Privacy Policy
Last updated September 24, 2026
This Privacy Policy describes how DND Software ("DND", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with the dndware.dev website, the DND loader, customer accounts, and related services (collectively, the "Services"). If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, this Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and other applicable data protection laws.
In short: we collect as little as we can. Your email address is stored encrypted and is only ever read to email you, we never store IP addresses, you have no password with us, and payments are handled entirely by Stripe and Link.
1. Data Controller
DND Software is the data controller responsible for your personal data processed through the Services. For all data protection inquiries, contact us at [email protected].
Data Protection Officer. DND has not designated a Data Protection Officer, as our processing activities do not meet the criteria set out in Article 37 of the GDPR (we are not a public authority, we do not carry out large-scale systematic monitoring of data subjects, and we do not carry out large-scale processing of special categories of data). For any data protection matters, please contact us at [email protected].
2. Categories of Personal Data We Collect
A. Account
- Username (chosen by you and shown publicly)
- Email address: stored as a one-way keyed hash (to find your account when you sign in) and encrypted with AES-256-GCM (to send you account and security emails). It is only decrypted at the moment an email is sent, and it is never shown to anyone, including our staff.
- Account role (user, staff, or owner) and the date your account was created
B. Purchases & Licenses
- Your licenses: product, expiry date, and each grant that added time (with the Stripe checkout reference or the redeemed key it came from)
- The time at which you accepted the Terms and requested immediate delivery (waiving the right of withdrawal), stored with your Stripe checkout
- Your Stripe customer ID, encrypted at rest
- Redeemed license keys, stored only in hashed form
Your name, billing address, email address for receipts, and payment details are collected by Stripe and Link as merchant of record. Payment card data never reaches our servers.
C. Security & Authentication
- One-time sign-in codes, stored hashed, valid for 10 minutes
- Website session tokens, stored hashed (the cookie holds the only readable copy)
- CSRF protection tokens, derived from your session and never stored
- Rate-limiting counters, kept in memory only and keyed with a hash of your IP address that changes every day. IP addresses are never written to disk or to our database.
- The result of a Cloudflare Turnstile check when you sign in or sign up (to stop automated sign-ups)
- Passkeys you add: the public key, the passkey's ID, whether it is synced between your devices, and when it was added and last used. The private key and your fingerprint or face never leave your device; we never receive them.
D. Loader & Devices
- Hardware identifier of the device you use the loader on, stored only as a keyed hash
- Operating system version, and a device name if you set one (encrypted at rest)
- When the device was approved and last seen, and the dates of device resets
- Loader session tokens, stored hashed
- A build ID for each loader download, linked to your account, so leaked copies can be traced
E. Communication
- Emails you send us
- Messages you send our staff on Discord
F. Administrative
- Admin Area audit log: which account opened or tried to open an admin page, when, and whether access was allowed
- If your account is blacklisted: the reason shown to you, an internal note for staff (encrypted), who made the decision, and when
We do not collect special categories of data (e.g. racial or ethnic origin, political opinions, health data, or biometric data), and we do not use analytics or advertising trackers.
3. Legal Basis for Processing
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfil our agreement with you: creating and signing in to your account, delivering and checking licenses, running the loader on your device, and providing support.
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws, including tax, accounting, and record-keeping requirements.
- Legitimate Interests (Art. 6(1)(f)): Fraud prevention, service security, rate limiting, abuse detection, one-session-per-account and one-device enforcement, and protection of our software and licenses from unauthorized distribution. We have assessed these interests against your rights and freedoms and concluded they are necessary, proportionate, and would be reasonably expected by users of a paid digital product. You may object to this processing at any time (see Section 9).
- Consent (Art. 6(1)(a)): At the moment of purchase you give express consent to the immediate delivery of digital content and acknowledge the resulting waiver of your right of withdrawal under Art. 16(m) of Directive 2011/83/EU. This consent is recorded at checkout and is auditable on request. You may withdraw consent at any time (see Section 9), though withdrawal does not affect the lawfulness of processing carried out beforehand.
4. How We Use Your Information
- Send you sign-in and confirmation codes, and authenticate you
- Provide, operate, and maintain the Services and the loader
- Deliver licenses after a purchase or key redemption, and remove them after a full refund or lost chargeback
- Enforce one device per license, the weekly device reset limit, and one website session per account
- Monitor for abuse, fraud, and unauthorized access, and enforce the Terms of Service
- Show aggregated, non-identifying statistics to our staff (such as the number of accounts or active licenses)
- Provide customer support and respond to inquiries
We only email you about your account: sign-in codes, security notices (a passkey added or removed), and blacklist decisions. We do not send marketing emails and we do not use your data for advertising.
5. Data Retention
- Account data: For as long as your account exists. When you ask us to delete your account, it is deleted together with its sessions, devices, and licenses.
- Purchase records: Invoices and payment records are kept by Link and Stripe as merchant of record, as long as tax law requires. Where the law requires us to keep an order reference as well (in the Netherlands, generally 7 years), we keep only that reference.
- Sign-in codes: Deleted within 24 hours.
- Website sessions: Until you sign out or the session expires (at the latest 30 days with "Remember me"; otherwise 24 hours, or 30 minutes without activity). Sessions ended by a newer sign-in are deleted within 24 hours.
- Loader sessions: Deleted one day after they expire.
- Device reset history: Deleted after 30 days.
- Passkeys: Until you remove them in the dashboard or your account is deleted.
- Loader download build IDs: Kept for 12 months.
- Admin Area audit log: Kept for 12 months.
- Rate-limiting counters: Memory only; they expire within 24 hours and are lost on every restart.
- Support correspondence: Kept for up to 24 months.
7. International Data Transfers
Your personal data is stored and processed on servers physically located in the European Union (Germany). We do not routinely transfer your personal data outside the European Economic Area (EEA).
Where a recipient listed in Section 6 may process data outside the EEA (for example Stripe's global payment infrastructure or Cloudflare's edge network), such transfers are governed by the European Commission's Standard Contractual Clauses (SCCs) as incorporated into that recipient's data processing terms, or by an equivalent transfer mechanism recognized under applicable data protection law.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS) on every connection
- Keyed one-way hashing of sign-in codes, session tokens, hardware identifiers, and license keys, and encryption of your email address, so a copy of our database does not reveal them
- AES-256-GCM encryption at rest for the few values we must be able to read back
- No passwords to leak: sign-in works with one-time codes only
- One active website session per account, and staff access restricted by role, checked on every request, and written to an audit log
- Servers that only accept traffic through Cloudflare, and rate limits on every sensitive action
9. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your account and personal data, subject to legal retention obligations.
- Right to Restriction: Request restriction of processing in certain circumstances.
- Right to Object: Object to processing based on legitimate interests.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on your consent, you may withdraw it at any time by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Withdrawing your consent to immediate delivery of digital content does not reinstate the right of withdrawal under Art. 16(m) of Directive 2011/83/EU once delivery has already begun.
- Right to Lodge a Complaint: File a complaint with your local data protection authority (in the Netherlands: the Autoriteit Persoonsgegevens).
To exercise any of these rights, email [email protected] from the email address linked to your account and include your username. Because we only store a hash of your email address, we check that the request comes from the account holder, for example by sending a code to that address.
10. Automated Decision-Making and Profiling
DND does not carry out any automated decision-making, including profiling, that produces legal effects or similarly significantly affects you within the meaning of Article 22 of the GDPR. Automatic security rules (rate limits, the one-session and one-device limits, and removing a license whose payment was refunded or charged back) apply the same fixed rules to everyone. Bans and account restrictions are decided by human staff.
12. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority, and where the risk is high also the affected users, in accordance with Articles 33 and 34 of the GDPR.
13. Children
The Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take prompt steps to delete such information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with a revised "Last updated" date. Where changes are material, we will also show a notice on the Services. Your continued use of the Services after any changes constitutes acceptance of the updated Policy.
15. Contact
For any questions or concerns regarding this Privacy Policy or our data practices, contact us at [email protected] or via our Discord.
