GDPR Compliance
GDPR Compliance Statement
Last Updated: May 25, 2026
LicenPal (“we,” “us,” or “our”) is committed to protecting the personal data of individuals in the European Union and the European Economic Area in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). This page explains how we comply with GDPR requirements and how you can exercise your data protection rights.
1. Lawful Basis for Processing Personal Data
Under Article 6 of the GDPR, we process your personal data only when we have a lawful basis. The lawful bases we rely on are:
- Contractual Necessity (Article 6(1)(b)) — We process your data to fulfill our contractual obligations when you purchase products or services from us. This includes processing payments, delivering digital licenses, and providing technical support.
- Consent (Article 6(1)(a)) — Where we ask for your consent to send marketing communications, you may withdraw that consent at any time by contacting us or using the unsubscribe link in our emails.
- Legitimate Interests (Article 6(1)(f)) — We process data for fraud prevention, network security, and the improvement of our services. These legitimate interests are not overridden by your data protection rights.
- Legal Obligation (Article 6(1)(c)) — We process data where required by applicable laws, including tax regulations, anti-money laundering requirements, and commercial law.
2. Data Controller Identity and Contact Details
The controller responsible for your personal data under the GDPR is:
PREMIUM HOSTING SERVICES LIMITED
Registered in Ireland: Company No. 718621
Address: The Black Church, St. Mary’s Place, Dublin 7, D07 P4AX, Ireland
Email: [email protected]
Website: https://licenpal.com
3. Your GDPR Rights
If you are a data subject residing in the EU or EEA, the GDPR grants you the following rights:
3.1 Right of Access (Article 15)
You have the right to request confirmation as to whether we are processing your personal data, and if so, to obtain a copy of that data along with information about the purposes of processing, categories of data, recipients, and storage periods. Requests can be submitted to [email protected] and will be responded to within one month.
3.2 Right to Rectification (Article 16)
You have the right to request the correction of inaccurate personal data and the completion of incomplete data without undue delay.
3.3 Right to Erasure — “Right to be Forgotten” (Article 17)
You have the right to request the deletion of your personal data when:
- The data is no longer necessary for the purpose it was collected
- You withdraw your consent and no other lawful basis applies
- You object to the processing and there is no overriding legitimate interest
- The data has been processed unlawfully
Please note that we may retain certain data where we have a legal obligation to do so, such as tax records, transaction history, or fraud prevention purposes.
3.4 Right to Restriction of Processing (Article 18)
You have the right to request that we restrict the processing of your personal data in the following circumstances:
- You contest the accuracy of the data — during the period we verify the accuracy
- The processing is unlawful and you oppose erasure
- We no longer need the data, but you require it for legal claims
- You have objected to processing — during the period we assess whether legitimate grounds override your objection
3.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance. This applies to data provided by you and processed on the basis of consent or contract.
3.6 Right to Object (Article 21)
You have the right to object, on grounds relating to your particular situation, to the processing of your personal data where we rely on legitimate interests. You also have the absolute right to object to direct marketing at any time.
3.7 Rights Related to Automated Decision-Making and Profiling (Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Our services do not currently involve automated decision-making of this nature.
4. Data Breach Notification (Article 33 and 34)
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
If you believe your data may have been compromised, please contact us immediately at [email protected].
5. Data Transfers Outside the EEA
As an Irish company, we may transfer your personal data outside the European Economic Area. Where we do so, we ensure that appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) — Binding contractual obligations imposed on our data processors and service providers outside the EEA
- Adequacy Decisions — Transfers to countries deemed adequate by the European Commission
- Technical and Organizational Measures — Encryption, access controls, and security protocols to protect data in transit and at rest
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. Retention periods vary by category of data:
- Account Data: Retained for the duration of your account and up to 7 years after closure (tax and legal requirements)
- Transaction Records: Retained for 7 years (commercial and tax law)
- Marketing Consent Records: Retained until consent is withdrawn, plus 12 months for compliance records
- Support Ticket Data: Retained for 2 years after ticket closure
- Analytics and Log Data: Retained for 12 months, then anonymized
7. Complaints and Supervisory Authority
If you believe we have processed your personal data in a manner not permitted by the GDPR, you have the right to lodge a complaint with a supervisory authority. As an Irish company, the relevant supervisory authority is:
The Data Protection Commission (Ireland)
23 Fitzwilliam Square South
Dublin 2, D02 XR20
Ireland
Website: https://www.dataprotection.ie
Email: [email protected]
We encourage you to contact us directly at [email protected] before lodging a complaint, so that we may address your concerns promptly.
8. Changes to This GDPR Policy
We may update this GDPR policy from time to time to reflect changes in legislation, our processing activities, or best practices. Any material changes will be communicated via email or a prominent notice on our website. We recommend reviewing this page periodically.
This GDPR statement supplements our Privacy Policy. In the event of any inconsistency, the GDPR-compliant provisions shall prevail for EU data subjects.
