Royal Apps GmbH processes personal data in connection with its website, its customer account portal, the sale of software licences, and customer support. This information explains what we process, on what basis, who receives it, and what rights you have.
Operation of the Royal Apps and related websites; operation of the customer account portal at my.royalapps.com; sale of software licences; verification of issued licences; provision of customer support; and email communication with customers and interested parties.
Royal Apps GmbH
Münichreiterstrasse 52/28, 1130 Vienna, Austria
Company register number: FN 531364 v
Company register court: Handelsgericht Wien
VAT ID: ATU75476334
Royal Apps GmbH, c/o Controller
Münichreiterstrasse 52/28, 1130 Vienna, Austria
Email: [email protected]
We have not appointed a Data Protection Officer; we are not required to under Art. 37 GDPR. Enquiries sent to the address above reach the person responsible for data protection matters.
We process personal data for the following purposes:
We store the IP addresses of visitors to our web servers and download sites in log files for a period of 7 days in order to detect and defend against targeted attacks in the form of server overloads (Denial of Service attacks) or other damage to the systems. Our interest in keeping our services available and secure outweighs the limited intrusion of a short-lived log entry (Recital 49 GDPR).
We use the Cloudflare Turnstile challenge service (see no. 11) on our licence request forms and on the reseller registration, login and password reset forms in order to distinguish human users from automated scripts. Without it, these forms can be used for mass requests, credential stuffing and spam at the expense of our customers. The service processes your IP address as well as browser and device characteristics; it does not identify you personally to us.
We store the IP addresses of licensed customers in order to verify the licence key and to detect misuse of a licence key. Our interest in protecting our software against unlicensed use outweighs the limited intrusion, since the data is used for no other purpose.
Where you have purchased a licence from us, we may send you information about our products
using the email address and preferences you gave us in connection with that purchase.
The messages relate only to your products and you can stop them at any time in your customer account at my.royalapps.com,
or you can object at any time free of charge by contacting our support.
We rely on Recital 47 GDPR and on Section 174 (4) of the Austrian Telecommunications Act [TKG 2021], and
we only use data which we already hold under the contractual relationship.
You are not generally obliged to provide personal data in order to browse our website. However, certain data is required for specific services:
Providing the data is a contractual requirement in each case, not a statutory one. The only consequence of not providing it is that we cannot supply the service concerned.
You are not subject to any automated decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR.
Our sales platform (see no. 11.2) carries out automated fraud and risk screening of payment transactions as part of its own obligations as seller, and a transaction may be declined as a result. This is carried out by the platform, not by us, and does not involve profiling of you by Royal Apps.
We use only cookies which are strictly necessary to provide a service you have requested, on our website and in the customer account portal. These are set without consent, as permitted by Section 165 (3) of the Austrian Telecommunications Act [TKG 2021]. We do not use analytics, advertising or cross-site tracking technologies, and nothing on this site therefore requires your consent. Section 165 (3) TKG 2021 covers any storing of information on your device, so anything we kept in your browser's local storage would be listed here as well.
If you reach our website through a campaign or partner link, we keep the referral parameter of that link for 30 minutes in the server-side session belonging to the cookie named above, so that an order or licence request can be attributed to it. Nothing is stored on your device for this purpose.
The Cloudflare Turnstile challenge on the forms named in no. 6 stores nothing on your device: it verifies a token against Cloudflare's servers, writes nothing to your browser storage and sets no cookie of its own (confirmed 25 August 2026).
We have concluded a data processing agreement under Art. 28 GDPR with each of the following.
Brevo (formerly Sendinblue SAS)
17 rue de Salneuve
75017 Paris - France
Email addresses of customers for email campaign mailing; click and delivery behaviour in those campaigns.
https://www.brevo.com/legal/privacypolicy/
Azure
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052-6399 - USA
Cloud hosting for our website and customer account portal; stores visitor IP addresses accessing web servers and download sites in log files and for security purposes. Our web tier runs in the West Europe region.
https://www.microsoft.com/en-us/TrustCenter/Privacy
Cloudflare
Cloudflare, Inc.
101 Townsend Street
San Francisco, California 94107 - USA
Content delivery, protection against attacks, and the Turnstile challenge service described in no. 6. Processes IP address as well as browser and device characteristics of visitors to our sites.
https://www.cloudflare.com/privacypolicy/
Zammad
Zammad GmbH
Marienstraße 18
10117 Berlin - Germany
Email addresses of customers and content of support requests by email and via the website.
https://zammad.com/company/privacy
Google Workspace
Google Cloud EMEA Limited
Velasco, Clanwilliam Place
Dublin 2 - Ireland
Email communication.
https://policies.google.com/privacy
Netmonic
TIMEWARP IT Consulting GmbH
Diefenbachgasse 5/7
1150 Vienna - Austria
Cloud provider stores IP addresses accessing web servers and download sites in log files and for security purposes.
https://timewarp.at/impressum
All processors can be written to and contacted via the controller with regard to questions of data protection law.
FastSpring
Bright Market, LLC (dba FastSpring)
Santa Barbara, California - USA
and FastSpring B.V.
De Cuserstraat 91
1081 CN Amsterdam - Netherlands
FastSpring is the seller and merchant of record for purchases of our software. When you place an order, the purchase contract for the licence is concluded with FastSpring, not with Royal Apps.
For the payment for your order, Royal Apps GmbH and FastSpring – Bright Market, LLC and FastSpring B.V. – are joint controllers within the meaning of Art. 26 GDPR. The essence of our arrangement is as follows.
We provide the information required by Art. 13 GDPR for the details you give us during the order process. FastSpring provides it for the processing it carries out, in its own privacy statement at https://fastspring.com/privacy.
You may exercise your rights under Art. 15 to 21 GDPR against either of us, irrespective of which of us holds the data (Art. 26 (3) GDPR). If you contact us about data held by FastSpring we will forward your request and tell you that we have done so, and FastSpring does the same in the other direction. Please note that data which we or FastSpring are required to retain under tax or commercial law cannot be erased on request (Art. 17 (3) (b) GDPR).
For questions about this arrangement, write to [email protected]. You may also contact FastSpring's Data Protection Officer at [email protected].
The following recipients are no longer used. They are named here because data transmitted to them while they were in use may still be held by them under their own retention duties.
MyCommerce / shareit
Mariahilferstrasse 50/2/11
Entrance Kirchengasse 1
1070 Vienna - Austria
Sales platform previously used for the sale of licences, acting as an independent controller.
The platform ceased operations on 27/28 January 2025.
Freshdesk
Freshworks
Alte Jakobstrasse 85/86
Hof 3, Haus 6
10179 Berlin - Germany
Helpdesk platform used as our processor until January 2026, when it was replaced by Zammad.
Email addresses of customers and content of support requests by email and via the website.
https://freshdesk.com/gdpr
Some of the recipients named in no. 11 are established outside the European Economic Area, or process data outside it. Where that is the case, the transfer is made on the following basis:
Standard Contractual Clauses are the clauses adopted by the European Commission under Art. 46 (2) (c) GDPR. You may request a copy of the safeguards in place by writing to the address in no. 3.
We maintain presences on social media channels to publicise our products and to communicate with customers. Our own websites link to them as ordinary links only: no content is loaded from the platforms, no social plugins or share buttons are used, and no data reaches them until you follow a link.
If you visit one of our presences, the platform operator processes your personal data for its own purposes and under its own responsibility - in particular by storing or reading identifiers on your device and using your behaviour there for interest-based advertising. We have no influence over that processing, which may take place outside the European Union under safeguards the operator applies and describes in its own privacy statement. Where you write to us on a platform, we process your message in order to answer it, on the basis of Art. 6(1)(f) GDPR.
Rights concerning the platforms' own processing must be addressed to the operator, and you can adjust the relevant advertising and privacy settings yourself in your account there.
Additional information is available at:
Facebook (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland)
Privacy statement: https://www.facebook.com/about/privacy
Opt-out: https://www.facebook.com/settings?tab=ads and http://www.youronlinechoices.com
Google/YouTube (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA)
Privacy statement: https://policies.google.com/privacy
Opt-out: https://adssettings.google.com/authenticated
X (X Corp., Attn: Privacy Policy Inquiry, 865 FM 1209, Building 2, Bastrop, TX 78602, USA)
Privacy statement: https://x.com/privacy
Opt-out: https://x.com/personalization
Mastodon (dotnet.social, operated by the instance administrators)
Privacy statement: https://dotnet.social/privacy-policy
Basis: Art 15 GDPR "Access"
Contents: The customer shall have the right to obtain confirmation as to whether or not his personal data is being processed.
Basis: Art 16 GDPR "Rectification"
Contents: The customer shall have the right to obtain without undue delay the rectification of inaccurate personal data or to have it completed.
Basis: Art 17 GDPR "Erasure"
Contents: The customer shall have the right to obtain the erasure of personal data without undue delay as long as the reasons stated in Art 17(1) GDPR are fulfilled.
Basis: Art 18 GDPR "Restriction"
Contents: The customer shall have the right to obtain restriction of processing of personal data as long as the reasons stated in Art 18(1) GDPR are fulfilled.
Basis: Art 21 GDPR "Objection"
Contents: The customer shall have the right to object to processing of his personal data at any time to the extent that the processing of personal data is based on an overriding legitimate interest of the controller.
Basis: Art 20 GDPR "Data portability"
Contents: The customer shall have the right to receive the personal data concerning him, which he has provided, in a structured, commonly used and machine-readable format.
Basis: Art 7 (3) GDPR "Withdrawal of consent"
Contents: Where processing is based on consent, the customer shall have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it. Newsletter consent can be withdrawn using the unsubscribe link in any message or by writing to us.
To exercise a right, write to the address in no. 3. We will respond within one month; where a request is complex we may extend that period by two further months and will tell you if we do. We may ask you to confirm your identity where we cannot otherwise establish it.
Where your request concerns data held by FastSpring as an independent controller (see no. 11.2) – in particular payment and tax records – we will forward it and tell you that we have done so. Please note that data which we or FastSpring are required to retain under tax or commercial law cannot be erased on request (Art. 17 (3) (b) GDPR).
Basis: Art 77 GDPR
Contents: Each customer shall have the right to lodge a complaint with the supervisory authority if he considers that the processing of personal data relating to him infringes this Regulation, in particular in the Member State of his habitual residence, place of work, or place of the alleged infringement.
Austrian Data Protection Authority [Österreichische Datenschutzbehörde]
Wickenburggasse 8-10
A-1080 Vienna
Phone: +43 1 52 152-0
Email: [email protected]
We update this information when our processing changes.
If only the masculine form is used to describe natural persons in this data protection information, it shall refer to all persons equally. The term customer refers to both consumers and entrepreneurs.