1. Controller
The controller responsible for the processing of your personal data within the meaning of the General Data Protection Regulation (GDPR) is:
StatInsight UG (haftungsbeschränkt)
Friedensstr. 2
66787 Wadgassen
Germany
Email: contact@statinsight.eu
2. Overview
We take the protection of your personal data seriously. Personal data is processed only to the extent necessary for the operation of the StatInsight software, the management of licenses and customer accounts, the processing of payments, and compliance with legal obligations. We do not sell your data to third parties.
3. Categories of Personal Data
Depending on how you interact with StatInsight, we may process the following categories of personal data:
- Email address — provided during license purchase or when contacting support.
- License data — license key, issue date, expiry date, and associated metadata.
- Device activation identifier (PC_UID) — a device-specific identifier generated locally and transmitted during license activation to associate a license with a device.
- IP address and server logs — recorded automatically when the software contacts our license validation server.
- Payment status and transaction references — confirmation of payment and references provided by the payment processor; we do not store full payment card data.
4. Purposes and Legal Bases
We process your data for the following purposes and on the following legal bases under the GDPR:
- License issuance and activation — necessary for the performance of the contract with you (Art. 6(1)(b) GDPR).
- Support and communication — to respond to your enquiries and provide customer support (Art. 6(1)(b) and (f) GDPR).
- Payment processing — to fulfil our contractual and legal obligations in connection with payment transactions (Art. 6(1)(b) and (c) GDPR).
- Fraud prevention and security — to prevent unauthorized use of licenses and protect the integrity of our systems, based on our legitimate interest (Art. 6(1)(f) GDPR).
5. Cookies and Tracking
This website does not use cookies, tracking technologies, advertising pixels, or analytics tools of any kind. No data about your browsing behavior is collected or transmitted to third parties for marketing or profiling purposes.
6. Payment Provider
Payment processing is handled by Stripe, Inc. When you make a purchase, you will interact with Stripe's payment interface. Stripe processes your payment data in accordance with their own Privacy Policy, available at stripe.com/privacy. StatInsight does not receive or store your full payment card details.
7. Data Recipients
Your personal data is shared with third parties only where strictly necessary:
- Payment providers (Stripe) for the processing of transactions.
- Hosting and infrastructure providers who process data on our behalf under appropriate data processing agreements.
- Competent authorities where disclosure is required by law.
We do not sell, rent, or otherwise commercially exploit your personal data.
8. Data Retention
- License data: Retained for the duration of the license and for an additional period sufficient to cover any applicable legal claims.
- Payment records: Retained for the period required by statutory commercial and tax retention obligations (typically 10 years under German law).
- Server logs: Retained for a limited operational period, then deleted or anonymized.
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access — to obtain confirmation of whether and what personal data we hold about you.
- Right to rectification — to have inaccurate data corrected.
- Right to erasure — to request deletion of your data where there is no longer a legal basis for processing.
- Right to restriction of processing — to limit how we use your data in certain circumstances.
- Right to data portability — to receive a copy of your data in a structured, machine-readable format.
- Right to object — to object to processing based on legitimate interests.
- Right to lodge a complaint — with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, please contact us at contact@statinsight.eu.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure. These measures are reviewed and updated regularly in line with current best practices. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.