Effective Date: 01 May 2025
This Privacy Policy explains how KeyMicrosoft.com (“we”, “us”, “our”) collects, uses, shares and safeguards your personal information when you visit our website or purchase a digital licence key.
1 — Information We Collect
- Personal Data —name, billing address, e-mail, phone, payment details. (GDPR Art 4(1))
- Usage Data —IP address, browser type, device ID, pages visited, time stamps.
- Cookie & Tracking Data —first-party cookies for cart/session, third-party analytics. (disclose per Osano guidance) :contentReference[oaicite:4]{index=4}
2 — How We Use Your Data
We process data only when we have a valid legal basis (GDPR Art 6):
- ✔ To fulfil a contract — process orders & deliver product keys.
- ✔ Legitimate interests — prevent fraud, maintain site security.
- ✔ Consent — send optional promo e-mails (you may withdraw any time).
- ✔ Legal obligation — keep tax & accounting records for 7 years (best-practice retention) :contentReference[oaicite:5]{index=5}.
3 — Sharing Your Information
We never sell or rent personal data. We disclose only to:
- • Payment processors (e.g. PayPal, Stripe) to complete your purchase.
- • Cloud-hosting & email providers that power our store.
- • Regulators or law-enforcement when required by law.
4 — Cookies & Similar Tech
Cookies store small text on your device so our cart remembers items and analytics help us improve UX. You can refuse non-essential cookies in our banner or in your browser settings. See our Cookie Policy for full list.
5 — Your Privacy Rights
Depending on your location you may:
- • Access, correct or delete personal data (GDPR Arts 15-17).
- • Export data (GDPR Art 20 portability).
- • Opt-out of sale/share of data (CCPA §1798.120). :contentReference[oaicite:6]{index=6}
- • Complain to a data-protection authority.
6 — Children’s Privacy
We do not knowingly collect information from anyone under 13. If we discover it, we delete it as required by COPPA. :contentReference[oaicite:7]{index=7}
7 — Security
We employ TLS encryption, PCI-DSS-compliant payment gateways, and role-based access controls to keep data safe. No method is 100 % secure, but we follow ISO/IEC 27001 best practices.
8 — Data Retention
Order records are kept for a minimum of seven (7) years to meet accounting laws and defend legal claims; marketing data is deleted 24 months after last interaction or earlier upon request. :contentReference[oaicite:8]{index=8}
9 — Updates to This Policy
We may update this notice to reflect changes in law or our practices. We will post the revised version here and update the “Effective Date.”
10 — Contact Us
Questions? E-mail our Data Protection Officer at [email protected]