Summary: PermitCore is a B2B SaaS platform. We collect minimal data necessary to provide the service. Our marketing site uses Google Analytics, but only after you accept it in our cookie preferences. If you use our "Permit AI" chat widget, your question and matching documentation excerpts are sent to Anthropic to generate a reply. We are GDPR compliant and do not sell your data.
1. Who We Are
PermitCore ("we", "us", "our") is a software-as-a-service platform for license key management. Our service is provided to businesses (tenants) and their administrators.
For GDPR purposes, PermitCore acts as a Data Controller for account and billing data, and as a Data Processor for data tenants upload or generate (e.g. license keys, customer records).
2. Data We Collect
2.1 Account Data
- Name and email address (required to create an account)
- Password (stored as Argon2id hash — never in plaintext)
- Company name and account tier
- IP address and user agent at time of login (for security)
- MFA secret (stored encrypted at rest)
- Billing country and, if you provide one at checkout, a tax identification number (e.g. an EU VAT ID) — collected to calculate applicable tax
2.2 Service Data (Tenant-Uploaded)
- License keys (encrypted with AES-256-GCM; we store only the ciphertext and a keyed HMAC-SHA256 lookup value)
- Customer email addresses (for license assignment)
- Product and order information
- Audit log entries (all administrative actions)
2.3 Usage Data
- API call logs (IP address, endpoint, response code, timestamp)
- Activation and validation events for license keys
- Dashboard analytics (aggregate, not personal)
3. Sub-Processors & Third-Party Services
We use the following sub-processors that may receive personal data:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing; for eligible plans, merchant of record via Stripe Link (see below) | Billing name, email, payment details, billing country, tax ID if provided | US (SCCs) |
| Hetzner / cloud host | Infrastructure & database hosting | All data at rest | EU |
| Google Analytics (GA4) | Aggregate marketing-site usage analytics on permitcore.dev — only loaded if you accept the Analytics cookie category (see our Cookie Policy) | Pages viewed, referrer, approximate location, device/browser type, pseudonymous client identifier — no admin panel account data | US (SCCs) |
| Anthropic (Claude API) | Generates replies for the "Permit AI" chat widget on this website — only when that widget is enabled and you choose to use it | The message you type and excerpts from PermitCore's own public documentation — no account data, no browsing history | US (SCCs) |
Stripe Managed Payments / Link disclosure: For eligible plans, your purchase may be completed through Stripe's Managed Payments service. When it is, Stripe (through its Link service) is the merchant of record for that transaction — it independently determines how it calculates and remits indirect tax (VAT/GST/sales tax), screens for fraud, and handles payment disputes and transaction-level support for that purchase, in addition to processing the payment on our behalf. See Stripe's own Privacy Policy for how it uses your data in that capacity.
4. Legal Basis for Processing (GDPR)
- Contract performance — Account data, license data, billing data processed to deliver the service
- Legitimate interest — Security audit logs, fraud prevention, abuse detection
- Consent — Marketing communications (opt-in only)
- Legal obligation — Billing records retained for 7 years per accounting law
5. Data Retention
- Account data: Retained while account is active + 30 days after deletion request
- Audit logs: Retained per your billing plan — 7 days (Free), 30 days (Starter), 90 days (Professional), unlimited (Enterprise)
- Server logs: 30 days (rolling)
- License activation events: the IP address, country/city, and end-user email tied to a license activation are anonymized after 365 days; the activation record itself (date, device identifier) is kept alongside the license for its lifetime
- Billing records: 7 years (legal requirement)
6. Your Rights (GDPR)
If you are in the EU/EEA, you have the following rights:
- Right of access — Request a copy of your personal data
- Right to rectification — Correct inaccurate data
- Right to erasure — Request deletion (subject to legal retention requirements)
- Right to portability — Export your data in machine-readable format
- Right to object — Object to processing based on legitimate interest
- Right to restrict processing — Limit how we use your data
To exercise any right, email: [email protected]. We respond within 30 days.
7. Security
- All data in transit encrypted via TLS 1.2+
- License keys stored with AES-256-GCM zero-knowledge encryption — we cannot see plaintext keys
- Passwords stored as Argon2id hashes with per-user salts
- MFA secrets encrypted at rest
- Security headers (HSTS, X-Frame-Options, CSP) on all responses
- Database encrypted at rest (TDE)
8. Cookies
Admin panel authentication uses JWT tokens stored in browser local storage, not a cookie. See our Cookie Policy for the complete, current list of cookies this site uses and how to control them.
9. Data Transfers Outside the EU
Stripe is US-based. Transfers are covered by Standard Contractual Clauses (SCCs). All other primary infrastructure is EU-based.
10. Changes to This Policy
We will notify account holders by email at least 14 days before any material changes take effect. The current version is always available at this URL.
11. Contact
PermitCore Data Controller
Email: [email protected]
For GDPR requests: [email protected]
© 2026 PermitCore. All rights reserved. · Home · Privacy Policy