The company Cense Data Inc. dba Licensespring, with registered office at 11383 W 8th Ave, Vancouver, BC V6H 3W4, Canada, Business Registration no. 81673 9726RT0001 (hereinafter referred to as “we” or “us”), in its capacity of data controller regarding the processing of Personal Data, is committed to protecting and respecting the privacy of its users, customers and suppliers, even prospective (hereinafter singularly and collectively referred to as the “you” or “your”), pursuant to the applicable national laws on data protection (hereinafter referred to as the “National Law”) and, if you are citizen of a Country in the European Economic Area, also pursuant to the European Regulation no. 679/2016 (hereinafter referred to as the “GDPR”) (hereinafter the National Law and the GDPR will be referred to as the “Applicable Law”).
This policy (hereinafter referred to as the “Privacy Policy”) is aimed to inform you about our practices related to our collection and use of your Personal Data either through our website www.licensespring.com (hereinafter referred to as the “Site”) or during the performance of any of our service (hereinafter collectively referred to as the “Services”).
“Personal Data” means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
We invite you to read this Privacy Policy carefully to understand our considerations and practices regarding the processing of your Personal Data.
When you visit the Site or when we provide you with our Services, we may collect the following Personal Data:
You may, through our Site, our Services or other contact channel (e.g., e-mail, etc.), voluntarily provide us Personal Data and/or information and documents containing Personal Data. In particular, such Personal Data may include your name, email, address, order number content and type, and any other information you send through our customer support. We will process these data in accordance with the Applicable Law and on the assumption that they refer to you or to third parties who have authorized you to provide them pursuant to an appropriate legal basis which legitimize the processing at stake. In this case, you act as independent data controller, assuming all relevant obligations and responsibilities according to the Applicable Law. In this regard, you hence waive, in the full sense of the term, the right to all disputes, claims, claims for damages due to processing, etc., which may be submitted to us by the said third parties whose Personal Data have been processed through your use of the Site or the Services in breach of the Applicable Law.
In order to provide you with the Services or in order to improve the performance thereof, we process your Personal Data and/or associate other data to your Personal Data, including: (i) generating license keys associated with the Services you requested; (ii) generating sales reports; (iii) developing or improving reporting tools; (iv) for general statistical purposes (e.g., case studies, business presentation, etc.).
Computer systems and software procedures used to operate the Site collect some Personal Data, the transmission of which is an integral part of internet communication protocols. This information is not collected to be associated with you but, by its very nature, it may allow you to be identified by processing and associating it with data held by third parties. Among collected Personal Data there are: (i) IP addresses or domain names of the devices used by you to connect to the Site; (ii) the URI (Uniform Resource Identifier) of requested resources; (iii) the time of the request, the method used to submit the request to the server; (iv) the size of the file received as a reply; (v) the numeric code indicating the status of the reply given by the server (successful, error, etc.); (vi) other parameters regarding your operating system and device environment.
We may collect Personal Data using cookies. You can find further information on the use of cookie and similar technologies here.
Personal Data provided by you will be processed by us for the purposes and legal basis specified below:
Processor role — data we process for our customers
End-user name and email, where the customer configures this.
Device ID.
IP address.
MAC address.
License and usage data.
Controller role — data we collect for ourselves
Customer and prospect contact information (name, email, phone, billing address).
Account information.
Employee data.
LicenseSpring does not intentionally collect special-category (sensitive) data. Customers are contractually restricted, via the MSA/DPA, from submitting such data through the platform without our prior written agreement.
We collect personal data through the following methods:
Directly from you: When you fill out forms, create accounts, or contact us.
Automatically: Through cookies, analytics tools, and logs when you use our website or services.
Third parties: From business partners, service providers, or publicly available sources.
Through use of our licensing SDK/API by end users of our customers’ products.
We process personal data only when permitted by law. The legal bases include:
Consent: When you provide explicit consent (e.g., marketing communications).
Contractual necessity: To fulfill a contract with you (e.g., processing orders).
Legal obligation: To comply with legal and regulatory requirements.
Legitimate interests: For fraud prevention, improving services, or ensuring security. This includes the processing of IP addresses in system and security logs for the purposes of service security, abuse detection, and troubleshooting.
For end-user/processor data, the legal basis is established and documented by the customer as Data Controller. LicenseSpring processes this data strictly on the customer’s documented instructions.
We use personal data for the following purposes:
Providing and improving our services.
Processing transactions and managing accounts.
Communicating with you regarding updates, offers, and support.
Conducting analytics and research to improve user experience.
Ensuring security, detecting fraud, and complying with legal obligations.
End-user/processor data is used only to deliver the licensing/entitlement service in accordance with customer instructions — including license validation, usage reporting to that customer, and anti-piracy/fraud detection. This data is never used for LicenseSpring’s own independent marketing or analytics.
We may share personal data under these circumstances:
Service providers: With vendors or contractors who perform services on our behalf.
Legal compliance: To comply with laws, subpoenas, or other legal processes.
Business transfers: In the event of mergers, acquisitions, or asset sales.
Consent: When you explicitly agree to share your data.
Additional controls:
All disclosures must be logged and recorded, including recipient, purpose, and data shared.
Third parties must sign data processing agreements (DPAs) with defined privacy obligations.
Sub-processors must be approved and monitored.
LicenseSpring maintains a Sub-processor List covering categories such as cloud hosting, CRM, email platform, support/ticketing tool, and ClickUp. This list is kept current and shared with customers per DPA notice requirements.
We retain personal data according to the following schedule:
End-user/license data: Retained for the life of the active license plus a 90-day post-termination purge window, unless a longer legal retention period applies.
CRM/prospect data: Retained for the duration of the business relationship and for up to 7 years after last meaningful engagement, subject to annual review; dormant non-converting leads are pruned at review.
Support tickets: Identifiable ticket data retained for the duration of the customer relationship plus 5 years.
System and security logs: Retained for the period defined in our Log Management Policy, after which they expire automatically.
Afterward, data is securely deleted or anonymized.
We implement industry-standard technical and organizational measures to safeguard personal data, including:
Encryption (at rest and in transit).
Access controls and authentication protocols.
Regular audits and security assessments.
Regular security testing including vulnerability assessments and audits.
Monitoring for unauthorized access and anomalies.
Personal data shall be securely deleted or destroyed using approved methods such as:
Secure wiping / cryptographic erasure
Physical destruction of media
Disposal actions must be logged and verified. Third-party disposal providers must comply with security requirements.
See our Information Security Policy for full technical and organizational control detail.
Depending on your jurisdiction, you may have the following rights:
Access: Request access to your data.
Rectification: Correct inaccurate or incomplete data.
Deletion: Request deletion of your data.
Data portability: Obtain a copy of your data in a portable format.
Restriction: Request a limitation on the processing of your data.
Objection: Object to certain processing activities (e.g., direct marketing).
Withdraw consent: Withdraw your consent when processing is based on consent.
Formal procedures exist to handle data subject requests within defined timelines. All requests are logged and tracked.
The right to erasure is not absolute. Our system and security logs are held in an append-only log store that does not permit the selective deletion of individual records. Where these logs contain personal data such as IP addresses, that data is retained for security, abuse detection, and troubleshooting purposes, and is deleted automatically on expiry of the applicable retention period rather than on request. This limitation is recognised under Article 17(3) GDPR and Recital 65. It does not affect your right to erasure in respect of any other personal data we hold about you.
If you are an end user of one of our customers’ products, please contact that company directly, as they are the Data Controller for your information. We support our customers in fulfilling such requests under our DPA.
If you are a LicenseSpring customer, prospect, or business contact, contact us at privacy@licensespring.com.
If you are located in the EU/EEA or the UK, you may also submit your request through our appointed representative, Prighter, at app.prighter.com/portal/licensespring — see “EU and UK Representatives” above.
Privacy Impact Assessments must be conducted for:
New systems or applications
New data processing activities
Changes to existing processing
Onboarding a new sub-processor
Adding a new integration/feature that processes end-user data
A DPIA must evaluate risks to individuals, data sensitivity, and processing scale. Mitigation measures must be defined and approved before implementation.
All data breaches must be reported immediately to the Privacy Lead. The regulator will be notified without undue delay and, where feasible, within 72 hours of becoming aware (GDPR Art. 33). As a processor, we will notify affected customers without undue delay so they can meet their own notification obligations, targeting customer notification within 24–48 hours of confirmation.
Where a supervisory authority in the EU or UK contacts our appointed representative in connection with an incident, the representative will forward that communication to the Privacy Lead without delay.
Incidents must be investigated, documented, and resolved. Regulatory and user notifications must be made within legally required timelines. Root cause analysis and corrective actions must be implemented.
Personal data transfers outside the originating jurisdiction must comply with applicable laws.
Sub-processor locations and applicable transfer mechanisms (Standard Contractual Clauses or adequacy decisions) are documented in our Sub-processor List, available on request.
Appropriate safeguards must be implemented, such as:
Standard Contractual Clauses (SCCs)
Adequacy decisions
Binding Corporate Rules (if applicable)
The Organization shall maintain records of:
Processing activities
Data disclosures
Consent records
DPIA assessments
Breach incidents
Records must be retained for audit and compliance purposes. These records are maintained in our Record of Processing Activities (ROPA).
The Organization shall ensure personal data is accurate, complete, and up to date.
Mechanisms shall exist to validate data at collection and to periodically review and update stored data. Inaccurate data must be corrected or deleted without delay.
See our Cookies Policy for details on the cookies we use and how to manage your preferences.
LicenseSpring’s own channels (website, CRM, marketing) are not directed at children, and we do not knowingly collect children’s data in that capacity. As a data processor, we do not collect age-related information about end users and therefore cannot determine whether an end user is a child.
Customers are contractually restricted, via the MSA/DPA, from submitting personal data relating to children through the platform without our prior written agreement. Where a customer’s product is directed at children, the customer, as Data Controller, is responsible for obtaining any parental consent required under Article 8 GDPR or equivalent law.
Our website or services may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their privacy policies.
The Organization will update this policy periodically to reflect changes in laws, regulations, or business practices.
Policy updates must be reviewed, approved, and communicated to relevant stakeholders.
This policy is reviewed at least annually and is included in our recurring compliance calendar.
Certain data processing responsibilities, consent mechanisms, and children’s data handling are further addressed in our Master Services Agreement (MSA) and Data Processing Agreement (DPA) with customers.