[Company], Business ID [ID], [ADDRESS], Finland. Contact: email us. We have not appointed a Data Protection Officer; the contact above handles all privacy matters.
zkLicensing is built so that buyers need no account, no email, and no name — a license is bought with a crypto wallet and proven with cryptography. What little we process, and why, is listed below. Vendors, by contrast, must be identified businesses; we process their registration data because the law requires sellers to be identifiable and invoiceable.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Legal name, address, country, email | Registration, listing, contract administration, consumer-law trader disclosure | Contract (GDPR Art. 6(1)(b)); legal obligation (6(1)(c)) | Account data: deleted within 60 days after account closure (extended from 30 days to cover the vendor sunset window in the Terms — see Terms §13.3); financial records retained per row below |
| VAT ID + VIES validation log, business-status evidence | Correct invoicing (reverse charge), EC sales listings | Legal obligation | Kept alongside the corresponding accounting records (see below) |
| Fee invoices, payment records incl. MINA/fiat valuation at transaction time | Accounting, tax | Legal obligation | 6 years (Finnish Kirjanpitolaki 2:10) |
| Sanctions-screening result | Compliance with EU restrictive measures | Legal obligation | Duration of relationship + 5 years |
| Terms-acceptance records (version, hash, timestamp) | Evidence of contract | Contract; legitimate interest | Relationship + statutory limitation period |
Providing this information is a legal and contractual precondition to registering as a vendor; without it we cannot onboard you.
We hold no buyer accounts and no buyer identity data. The following limited processing occurs:
The site uses only strictly necessary cookies/local storage (e.g., wallet-connection state); no analytics, no advertising cookies, no third-party trackers. We do not maintain access logs for the public website or marketplace API beyond the security context described below.
To protect against brute-force login attempts and network abuse, our firewall and intrusion-prevention system log source IP addresses of denied administrative access attempts, and temporarily block IPs showing abusive behavior. Blocks are automatically lifted after a short cool-off period. Logs are rotated regularly and retained only for as long as needed to review recent security events — typically no longer than a few weeks. Legal basis: legitimate interest in network security (GDPR Art. 6(1)(f)).
Personal data we process may be shared with the following categories of recipients:
We do not sell personal data.
Data written to the Mina blockchain (wallet addresses, license hashes, transaction events) is replicated across a public, decentralized network. Neither zkLicensing nor any vendor can rectify or erase it. We minimize what goes on-chain: no names, no contact data — only pseudonymous keys and hashes. If you wish to avoid long-term linkability, use a dedicated wallet address for purchases.
For data we control off-chain, you have the usual GDPR rights: access, rectification, erasure, restriction, portability, and objection — subject to statutory retention duties (e.g., we cannot delete invoice records the law obliges us to keep). Contact email us. You may lodge a complaint with the Finnish supervisory authority — Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi — or your local EU/EEA supervisory authority.
Closing your vendor account. Email email us from your registered contact address. We will confirm the request, deactivate your listings, and delete account data within 60 days. The window is deliberately aligned with the vendor sunset process in the Terms (§13.3): a 30-day buyer-notice period followed by a 30-day account-purge grace so buyers have time to migrate off before the vendor's record disappears from our systems. Financial records covered by the 6-year retention row in Section 3.1 are retained until the statutory period expires; we cannot delete them earlier.
Primary processing (including hosting) occurs in the European Economic Area. Correspondence sent to email us and other email traffic is handled by an email service provider located in the United States; that transfer relies on the EU–US Data Privacy Framework (where the provider is DPF-certified) with Standard Contractual Clauses as a fallback safeguard. Any other non-EEA transfer, if introduced, will rely on an adequacy decision or Standard Contractual Clauses.
Offline signing keys for platform manifests; no buyer secrets ever transmitted to or stored by our servers (ownership passphrases never leave your device); TLS on all endpoints; access-controlled, logged administration; smart-contract circuit with published verification-key attestations.
License grant/deny at verification time is automated: the verifier checks a cryptographic proof against on-chain state and returns a valid/invalid result. There is no profiling and no decision with legal or similarly significant effect beyond the license grant/deny itself.
The service is not directed at children. Minimum age to use zkLicensing is 16 years.
We do not profile users or tailor marketing based on the personal data we collect (vendor records, wallet addresses, license activity, buyer-country codes, security logs, or any other data described above). Any general marketing we send — such as newsletters or product announcements — is the same for all recipients, is sent only where you have opted in, and can be unsubscribed from at any time. Service-operational notices (e.g., policy changes, incident notifications, transactional receipts) are separate from marketing and continue regardless of marketing preferences.
Material changes are announced on the site and, for vendors, by email with reasonable advance notice. Each version carries a number, date, and document hash.