Certeasy is now Hortval

Same product, same team, same company behind it. Only the name has changed, and nothing changes for a running deployment.

Learn more

Privacy Policy

Last updated: August 2026

1. Who we are

Hortval ([email protected]) publishes this site and operates the license management service available at hortval.com. We are the data controller within the meaning of the GDPR (Regulation (EU) 2016/679).

2. What data we collect and why

We collect the minimum necessary to operate the service:

Data Purpose Legal basis
Email address Deliver the license file, send renewal reminders, re-send licenses on request Contract performance (Art. 6(1)(b))
Full name Personalise the welcome email and identify the license holder Contract performance (Art. 6(1)(b))
IP address Rate limiting and abuse prevention — processed in memory Legitimate interest (Art. 6(1)(f))
IP address and user agent Evidence of acceptance of the terms — stored with it Legitimate interest (Art. 6(1)(f))
Web server logs Security, abuse detection and diagnostics — retained 1 year Legitimate interest (Art. 6(1)(f))
Email address Messages about the product — a new version, documentation, an offer, or a download that went no further (commercial solicitation); separately, support exchanges Legitimate interest (Art. 6(1)(f)) — object from your personal area, from the link at the foot of each message, or at [email protected]
Sign-in history Letting the user spot an access they did not make — retained 12 months Legitimate interest (Art. 6(1)(f))

Payment data (card, billing address) is handled exclusively by Stripe and never passes through our servers. Stripe acts as an independent data controller for payment processing. See stripe.com/privacy.

3. Analytics

We use Cloudflare Web Analytics to measure traffic on this site (page views, unique visitors, country of origin, referrers).

  • Cloudflare Web Analytics is cookie-free — no tracking cookie is set.
  • It does not collect personal data or build individual profiles.
  • Data is aggregated and anonymised before being stored.
  • No consent banner is required under the GDPR or ePrivacy Directive.

See Cloudflare's privacy policy for details on how aggregated analytics data is handled.

4. What we do not do

  • We do not sell, rent or share your data with third parties for marketing purposes.
  • We do not use your email for profiling, nor for third-party advertising. We may write to you about the product — rarely, and you can object at any time, in one click, from any such message.
  • We do not use tracking pixels or advertising cookies.
  • We do not set any tracking or advertising cookies.

5. Cookies

The public website sets no cookies. The portal sets three, strictly necessary to its operation — session, anti-CSRF protection, language — and therefore exempt from consent. They are detailed in the terms of use. No audience-measurement cookie, no advertising tracker, no third-party cookie.

6. Data retention

We retain your email address and name for as long as your license is active, plus 3 years after the last license expires (for accounting and dispute resolution purposes). You may request earlier deletion — see section 7.

If you object to our follow-up messages, we keep the bare minimum needed not to write to you again. Web server logs are retained for 1 year. Acceptances of the terms, and the IP address recorded with them, are retained for 5 years from the day the accepted version ceases to be in force — the ordinary limitation period.

7. Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interest. For our emails it is immediate and needs no message to us: the Reminder settings page of your personal area, also reachable from the link at the foot of each of them, governs what you receive — expiry reminders one License and one Server at a time, product messages, or all of it at once.
  • Restriction — ask us to limit processing while a dispute is resolved.

To exercise any of these rights, email us at [email protected] with the subject line "GDPR request". We will respond within 30 days.

You also have the right to lodge a complaint with your national supervisory authority (in France: CNIL).

8. Data transfers outside the EU

Our infrastructure is hosted in the EU. Transfers outside the EU concern: Stripe (United States, payment processing) and Cloudflare (United States, analytics) — both covered by Standard Contractual Clauses and the EU–US Data Privacy Framework.

9. Security

License files are cryptographically signed with Ed25519. Email addresses are stored in a local database with restricted access. We apply rate limiting on all public endpoints to prevent abuse.

10. Contact

[email protected]