LicenseSpring

LicenseSpring Data Privacy Policy

PRIVACY POLICY

Effective date: September 2, 2026

GENERAL INFORMATION

The company Cense Data Inc. dba Licensespring, with registered office at 11383 W 8th Ave, Vancouver, BC V6H 3W4, Canada, Business Registration no. 81673 9726RT0001 (hereinafter referred to as “we” or “us”), in its capacity of data controller regarding the processing of Personal Data, is committed to protecting and respecting the privacy of its users, customers and suppliers, even prospective (hereinafter singularly and collectively referred to as the “you” or “your”), pursuant to the applicable national laws on data protection (hereinafter referred to as the “National Law”) and, if you are citizen of a Country in the European Economic Area, also pursuant to the European Regulation no. 679/2016 (hereinafter referred to as the “GDPR”) (hereinafter the National Law and the GDPR will be referred to as the “Applicable Law”).

This policy (hereinafter referred to as the “Privacy Policy”) is aimed to inform you about our practices related to our collection and use of your Personal Data either through our website www.licensespring.com (hereinafter referred to as the “Site”) or during the performance of any of our service (hereinafter collectively referred to as the “Services”).

Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

We invite you to read this Privacy Policy carefully to understand our considerations and practices regarding the processing of your Personal Data.

PERSONAL DATA WE PROCESS

When you visit the Site or when we provide you with our Services, we may collect the following Personal Data:

Information you give us.

You may, through our Site, our Services or other contact channel (e.g., e-mail, etc.), voluntarily provide us Personal Data and/or information and documents containing Personal Data. In particular, such Personal Data may include your name, email, address, order number content and type, and any other information you send through our customer support. We will process these data in accordance with the Applicable Law and on the assumption that they refer to you or to third parties who have authorized you to provide them pursuant to an appropriate legal basis which legitimize the processing at stake. In this case, you act as independent data controller, assuming all relevant obligations and responsibilities according to the Applicable Law. In this regard, you hence waive, in the full sense of the term, the right to all disputes, claims, claims for damages due to processing, etc., which may be submitted to us by the said third parties whose Personal Data have been processed through your use of the Site or the Services in breach of the Applicable Law.

Information processed by us.

In order to provide you with the Services or in order to improve the performance thereof, we process your Personal Data and/or associate other data to your Personal Data, including: (i) generating license keys associated with the Services you requested; (ii) generating sales reports; (iii) developing or improving reporting tools; (iv) for general statistical purposes (e.g., case studies, business presentation, etc.).

Browsing data.

Computer systems and software procedures used to operate the Site collect some Personal Data, the transmission of which is an integral part of internet communication protocols. This information is not collected to be associated with you but, by its very nature, it may allow you to be identified by processing and associating it with data held by third parties. Among collected Personal Data there are: (i) IP addresses or domain names of the devices used by you to connect to the Site; (ii) the URI (Uniform Resource Identifier) of requested resources; (iii) the time of the request, the method used to submit the request to the server; (iv) the size of the file received as a reply; (v) the numeric code indicating the status of the reply given by the server (successful, error, etc.); (vi) other parameters regarding your operating system and device environment.

Cookies and similar technologies.

We may collect Personal Data using cookies. You can find further information on the use of cookie and similar technologies here.

PURPOSES AND LEGAL BASIS OF THE PROCESSING

Purposes.

Personal Data provided by you will be processed by us for the purposes and legal basis specified below:

Processor role — data we process for our customers

End-user name and email, where the customer configures this.

Device ID.

IP address.

MAC address.

License and usage data.

Controller role — data we collect for ourselves

Customer and prospect contact information (name, email, phone, billing address).

Account information.

Employee data.

Data we do not collect

LicenseSpring does not intentionally collect special-category (sensitive) data. Customers are contractually restricted, via the MSA/DPA, from submitting such data through the platform without our prior written agreement.

How we handle personal data

How we collect personal data

We collect personal data through the following methods:

Legal bases for processing personal data

We process personal data only when permitted by law. The legal bases include:

For end-user/processor data, the legal basis is established and documented by the customer as Data Controller. LicenseSpring processes this data strictly on the customer’s documented instructions.

How we use personal data

We use personal data for the following purposes:

End-user/processor data is used only to deliver the licensing/entitlement service in accordance with customer instructions — including license validation, usage reporting to that customer, and anti-piracy/fraud detection. This data is never used for LicenseSpring’s own independent marketing or analytics.

Data sharing and disclosure

We may share personal data under these circumstances:

Additional controls:

LicenseSpring maintains a Sub-processor List covering categories such as cloud hosting, CRM, email platform, support/ticketing tool, and ClickUp. This list is kept current and shared with customers per DPA notice requirements.

Data retention

We retain personal data according to the following schedule:

Afterward, data is securely deleted or anonymized.

Data security

We implement industry-standard technical and organizational measures to safeguard personal data, including:

Personal data shall be securely deleted or destroyed using approved methods such as:

Disposal actions must be logged and verified. Third-party disposal providers must comply with security requirements.

See our Information Security Policy for full technical and organizational control detail.

Your rights

Depending on your jurisdiction, you may have the following rights:

Formal procedures exist to handle data subject requests within defined timelines. All requests are logged and tracked.

Limits on the right to erasure

The right to erasure is not absolute. Our system and security logs are held in an append-only log store that does not permit the selective deletion of individual records. Where these logs contain personal data such as IP addresses, that data is retained for security, abuse detection, and troubleshooting purposes, and is deleted automatically on expiry of the applicable retention period rather than on request. This limitation is recognised under Article 17(3) GDPR and Recital 65. It does not affect your right to erasure in respect of any other personal data we hold about you.

How to make a request

How we govern privacy

Privacy Impact Assessments (DPIA / PIA)

Privacy Impact Assessments must be conducted for:

A DPIA must evaluate risks to individuals, data sensitivity, and processing scale. Mitigation measures must be defined and approved before implementation.

Privacy incident management and breach notification

All data breaches must be reported immediately to the Privacy Lead. The regulator will be notified without undue delay and, where feasible, within 72 hours of becoming aware (GDPR Art. 33). As a processor, we will notify affected customers without undue delay so they can meet their own notification obligations, targeting customer notification within 24–48 hours of confirmation.

Where a supervisory authority in the EU or UK contacts our appointed representative in connection with an incident, the representative will forward that communication to the Privacy Lead without delay.

Incidents must be investigated, documented, and resolved. Regulatory and user notifications must be made within legally required timelines. Root cause analysis and corrective actions must be implemented.

Cross-border data transfers

Personal data transfers outside the originating jurisdiction must comply with applicable laws.

Sub-processor locations and applicable transfer mechanisms (Standard Contractual Clauses or adequacy decisions) are documented in our Sub-processor List, available on request.

Appropriate safeguards must be implemented, such as:

Record keeping and accountability

The Organization shall maintain records of:

Records must be retained for audit and compliance purposes. These records are maintained in our Record of Processing Activities (ROPA).

Data accuracy and quality management

The Organization shall ensure personal data is accurate, complete, and up to date.

Mechanisms shall exist to validate data at collection and to periodically review and update stored data. Inaccurate data must be corrected or deleted without delay.

Other notices

Cookies and tracking technologies

See our Cookies Policy for details on the cookies we use and how to manage your preferences.

Children’s privacy

LicenseSpring’s own channels (website, CRM, marketing) are not directed at children, and we do not knowingly collect children’s data in that capacity. As a data processor, we do not collect age-related information about end users and therefore cannot determine whether an end user is a child.

Customers are contractually restricted, via the MSA/DPA, from submitting personal data relating to children through the platform without our prior written agreement. Where a customer’s product is directed at children, the customer, as Data Controller, is responsible for obtaining any parental consent required under Article 8 GDPR or equivalent law.

Third-party links

Our website or services may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their privacy policies.

Updates to this policy

The Organization will update this policy periodically to reflect changes in laws, regulations, or business practices.

Policy updates must be reviewed, approved, and communicated to relevant stakeholders.

This policy is reviewed at least annually and is included in our recurring compliance calendar.

Contractual cross-references

Certain data processing responsibilities, consent mechanisms, and children’s data handling are further addressed in our Master Services Agreement (MSA) and Data Processing Agreement (DPA) with customers.