Doxpro Privacy Policy

Version 2026-08-21

Summary

This summary is for orientation only; the numbered sections below are the notice we owe you under article 13 of the GDPR.

  • We collect what running the store and the licences requires: your name and email, what you bought, and the reviews and issues you post.
  • We record your IP address and device identifier when you sign in, and your IP address when you accept our terms or confirm a purchase. Section 3 explains why each of those exists.
  • We never see or store your card number — Stripe handles payment and we receive only the result.
  • The Doxpro Packages Installer works on your documents on your own machine. It does not send us the contents of your files.
  • We do not sell your personal data, and we do not use it for profiling.
  • You can ask for a copy of your data, correction, deletion, or a copy to take elsewhere — see section 8 — and you can complain to the Polish data protection authority.

1. Who we are

1.1 The controller of your personal data is Doxpro Igor Valuev, a sole trader established in Poland and entered in the Central Registration and Information on Business (Centralna Ewidencja i Informacja o Działalności Gospodarczej, “CEIDG”), NIP 7831865344, REGON 523308517, address for service ul. Engeströma 10, 60-571 Poznań, Poland (“Doxpro”, “we”, “us”, “our”).

1.2 For anything about this policy or your data, write to support@doxpro.cc. We are not required to appoint a data protection officer and have not appointed one, so that address reaches us directly.

1.3 This policy covers the Doxpro website at doxpro.cc (the “Store”), the Doxpro Packages Installer, and the packages delivered through it. It sits alongside our Terms of Service.

2. What the Packages Installer does and does not send us

2.1 Packages run inside Microsoft Office on your own machine and act on your documents there. The contents of your documents, presentations and workbooks are not transmitted to us, and we have no ability to read them.

2.2 What the Packages Installer does send us is the information needed to sign you in, confirm which licences your account holds, and fetch updates. That is covered by section 3.

3. What we collect, why, and on what legal basis

3.1 Account details — your name, email address, password (stored only as a bcrypt hash, never in readable form), profile picture if you upload one, and any organisation or vendor you belong to. Collected to create and run your account. Legal basis: performance of our contract with you (article 6(1)(b) GDPR).

3.2 Email verification — a token sent to your address and the record of whether it was confirmed. Basis: performance of our contract, and our legitimate interest in knowing that accounts belong to reachable people (article 6(1)(f)).

3.3 Licences and purchases — which packages your account holds, whether each is a trial or purchased, your orders, the prices at the time, and the payment status. Basis: performance of our contract, and compliance with our tax and accounting obligations (article 6(1)(c)).

3.4 Payment data — handled by Stripe. Your card number never reaches our servers; we receive the outcome of the payment and an identifier for it. Basis: performance of our contract.

3.5 Sign-in records — for each sign-in attempt from the Store or the Packages Installer, whether it succeeded or failed, we record the email address used, your IP address, a hardware identifier for the device, and the time. This is how we detect credential stuffing and shared or resold licences. Basis: our legitimate interest in the security of the service and in enforcing our licence terms (article 6(1)(f)).

3.6 Terms acceptance — when you accept our terms we record the date and time, which revision you accepted, your IP address, your browser’s user agent and language, and where in the product you accepted. One entry per revision. Basis: our legitimate interest in being able to prove what was agreed, and compliance with consumer information law (articles 6(1)(f) and 6(1)(c)).

3.7 Purchase confirmations — when you confirm at checkout that you want immediate delivery and accept that this ends your right of withdrawal, we record the same details against that order, together with the exact wording you were shown. Basis: compliance with consumer protection law and our legitimate interest in defending claims (articles 6(1)(c) and 6(1)(f)).

3.8 Content you post — reviews, ratings, likes, issue reports and comments, shown alongside your display name. Basis: performance of our contract.

3.9 Messages you send us — what you put in the contact form or in an email to support, so we can answer. Basis: our legitimate interest in responding to enquiries, and performance of our contract where you are already a customer.

3.10 Technical and error data — when something fails, our error monitoring captures the error, a stack trace and the state of the code at the point of failure, which can incidentally include values being processed at that moment. Basis: our legitimate interest in keeping the service working (article 6(1)(f)).

3.11 Server logs — ordinary web server records of requests, including IP address, time and the page requested. Basis: our legitimate interest in security and in operating the service.

3.12 Providing this data is not a statutory requirement, but without the items in 3.1, 3.3 and 3.6 we cannot open an account, sell you a licence, or prove what you agreed to — so we cannot provide the service.

4. Cookies

4.1 We use cookies that are strictly necessary to run the Store:

  • dp-token and dp-refresh-token — keep you signed in. Both are HTTP-only, so scripts in your browser cannot read them. The refresh cookie lasts 30 days; the access cookie is short-lived.
  • dp-logged-in — lets the page know whether to render the signed-in view.

4.2 Because these are strictly necessary to deliver a service you asked for, they do not require consent. We do not use advertising cookies, and we do not run third-party analytics.

4.3 Google reCAPTCHA runs on our contact form and sets its own cookies to tell people from bots. This is described in section 5.

4.4 You can block or delete cookies in your browser, but if you block the ones above you will not be able to stay signed in.

5. Who we share data with

5.1 We do not sell your personal data and we do not share it for anyone else’s marketing. We share it only with the providers we need to run the service, each acting on our instructions or as an independent controller for their own part:

  • Stripe — payment processing. Receives what a payment needs, including your email and billing details, and applies its own privacy policy as a controller for fraud prevention and regulatory purposes.
  • Mailtrap — sends transactional email such as address verification and support replies. Receives your email address and the contents of those messages.
  • Sentry — error monitoring. Receives the technical data in 3.10.
  • Google — reCAPTCHA on our contact form, to stop automated abuse. Receives your IP address and interaction data, as its own controller.
  • Our hosting and infrastructure providers — run the servers, database and file delivery on our behalf and can access data only as needed to do so.

5.2 We may also disclose data where the law requires it, to establish, exercise or defend legal claims, or to our advisers under a duty of confidence.

5.3 If the business is ever transferred, your data may transfer with it. We will tell you before that happens and this policy will continue to apply until you are told otherwise.

6. Transfers outside the EEA

6.1 Some providers in section 5 process data outside the European Economic Area, principally in the United States.

6.2 Where they do, the transfer relies either on an adequacy decision of the European Commission — including the EU–US Data Privacy Framework where the provider is certified under it — or on the Commission’s standard contractual clauses together with additional safeguards. You can ask us at support@doxpro.cc for details of the safeguards applying to a particular provider.

7. How long we keep it

7.1 Account data — while your account exists, and then deleted or anonymised, subject to the periods below.

7.2 Orders, invoices and tax records — five years from the end of the calendar year in which the tax became due, as Polish tax and accounting law requires. We cannot delete these earlier, even on request.

7.3 Terms acceptances and purchase confirmations — for as long as a claim could be brought about the contract they relate to, which under the Polish Civil Code is generally six years, or three years for claims connected with a business. Deleting them earlier would leave us unable to show what you agreed to, which is the reason they exist.

7.4 Sign-in records — kept for a rolling period no longer than needed to investigate security incidents and licence abuse, and then deleted.

7.5 Error data — kept for the retention period of our monitoring provider, which is short by design.

7.6 Content you post — until you delete it or we remove it under the Terms. If you close your account we may keep reviews in a form that no longer identifies you.

8. Your rights

8.1 Under the GDPR you have the right to:

  • ask whether we hold data about you and get a copy of it (article 15);
  • have inaccurate data corrected and incomplete data completed (article 16);
  • have data erased where we no longer have grounds to keep it (article 17) — bearing in mind 7.2 and 7.3, where the law requires us to retain it;
  • ask us to restrict processing while a dispute is resolved (article 18);
  • receive the data you gave us in a machine-readable form, or have it sent to another provider (article 20);
  • object to processing we base on legitimate interests, including everything in 3.5, 3.10 and 3.11, on grounds relating to your situation (article 21). We will stop unless we have compelling grounds that override yours;
  • withdraw consent at any time where we rely on it, without affecting what came before.

8.2 We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.

8.3 To exercise any of these, email support@doxpro.cc. We answer within one month, and will tell you if we need longer because a request is complex. We may ask you to confirm your identity first.

8.4 If you think we have handled your data wrongly, you can complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland, or to the supervisory authority where you live or work. We would rather you came to us first, but you do not have to.

9. Marketing

9.1 We send service messages you cannot opt out of while you hold an account — address verification, order confirmations, security notices and changes to our terms. These are not marketing.

9.2 We only send promotional email where you have asked for it. Every such message carries an unsubscribe link, and you can also write to support@doxpro.cc. Basis: consent (article 6(1)(a)) together with Polish electronic communications law.

10. Security

10.1 Passwords are stored only as bcrypt hashes. Traffic to the Store is encrypted in transit. Access to the database is limited to what operating the service requires. Authentication cookies are HTTP-only.

10.2 No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights, we will tell you without undue delay, and we will notify the supervisory authority as article 33 requires.

11. Children

11.1 The Store is not intended for children. You must be at least 16 to hold an account and at least 18 to buy. If you believe a child has given us personal data, write to support@doxpro.cc and we will delete it.

12. Changes to this policy

12.1 We will update this policy when what we do with data changes. Each revision carries a version identifier, shown at the top of this page.

12.2 Where a change materially affects you, we will tell you by email to the address on your account, or in the Store, before it takes effect.

13. Contact

13.1 Doxpro, ul. Engeströma 10, 60-571 Poznań, Poland. Email support@doxpro.cc.