Privacy Policy

Last updated: February 2026


1. Identity of the Data Controller

In accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR):

I operate as an independent software developer under the brand Securitycheck Extensions.

For the purposes of applicable data protection legislation, I act as:

  • Independent Data Controller for website and support data
  • Service Provider / Vendor in relation to commercial transactions processed by Paddle

2. Related Legal Documents

This Privacy Policy must be read together with:

All documents are aligned and consistent with this Privacy Policy.

3. Merchant of Record Structure (Important Legal Clarification)

All product sales are processed by Paddle.com Market Limited, acting as:

  • Merchant of Record
  • Reseller of software
  • Independent Data Controller for payment and billing data

Paddle is contractually responsible for:

  • Payment processing
  • Tax calculation and remittance
  • Invoice issuance
  • Handling billing disputes

We do not collect, store, or process full payment card details.

Customers are subject to Paddle’s own Privacy Policy for billing-related processing.

This allocation of responsibilities reduces unnecessary data exposure and supports compliance with international financial and data protection regulations.

4. Categories of Data Processed

4.1 Website Technical & Security Data

When accessing the website:

  • IP address
  • Device and browser information
  • Access timestamps
  • Security logs

Purpose: Cybersecurity, fraud prevention, infrastructure protection.

Legal Basis: Legitimate interest (Art. 6(1)(f) GDPR). Security of systems is considered a compelling legitimate interest.

Logs are not used for profiling or marketing.

4.2 License & Download Credentials

For product delivery and licensing, we store:

  • License keys
  • Download account identifiers
  • Purchase reference identifiers

These are necessary to:

  • Provide software access
  • Validate license compliance
  • Deliver updates

Legal Basis: Performance of contract (Art. 6(1)(b) GDPR).

Retention: Duration of the license/subscription plus applicable legal retention obligations.

No excessive personal data is stored.

4.3 Support Communications

When contacting support, we may process:

  • Name
  • Email
  • Technical information voluntarily provided
  • Website configuration data if shared

Important: We do not permanently store customer backend login credentials for support purposes.

If temporary access is required:

  • Access is provided via secure, time-limited links
  • One-time tokens may be used
  • Credentials are deleted after the support intervention

Legal Basis: Performance of contract + legitimate interest (security).

5. Data Minimisation Principle

In accordance with Article 5 GDPR:

  • Only strictly necessary data is collected
  • No unnecessary personal profiling
  • No behavioural advertising
  • No data resale

The business model is structured to minimise data exposure by outsourcing billing to Paddle.

6. Cookies & Tracking

Cookies are governed by our Cookies Policy:

https://securitycheck.protegetuordenador.com/cookies-policy

Non-essential cookies require prior consent in the EU/EEA.

7. International Transfers

Because:

  • Customers are worldwide
  • Paddle operates internationally
  • Infrastructure providers may operate globally

Personal data may be transferred outside the EEA.

Safeguards include:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Contractual necessity

Further EU-specific information is available at:

https://securitycheck.protegetuordenador.com/eu-data

8. Data Retention

Data Category Retention
Security logs Max. 12 months
Support communications Up to 5 years
License records Duration of license + legal obligation
Accounting data As required by Spanish tax law

Data is securely deleted or anonymised once no longer required.

9. Data Sharing

We do not sell personal data.

Data may be shared only with:

  • Paddle (Merchant of Record)
  • Hosting providers
  • Infrastructure providers
  • Legal authorities where required

All processors operate under contractual confidentiality and data protection obligations.

10. Security Measures

We implement appropriate technical and organisational measures, including:

  • HTTPS encryption
  • Server hardening
  • Access controls
  • Limited data retention
  • Token-based temporary access
  • Regular software updates

No system can guarantee absolute security, but reasonable industry-standard safeguards are applied.

11. Data Subject Rights (GDPR)

EU/EEA residents may exercise:

  • Right of access
  • Rectification
  • Erasure
  • Restriction
  • Portability
  • Objection
  • Withdrawal of consent

Contact: contacto at this domain name

Supervisory authority in Spain: Agencia Española de Protección de Datos (AEPD) – https://www.aepd.es

Response time: within one month.

12. Non-EU Rights

Depending on jurisdiction (e.g., California, Brazil, UK), individuals may have additional rights.

We do not sell or monetise personal data.

Contact: contacto at this domain name

13. No Automated Decision-Making

We do not perform automated decision-making producing legal or similarly significant effects.

14. Children

Services are not directed to individuals under 16.

15. Limitation of Data Processing Responsibility

Where data is processed by third-party providers (e.g., Paddle), such providers act as independent controllers within their scope of responsibility.

We are not responsible for third-party privacy practices beyond contractual obligations.

16. Policy Updates

This policy may be updated to reflect legal, technical, or operational changes.

The current version is always available on this page.