DRAFT — PROFESSIONAL PRIVACY REVIEW REQUIRED BEFORE RELIANCE.
This notice is a review scaffold. The final notice must match the production data map, processors, hosting locations, retention periods, legal bases, security measures and international transfers actually used at launch.
Controller
Controller: [[LEGAL_ENTITY_NAME_AND_ADDRESS]]. Privacy contact: [[PRIVACY_CONTACT]]. Data Protection Officer: [[DPO_IF_REQUIRED_OR_APPOINTED]].
Data categories currently expected
Account/contact information; authentication and security records; licence and entitlement records; machine activation identifiers/hashes; payment/order references and provider event metadata; support messages; download/audit history; public-demo abuse-control identifiers; worker/administrator operational records; and technical logs required for security and reliability.
Purposes and legal bases
The final notice must map each processing purpose to its actual legal basis. Expected purposes include account/service delivery, contract/licence administration, payment reconciliation, security and fraud prevention, support, legal compliance and platform operations. Do not copy this list into production without completing the legal-basis assessment.
Recipients and processors
The final notice must identify or categorise actual processors and recipients, including hosting, database/storage, payment, email, security/bot-protection, support and professional advisers where used.
International transfers
The final notice must document any transfers outside the EEA and the actual safeguards relied on. No transfer mechanism is assumed by this draft.
Retention
Retention schedules must be documented per data category, including account, billing, audit/security, support, licence and backup records.
Data-subject rights
The final notice should explain applicable access, rectification, erasure, restriction, portability, objection and complaint rights, plus how requests are authenticated and handled. The competent supervisory authority must be identified where applicable.
Automated decisions
Document any profiling or solely automated decision-making that has legal or similarly significant effects. Current security/rate-limit controls must be reviewed to determine what disclosure is appropriate.
Cookies and similar technologies
See the separate Cookie Policy. Authentication/security storage and optional anti-bot tooling must be audited in the deployed system before the final notice is published.
Changes and contact
Versioning, effective date and change-notice procedure must be confirmed before activation.