Legal
In short: we collect an email address so you can hold a licence, a message if you write to us, and a machine identifier so a licence runs on your computers and not on a stranger’s. There is no analytics on this site, no advertising, no tracking pixels and no third party watching you read this page. We do not sell data, and we never will.
Last updated: 27 August 2026
The data controller — the company that decides why and how your data is processed — is:
DC FINANZINVEST S.R.L.
A company incorporated in Romania in 2020. Not currently registered for VAT.
Registered office: Str. Teatrului nr. 3A, et. 4, ap. 3, Municipiul Botoșani, județul Botoșani, Romania
Trade Register No.: J7/565/09.10.2020 · EUID: ROONRC.J7/565/2020
CUI: 43168173 (registered 9 October 2020) · Share capital: 200 RON
Email: privacy@dctradelab.com
This policy covers both dctradelab.com and the licence portal at portal.dctradelab.com.
Because the company is established in the European Union, the GDPR applies to everything described here — including to customers outside the EU. We are not required to appoint a Data Protection Officer, and we have not appointed one: we are not a public authority, our business is selling software rather than monitoring people, and we process no special-category data. Every data protection question goes to privacy@dctradelab.com and is answered by the person who runs the company.
Four things happen here, and each one has its own purpose, its own legal basis and its own retention period. A single blanket statement covering everything would tell you nothing.
| What we do | Data | Legal basis | Kept for |
|---|---|---|---|
| You write to us or download a free tool The contact and download forms on this site. |
Name, email, and whatever you write in the message box. | Where you ask for a download or a quote: Art. 6(1)(b) — steps taken at your request before a contract. Where it is a general question: Art. 6(1)(f), our legitimate interest in answering people who contact us. | 24 months from the last message in the exchange. |
| You hold a licence account The portal where you see your licences. |
Email, your name if you choose to give it, and a cryptographic hash of your password. | Art. 6(1)(b) — necessary to perform the licence contract. | As long as you hold a licence, then 12 months. |
| The activity log Activations, sign-ins, refused checks. |
Licence key, machine identifier, the IP address the request came from, and what happened. | Art. 6(1)(b) for records of your own activations, and Art. 6(1)(f) for security: our legitimate interest in keeping the portal safe, spotting licence sharing and credential-stuffing, and being able to investigate an incident. | 12 months. |
| Binding a licence to your machines | A machine identifier derived from your computer. See the section below. | Art. 6(1)(b) — the three-machine limit is a term of your licence — and Art. 6(1)(f) for detecting use beyond that limit. | Until you release the machine, or the licence ends. |
We never store your password. What the database holds is a PBKDF2-HMAC-SHA256 hash with a per-account salt, from which the password cannot be recovered — not by us, not by anyone who steals a backup. Giving a name is optional and the form says so. If you do not give an email address we cannot create an account or deliver a licence, because there would be nowhere to send it.
Please do not put payment card details, identity document numbers, health information or information about other people into the message box. We do not need any of it.
When you activate an indicator or the copier, the software reads a small set of characteristics of your computer and derives a single identifier from them. That identifier is how a licence knows it is running on one of your three machines.
It is personal data, and we treat it as such. A hardware-derived identifier is an online identifier under Article 4(1) GDPR: even though it is a one-way hash and tells us nothing about you on its own, it is tied to your licence and therefore to you. We will not tell you it is “anonymous”, because that would not be true, and because a company that plays that game with one field is probably playing it with others.
We use it for one thing: enforcing the three-machine limit written into your licence, and letting you move a licence between machines. It is not used to profile you, is never combined with anything else, and is never shared.
There is always a human on the other side. If an activation is refused — you reinstalled Windows, you changed a computer, all three slots are taken — you can free a slot yourself in the portal, and if that does not work, write to support@dctradelab.com and a person will do it for you. No decision about your licence is made by software alone with no way to reach us.
Four names, and no more. Each acts on our written instructions and cannot use your data for anything of its own.
Hosts this website and our email. IONOS SE is established in Germany and the data stays inside the European Economic Area.
The content platform this site is built and published with. Messages sent through the contact forms are stored there until we export or delete them.
Runs on our own server. Nobody else operates it, and no third party has access to the licence database.
We intend to take payments through Skrill (Paysafe). Nothing is sold on this site today, so no payment data exists yet. This page will be updated, with a new date, before the first payment is taken.
We also disclose data where the law requires it — a court order, a tax inspection, a lawful request from an authority. If that ever happens and we are permitted to tell you, we will.
We do not sell personal data, do not share it for advertising, and run no advertising or analytics on this site.
This site sets no analytics cookies, no advertising cookies and no third-party cookies. There is no consent banner because there is nothing to consent to.
The licence portal sets three cookies, and only after you sign in. They keep you signed in and protect the forms from cross-site attacks. They are strictly necessary for a service you asked for, they are HttpOnly and Secure, they contain no tracking identifier, and they cannot follow you to another website.
Fonts are served from this domain, not from a third-party font service, so reading this page sends your IP address to nobody but our own host. If we ever add analytics, a consent banner will appear first and this page will say so.
Under the GDPR you have the following rights over your data. Exercising any of them is free and we answer within one month.
Ask what we hold about you and get a copy of it. Art. 15.
Have anything wrong corrected. Art. 16.
Ask us to delete it, where we have no overriding reason to keep it. Art. 17.
Have processing paused while a dispute is resolved. Art. 18.
Receive your data in a machine-readable file, or have it sent elsewhere. Art. 20.
Object to anything we do on the basis of legitimate interest. Art. 21.
Write to privacy@dctradelab.com. We may ask you to confirm you control the email address on the account — not to make it difficult, but because handing someone’s data to a stranger who asked nicely is the most common way it leaks.
If we get it wrong, complain. You can lodge a complaint with the Romanian supervisory authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, anspdcp@dataprotection.ro — or with the authority in the EU country where you live. You can also go to court. Telling us first is usually faster, but it is not a condition.
Everything travels over HTTPS. The portal refuses to send its session cookies over an unencrypted connection.
Hashed with PBKDF2-HMAC-SHA256 over 240,000 iterations and a per-account salt. Changing your password signs out every other device.
One operator, with a separate password and a session that expires in hours rather than weeks. Every administrative action is written to the activity log.
A breach that puts you at risk is reported to ANSPDCP within 72 hours and, where the risk to you is high, we tell you directly.
No system is perfectly secure and anyone who tells you otherwise is selling something. What we can say is that we collect as little as possible, keep it as briefly as we can justify, and do not put it anywhere it does not need to be.
These products are not sold to anyone under 18, and this site is not directed at children. We do not knowingly collect data from a child. If you believe a child has given us data, write to privacy@dctradelab.com and it will be deleted.
When this policy changes, the date at the top changes with it. Two things will happen before the next substantial version: a payment provider will be added, and the update will be described here rather than slipped in.
If a change affects how we use data you have already given us, we will tell account holders by email before it takes effect — not because we must, but because finding out afterwards is how people stop trusting a company.
Questions about anything on this page: privacy@dctradelab.com. It reaches the person who wrote the code.