Privacy Policy

Effective Date: 01 May 2025

This Privacy Policy explains how KeyMicrosoft.com (“we”, “us”, “our”) collects, uses, shares and safeguards your personal information when you visit our website or purchase a digital licence key.

1 — Information We Collect

  • Personal Data —name, billing address, e-mail, phone, payment details. (GDPR Art 4(1))
  • Usage Data —IP address, browser type, device ID, pages visited, time stamps.
  • Cookie & Tracking Data —first-party cookies for cart/session, third-party analytics. (disclose per Osano guidance) :contentReference[oaicite:4]{index=4}

2 — How We Use Your Data

We process data only when we have a valid legal basis (GDPR Art 6):

  • ✔ To fulfil a contract — process orders & deliver product keys.
  • ✔ Legitimate interests — prevent fraud, maintain site security.
  • ✔ Consent — send optional promo e-mails (you may withdraw any time).
  • ✔ Legal obligation — keep tax & accounting records for 7 years (best-practice retention) :contentReference[oaicite:5]{index=5}.

3 — Sharing Your Information

We never sell or rent personal data. We disclose only to:

  • • Payment processors (e.g. PayPal, Stripe) to complete your purchase.
  • • Cloud-hosting & email providers that power our store.
  • • Regulators or law-enforcement when required by law.

4 — Cookies & Similar Tech

Cookies store small text on your device so our cart remembers items and analytics help us improve UX. You can refuse non-essential cookies in our banner or in your browser settings. See our Cookie Policy for full list.

5 — Your Privacy Rights

Depending on your location you may:

  • • Access, correct or delete personal data (GDPR Arts 15-17).
  • • Export data (GDPR Art 20 portability).
  • • Opt-out of sale/share of data (CCPA §1798.120). :contentReference[oaicite:6]{index=6}
  • • Complain to a data-protection authority.

6 — Children’s Privacy

We do not knowingly collect information from anyone under 13. If we discover it, we delete it as required by COPPA. :contentReference[oaicite:7]{index=7}

7 — Security

We employ TLS encryption, PCI-DSS-compliant payment gateways, and role-based access controls to keep data safe. No method is 100 % secure, but we follow ISO/IEC 27001 best practices.

8 — Data Retention

Order records are kept for a minimum of seven (7) years to meet accounting laws and defend legal claims; marketing data is deleted 24 months after last interaction or earlier upon request. :contentReference[oaicite:8]{index=8}

9 — Updates to This Policy

We may update this notice to reflect changes in law or our practices. We will post the revised version here and update the “Effective Date.”

10 — Contact Us

Questions? E-mail our Data Protection Officer at [email protected]

en_USEnglish