Data Processing Agreement
Last updated: 2026-08-31
This Data Processing Agreement ("DPA") forms part of the LicenseSeat Terms of Service (the "Agreement") between Latent Software LLC, a Wyoming limited liability company ("LicenseSeat", "we", "us"), and the customer that has agreed to the Agreement ("Customer", "you").
This DPA is based on the Common Paper DPA Standard Terms, Version 1.1, used and adapted under CC BY 4.0.
How this DPA is executed. This DPA is incorporated into the Agreement by reference and is automatically effective, and deemed executed by both parties, for every Customer whose use of the Service involves the processing of personal data subject to Data Protection Laws. No signature is required, on either side: by accepting the Agreement and using the Service, both parties are deemed to have executed this DPA and the Standard Contractual Clauses it incorporates (Art. 28(9) GDPR permits electronic form; this is the same construction used by comparable infrastructure providers). We do not execute customer-specific copies, sign third-party DPA templates, or negotiate custom data processing terms; one consistent, carefully maintained DPA for all customers is how we keep the Service reliable and affordable.
1. Definitions
"Data Protection Laws" means all laws applicable to the processing of personal data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as retained in the law of the United Kingdom ("UK GDPR"), and the Swiss Federal Act on Data Protection ("FADP"), in each case as amended.
"Customer Personal Data" means personal data that LicenseSeat processes on Customer's behalf in providing the Service, as described in Annex I.B. It does not include data for which LicenseSeat is a controller, such as Customer's own account, billing, and support data, which is governed by the Privacy Policy.
"SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, Version B1.0, issued by the UK Information Commissioner under s.119A of the Data Protection Act 2018.
"Subprocessor" means a third party engaged by LicenseSeat to process Customer Personal Data.
Terms such as "controller", "processor", "processing", "data subject", "personal data", and "personal data breach" have the meanings given in the GDPR.
2. Roles and scope
- Customer is the controller (or, where Customer acts on behalf of its own customers, a processor) of Customer Personal Data. LicenseSeat is Customer's processor (or subprocessor, respectively).
- Each party will comply with its own obligations under Data Protection Laws.
- This DPA applies to the processing of Customer Personal Data for the duration of the Agreement.
3. Processing instructions
- LicenseSeat will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law, in which case LicenseSeat will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
- The Agreement, this DPA, and Customer's use and configuration of the Service constitute Customer's complete documented instructions. Additional instructions require prior written agreement.
- LicenseSeat will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws. LicenseSeat is not obliged to perform a legal review of Customer's instructions.
- Customer must not submit special categories of personal data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR), or data of a similar sensitive character to the Service, including through free-form fields such as license or user
metadata. The Service is not designed for such data, and Customer is solely responsible if it submits any.
4. Confidentiality
LicenseSeat ensures that every person it authorizes to process Customer Personal Data is bound by a contractual or statutory duty of confidentiality.
5. Security
- LicenseSeat implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to data subjects (Article 32 GDPR).
- LicenseSeat may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
6. Subprocessors
- Customer grants LicenseSeat general written authorisation to engage Subprocessors for the processing of Customer Personal Data.
- The current list of Subprocessors is published at licenseseat.com/legal/subprocessors, including each Subprocessor's legal entity, purpose, and processing location.
- LicenseSeat will update that page at least 10 business days before enabling a new Subprocessor to process Customer Personal Data. The updated page constitutes notice.
- Customer may object on reasonable data-protection grounds within 10 business days of the notice. The parties will discuss the objection in good faith; if it cannot be resolved, Customer may terminate the affected subscription.
- LicenseSeat will impose on each Subprocessor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains fully liable to Customer for each Subprocessor's performance.
7. Assistance to Customer
- Data subject requests. Taking into account the nature of the processing, LicenseSeat will assist Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to data subjects' requests to exercise their rights (Chapter III GDPR). If a data subject contacts LicenseSeat directly regarding Customer Personal Data, LicenseSeat will promptly refer them to Customer and will not respond substantively except on Customer's instruction or where legally required.
- Security, breach notification, DPIAs, and prior consultation. Taking into account the nature of the processing and the information available to it, LicenseSeat will assist Customer in ensuring compliance with Customer's obligations under Articles 32 to 36 GDPR, including, for the avoidance of doubt, reasonable assistance with Customer's data protection impact assessments (Article 35) and prior consultations with supervisory authorities (Article 36), insofar as they relate to the Service.
8. Personal data breach
LicenseSeat will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. LicenseSeat will provide timely updates as further information becomes available. LicenseSeat's notification is not an acknowledgement of fault or liability.
9. Deletion and return
- Upon termination of the Agreement, LicenseSeat will, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires longer storage.
- During the term, Customer can delete Customer Personal Data through the Service (including deleting licenses, activations, end-user records, and products). Data deleted through the Service, and data deleted after termination, is removed from live systems promptly and expires from encrypted backups on the backup rotation schedule described in Annex II.
- Absent a written request within 30 days of termination, LicenseSeat will proceed with deletion on its standard schedule.
10. Audits and information
- LicenseSeat will make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, including the documentation in Annex II, this DPA and the subprocessor list.
- LicenseSeat does not currently hold SOC 2 or ISO 27001 certification; Annex II is maintained at a level of detail intended to substitute for such reports.
- Where the information above is insufficient to demonstrate compliance, Customer (or an independent auditor mandated by Customer that is not a competitor of LicenseSeat) may conduct an audit, limited to information and systems relevant to Customer Personal Data, no more than once per 12 months, on at least 30 days' written notice, during business hours, without disruption to the Service, and subject to confidentiality. Customer bears its own audit costs and will reimburse LicenseSeat's reasonable costs of supporting the audit. Audits mandated by a supervisory authority or following a personal data breach are not subject to the frequency limit.
11. International transfers
- Customer acknowledges that LicenseSeat processes Customer Personal Data in the United States, and authorises transfers to the locations set out in the subprocessor list.
- For transfers from the EEA subject to the GDPR, the parties hereby enter into the SCCs, which are incorporated into this DPA by reference:
- Module Two (controller → processor) applies where Customer is a controller; Module Three (processor → processor) applies where Customer is a processor. Customer is the "data exporter"; LicenseSeat is the "data importer".
- Clause 7 (docking): not included.
- Clause 9(a): Option 2 (general written authorisation) applies, with the notice period in Section 6.3 of this DPA.
- Clause 11(a): the optional independent-dispute-resolution wording is not included.
- Clause 13 / Annex I.C: the competent supervisory authority is determined by the data exporter's establishment, as set out in Annex I.C.
- Clause 17: Option 1, the SCCs are governed by the law of Ireland.
- Clause 18(b): disputes shall be resolved before the courts of Ireland.
- Annexes I and II of the SCCs are the Annexes I and II of this DPA. Annex III of the SCCs is the subprocessor list referenced in Section 6.2.
- The parties are deemed to have signed the SCCs, including their Annexes, upon execution of this DPA.
- For transfers from the United Kingdom, the UK Addendum is incorporated by reference and deemed executed. Tables 1–3 of the UK Addendum are completed with the information in the SCCs and the Annexes to this DPA; for Table 4, neither party may terminate the UK Addendum as set out in Section 19 of the UK Addendum.
- For transfers from Switzerland, the SCCs apply as adapted for the FADP: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority under Annex I.C; references to the GDPR are understood as references to the FADP; references to "EU Member State" do not exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence in Switzerland.
- LicenseSeat is not certified under the EU-U.S. Data Privacy Framework; the SCCs are the transfer mechanism relied upon under this DPA. Where LicenseSeat's Subprocessors are themselves DPF-certified, that certification is additional to, not a substitute for, the contractual safeguards above.
12. Liability and precedence
- Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set out in the Agreement, except that nothing in this Section limits (a) either party's liability to data subjects under Clause 12 of the SCCs, or (b) any liability that cannot be limited under applicable Data Protection Laws.
- If there is any conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA prevails; and if there is any conflict between the SCCs and this DPA or the Agreement, the SCCs prevail.
- This DPA does not alter the parties' rights and obligations with respect to data for which LicenseSeat is a controller, which remain governed by the Privacy Policy.
Annex I, Description of processing
A. List of parties
Data exporter: the Customer identified in the Agreement (name, address, and contact details as provided in the Customer's LicenseSeat account). Role: controller (or processor, where Section 2.1 so provides). Activities: use of the LicenseSeat software-licensing service for the Customer's software products.
Data importer: Latent Software LLC, a Wyoming limited liability company (United States). Contact: [email protected]. Role: processor. Activities: provision of the LicenseSeat licensing, distribution, and telemetry service described in the Agreement.
B. Description of transfer
- Categories of data subjects: end users of the Customer's software (licensees); the Customer's personnel who access the LicenseSeat dashboard.
- Categories of personal data: license keys and license status; activation status and seat usage; hardware identifiers (device fingerprint / hardware ID / unique device ID); IP address at activation and validation; end-user email address (where the Customer provides it); SDK telemetry, device model and type, hardware architecture, CPU cores, memory, operating system name and version, platform, app and SDK version, language, locale, timezone, and screen properties; approximate location derived from IP address (city-level, computed locally, see Annex II); any personal data the Customer chooses to place in free-form metadata fields (prohibited for sensitive data, Section 3.4).
- Sensitive data: none. The submission of special categories of data is contractually prohibited (Section 3.4).
- Frequency: continuous, for the duration of the Agreement.
- Nature of processing: storage, license validation and enforcement, device activation and seat management, software distribution and update delivery, fraud prevention, usage telemetry and analytics presented to the Customer, and transactional email to end users on the Customer's behalf.
- Purpose: provision of the Service to the Customer on the Customer's instructions.
- Retention: for the duration of the Agreement, subject to: IP addresses associated with device activations are deleted 90 days after the activation is deactivated; telemetry IP addresses are deleted after 90 days; inactive dashboard sessions are removed after 12 months; deletion on termination per Section 9.
- Transfers to subprocessors: as set out in the subprocessor list, for hosting, content delivery, backup storage, and transactional email.
C. Competent supervisory authority
The supervisory authority of the EEA Member State in which the data exporter is established (for exporters established in Germany, the competent supervisory authority of the relevant Land); for UK transfers, the Information Commissioner; for Swiss transfers, the Federal Data Protection and Information Commissioner.
Annex II, Technical and organisational measures
Measures are stated as implemented and verifiable in LicenseSeat's systems and configuration.
- Encryption in transit. All traffic to and within the Service's public surface is encrypted with TLS 1.2 or higher; HTTPS is enforced on all endpoints, with certificates provisioned and renewed automatically.
- Backup encryption. Full database backups are taken nightly, compressed, and stored off-site with server-side encryption (AES-256) at the storage provider; backup freshness is continuously monitored, and stale backups raise an operational alert.
- Credential protection. Account passwords are stored only as salted adaptive hashes (bcrypt). API keys are scoped, revocable, and displayed once at creation.
- Access control. Customer data is segregated per organization and enforced at the application layer on every request; dashboard access requires authentication; administrative access to production systems is restricted to a single named operator over key-based SSH; the principle of least privilege is applied to service credentials.
- Data minimisation by design. Software download events are recorded without IP addresses or device identifiers at the schema level. IP-derived location is computed locally against on-server geolocation databases; IP addresses are not sent to any third-party geolocation service, and derived coordinates are city-level approximations, never GPS readings from the device.
- Retention enforcement in code. Scheduled jobs enforce the retention periods in Annex I.B automatically (daily anonymisation of expired activation and telemetry IPs; periodic sweep of inactive sessions), so retention does not depend on manual action.
- Development security. Changes ship through version control with an automated test suite and continuous integration; dependencies are monitored and updated; production configuration and secrets are stored encrypted and never committed in plaintext.
- Incident response. Operational monitoring and alerting are in place for service health and backup freshness; personal data breaches are handled per Section 8 of this DPA, with a documented internal escalation path to the operator.
- Subprocessor safeguards. Each subprocessor processes Customer Personal Data under a written data processing agreement incorporating the SCCs or equivalent safeguards, as set out in the subprocessor list.
- Assistance measures. Data subject requests relating to Customer Personal Data can be fulfilled by the Customer directly through the Service (access, correction, deletion of licenses, activations, and end-user records); LicenseSeat provides assistance per Section 7.
Annex III, List of subprocessors
The authorised subprocessors, including legal entity, purpose, and location, are published and maintained at licenseseat.com/legal/subprocessors, which is incorporated into this DPA by reference. Section 6 governs updates and objections.