Privacy and Cookie Policy

Privacy and Cookie Policy

Effective from 31 July 2026

1. Data controller

The controller of personal data processed in connection with the oaksoft.cz/eshop online shop is:

Pavel Václavíček, sole trader
Company ID: 69455686
Registered office: Požární 824/10, Rybáře, 360 05 Karlovy Vary, Czech Republic
Privacy contact: pavel.vaclavicek@oaksoft.cz
Telephone: +420 774 086 458
hereinafter the “Controller”.

This Policy applies to online-shop visitors, customers, account holders, prospective customers, support users, reviewers and newsletter subscribers.

The shop is intended primarily for software licences and related services. Processing therefore concerns mainly records of the authorised licensee, software delivery and activation, and subsequent technical support. Delivery information for physical goods is processed only exceptionally where such goods are actually included in an order.

The Controller is established in the Czech Republic and this Policy is primarily based on the General Data Protection Regulation (GDPR) and Czech law. Where another privacy law mandatorily applies to a person using the shop, the Controller will also respect the non-excludable rights provided by that law.

2. Personal data we process

Depending on how you use the shop, we may process:

  • name, country, customer status as a consumer or business, business name, company or VAT number, billing address and delivery address;
  • e-mail address, telephone number and the content of communications;
  • ordered software, licence type and scope, number of devices or users, price, payment, delivery of activation details, installation, complaint and support information;
  • account details and selected settings;
  • technical data needed to operate and secure the website, including IP address, request date and time, requested URL, browser type and error information;
  • the content of a review, enquiry or other information you voluntarily provide;
  • information needed for software activation or technical support, including licence and activation-key identification, activation status and history, software version and proportionate identification of the device or hardware configuration where used by the relevant licensing mechanism.

Activation information is used to verify licence entitlement, provide access to purchased software, prevent misuse of licence keys, and resolve activation transfer or recovery requests. It does not give us access to documents created by the customer in our software or to the ordinary contents of the customer’s computer.

We do not receive complete payment-card numbers or PayPal credentials. These are processed by the relevant payment provider. We receive only information needed to identify and confirm the payment.

3. Online activation and licence verification

Software may use Key Management Services. At first activation and subsequently at regular intervals, a web licensing service verifies whether a licence is valid, who holds it, and the authorised number of devices or users. The software does not connect directly to the licence database; the database request is handled by a server-side application.

Verification may involve processing:

  • the software name and version;
  • licence, activation-key and authorised-licensee identifiers;
  • a device or selected hardware-configuration identifier to which the licence is bound;
  • encoded time information associated with issue and verification of activation;
  • IP address, date, time and technical result of the request;
  • the history of activations, deactivations and authorised licence transfers.

We process this information to deliver and perform the licence contract, restore or transfer activation, provide technical support, protect activation keys and prevent unauthorised distribution. The legal bases are performance of the contract and our legitimate interest in protecting the software and licence rights.

Licence verification does not transmit documents, accounting data or other ordinary contents of the computer. Activation information sent by a customer through e-mail may be technically encoded; we do not describe such encoding by itself as cryptographic encryption. Licensing-service transmission is protected through available security measures, particularly a secure web connection and restricted database access.

Temporary unavailability may be recorded for diagnostic purposes. After the last successful verification, the software provides a seven-day emergency period during which the customer can restore connectivity or contact support.

4. Other purposes and legal bases

The legal bases stated in this section use GDPR terminology. Where another applicable privacy law uses different terminology, we process the information only for the purposes described here and in accordance with that law.

PurposeLegal basis
Software order and delivery, licence records, activation, installation, payment, customer account, complaint and technical supportEntering into and performing a contract, or taking steps at your request before a contract
Accounting and tax documents and compliance with statutory consumer rightsCompliance with a legal obligation
Website security, fraud prevention, technical diagnostics, and establishment or defence of legal claimsOur legitimate interest in secure operation and protection of rights
Responding to a non-binding enquiryPre-contractual steps or our legitimate interest in responding to communications
Publication of a review where enabledThe author’s consent or a legitimate interest, depending on the submission process
Marketing to a person who is not an existing customerConsent
Offers of similar products to an existing customer where permitted by lawLegitimate interest; every message provides a simple opt-out

We do not ask for consent where information is required to perform a contract or retain records required by law. Consent may be withdrawn at any time without affecting the lawfulness of earlier processing.

5. Recipients

We disclose data only to the extent necessary to providers involved in operating the shop and fulfilling orders, in particular:

  • website hosting, domain, database, backup and technical administration providers;
  • e-mail and communication providers;
  • PayPal or the relevant bank for payment processing;
  • exceptionally, a carrier where an order includes physical goods or a hardware licence key;
  • accounting, tax or legal advisers;
  • public authorities where disclosure is legally required or necessary to protect rights.

Providers act as processors or independent controllers according to their role. We do not sell personal data.

The licence database is stored by our web-hosting provider. Access is restricted to the Controller and persons performing necessary technical administration. We do not publicly disclose server-script addresses, database structure, activation-key calculation or other security-sensitive details.

6. Transfers outside the European Economic Area

Some providers, in particular PayPal and providers of any externally loaded web resources, may process information outside the European Economic Area. A transfer takes place only where the GDPR conditions are met, such as an adequacy decision, standard contractual clauses or another valid safeguard. Details concerning a particular transfer may be requested from the Controller.

7. Retention

  • licensee, licence-scope and activation records are retained for the validity or use of the licence and then as needed to demonstrate entitlement, provide support and protect legal claims; for a perpetual licence, this record may be retained for as long as the customer lawfully uses the software;
  • order, complaint and related communication data are retained for performance of the contract and then as needed to protect legal claims, normally no longer than four years unless the law or an ongoing licence requires longer retention;
  • accounting and tax documents are retained for the statutory period, normally five or ten years depending on the document;
  • an account is kept while it is used and can be closed on request, except for information still required by contract or law;
  • non-binding enquiries are normally retained for no more than three years after resolution;
  • technical and security logs are kept for the period necessary for security and diagnostics, normally no more than 90 days unless a particular entry is required to investigate an incident;
  • newsletter details are retained until consent is withdrawn or marketing is refused; evidence of consent or opt-out may be retained as needed to demonstrate compliance.

After the relevant period, information is deleted or securely anonymised.

8. Required and optional information

Information marked as required in an order is needed to conclude and perform the licence contract, issue an accounting document, and deliver and activate the software. A delivery address is needed only where an order includes physical goods. Without necessary information, we may be unable to accept the order or activate the licence. Creating an account, posting a review, subscribing to a newsletter and other optional fields are voluntary unless a form clearly states otherwise.

9. Automated decision-making

We do not make decisions producing legal or similarly significant effects based solely on automated processing. Ordinary automated checks of availability, price, payment or misuse prevention do not constitute such decision-making.

10. Cookies and similar technologies

The online shop uses technical cookies needed for the shopping cart, sign-in, session security, language and currency selection, and basic preferences. These cookies may be used without consent because the requested service cannot operate correctly without them.

The obsolete Universal Analytics tool is not intended to remain in operation after this update. We do not activate analytics or marketing cookies without prior consent. If introduced in future, visitors will be offered equally clear “Accept” and “Reject” options before activation and will be able to change their choice later.

You can configure your browser to block or delete cookies. Blocking technical cookies may prevent the cart, sign-in or checkout from working.

11. Your rights

Subject to the conditions of the GDPR, you have the right to:

  • obtain confirmation whether we process your data and request access;
  • request correction of inaccurate or completion of incomplete data;
  • request erasure where there is no longer a legal basis for processing;
  • request restriction of processing;
  • receive eligible data in a structured, commonly used and machine-readable format and request portability;
  • object to processing based on legitimate interests, including direct marketing;
  • withdraw consent at any time;
  • lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, https://uoou.gov.cz/.

Depending on your country and the law applicable to the Controller, you may have additional rights concerning access, correction, deletion, restriction, objection, portability, withdrawal of consent, direct marketing, sale or sharing of personal data, or review by a competent privacy authority. We do not sell personal data. Where such a local right mandatorily applies, it may be exercised through the same privacy contact.

Send a request to pavel.vaclavicek@oaksoft.cz. Please identify the right you wish to exercise and your country of residence. We may request only the information reasonably necessary to verify the requester’s identity and protect the account or licence from unauthorised access. We respond without undue delay and within the period required by the applicable law.

12. Security and Policy changes

We use technical and organisational measures appropriate to the nature of the data and risks, including encrypted transmission, access control, updates, backups and data minimisation. No transmission or storage method can be guaranteed to be absolutely secure.

We may update this Policy when services or legal requirements change. The current version and effective date are published on this page. A material change will not be applied retroactively in a manner contrary to applicable law.