Privacy Policy
Last updated: 24 August 2026
Peters Development operates larsasub.eu and is the controller for the personal data processed here. Contact: info@larsasub.eu.
Peters Development · Bijsterhuizen 2414, 6604 LL Wijchen · Netherlands · Chamber of Commerce 77119185 · VAT ID NL003151172B94
What we process, and why
- Account data: name, e-mail address, password (hashed) and the date you last signed in, used to provide your customer account and license access. Legal basis: performance of a contract.
- Security data: if you switch on two-factor authentication, the shared secret and your recovery codes, stored encrypted. We also keep a record of your active sessions (browser, operating system and time of last activity — not your IP address) so you can see where you are signed in and sign other devices out. Legal basis: performance of a contract and legitimate interest (account security). Retention: sessions expire automatically; secrets are deleted when you turn two-factor off.
- Change history: we log when an account's e-mail address, password, two-factor setting or deletion status changes. This exists to answer "why did my access stop working", not to profile you. Legal basis: legitimate interest.
- Order and license data: purchases, license status, license tokens and package download logs, used to deliver the product, enforce license terms and provide support. Legal basis: performance of a contract and legitimate interest (abuse prevention).
- Invoicing data: invoice details including name, e-mail and amounts, kept to meet legal bookkeeping obligations. Legal basis: legal obligation. Retention: 7 years (Dutch fiscal retention duty).
- Payment data: payments are processed by Mollie B.V. (Amsterdam); we never see or store full payment credentials. Mollie processes your data under its own privacy policy.
- Technical logs: IP address and request data in server logs, for security and abuse prevention. Legal basis: legitimate interest. Retention: short-term, rotated automatically.
- Visitor statistics: we count visits to our own public pages ourselves — no Google Analytics, no third party, nothing leaves our server. We store a pseudonymous digest,
sha256(daily salt | IP | user agent), together with the page, a rough device and browser label, and the referring domain. Your IP address, your full user agent and the full referring URL are never stored. The salt rotates every day, so the digest cannot be linked from one day to the next. Legal basis: legitimate interest (statistics about our own site). Retention: raw rows 7 days, per-day totals 13 months, monthly totals indefinitely. We honour DNT: 1.
- E-mail: transactional e-mail (verification, license credentials, expiry and renewal notices) is sent to the address on your account. We do not send marketing e-mail without separate consent.
What we don't do
- No sale or sharing of personal data with third parties for their own purposes.
- No advertising or cross-site tracking cookies, and no fingerprinting script. Our visitor statistics store nothing in your browser and read nothing from it, which is why there is no cookie banner for them.
- To be precise about what the site does put in your browser: a session cookie (
larsasub-session) and a CSRF cookie (XSRF-TOKEN) on every page, both strictly necessary for the sign-in and order forms and therefore consent-free, plus your theme preference in local storage. Saying “we use no cookies” would simply be untrue.
- No profiling or automated decision-making.
Processors and transfers
We use a small set of processors to run the service: our hosting provider (EU), Mollie for payments (EU) and our e-mail provider (EU). Data is stored within the European Union.
Doing it yourself
You do not have to e-mail us to exercise the two rights people ask for most. Both are buttons on your account profile page.
- Download my data packs everything we hold about you into one archive: your profile, billing details, licenses and license keys, orders, every invoice as a PDF, and your download history. We e-mail you a link that is valid for 24 hours and only works while you are signed in; the file is deleted from our server after 7 days. The archive contains a README explaining each file. It leaves out one thing on purpose: the IP address recorded with each package download, which we keep to detect abuse of a shared license key and which tells you nothing useful.
- Delete my account asks for your password, then sends a confirmation link to your e-mail address. After you confirm we wait 14 days before anything happens — your licenses keep working, and you can cancel from any page in your account during that period. After that we remove your sign-in, two-factor secrets, sessions, license keys, download history and the billing details on your profile, and we deactivate your licenses.
What deletion does not remove: your invoices. Dutch tax law requires us to keep them for seven years, and an invoice is only valid if it carries the customer's name and address — anonymising them would make our books invalid. Article 17(3)(b) GDPR provides for exactly this. Everything else about you goes, and we say so in the confirmation e-mail too rather than promising "everything is erased".
Your rights
Beyond the self-service options above, under the GDPR you can request access, correction, deletion, restriction and portability of your personal data, and object to processing based on legitimate interest. E-mail info@larsasub.eu; we respond within 30 days. Note that invoice data under the fiscal retention duty cannot be deleted early. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Changes
We may update this policy; changes are published on this page with an updated date.