1. Who is responsible
The controller for personal data on desk9design.com/ is desk9 — full contact details are on the Legal Disclosure page. For anything privacy-related, contact us via the support page.
2. What we collect, and why
Account and purchases. When you buy something, an account is created with your email address (and name, if provided). We store your licenses, subscription references and the Paddle customer ID that links your purchases. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Payment data. We never see or store card numbers or bank details. Payments run entirely through Paddle, our Merchant of Record, which processes them under its own privacy policy.
License activations. When you activate a license, your site’s URL is stored so we can enforce plan limits and deliver updates to the right sites. Legal basis: performance of the contract.
Support tickets. Whatever you send us in a ticket, so we can answer it. Legal basis: performance of the contract.
Emails. We send transactional email only: license keys, sign-in links, renewal reminders, ticket replies. No marketing emails without your explicit consent.
Server logs. Our web server records IP addresses and request data for a short period to keep the site secure and diagnose problems. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
3. Cookies
This site sets functional cookies only: a session cookie when you sign in to your account. There are no analytics, advertising or social-media cookies. During checkout, the embedded Paddle payment frame sets the cookies it needs to process your payment — details in Paddle’s privacy policy linked above.
4. Who receives your data
Two categories of recipients: Paddle (payment processing, invoicing, tax — as Merchant of Record they are an independent controller for the transaction) and our hosting provider in the EU, which processes data on our behalf under a data-processing agreement. We do not sell personal data, and we do not share it with anyone else unless the law requires it.
5. How long we keep data
Your account and license data are kept for as long as you have an account; ask us and we delete it (invoices are retained by Paddle for the statutory retention periods). Server logs are deleted after a short rotation period. Support tickets are kept so we can reference past issues — you can request their deletion at any time.
6. Your rights
Under the GDPR you can request access to your data, correction, deletion, restriction of processing and a portable copy, and you can object to processing based on legitimate interest. Most of it you can do yourself in your account (profile, email, password). You also have the right to complain to a data-protection supervisory authority.
7. Security
The site is served over TLS. Sign-in tokens are single-use, expire quickly and are stored hashed. License keys can be regenerated from your account at any time if one leaks.
8. Changes
When this policy changes, the date at the top changes with it. Material changes are announced to account holders by email.