Last updated: July 17, 2026
1. Our commitment
We built the data we collect around what's actually needed to issue and validate a license - not around collecting as much as possible. Where we've had a choice, we've defaulted to privacy-by-design rather than bolting compliance on afterward.
2. Controller and processor roles
For account and billing data (your name, email, payment records, license details), we act as the data controller. For anything running inside VPS guests on a Virtlix installation - the panel runs on your own server, not ours - you are the controller of that data, and we have no access to it at all.
3. Your rights
If you're in the EU or UK, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request erasure ("right to be forgotten"), subject to legal retention requirements such as billing records;
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Lodge a complaint with your local data protection supervisory authority.
4. Data processing agreement
If you need a signed Data Processing Agreement for your own compliance records, request one via our Contact page and we'll send it over.
5. Sub-processors
We use a small number of vetted third parties to run the business - a payment processor for billing and an email delivery provider for transactional mail. Each operates under its own GDPR-compliant terms; we don't add new sub-processors without reviewing their compliance first.
6. Data location
Account and license data is stored on infrastructure we control directly. Where a sub-processor is located outside your region, transfers are covered by that provider's own Standard Contractual Clauses or equivalent safeguard.
7. Breach notification
In the event of a data breach affecting your personal information, we'll notify affected customers and, where required, the relevant supervisory authority, within the timeframes GDPR requires.
8. Exercising your rights
To exercise any of the rights above, contact us through the Contact page with "GDPR request" as the topic. We aim to respond within the one-month window GDPR allows for these requests.