Back to PermitCore

Data Processing Agreement

Last updated: June 21, 2026  ·  Incorporates GDPR Article 28 requirements

This DPA forms part of the Terms of Service and is automatically applicable to all PermitCore customers who are subject to GDPR or similar data protection regulations. No signature is required — accepting the Terms of Service constitutes acceptance of this DPA.

1. Definitions

"Controller" means the Customer (Tenant) who determines the purposes and means of processing personal data through PermitCore. "Processor" means PermitCore, processing personal data on behalf of the Controller. "Data Subject" means any natural person whose personal data is processed. "GDPR" means Regulation (EU) 2016/679.

2. Roles and Subject Matter

PermitCore processes personal data as a Processor acting on behalf of the Controller (Customer). The subject matter is the provision of software license management services as described in the Terms of Service. Processing continues for the duration of the service agreement.

3. Categories of Personal Data Processed

PermitCore may process the following personal data as instructed by the Controller:

  • End-customer records: name, email address (if provided by Controller)
  • Activation records: IP address, country, city, user agent string at the time of license activation
  • License store orders: name, email, delivery address if physical delivery is configured
  • Support interactions: content of messages sent through the License Store portal

Controller account data (admin users' names and email addresses) is processed by PermitCore as a Controller for its own purposes, governed by the Privacy Policy.

4. Processing Instructions

PermitCore shall process personal data only on documented instructions from the Controller (via the PermitCore platform), unless required to do so by applicable law. If required by law, PermitCore shall inform the Controller before processing, unless legally prohibited from doing so.

5. Security Measures

PermitCore implements the following technical and organizational measures (TOMs):

  • AES-256-GCM encryption of license keys (client-side, zero-knowledge)
  • Argon2id hashing for all passwords
  • TLS 1.2+ for all data in transit
  • Database encryption at rest
  • JWT authentication with short-lived tokens
  • TOTP multi-factor authentication support
  • Append-only audit logging of all data access and modifications
  • Role-based access control within each tenant

6. Sub-Processors

PermitCore uses the following sub-processors. The Controller authorizes these sub-processors as part of accepting these Terms. PermitCore will provide 30 days notice before adding new sub-processors:

Sub-Processor Purpose Location
Stripe, Inc. Payment processing and billing USA (SCC)
Cloud hosting provider Infrastructure and data storage EU
Google LLC (Google Workspace) Transactional email delivery USA (SCC)

7. Data Subject Rights

PermitCore will assist the Controller in fulfilling obligations regarding Data Subject rights (access, rectification, erasure, portability, restriction, objection) to the extent technically feasible. Controllers can export and delete their tenant data via the Settings → GDPR section of the admin panel. Requests that cannot be fulfilled through the platform should be sent to [email protected].

8. Data Breach Notification

PermitCore will notify the Controller without undue delay, and where feasible within 72 hours, upon becoming aware of a personal data breach that affects Controller data. Notification will be sent to the registered account email and will include the nature of the breach, approximate number of records affected, and mitigation measures taken.

9. Data Deletion

Upon termination of the service agreement, PermitCore will retain Customer data for 30 days to allow export. After that period, all personal data is permanently deleted from active systems. Backups are rotated within 90 days. Controllers may request immediate deletion at [email protected].

10. Audit Rights

PermitCore will provide reasonable information to demonstrate compliance with this DPA upon written request. On-site audits may be conducted with 30 days written notice, at the Controller's expense, and are limited to security and data processing practices relevant to this DPA.

11. Contact for DPA Matters

DPA inquiries: [email protected]