PhotonDSP Privacy Policy
Version 1.3
16 August 2026
This Privacy Policy explains how PhotonDSP collects, uses, stores, protects and shares personal data in connection with the PhotonDSP website, digital audio plug-ins, purchases, licence issuance, key delivery, activation, trials, protected downloads, customer support, business correspondence, analytics, cookies and marketing.
It also explains the separate role of FastSpring when FastSpring processes a purchase as authorised reseller and Merchant of Record. This Policy does not replace the FastSpring Privacy Statement for FastSpring checkout, payment, tax, fraud, invoice, refund or buyer-account processing.
The Privacy Policy is acknowledged in PhotonDSP acceptance flows so the User can see how data is handled. That acknowledgement is not consent to processing necessary to perform a contract, comply with law or pursue a legitimate interest. Optional marketing and non-essential cookie consent are requested separately where required.
1. CONTROLLER
For PhotonDSP website, licensing, acceptance, key-delivery, activation, trial, support, security, analytics and PhotonDSP marketing processing, the controller is Individual Entrepreneur Pivneva Svitlana Victorivna, Ukrainian taxpayer registration number (RNOKPP) 2558221521, registered in Ukraine as a Group 3 single-tax payer, with the registered address at 11 Voskresenska Street, Apt. 102, Kyiv 02130, Ukraine, trading under the PhotonDSP name.
Registered address: 11 Voskresenska Street, Apt. 102, Kyiv 02130, Ukraine.
Official website: https://photondsp.com
Support/contact form: https://photondsp.com/#support
Privacy and assistance email: assistance@photondsp.com
For purchases processed through FastSpring, FastSpring is the authorised reseller and Merchant of Record. Depending on the processing activity and applicable law, FastSpring and PhotonDSP may each act as a separate controller or may have controller responsibilities described in FastSpring's Privacy Statement for certain transaction data.
FastSpring Privacy Statement: https://fastspring.com/privacy/
FastSpring buyer support: https://fastspring.com/consumer-support/
2. PERSONAL DATA WE COLLECT
The categories below depend on how you use PhotonDSP products and services.
2.1 Website, security and analytics data
We may process IP address, browser and version, operating system, device class, pages and features viewed, referrer, approximate country or region derived from IP, security events, rate-limit events, consent preference, cookie or local-storage identifiers, campaign or affiliate reference where enabled, and privacy-respecting analytics events.
2.2 Purchase and FastSpring order data
FastSpring collects the data required to act as Merchant of Record. PhotonDSP may receive the purchaser email, name where made available, country or region, FastSpring order or transaction reference, product and licence type, purchase timestamp, currency and status, refund, reversal or chargeback status, and limited tax, invoice or support metadata. PhotonDSP does not receive or store full payment-card numbers processed by FastSpring.
2.3 Legal-document acceptance data
For purchase fulfilment, trial issuance, trial or protected installer download, and protected update download, PhotonDSP may record the action, product, exact document names, versions, locales and full SHA-256 hashes, exact checkbox text, server UTC timestamp, browser timezone or UTC offset, FastSpring order reference where applicable, licence or request reference, verified email reference, IP address, user agent, source page, session reference and acceptance method. Acceptance records do not contain the plaintext licence key.
2.4 Licence and activation data
We may process a non-plaintext licence identifier or hash, product and version, licence status, activation and last-contact timestamps, IP address, operating-system information, a product-scoped installation identifier or cryptographic public-key identifier, activation-slot number, activation history, and refund, chargeback, blocked or revoked status. The current design does not intentionally collect a hardware fingerprint, CPU serial, motherboard serial, disk serial or raw hardware identifier.
The local licensing identity is product-scoped and protected by operating-system security. It is used to bind server-signed activation state to the local installation without intentionally identifying personal files, audio projects or hardware components.
2.5 Licence-key generation and delivery data
PhotonDSP receives authenticated FastSpring order data, verifies the purchase email, records the required acceptance bundle and generates the plaintext key inside the PhotonDSP-controlled licensing system. The same key is displayed on an active PhotonDSP result-page session and submitted to the verified purchase email through PhotonDSP transactional email. FastSpring does not generate, receive or store the plaintext key under the selected fulfilment model.
We may record result-page creation and expiry, key-render timestamp, copy or acknowledgement event where implemented, order and licence references, IP address for the applicable evidentiary period, browser timezone or offset, user agent, email submission identifier, provider acceptance, delivery, deferral or bounce status, and whether the exact accepted legal copies were offered or downloaded. A provider acceptance or absence of a bounce is not proof that a message reached the recipient's inbox.
A plaintext key may be retained only in an encrypted temporary delivery buffer, normally for no more than seven days, solely to complete original delivery or address an immediate delivery failure. This is not a customer key-recovery service. The key cannot be recovered if lost after the delivery process. Long-term records contain only non-plaintext identifiers, hashes or references.
2.6 Trial data
We may process the requested product, verified email reference, IP address, request and confirmation timestamps, trial start and expiry, short-term authorisation status, repeated-attempt count and abuse flags. The current eligibility design may permanently remember that the same verified email received a trial for that product and may temporarily restrict another trial from the same exact public IP address. It does not intentionally use a hardware fingerprint.
2.7 Support and business correspondence
We may process name, email, message content, subject, selected request category, attachments, product and licence references supplied by you, authentication results for received email, delivery and bounce status, internal priority, tags, notes, status, response history, refund workflow status, and relevant licence, activation, trial or order information linked to the same customer record.
2.8 Marketing data
Where you separately opt in, we may process email address, consent wording, consent timestamp, IP address, user agent, source, double-opt-in status, unsubscribe and suppression status, campaign interactions and editable audience tags. Purchase, trial or support data is not automatically treated as marketing consent.
2.9 Cookies, referral and consent data
We may store essential preferences and security data. Where enabled after the required consent, we may store analytics or affiliate/referral identifiers, including a potential referral attribution period of up to 180 days. Consent choices and the version of the notice shown may be retained as evidence.
3. DATA WE DO NOT INTEND TO COLLECT
PhotonDSP plug-ins are not intended to transmit your audio signal, rendered audio, DAW project files, project names, track names, preset contents, musical content, microphone input or local documents to PhotonDSP.
The licensing design does not intentionally collect a hardware fingerprint or raw hardware serial numbers. PhotonDSP does not receive full payment-card numbers handled by FastSpring and does not use purchase or trial email as marketing consent without a separate opt-in.
If you voluntarily attach audio, project material, screenshots, logs or other files to a support request, we process those materials only to handle the request and for related security, legal or quality purposes described in this Policy.
4. Protective Audio Processing and Privacy
Some PhotonDSP products may use internal protective processing, smoothing, filtering, parameter constraints, safety mapping or signal-protection behaviour.
This may affect how plug-in controls respond or how audio is processed at certain values.
Such protective audio processing occurs locally inside the plug-in and is not intended to transmit your audio signal or project content to PhotonDSP.
Product behaviour of this kind is explained in the applicable product documentation, manual or PhotonDSP Supplemental Product and Licence Terms.
5. PURPOSES OF PROCESSING
We process personal data to operate and secure the website; verify FastSpring orders; verify purchase email addresses; record legal acceptance; issue, display and email licence keys; provide immutable accepted legal copies; activate and verify licences; administer trials and protected downloads; prevent licence sharing, piracy, repeat-trial abuse, fraud and automated form abuse; process client-side refund resets and acknowledgements; provide support and business correspondence; manage delivery failures and bounces; maintain audit and business records; improve products, documentation and support; perform privacy-respecting analytics; send marketing where separately permitted; comply with tax, accounting, sanctions and legal obligations; and establish, exercise or defend legal claims.
6. LEGAL BASES AND REQUIRED DATA
Where GDPR, UK GDPR or similar law applies, one or more of the following bases may apply:
6.1 Contract - processing necessary to verify an order, record required licence acceptance, deliver a key, activate a licence, provide a trial or protected download, perform support requested by you, and administer the voluntary refund workflow.
6.2 Legitimate interests - security, fraud and abuse prevention, licence enforcement, repeat-trial prevention, delivery evidence, service improvement, business records, support continuity and legal claims, balanced against the rights and interests of affected persons.
6.3 Consent - optional marketing, non-essential cookies, analytics or affiliate/referral storage where consent is required. Consent can be withdrawn without affecting prior lawful processing.
6.4 Legal obligation - tax, accounting, sanctions, court, regulatory, law-enforcement and other binding requirements.
6.5 Required and optional data - purchase and licensing data are contractual or pre-contractual requirements needed to verify an order, issue and activate a licence, provide protected downloads and administer refunds; without them, PhotonDSP cannot complete those functions. Trial verification data are required to issue and administer a trial; without them, no trial can be issued. Optional marketing, non-essential analytics and affiliate/referral data are not required to buy, activate or use a paid licence, and refusal does not affect those functions.
7. SHARING OF PERSONAL DATA
We may share only the data reasonably necessary with FastSpring as Merchant of Record; Cloudflare and related hosting, CDN, email-routing, database, object-storage, bot-protection and security services; transactional email providers; future newsletter providers; professional advisers; accountants; fraud and abuse-prevention providers; and courts, regulators or authorities where lawfully required.
FastSpring may provide PhotonDSP with limited order, purchaser, product, status, refund and chargeback data needed to verify purchases, issue licences, prevent fraud, provide support and administer refunds. Under the selected fulfilment model, PhotonDSP does not provide FastSpring with the plaintext PhotonDSP licence key.
We do not sell customer lists for money. If a future advertising, analytics or affiliate practice constitutes a regulated sale, sharing or targeted-advertising disclosure, PhotonDSP will provide the notice and choices required by applicable law before enabling it.
Service providers receive only the access needed for their function and are subject to applicable contractual, confidentiality and security obligations.
8. International Transfers
PhotonDSP currently uses FastSpring for Merchant-of-Record transaction processing and Cloudflare services for website, Workers, database, object storage, access control, bot protection, email routing/sending and security functions. The exact services and processing regions used may change as the production configuration changes.
Personal data may be processed in Ukraine, the European Economic Area, the United States, the United Kingdom or other countries in which an approved provider or subprocessor operates.
PhotonDSP enters into provider data-processing agreements where required. Where an international-transfer mechanism is required by applicable law, PhotonDSP relies on adequacy decisions, standard contractual clauses or another lawful transfer mechanism.
PhotonDSP maintains an internal provider and transfer map describing the role, data categories, region, transfer mechanism, retention and security safeguards for active providers. A new provider is not activated for personal data until this assessment is completed.
FastSpring may process transaction data through FastSpring entities and service providers in multiple jurisdictions under its own Privacy Statement and Data Processing Agreement. FastSpring is responsible for the safeguards applicable to its own transfers and processing.
9. DATA RETENTION
We retain personal data only for as long as reasonably necessary for the stated purpose, legal obligations, security and claims. Criteria may vary by record type:
- FastSpring order and accounting records: for the period required for tax, accounting, refund, chargeback and legal obligations;
- core licence ownership, activation, legal-acceptance and delivery evidence: for the active licence term and afterward for support, fraud prevention and the applicable limitation period;
- minimal server UTC timestamp, browser timezone or offset, document-version and hash evidence: may be retained indefinitely after other identifiers are deleted or minimised where reasonably necessary to prove which terms were accepted and when;
- exact accepted legal PDFs, versions and hashes: preserved immutably for evidentiary and durable-medium purposes and not overwritten by later versions;
- temporary encrypted plaintext key buffer: normally no more than seven days and only to complete the original delivery or address an immediate delivery failure; it is not a recovery service;
- long-term key record: only non-plaintext identifier, hash or reference, order linkage, delivery and acceptance evidence;
- ordinary activation, delivery and administrative connection metadata: retained for the shortest period reasonably needed for operation and troubleshooting and normally no longer than six months unless linked to security, abuse, refund, dispute or legal evidence;
- security, anti-abuse, licence-enforcement and fraud evidence, including relevant raw IP data: generally no longer than twenty-four months unless a longer period is reasonably required for an active incident, dispute, investigation, limitation period or legal obligation;
- dispute, chargeback, regulator, court or legal-claim evidence: until final resolution and for the applicable legal limitation or recordkeeping period;
- exact trial-start IP eligibility: the current repeat-trial restriction is approximately thirty days, with associated derived IP-hash cleanup designed for approximately thirty-seven days; other security logs may follow the general security-retention period;
- trial email eligibility: retained for as long as needed to enforce the one-trial-per-product rule and prevent repeated abuse, potentially for the operational life of that trial programme;
- support and business correspondence: generally up to two years after the last substantive interaction, and longer where starred, escalated, linked to an active licence, refund, dispute, security incident or legal claim;
- marketing consent and suppression: until consent is withdrawn or the purpose ends, while a minimal suppression record may be retained to honour an unsubscribe;
- cookie and consent evidence: for the period reasonably needed to honour the preference and demonstrate compliance;
- FastSpring transaction and buyer-account records: retained independently by FastSpring under its own rules and legal obligations.
Where appropriate, data may be deleted, shortened, aggregated, pseudonymised or anonymised after the relevant period.
10. SECURITY
PhotonDSP uses reasonable technical and organisational measures designed to protect personal data and licensing records, including encrypted connections, restricted administrative access protected by Cloudflare Access and multi-factor authentication, server-side signature verification, secret separation, database and object-storage access controls, encrypted temporary key handling, non-plaintext long-term key identifiers, audit logging, rate limits, bot protection, email-authentication checks, backups and tested restoration materials.
The plug-ins use signed server state and an operating-system-protected local cryptographic identity. Product-specific refund resets remove product paid-access state without intentionally deleting the shared local identity used by another PhotonDSP product.
No internet service or software system is completely secure. Users must protect their email accounts, licence keys and devices and must not share licence data.
11. Your Rights
Depending on your location and applicable law, you may have rights to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of data;
- request restriction of processing;
- object to certain processing;
- request data portability;
- withdraw consent where processing is based on consent;
- unsubscribe from marketing communications;
- lodge a complaint with a data-protection authority. Some requests may be limited where we need to keep data for licence verification, security, anti-fraud, tax, accounting, legal claims or other legitimate or legal purposes.
To exercise your rights, contact us through the official contact form or at:
We may need to verify your identity before fulfilling a request.
Requests concerning data controlled or jointly controlled by FastSpring in connection with checkout, payment, tax, invoicing or the FastSpring buyer account may also be submitted to FastSpring. Where required by applicable law, PhotonDSP and FastSpring may coordinate on a data-subject request relating to jointly controlled transaction data.
12. COOKIES AND CONSENT CHOICES
Where required, PhotonDSP provides a clear cookie notice and choices to accept, reject or manage non-essential cookies. Refusing non-essential cookies does not prevent access to public content, although optional analytics, affiliate attribution or preference features may not work.
Essential cookies or storage may be used without consent where necessary for security, rate limiting, consent memory, checkout handoff, email verification, protected download, fraud prevention or functionality requested by the User.
Non-essential analytics, marketing and affiliate/referral storage is not enabled before the required choice. A future affiliate identifier may be retained for up to 180 days only under the applicable consent and notice rules.
You may also control cookies in the browser. Clearing browser storage may cause the notice to reappear because the site can no longer read the saved preference.
13. NEWSLETTERS AND MARKETING
PhotonDSP sends marketing only where permitted and based on a separate opt-in or another lawful basis expressly permitted by applicable law. Purchase, trial, download or support submission alone is not marketing consent.
Where double opt-in is used, the subscription is not active until the verification link is confirmed. Every marketing email includes an unsubscribe mechanism. Unsubscribing does not prevent necessary purchase, licence, security, refund or support messages.
14. Children
PhotonDSP products and services are not directed to children.
We do not knowingly collect personal data from children where parental consent is required by applicable law.
If you believe a child has provided personal data to us without appropriate consent, please contact us.
15. Third-Party Links and Services
Our website, checkout, documentation or emails may contain links to third-party websites or services.
We are not responsible for the privacy practices of third parties.
Please review the privacy policies of third-party services you use. For PhotonDSP purchases processed by FastSpring, the FastSpring Privacy Statement applies to FastSpring's checkout, payment, tax, fraud, refund and buyer-account processing.
16. CHANGES TO THIS POLICY
PhotonDSP may update this Policy and will publish the new version number and effective date. Material changes will be communicated by a reasonable method where required by law.
Acceptance or acknowledgement records continue to identify the exact version and full SHA-256 hash shown for the relevant action. Later publication does not overwrite those historical records or exact accepted copies.
17. CONTACT
Controller: Individual Entrepreneur Pivneva Svitlana Victorivna, Ukrainian taxpayer registration number (RNOKPP) 2558221521, registered in Ukraine as a Group 3 single-tax payer, with the registered address at 11 Voskresenska Street, Apt. 102, Kyiv 02130, Ukraine, trading under the PhotonDSP name.
Registered address: 11 Voskresenska Street, Apt. 102, Kyiv 02130, Ukraine.
Privacy and assistance email: assistance@photondsp.com
Support/contact form: https://photondsp.com/#support
Official website: https://photondsp.com
FastSpring privacy and buyer matters: https://fastspring.com/privacy/ and https://fastspring.com/consumer-support/
This HTML text is provided for accessible browser reading. Download the PDF above to retain the exact published document.