ts
win
#eb9526

Data Protection Information

Deutsch | English

Royal Apps GmbH processes personal data in connection with its website, its customer account portal, the sale of software licences, and customer support. This information explains what we process, on what basis, who receives it, and what rights you have.

1. Processing activities

Operation of the Royal Apps and related websites; operation of the customer account portal at my.royalapps.com; sale of software licences; verification of issued licences; provision of customer support; and email communication with customers and interested parties.

2. Controller

Royal Apps GmbH
Münichreiterstrasse 52/28, 1130 Vienna, Austria
Company register number: FN 531364 v
Company register court: Handelsgericht Wien
VAT ID: ATU75476334

3. Contact details of the controller

Royal Apps GmbH, c/o Controller
Münichreiterstrasse 52/28, 1130 Vienna, Austria
Email: [email protected]

We have not appointed a Data Protection Officer; we are not required to under Art. 37 GDPR. Enquiries sent to the address above reach the person responsible for data protection matters.

4. Purposes of data processing

We process personal data for the following purposes:

  • a. Provision of the websites. Delivering the pages you request, maintaining availability, and defending against attacks and abuse.
  • b. Customer account. Creating and administering your account, authenticating you, linking your licences to your account, and giving you access to your licence and order history.
  • c. Sale of licences. Preparing and performing the purchase contract, transmitting your order data to our sales platform for completion of the sale, issuing and delivering licence keys, and administering renewals.
  • d. Licence verification. Verifying that a licence key in use is valid and preventing misuse of licence keys.
  • e. Customer support. Receiving, processing and answering support requests and keeping a record of the correspondence.
  • f. Email marketing. Sending our newsletter and product information where you have subscribed.
  • g. Compliance with legal obligations. In particular retention duties under tax and commercial law.

5. Legal basis for data processing

  • a. Website provision – delivering requested content: Art. 6 (1) (b) GDPR (performance or preparation of a contract) and Art. 6 (1) (f) GDPR
  • a. Website provision – security, abuse and bot defence: Art. 6 (1) (f) GDPR – legitimate interests (see no. 6)
  • b. Customer account: Art. 6 (1) (b) GDPR
  • c. Sale of licences: Art. 6 (1) (b) GDPR
  • d. Licence verification: Art. 6 (1) (f) GDPR – legitimate interests (see no. 6)
  • e. Customer support: Art. 6 (1) (b) GDPR; Art. 6 (1) (f) GDPR where you are not yet a customer
  • f. Email marketing – subscribers who opted in: Art. 6 (1) (a) GDPR – your consent, which you may withdraw at any time with effect for the future
  • f. Email marketing – existing customers, own similar products: Art. 6 (1) (f) GDPR – legitimate interests (Recital 47 GDPR, see no. 6), with sending permitted under Section 174 (4) of the Austrian Telecommunications Act [TKG 2021]
  • g. Legal retention duties: Art. 6 (1) (c) GDPR

6. Description of (overriding) legitimate interests for the purposes

of IT security:

We store the IP addresses of visitors to our web servers and download sites in log files for a period of 7 days in order to detect and defend against targeted attacks in the form of server overloads (Denial of Service attacks) or other damage to the systems. Our interest in keeping our services available and secure outweighs the limited intrusion of a short-lived log entry (Recital 49 GDPR).

of protection against automated abuse:

We use the Cloudflare Turnstile challenge service (see no. 11) on our licence request forms and on the reseller registration, login and password reset forms in order to distinguish human users from automated scripts. Without it, these forms can be used for mass requests, credential stuffing and spam at the expense of our customers. The service processes your IP address as well as browser and device characteristics; it does not identify you personally to us.

of verifying the licence:

We store the IP addresses of licensed customers in order to verify the licence key and to detect misuse of a licence key. Our interest in protecting our software against unlicensed use outweighs the limited intrusion, since the data is used for no other purpose.

of direct marketing to existing customers:

Where you have purchased a licence from us, we may send you information about our products using the email address and preferences you gave us in connection with that purchase. The messages relate only to your products and you can stop them at any time in your customer account at my.royalapps.com, or you can object at any time free of charge by contacting our support.
We rely on Recital 47 GDPR and on Section 174 (4) of the Austrian Telecommunications Act [TKG 2021], and we only use data which we already hold under the contractual relationship.

7. Obligation to provide data

You are not generally obliged to provide personal data in order to browse our website. However, certain data is required for specific services:

  • To create a customer account, we need an email address and a password. Without them an account cannot be created.
  • To purchase a licence, we need the billing details required to conclude and invoice the contract (name, address, country and, for business customers, VAT ID). Without them the purchase cannot be completed.
  • To receive support, we need an email address and a description of your request.
  • To receive the newsletter, we need an email address and your consent.

Providing the data is a contractual requirement in each case, not a statutory one. The only consequence of not providing it is that we cannot supply the service concerned.

8. Automated decision-making

You are not subject to any automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.

Our sales platform (see no. 11.2) carries out automated fraud and risk screening of payment transactions as part of its own obligations as seller, and a transaction may be declined as a result. This is carried out by the platform, not by us, and does not involve profiling of you by Royal Apps.

9. Processed types of data

provided by the customer:

  • Name/Company name
  • Address(es)
  • Phone number(s)
  • Email address(es)
  • VAT identification number (for business purchases)
  • Account credentials (your password is stored only as a cryptographic hash, never in readable form)
  • Public display name, where you choose to provide one for the community forums
  • Content of support requests and correspondence

additionally collected by us:

  • IP addresses (log files and licence verification)
  • Information of the terminal device (e.g. operating system version, language, etc.)
  • Browser used
  • Equipment used
  • Information on use of account and licence (e.g. date created, user name, computer name, number of logins, date of the last request, error reports)
  • Information on newsletter subscription
  • Communications protocol
  • Security and challenge signals used to detect automated access (see no. 6 and no. 10)

received from third parties:

  • Order and licence data from our sales platforms (see no. 11.2)
  • Click and delivery behaviour in email campaigns, where you are subscribed to the newsletter (see no. 11.1)

10. Cookies and similar technologies

We use only cookies which are strictly necessary to provide a service you have requested, on our website and in the customer account portal. These are set without consent, as permitted by Section 165 (3) of the Austrian Telecommunications Act [TKG 2021]. We do not use analytics, advertising or cross-site tracking technologies, and nothing on this site therefore requires your consent. Section 165 (3) TKG 2021 covers any storing of information on your device, so anything we kept in your browser's local storage would be listed here as well.

strictly necessary:

  • ra_selected_page (Royal Apps) – remembers the product page you last selected so that navigation returns you to it; 20 minutes.
  • PHPSESSID (Royal Apps) – retains the state of your visit between requests, for example the steps of the order process; session.
  • .AspNetCore.Antiforgery.* (Royal Apps) – protects the forms of the customer account portal against cross-site request forgery; session (deleted when the browser closes).
  • .AspNetCore.Identity.Application (Royal Apps) – keeps you logged in to the customer account portal; session – the login itself lapses after 14 days without use.
  • .AspNetCore.Session (Royal Apps) – retains the state of the order process between steps; session – the data behind it is discarded after 20 minutes of inactivity.

If you reach our website through a campaign or partner link, we keep the referral parameter of that link for 30 minutes in the server-side session belonging to the cookie named above, so that an order or licence request can be attributed to it. Nothing is stored on your device for this purpose.

The Cloudflare Turnstile challenge on the forms named in no. 6 stores nothing on your device: it verifies a token against Cloudflare's servers, writes nothing to your browser storage and sets no cookie of its own (confirmed 25 August 2026).

11. External recipients of data

11.1 Processors acting on our instructions

We have concluded a data processing agreement under Art. 28 GDPR with each of the following.

Brevo (formerly Sendinblue SAS)
17 rue de Salneuve
75017 Paris - France

Types of data:

Email addresses of customers for email campaign mailing; click and delivery behaviour in those campaigns.
https://www.brevo.com/legal/privacypolicy/

Azure
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399 - USA

Types of data:

Cloud hosting for our website and customer account portal; stores visitor IP addresses accessing web servers and download sites in log files and for security purposes. Our web tier runs in the West Europe region.
https://www.microsoft.com/en-us/TrustCenter/Privacy

Cloudflare
Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107 - USA

Types of data:

Content delivery, protection against attacks, and the Turnstile challenge service described in no. 6. Processes IP address as well as browser and device characteristics of visitors to our sites.
https://www.cloudflare.com/privacypolicy/

Zammad
Zammad GmbH
Marienstraße 18
10117 Berlin - Germany

Types of data:

Email addresses of customers and content of support requests by email and via the website.
https://zammad.com/company/privacy

Google Workspace
Google Cloud EMEA Limited
Velasco, Clanwilliam Place
Dublin 2 - Ireland

Types of data:

Email communication.
https://policies.google.com/privacy

Netmonic
TIMEWARP IT Consulting GmbH
Diefenbachgasse 5/7
1150 Vienna - Austria

Types of data:

Cloud provider stores IP addresses accessing web servers and download sites in log files and for security purposes.
https://timewarp.at/impressum


All processors can be written to and contacted via the controller with regard to questions of data protection law.

11.2 Recipients acting as independent controllers

FastSpring
Bright Market, LLC (dba FastSpring)
Santa Barbara, California - USA
and FastSpring B.V.
De Cuserstraat 91
1081 CN Amsterdam - Netherlands

FastSpring is the seller and merchant of record for purchases of our software. When you place an order, the purchase contract for the licence is concluded with FastSpring, not with Royal Apps.

  • We transmit to FastSpring the order data you enter in our order process: name, company name, billing address, country, email address and, where provided, VAT ID, together with the products selected.
  • FastSpring processes your payment data directly. Royal Apps never receives or stores your card or payment account details.
  • FastSpring determines the purposes and means of processing for payment execution, transaction security and fraud prevention, and for the collection, reporting and remittance of VAT and sales tax. For those purposes it acts as an independent controller and its own privacy statement applies: https://fastspring.com/privacy
  • FastSpring returns order and licence data to us, which we use to issue your licence, service your subscription, and meet our own record-keeping duties.

11.3 Joint controllership with FastSpring (Art. 26 GDPR)

For the payment for your order, Royal Apps GmbH and FastSpring – Bright Market, LLC and FastSpring B.V. – are joint controllers within the meaning of Art. 26 GDPR. The essence of our arrangement is as follows.

Who is responsible for what:

  • Royal Apps GmbH: presentation of our products, the order process on our site, and the details you enter before checkout.
  • FastSpring, jointly with us: payment processing, transaction security and fraud prevention, invoicing, and the collection, reporting and remittance of VAT and sales tax.
  • FastSpring, acting on our instructions as our processor: hosting the checkout and sending order confirmations.
  • Royal Apps GmbH: issuing and administering your licence, your customer account, and customer support.
  • FastSpring: retention of the transaction and tax records generated by the sale.

Information duties:

We provide the information required by Art. 13 GDPR for the details you give us during the order process. FastSpring provides it for the processing it carries out, in its own privacy statement at https://fastspring.com/privacy.

Your rights:

You may exercise your rights under Art. 15 to 21 GDPR against either of us, irrespective of which of us holds the data (Art. 26 (3) GDPR). If you contact us about data held by FastSpring we will forward your request and tell you that we have done so, and FastSpring does the same in the other direction. Please note that data which we or FastSpring are required to retain under tax or commercial law cannot be erased on request (Art. 17 (3) (b) GDPR).

Contact point:

For questions about this arrangement, write to [email protected]. You may also contact FastSpring's Data Protection Officer at [email protected].

11.4 Former recipients

The following recipients are no longer used. They are named here because data transmitted to them while they were in use may still be held by them under their own retention duties.

MyCommerce / shareit
Mariahilferstrasse 50/2/11
Entrance Kirchengasse 1
1070 Vienna - Austria

Sales platform previously used for the sale of licences, acting as an independent controller.
The platform ceased operations on 27/28 January 2025.

Freshdesk
Freshworks
Alte Jakobstrasse 85/86
Hof 3, Haus 6
10179 Berlin - Germany

Helpdesk platform used as our processor until January 2026, when it was replaced by Zammad.

Types of data:

Email addresses of customers and content of support requests by email and via the website.
https://freshdesk.com/gdpr

12. Transfer to third countries

Some of the recipients named in no. 11 are established outside the European Economic Area, or process data outside it. Where that is the case, the transfer is made on the following basis:

  • Google LLC (USA), as sub-processor of Google Cloud EMEA Limited – email communication: EU-U.S. Data Privacy Framework certification, supplemented by Standard Contractual Clauses. Our contracts are with the Irish entities; transfers to the US parent occur as sub-processing.
  • Microsoft Corporation (USA) – IP addresses in log files: EU-U.S. Data Privacy Framework certification, supplemented by Standard Contractual Clauses. Our Azure web tier is hosted in the West Europe region and Microsoft's EU Data Boundary keeps customer data for these services within the EU, so a transfer occurs only in the limited cases which Microsoft documents (for example certain support scenarios).
  • Cloudflare, Inc. (USA) – IP addresses, browser and device characteristics: EU-U.S. Data Privacy Framework certification, supplemented by Standard Contractual Clauses.
  • Bright Market, LLC (dba FastSpring) (USA) – order and billing data: EU-U.S. Data Privacy Framework, certified for non-HR personal data.

Standard Contractual Clauses are the clauses adopted by the European Commission under Art. 46 (2) (c) GDPR. You may request a copy of the safeguards in place by writing to the address in no. 3.

13. Social media presence

We maintain presences on social media channels to publicise our products and to communicate with customers. Our own websites link to them as ordinary links only: no content is loaded from the platforms, no social plugins or share buttons are used, and no data reaches them until you follow a link.

If you visit one of our presences, the platform operator processes your personal data for its own purposes and under its own responsibility - in particular by storing or reading identifiers on your device and using your behaviour there for interest-based advertising. We have no influence over that processing, which may take place outside the European Union under safeguards the operator applies and describes in its own privacy statement. Where you write to us on a platform, we process your message in order to answer it, on the basis of Art. 6(1)(f) GDPR.

Rights concerning the platforms' own processing must be addressed to the operator, and you can adjust the relevant advertising and privacy settings yourself in your account there.

Additional information is available at:

Facebook (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
Privacy statement: https://www.facebook.com/about/privacy
Opt-out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com

Google/YouTube (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
Privacy statement: https://policies.google.com/privacy
Opt-out: https://adssettings.google.com/authenticated

X (X Corp., Attn: Privacy Policy Inquiry, 865 FM 1209, Building 2, Bastrop, TX 78602, USA)
Privacy statement: https://x.com/privacy
Opt-out: https://x.com/personalization

Mastodon (dotnet.social, operated by the instance administrators)
Privacy statement: https://dotnet.social/privacy-policy

14. Storage period

  • Server log files including IP addresses of visitors: 7 days.
  • Security and challenge data: as applied by our security provider (see no. 11.1).
  • Customer account data: for the duration of the account. On deletion of the account, erased or anonymised, except where a longer period applies below.
  • Licence and subscription records: for the term of the contract and thereafter for another 40 months (= 36 months for potential contractual claims for damages + a service period of a maximum of 4 months for service of a claim).
  • Accounting records and invoices: 7 years from the end of the year in which the transaction occurred (Section 132 of the Austrian Federal Fiscal Code [BAO]). Where FastSpring is the seller, that duty rests with FastSpring and we retain only our own payout records.
  • Support requests and correspondence: 36 months from closure of the ticket.
  • Newsletter subscription: until you withdraw your consent; the record of consent is kept with your customer account data.

15. Rights of the data subject

Basis: Art 15 GDPR "Access"
Contents: The customer shall have the right to obtain confirmation as to whether or not his personal data is being processed.

Basis: Art 16 GDPR "Rectification"
Contents: The customer shall have the right to obtain without undue delay the rectification of inaccurate personal data or to have it completed.

Basis: Art 17 GDPR "Erasure"
Contents: The customer shall have the right to obtain the erasure of personal data without undue delay as long as the reasons stated in Art 17(1) GDPR are fulfilled.

Basis: Art 18 GDPR "Restriction"
Contents: The customer shall have the right to obtain restriction of processing of personal data as long as the reasons stated in Art 18(1) GDPR are fulfilled.

Basis: Art 21 GDPR "Objection"
Contents: The customer shall have the right to object to processing of his personal data at any time to the extent that the processing of personal data is based on an overriding legitimate interest of the controller.

Basis: Art 20 GDPR "Data portability"
Contents: The customer shall have the right to receive the personal data concerning him, which he has provided, in a structured, commonly used and machine-readable format.

Basis: Art 7 (3) GDPR "Withdrawal of consent"
Contents: Where processing is based on consent, the customer shall have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it. Newsletter consent can be withdrawn using the unsubscribe link in any message or by writing to us.

To exercise a right, write to the address in no. 3. We will respond within one month; where a request is complex we may extend that period by two further months and will tell you if we do. We may ask you to confirm your identity where we cannot otherwise establish it.

Where your request concerns data held by FastSpring as an independent controller (see no. 11.2) – in particular payment and tax records – we will forward it and tell you that we have done so. Please note that data which we or FastSpring are required to retain under tax or commercial law cannot be erased on request (Art. 17 (3) (b) GDPR).

16. Right to lodge a complaint

Basis: Art 77 GDPR
Contents: Each customer shall have the right to lodge a complaint with the supervisory authority if he considers that the processing of personal data relating to him infringes this Regulation, in particular in the Member State of his habitual residence, place of work, or place of the alleged infringement.

17. Supervisory authority

Austrian Data Protection Authority [Österreichische Datenschutzbehörde]
Wickenburggasse 8-10
A-1080 Vienna
Phone: +43 1 52 152-0
Email: [email protected]

18. Changes to this information

We update this information when our processing changes.

  • 01 August, 2026 – consolidated version, covering the website, the customer account portal, the shop and customer support.

 

If only the masculine form is used to describe natural persons in this data protection information, it shall refer to all persons equally. The term customer refers to both consumers and entrepreneurs.