Privacy Policy
This policy explains what personal data Softy processes, why, on what legal basis, who receives it, how long we keep it, and the rights you can exercise. It is written to satisfy Articles 13 and 14 of the GDPR (Regulation (EU) 2016/679).
Controller
The controller is Softy. For any question about this policy, or to exercise the rights described in section 7, write to softy.managment@gmail.com.
We have not appointed a Data Protection Officer, as none of the cases in Article 37 of the GDPR applies to our activity. The contact above handles all requests.
What we collect and why
We collect only what each purpose needs.
| Purpose | Data | Legal basis |
|---|---|---|
| Processing your order and delivering your licence | E-mail address, order reference, product and duration, amount, payment method, invoice | Performance of the contract (Art. 6(1)(b)) |
| Linking your purchases to your account and granting your customer role | Discord ID, username, avatar, e-mail; OAuth tokens | Performance of the contract (Art. 6(1)(b)) |
| Licence activation and preventing key sharing | Hardware identifier, activation dates, IP address (see section 3) | Legitimate interest in protecting our product (Art. 6(1)(f)) |
| Preventing fraud, chargeback abuse and abusive resale | IP address, country, user agent, payment signals, blacklist entries | Legitimate interest in security (Art. 6(1)(f)) |
| Customer support and ticket history | Messages you send us, ticket transcripts, order reference | Performance of the contract (Art. 6(1)(b)) |
| Publishing reviews you choose to leave | Discord username or masked e-mail, rating, review text, any image you attach | Consent (Art. 6(1)(a)) |
| Affiliate and referral attribution | Referral code, order amount, first-party sa_aff cookie |
Consent for the cookie; contract for the payout. See Cookies |
| Accounting and tax obligations | Invoices and transaction records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have weighed that interest against your rights and you may object at any time under section 7.
We do not process special categories of data, we do not sell your data, and we do not use it for advertising profiling.
Providing the data marked as necessary for an order is a contractual requirement: without an e-mail address we cannot deliver your licence.
Hardware identifiers
Some products bind a licence to your machine using a hardware identifier derived from characteristics of your computer. We store it as a one-way fingerprint, not as a readable inventory of your components.
This identifier is personal data because it singles out a device linked to you. We use it only to check that a licence is used on the number of machines it covers, and to allow support to reset a binding when you change hardware.
Our software may record technical events indicating tampering or an attempt to run the licence outside its terms. These records are limited to what is needed to establish the abuse and are never used to observe what you do on your computer generally.
Decisions to block a licence are reviewed by a person before becoming permanent. You may contest one under Article 22(3) of the GDPR by contacting support.
Who receives your data
We use the following processors and partners.
| Recipient | Role | What it receives |
|---|---|---|
| SellAuth | Storefront and order platform | E-mail, order, payment status, invoice |
| Supabase | Database hosting | Account, licence and order records |
| Vercel | Website and API hosting | Technical logs, IP address |
| Discord | Authentication, community, support tickets | Discord identifiers, messages, roles |
| GitHub | Private storage of the review archive | Reviews you chose to publish |
Each of these acts on our instructions under a contract meeting Article 28 of the GDPR.
Payment providers. Card and cryptocurrency payments are handled on the provider's own pages. Your card number never reaches our systems, and we do not receive or store your banking details. The provider processes that information under its own responsibility and its own privacy policy.
Reviews. A review you submit is displayed publicly on our site and on our Discord, under the name you chose. A copy is kept in a private archive for backup, not for publication. Do not include anything in a review that you would not want other customers to see. You may ask us to remove yours at any time.
We disclose data to a public authority only where the law obliges us to.
Transfers outside the EU
Several of our providers are established in the United States. Transfers there rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the European Commission, together with the additional measures required by Chapter V of the GDPR.
You may ask us for a copy of the safeguards applying to a given transfer.
How long we keep it
| Data | Retention |
|---|---|
| Account and licence records | For as long as your account exists, then 12 months |
| Invoices and accounting records | 10 years, as required by Article L123-22 of the Code de commerce |
| Support tickets and transcripts | 3 years from the last exchange |
| Technical and security logs | 12 months |
| Fraud and blacklist entries | 3 years from the event, then reviewed |
| Published reviews | Until you ask for removal |
| OAuth tokens | Until you disconnect the account or the token expires |
At the end of a retention period the data is deleted or irreversibly anonymised. Backups are overwritten on their own cycle, which may briefly outlast deletion in the live database.
Your rights
Under the GDPR you may exercise the following rights:
- Access: obtain confirmation that we process your data and a copy of it (Art. 15).
- Rectification: correct inaccurate or incomplete data (Art. 16).
- Erasure: have your data deleted where one of the grounds in Art. 17 applies.
- Restriction: freeze processing while a dispute is resolved (Art. 18).
- Portability: receive the data you provided in a machine-readable format (Art. 20).
- Objection: object to processing based on our legitimate interest (Art. 21).
- Withdraw consent: at any time, without affecting processing already carried out (Art. 7(3)).
- Post-mortem directives: define what becomes of your data after your death (Art. 85 of the French Data Protection Act).
Write to softy.managment@gmail.com. We answer within one month, which may be extended by two months for complex requests; we will tell you if that happens. We may ask for proof of identity where there is genuine doubt.
Some data cannot be erased on request, notably invoices we must keep for accounting purposes. We will tell you which data that is and why.
You may lodge a complaint with a supervisory authority, in France the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr, or with the authority of your country of residence.
Security
We use encryption in transit, signed session cookies, access restricted to the people who need it, and server-side secrets that are never exposed to the browser. Payment card details never reach our systems.
No system is perfectly secure. In the event of a breach likely to result in a risk to your rights, we notify the CNIL within 72 hours and inform you where the risk is high, as Articles 33 and 34 require.
Children
The Services are not intended for minors and we do not knowingly collect their data. If you believe a minor has given us data, contact us and we will delete it.
Last updated 27 August 2026. We publish the current version of every document on this site; earlier versions are available on request.
