GDPR Compliance

Last updated: August 06, 2026

AuthVaultix is fully committed to compliance with the General Data Protection Regulation (GDPR). We respect your privacy and are dedicated to protecting the personal data of European Union citizens and all global users.

1. Overview

The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union. AuthVaultix operates as both a Data Controller (for our direct developer customers) and a Data Processor (for the end-users authenticating through our API). We implement strict security measures by design and by default.

2. Data We Collect

In the course of providing our software licensing and authentication services, we minimize the personal data collected to what is strictly necessary:

  • Account Data: Email addresses, usernames, and payment information (processed by secure third-party gateways like Paddle and Razorpay).
  • Authentication Telemetry: Hardware Identifiers (HWIDs), IP addresses, and session tokens used exclusively to prevent piracy and enforce license limits.

3. Your GDPR Rights

If you reside within the European Economic Area (EEA), you are granted robust rights regarding your personal data under the GDPR:

  • Right to Access: You may request a complete export of all personal data we hold about you.
  • Right to Rectification: You may correct any inaccurate or incomplete data.
  • Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your account and all associated data, provided it does not conflict with legal retention obligations.
  • Right to Restrict Processing: You may limit how we use your data under certain circumstances.
  • Right to Data Portability: You may request your data in a structured, commonly used, and machine-readable format.

4. Data Processing and Security

All data processed by AuthVaultix is encrypted both in transit (using TLS 1.3) and at rest (using AES-256 encryption on our database clusters). HWIDs and passwords are irreversibly hashed using industry-standard algorithms (such as bcrypt or Argon2) before being stored.

5. Third-Party Sub-processors

To deliver our services reliably, we utilize a vetted network of third-party sub-processors (e.g., cloud hosting providers and payment gateways). We ensure that all sub-processors enter into rigorous Data Processing Agreements (DPAs) and adhere to GDPR standards. We do not sell your data to advertisers or data brokers.

6. Data Breach Notification

In the highly unlikely event of a data breach that compromises your personal data, AuthVaultix guarantees to notify the relevant supervisory authorities and all affected users within 72 hours of becoming aware of the incident, in strict accordance with GDPR Article 33.

7. Contact our Data Protection Officer

If you wish to exercise any of your GDPR rights, request a Data Processing Agreement, or have privacy-related inquiries, please contact our Data Protection Officer (DPO) at:

Email: support@authvaultix.com

We aim to respond to all formal GDPR requests within 30 days.

Ready to start securing applications, delivering amazing user experiences, or building the next big B2B app?