the Code de commerce
Support tickets and transcripts3 years from the last exchange
Technical and security logs12 months
Fraud and blacklist entries3 years from the event, then reviewed
Published reviewsUntil you ask for removal
OAuth tokensUntil you disconnect the account or the token expires
6.1

At the end of a retention period the data is deleted or irreversibly anonymised. Backups are overwritten on their own cycle, which may briefly outlast deletion in the live database.

07

Your rights

Under the GDPR you may exercise the following rights:

7.1

Write to softy.managment@gmail.com. We answer within one month, which may be extended by two months for complex requests; we will tell you if that happens. We may ask for proof of identity where there is genuine doubt.

7.2

Some data cannot be erased on request, notably invoices we must keep for accounting purposes. We will tell you which data that is and why.

7.3

You may lodge a complaint with a supervisory authority, in France the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr, or with the authority of your country of residence.

08

Security

8.1

We use encryption in transit, signed session cookies, access restricted to the people who need it, and server-side secrets that are never exposed to the browser. Payment card details never reach our systems.

8.2

No system is perfectly secure. In the event of a breach likely to result in a risk to your rights, we notify the CNIL within 72 hours and inform you where the risk is high, as Articles 33 and 34 require.

09

Children

9.1

The Services are not intended for minors and we do not knowingly collect their data. If you believe a minor has given us data, contact us and we will delete it.

Last updated 27 August 2026. We publish the current version of every document on this site; earlier versions are available on request.