Privacy Policy
Webdesignelite License Server
Last updated: July 2026
This policy applies to lizenz.elitestack.de. For the website elitestack.de, the privacy policy published there applies.
Table of Contents
1. Data Controller
Information about the data controller within the meaning of the GDPR can be found in our Imprint.
2. Processing Overview
This license server processes personal data exclusively to provide the following services:
- User account management (registration, login, profile)
- License management and verification for software products
- Support ticket system
- Transactional emails (license delivery, reminders, support notifications)
- Security and system logging
- Purchase and payment processing via Stripe (section 14)
Processed Data Categories
| Category | Data | Purpose |
|---|---|---|
| Identity data | Name, email address | Account management, communication |
| Access credentials | Password (hashed), 2FA secret (encrypted) | Authentication |
| License data | License key, activation domains, plugin version, last check-in | License verification, update checks |
| Support data | Ticket content, attachments, timestamps | Customer support |
| Log data | User actions, timestamps, IP (on login) | Security, error analysis |
| Technical data | Session ID, CSRF token, language preference | Session management |
| Payment and invoice data | Name, billing address, email, VAT ID (for businesses), subscription and invoice numbers. No card details — these are entered exclusively at Stripe and are never transmitted to us | Purchase processing, invoicing, statutory retention |
3. Legal Basis
- Art. 6(1)(b) GDPR – Performance of a contract: license provision, support, account management, purchase and payment processing
- Art. 6(1)(c) GDPR – Legal obligation: retention of invoices and accounting records (§ 147 AO, § 257 HGB)
- Art. 6(1)(f) GDPR – Legitimate interests: security logging, abuse prevention
- Art. 6(1)(a) GDPR – Consent: where separately obtained (currently not in use)
4. Registration & User Account
The following data is processed when creating an account:
- Name – for personalization and salutation
- Email address – as login identifier and for system notifications
- Password – stored as a Bcrypt hash, never in plain text
- Language preference – for the dashboard interface (DE/EN)
- Avatar – optional, as upload or preset
Two-factor authentication (TOTP) can optionally be enabled. The 2FA secret and recovery codes are stored encrypted.
5. License Management
The following data is processed when using our software licenses:
- License key – for unique identification
- Activation domains – to verify that the license is used on authorized websites
- Plugin version and WordPress version – for update compatibility checks
- Last check-in – timestamp of the last verification
- HMAC secret – optional signing of API responses for integrity assurance
License verification is performed via API (server-to-server, not browser-based). No end-user IP addresses are stored.
6. Support System
The following data is processed when using the integrated ticket system:
- Ticket subject and content – to process the inquiry
- Replies – including internal notes (visible to admins only)
- File attachments – max. 5 MB, PDF and image files only (JPEG, PNG, GIF, WebP), stored on the server's local storage
- Timestamps – creation and update timestamps
Attachments are automatically removed from the server when the associated ticket or reply is deleted.
7. Email Communication
The license server sends transactional emails via its own mail server (Mailcow). The following email types are sent:
- License key delivery
- Expiration reminders
- Welcome emails
- Support notifications (new ticket, new reply, status changes)
No newsletters are sent. Email templates are managed internally. Sent emails are logged for traceability (recipient, subject, timestamp).
8. Logging
For security and traceability, the following actions are automatically logged:
- Creation, modification, and deletion of licenses, products, users, and tickets
- Email dispatch
- System actions (cache clearing, maintenance)
Logs are automatically limited to a maximum of 500 entries (auto-pruning). Older entries are automatically deleted.
9. Cookies & Sessions
This license server uses strictly necessary cookies only within the meaning of Section 25(2)(2) TDDDG — they are strictly necessary for us to provide the service you have explicitly requested (login, license management). No consent is required for them:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Session management, authentication | Until browser close / max. 120 min. |
| XSRF-TOKEN | Cross-Site Request Forgery protection | Session duration |
In addition, your browser stores your language and theme preference (light/dark) locally when you actively click the corresponding control. This too is a direct consequence of your own choice and therefore requires no consent.
No tracking, analytics, or marketing cookies are used and no third-party scripts (Google Analytics, Meta Pixel, etc.) are loaded. Fonts and stylesheets are served from our own server; no connection to a content delivery network is established when the page loads. A cookie consent banner is therefore not required.
Note: The consent management on elitestack.de technically does not extend to this subdomain. Since nothing requiring consent is loaded here, this creates no gap.
10. Security Measures
To protect your data, we implement the following technical and organizational measures:
- Transport encryption – HTTPS only (TLS)
- Password hashing – Bcrypt with salt
- Two-factor authentication – TOTP (mandatory for administrators)
- Session encryption – sessions are stored encrypted on the server
- Secure cookies – session cookies are only transmitted over HTTPS
- CSRF protection – every form is protected against Cross-Site Request Forgery
- Rate limiting – API endpoints are limited to 30 requests/min (verification) or 10 requests/min (downloads)
- Role-based access control – customers can only see their own data
- Input validation – all inputs are validated and sanitized server-side
- CORS restriction – no cross-origin browser access possible
11. Retention & Deletion
| Data Category | Retention Period | Deletion |
|---|---|---|
| User account | Until deletion by admin or upon request | Complete deletion including profile picture |
| Licenses | Until deletion by admin | License and associated activations are removed |
| Activations | Until deactivation or license binding | Soft delete (reactivation possible), permanent upon license deletion |
| Support tickets | Until manual deletion (superadmin only) | Ticket, replies, and attachments are completely removed |
| Email logs | Until manual deletion | Deletable by admin |
| Activity logs | Max. 500 entries (auto-pruning) | Automatic cleanup, manually deletable |
| Sessions | Max. 120 minutes | Automatic cleanup |
12. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) – information about what data is stored about you
- Right to rectification (Art. 16 GDPR) – correction of inaccurate data
- Right to erasure (Art. 17 GDPR) – deletion of your data, unless retention obligations apply
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR) – export of your data in a machine-readable format
- Right to object (Art. 21 GDPR) – against processing based on legitimate interests
To exercise your rights, please contact: info@webdesignelite.de
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) if you believe that the processing of your data violates the GDPR. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
www.ldi.nrw.de
13. Recipients & Third Parties
Your data is never sold and never used for advertising. It is shared only with the following service providers, and only where necessary to perform the contract:
- Web server – netcup GmbH, Karlsruhe (Germany), for hosting and data processing. Processing on our behalf under Art. 28 GDPR.
- Mail server – Mailcow on our own netcup server (Germany), for email delivery. No external mail provider.
- Payment service provider – Stripe Payments Europe, Limited (Ireland). Details in section 14.
Beyond this, we disclose data only where legally required (for example to tax authorities under statutory retention obligations).
14. Purchase & Payment Processing (Stripe)
To purchase a license we use Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland ("Stripe").
Roles
We are the seller and your sole contractual partner. We issue the invoice in our own name and remit VAT. Stripe processes the payment only and does not act as seller or reseller.
Process and data processed
When you click a purchase button, you are redirected to a payment page operated by Stripe, where you enter your payment details directly with Stripe.
- Full card details, bank details and wallet credentials never reach our servers and are not stored by us.
- Stripe transmits back to us: name, billing address, email address, VAT ID where applicable, purchase and subscription identifiers, invoice numbers, amount and payment status.
- We need this data to provision your license, issue your invoice and process cancellations or refunds.
Legal bases: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory retention obligations for invoices).
Transfers to third countries
Our contracting party Stripe Payments Europe is based in Ireland (EU). Stripe may transfer data to its parent company Stripe, Inc. in the USA. Such transfers are safeguarded by the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and by Stripe, Inc.'s certification under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023).
Stripe processes some of your data as an independent controller, in particular for fraud prevention and to meet its own obligations under anti-money-laundering and financial supervision law. Details are set out in Stripe's privacy policy.
Customer portal
From the dashboard you can open a customer portal operated by Stripe to view invoices, change payment methods or cancel your subscription. This also redirects you to a page hosted by Stripe.
15. Changes to This Privacy Policy
We reserve the right to update this privacy policy to reflect changes in legal requirements or modifications to our services. The current version is always available on this page.