Data Processing Agreement

Last updated June 4, 2026

Effective date: June 4, 2026  ·  Applies to all users of License Vault

Last updated: June 2025

Introduction

This Data Processing Agreement forms part of the agreement between you (the Controller) and License Vault (the Processor) for the use of the License Vault service. It sets out how we process personal data on your behalf in accordance with the UK GDPR, the EU General Data Protection Regulation (2016/679), and the Data Protection Act 2018.


Definitions

Controller means you, the customer, who determines the purposes and means of processing personal data.

Processor means License Vault, who processes personal data on your behalf.

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion.

Sub-processor means any third party engaged by License Vault to process personal data in connection with the service.


Data Processing Details

We process personal data for the duration of your active subscription and for up to 90 days after account termination, after which all personal data is permanently deleted. We process data solely to provide and improve the License Vault service. We do not process personal data for our own commercial purposes and we never sell it to third parties.

Types of Personal Data Processed

Account data: name, email address, company name. Usage data: login timestamps, feature usage, session identifiers. Team member data: names and email addresses of invited team members. Billing data: billing name and address (full card details are processed by Stripe directly and never stored by us).

Categories of Data Subjects

Your account holders and administrators; team members you invite to your License Vault account; and any individuals whose personal data you upload as part of license records.


Controller Obligations

As Controller, you agree to ensure you have a lawful basis for any personal data you provide or store within License Vault; ensure any personal data you upload complies with applicable data protection law; provide clear privacy notices to data subjects (such as invited team members); and respond to data subject rights requests promptly.


Processor Obligations

As Processor, License Vault agrees to process personal data only on your documented instructions; ensure all personnel with access to personal data are bound by appropriate confidentiality obligations; implement and maintain appropriate technical and organisational security measures; notify you without undue delay (and within 72 hours where feasible) of any personal data breach affecting your data; provide reasonable assistance to help you fulfil data subject rights requests; and delete or return all personal data upon termination of the agreement.


Sub-Processors

We engage the following sub-processors to deliver the service. We will notify you at least 14 days before adding or replacing any sub-processor.

Hosting provider: Hostinger VPS — Infrastructure hosting — EU/UK

Payment processor: Stripe — Secure payment processing — USA (SCCs in place)

AI features (optional): OpenAI — AI-assisted draft features when enabled — USA (SCCs in place)


Data Subject Rights

We will assist you in responding to requests from data subjects exercising their rights under GDPR, including rights of access, rectification, erasure, portability, restriction, and objection. Contact us at hello@licensemanager.viraloo.org.


Security Measures

We implement the following protections: encryption of data in transit using TLS 1.3; encryption of sensitive fields at rest using AES-256; access controls and least-privilege principles for staff; regular security assessments and dependency auditing; and automated backups with point-in-time recovery.


International Transfers

Where personal data is transferred outside the UK or EEA (for example to Stripe or OpenAI in the USA), such transfers are governed by Standard Contractual Clauses approved by the relevant supervisory authority.


Contact and Supervisory Authority

Data protection contact: hello@licensemanager.viraloo.org

You have the right to lodge a complaint with your relevant supervisory authority. In the UK this is the Information Commissioner's Office at ico.org.uk. In the EU, contact your local Data Protection Authority.