Privacy Policy
Last updated: August 2026
1. Who we are
Hortval ([email protected]) publishes this site and operates the license management service available at hortval.com. We are the data controller within the meaning of the GDPR (Regulation (EU) 2016/679).
2. What data we collect and why
We collect the minimum necessary to operate the service:
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Deliver the license file, send renewal reminders, re-send licenses on request | Contract performance (Art. 6(1)(b)) |
| Full name | Personalise the welcome email and identify the license holder | Contract performance (Art. 6(1)(b)) |
| IP address | Rate limiting and abuse prevention — processed in memory | Legitimate interest (Art. 6(1)(f)) |
| IP address and user agent | Evidence of acceptance of the terms — stored with it | Legitimate interest (Art. 6(1)(f)) |
| Web server logs | Security, abuse detection and diagnostics — retained 1 year | Legitimate interest (Art. 6(1)(f)) |
| Email address | Messages about the product — a new version, documentation, an offer, or a download that went no further (commercial solicitation); separately, support exchanges | Legitimate interest (Art. 6(1)(f)) — object from your personal area, from the link at the foot of each message, or at [email protected] |
| Sign-in history | Letting the user spot an access they did not make — retained 12 months | Legitimate interest (Art. 6(1)(f)) |
Payment data (card, billing address) is handled exclusively by Stripe and never passes through our servers. Stripe acts as an independent data controller for payment processing. See stripe.com/privacy.
3. Analytics
We use Cloudflare Web Analytics to measure traffic on this site (page views, unique visitors, country of origin, referrers).
- Cloudflare Web Analytics is cookie-free — no tracking cookie is set.
- It does not collect personal data or build individual profiles.
- Data is aggregated and anonymised before being stored.
- No consent banner is required under the GDPR or ePrivacy Directive.
See Cloudflare's privacy policy for details on how aggregated analytics data is handled.
4. What we do not do
- We do not sell, rent or share your data with third parties for marketing purposes.
- We do not use your email for profiling, nor for third-party advertising. We may write to you about the product — rarely, and you can object at any time, in one click, from any such message.
- We do not use tracking pixels or advertising cookies.
- We do not set any tracking or advertising cookies.
5. Cookies
The public website sets no cookies. The portal sets three, strictly necessary to its operation — session, anti-CSRF protection, language — and therefore exempt from consent. They are detailed in the terms of use. No audience-measurement cookie, no advertising tracker, no third-party cookie.
6. Data retention
We retain your email address and name for as long as your license is active, plus 3 years after the last license expires (for accounting and dispute resolution purposes). You may request earlier deletion — see section 7.
If you object to our follow-up messages, we keep the bare minimum needed not to write to you again. Web server logs are retained for 1 year. Acceptances of the terms, and the IP address recorded with them, are retained for 5 years from the day the accepted version ceases to be in force — the ordinary limitation period.
7. Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest. For our emails it is immediate and needs no message to us: the Reminder settings page of your personal area, also reachable from the link at the foot of each of them, governs what you receive — expiry reminders one License and one Server at a time, product messages, or all of it at once.
- Restriction — ask us to limit processing while a dispute is resolved.
To exercise any of these rights, email us at [email protected] with the subject line "GDPR request". We will respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority (in France: CNIL).
8. Data transfers outside the EU
Our infrastructure is hosted in the EU. Transfers outside the EU concern: Stripe (United States, payment processing) and Cloudflare (United States, analytics) — both covered by Standard Contractual Clauses and the EU–US Data Privacy Framework.
9. Security
License files are cryptographically signed with Ed25519. Email addresses are stored in a local database with restricted access. We apply rate limiting on all public endpoints to prevent abuse.