[Company], Business ID [ID], [ADDRESS]. Contact: [privacy@zklicensing.com]. We have not appointed a Data Protection Officer; the contact above handles all privacy matters.
zkLicensing is built so that buyers need no account, no email, and no name — a license is bought with a crypto wallet and proven with cryptography. What little we process, and why, is listed below. Vendors, by contrast, must be identified businesses; we process their registration data because the law requires sellers to be identifiable and invoiceable.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Legal name, address, country, email | Registration, listing, contract administration, consumer-law trader disclosure | Contract (GDPR Art. 6(1)(b)); legal obligation (6(1)(c)) | Duration of the relationship + statutory limitation periods |
| VAT ID + VIES validation log, business-status evidence | Correct invoicing (reverse charge), EC sales listings | Legal obligation | [JURISDICTION] bookkeeping / VAT rules: 6–10 years |
| Fee invoices, payment records incl. MINA/fiat valuation at transaction time | Accounting, tax | Legal obligation | 6–10 years |
| Sanctions-screening result | Compliance with EU restrictive measures | Legal obligation | Duration of relationship + 5 years |
| Terms-acceptance records (version, hash, timestamp) | Evidence of contract | Contract; legitimate interest | Relationship + limitation period |
We hold no buyer accounts and no buyer identity data. The following limited processing occurs:
The site uses only strictly necessary cookies/local storage (e.g., wallet-connection state); no analytics or advertising cookies.
Hosting and infrastructure providers in the EEA ([PROVIDER]); the vendor whose product you buy (license events surfaced to their own dashboard); auditors and authorities where legally required. We do not sell personal data.
Data written to the Mina blockchain (wallet addresses, license hashes, transaction events) is replicated across a public, decentralized network. Neither zkLicensing nor any vendor can rectify or erase it. We minimize what goes on-chain: no names, no contact data — only pseudonymous keys and hashes. If you wish to avoid long-term linkability, use a dedicated wallet address for purchases.
For data we control off-chain, you have the usual GDPR rights: access, rectification, erasure, restriction, portability, and objection — subject to statutory retention duties (e.g., we cannot delete invoice records the law obliges us to keep). Contact [privacy@zklicensing.com]. You may lodge a complaint with the [JURISDICTION] data protection supervisory authority or your local supervisory authority.
Primary processing occurs in the EEA. Where a processor operates outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
Offline signing keys for platform manifests; no buyer secrets ever transmitted to or stored by our servers (ownership passphrases never leave your device); TLS on all endpoints; access-controlled, logged administration; smart-contract circuit with published verification-key attestations.
Material changes are announced on the site and, for vendors, by email with 30 days' notice. Each version carries a number, date, and document hash.