USE CODE "VERTIGO10" FOR 10% OFF AT CHECKOUT

Privacy Policy

How we handle and protect your data.

Privacy Policy

Effective Date: January 19, 2026

At Vertigo, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your information when you use our website, software, and services, and how you can exercise your rights over that data.

Who we are: Vertigo is the data controller for the personal data described below. For any privacy request, contact us via a support ticket in our Discord server [or an email address — add one here; a Discord ticket alone is unlikely to satisfy the accessible-contact-channel expectation under GDPR Art. 12].


1. Data We Collect

To provide our services and prevent license abuse, we collect the following information:

  • Account Information: Email address and username (if applicable).
  • Payment Data: Transaction IDs and payment status. We do not store full card numbers; these are handled directly by our payment processors (Stripe / PayPal).
  • Technical Identifiers: IP address, Hardware ID (HWID), and basic system details (OS version and CPU type).
  • Usage Logs: Timestamps of software launches and authentication attempts.

2. How We Use Your Data, and Our Legal Basis

Under the GDPR, we may only process personal data where we have a valid legal basis. Ours are:

  • Authentication — necessary to perform our contract with you (verifying a valid license on an authorized machine).
  • Security & fraud prevention — our legitimate interest in detecting fraud, account sharing, or tampering, balanced against your rights; you may object to this processing (see Section 5).
  • Support — necessary to perform our contract with you when you request help or a HWID reset.
  • Compliance — necessary to meet our legal and tax obligations.

3. Data Retention

We keep personal data only as long as necessary for the purposes above:

  • Active Licenses: retained for the duration of your subscription, plus a limited period after expiry to handle support and disputes.
  • Security Logs: retained for a limited period sufficient to identify patterns of abuse, then deleted or anonymized.
  • Legal & Tax Records: purchase history is retained as required under Swedish accounting/tax law (generally up to 7 years), regardless of whether your account remains active.

4. Third-Party Disclosures & International Transfers

We do not sell, rent, or trade your personal data. We share it only where necessary:

  • Payment Processors: Stripe, PayPal, or crypto payment gateways, to complete your transaction. These providers act as independent controllers for the payment data they process.
  • Legal Requirements: where required by law, court order, or a valid legal process.

Where any of these providers are located outside the EU/EEA, transfers are made subject to appropriate safeguards, such as Standard Contractual Clauses, as required under Chapter V of the GDPR.

5. Your Rights (GDPR)

If you are located in the EU/EEA (or another jurisdiction with equivalent protections), you have the right to:

  • Access — request a copy of the data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your data, subject to our legal retention obligations (see Section 3).
  • Restriction — request that we limit processing of your data in certain circumstances.
  • Objection — object to processing based on our legitimate interest, including security processing under Section 2.
  • Data Portability — receive your data in a structured, machine-readable format.
  • Complaint — lodge a complaint with your local data protection supervisory authority (in Sweden, the Integritetsskyddsmyndigheten, IMY) if you believe we have mishandled your data.

To exercise any of these rights, contact us via the channel listed in the "Who we are" note above. We will respond within the timeframe required by applicable law.

6. Security Measures

We implement industry-standard encryption and access controls to protect your data from unauthorized access, loss, or alteration. No method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. In the event of a data breach likely to result in a risk to your rights, we will notify affected users and relevant authorities as required by applicable law.

7. Cookies

Our website uses strictly necessary cookies to maintain your session. Where we use any non-essential cookies (e.g., analytics or preferences), we will request your consent before setting them, and you may withdraw that consent at any time via your cookie settings. Disabling non-essential cookies will not affect core site functionality; disabling essential cookies may prevent the site from working correctly.

8. Children's Privacy

Our services are not directed at individuals under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.


9. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via our website or Discord server, and, where required by law, we will seek renewed consent before applying changes to previously collected data.