1. Data controller
The data controller is imPRESS Studio, contact: impress_studio@proton.me. For any data-protection enquiry, write to that address.
2. What data we collect
We collect only the minimum needed to issue licenses and prevent abuse:
- Contact details — full name, email, optional company name.
- Machine fingerprint (MachineHash) — a SHA-256 derived from your computer's NIC MAC, disk serial and motherboard UUID. It is not the raw MAC or serial; the original values cannot be reversed from the hash.
- IP address from which the trial request was sent — only for abuse prevention (rate-limit, blocking mass requests).
- Browser User-Agent, request timestamp, browser locale — in standard server logs.
- Installer download events (timestamp, IP, asset, referrer) — for traffic analytics.
We do not use tracking cookies, Google Analytics, Facebook Pixel, or any profiling tools.
3. Purpose and legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Issue and support the trial license | Art. 6(1)(b) GDPR (contract) | trial expiry + 30 days |
| Prevent abuse (multiple trials from the same machine/IP/email) | Art. 6(1)(f) GDPR (legitimate interest) | 3 years from issuance |
| Send product updates (only if you ticked the optional consent) | Art. 6(1)(a) GDPR (consent) | until consent is withdrawn |
| Service security and technical logs | Art. 6(1)(f) GDPR | 12 months |
4. Who we share data with
- Server hosting provider — to the extent required to run the service, under a data processing agreement.
- Email provider (Proton Mail) — to deliver license keys and reply to enquiries.
We do not sell your data. We do not transfer it outside the European Economic Area. We do not use it for automated decision-making or profiling within the meaning of Art. 22 GDPR.
5. Your rights
Under the GDPR you have the following rights, exercised by emailing impress_studio@proton.me:
- access to your data (Art. 15);
- rectification (Art. 16);
- erasure / "right to be forgotten" (Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- objection to processing based on legitimate interest (Art. 21);
- withdrawal of consent at any time, without affecting the lawfulness of processing prior to withdrawal (Art. 7(3));
- lodge a complaint with your national supervisory authority. In Poland: President of the Personal Data Protection Office (UODO), uodo.gov.pl/en.
6. Security
- All website and API traffic is HTTPS only (TLS 1.2+).
- The RSA private signing key is stored under directory permissions 700, accessible only to the server process.
- The license database is stored in the same restricted directory and is not exposed externally.
- The admin endpoint is protected by a Bearer token.
7. Cookies
impressstudio.pl does not use tracking cookies. A single technical session cookie may be used while a form is open — strictly necessary for its operation (Art. 6(1)(f) GDPR, ePrivacy Directive Art. 5(3)).
8. Changes to this policy
Updates to this document are published on this page with a new "last updated" date. Material changes affecting the scope of data processing will additionally be notified by email to users with an active license.
Full text of the GDPR: eur-lex.europa.eu.
