Data Processing Agreement
Last updated: June 21, 2026 · Incorporates GDPR Article 28 requirements
This DPA forms part of the Terms of Service and is automatically applicable to all PermitCore customers who are subject to GDPR or similar data protection regulations. No signature is required — accepting the Terms of Service constitutes acceptance of this DPA.
1. Definitions
"Controller" means the Customer (Tenant) who determines the purposes and means of processing personal data through PermitCore. "Processor" means PermitCore, processing personal data on behalf of the Controller. "Data Subject" means any natural person whose personal data is processed. "GDPR" means Regulation (EU) 2016/679.
2. Roles and Subject Matter
PermitCore processes personal data as a Processor acting on behalf of the Controller (Customer). The subject matter is the provision of software license management services as described in the Terms of Service. Processing continues for the duration of the service agreement.
3. Categories of Personal Data Processed
PermitCore may process the following personal data as instructed by the Controller:
- End-customer records: name, email address (if provided by Controller)
- Activation records: IP address, country, city, user agent string at the time of license activation
- License store orders: name, email, delivery address if physical delivery is configured
- Support interactions: content of messages sent through the License Store portal
Controller account data (admin users' names and email addresses) is processed by PermitCore as a Controller for its own purposes, governed by the Privacy Policy.
4. Processing Instructions
PermitCore shall process personal data only on documented instructions from the Controller (via the PermitCore platform), unless required to do so by applicable law. If required by law, PermitCore shall inform the Controller before processing, unless legally prohibited from doing so.
5. Security Measures
PermitCore implements the following technical and organizational measures (TOMs):
- AES-256-GCM encryption of license keys (client-side, zero-knowledge)
- Argon2id hashing for all passwords
- TLS 1.2+ for all data in transit
- Database encryption at rest
- JWT authentication with short-lived tokens
- TOTP multi-factor authentication support
- Append-only audit logging of all data access and modifications
- Role-based access control within each tenant
6. Sub-Processors
PermitCore uses the following sub-processors. The Controller authorizes these sub-processors as part of accepting these Terms. PermitCore will provide 30 days notice before adding new sub-processors:
7. Data Subject Rights
PermitCore will assist the Controller in fulfilling obligations regarding Data Subject rights (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. Controllers can export and delete their tenant data via the Settings → GDPR section of the admin panel. Requests that cannot be fulfilled through the platform should be sent to [email protected].
8. Data Breach Notification
PermitCore will notify the Controller without undue delay, and where feasible within 72 hours, upon becoming aware of a personal data breach that affects Controller data. Notification will be sent to the registered account email and will include the nature of the breach, approximate number of records affected, and mitigation measures taken.
9. Data Deletion
Upon termination of the service agreement, PermitCore will retain Customer data for 30 days to allow export. After that period, all personal data is permanently deleted from active systems. Backups are rotated within 90 days. Controllers may request immediate deletion at [email protected].
10. Audit Rights
PermitCore will provide reasonable information to demonstrate compliance with this DPA upon written request. On-site audits may be conducted with 30 days written notice, at the Controller's expense, and are limited to security and data processing practices relevant to this DPA.
11. Contact for DPA Matters
DPA inquiries: [email protected]