PRIVACY POLICY
AMP Studio Ltd. (АМП Студио ЕООД)
Keyper - Multi-Tier Software Licensing Platform
Last Updated: August 7, 2025
COMPANY INFORMATION
Data Controller: AMP Studio Ltd.
Legal Form: Single-member limited liability company (EOOD)
Company Registration Number (EIK): 208265294
Registered Address: 9Zh Boris Rumenov Street, Entrance B
Lozenets District, Sofia 1421,
Sofia Municipality, Bulgaria
Country of Incorporation: Bulgaria
Managing Director: Asaf Yosef Mazuz
Contact Email: ampstudiobg@gmail.com
Privacy Contact: ampstudiobg@gmail.com
1. INTRODUCTION
This Privacy Policy explains how AMP Studio Ltd. ("we," "us," or "our") collects, uses, processes, and protects personal data in connection with the Keyper platform ("Platform"). We are committed to protecting your privacy and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
AMP Studio Ltd. acts as the data controller for personal data processed through the Platform. For privacy-related inquiries, please contact us at ampstudiobg@gmail.com.
3. SCOPE OF APPLICATION
This Privacy Policy applies to:
- B2B clients (software vendors) using our platform ("Users")
- End customers managing their licensed software and devices ("End Customers")
- Visitors to our website and platform
4. PERSONAL DATA WE COLLECT
- Data Collected from B2B Clients (Users):
- Identity Data: Full name, business title, company name
- Contact Data: Email address, phone number, business address
- Financial Data: Billing information, payment card details (processed by Stripe)
- Transaction Data: Subscription details, payment history, usage records
- Technical Data: IP addresses, browser type, device information
- Usage Data: Platform interaction data, feature usage analytics
Important Note on Payment Data: All payment and transaction data, including credit card information, payment details, and transaction records, are processed and stored exclusively by Stripe. We do not directly store, process, or have access to any payment card information or detailed transaction data in our database. We only store basic subscription status and billing reference information necessary for platform functionality.
- Data Collected from End Customers:
- Identity Data: Name, email address
- Device Data: Device identifiers, device names/titles, hardware information – all device identifiers are encrypted with one-way encryption.
- Usage Data: License activation/deactivation history, device usage patterns
- Technical Data: IP addresses, browser information, device specifications
- Transaction Data: Purchase history, license ownership records
- Communication Data: Support requests, feedback, correspondence
- Automatically Collected Data:
- Cookies and similar tracking technologies
- Log files and server data
- Analytics data (Google Analytics, if applicable)
- Performance and diagnostic information
- API usage logs (e.g., endpoints accessed, timestamps) for monitoring and abuse prevention
5. LEGAL BASIS FOR PROCESSING
We process personal data based on the following legal grounds:
- Contract Performance (Article 6(1)(b) GDPR):
- Providing platform services to B2B clients
- License validation and device management for end customers
- Payment processing and billing
- Legitimate Interest (Article 6(1)(f) GDPR):
- Platform security and fraud prevention
- Service improvement and analytics
- Marketing communications (with opt-out option)
- Legal compliance and dispute resolution
- Consent (Article 6(1)(a) GDPR):
- Marketing communications where required
- Non-essential cookies and tracking
- Optional features and services
- Legal Obligation (Article 6(1)(c) GDPR):
- Tax and accounting requirements
- Anti-money laundering compliance
- Regulatory reporting
6. HOW WE USE YOUR PERSONAL DATA
- Platform Operation:
- User account creation and management
- License key generation and validation
- Device activation/deactivation services
- Customer relationship management
- Payment processing and billing (handled by Stripe)
Payment Processing: All payment processing, including credit card transactions, payment verification, and financial data storage, is handled exclusively by Stripe. We do not process, store, or have access to any payment card information or detailed financial transaction data. We only receive basic payment status information from Stripe to manage subscriptions and platform access.
- Service Improvement:
- Analytics and usage statistics
- Performance monitoring and optimization
- New feature development
- Security enhancements
- Communication:
- Service-related notifications
- Technical support and customer service
- Marketing communications (with consent)
- Legal and regulatory communications
- Legal and Security:
- Fraud prevention and detection
- Security incident investigation
- Legal compliance and enforcement
- Dispute resolution
7. DATA SHARING AND THIRD PARTIES
We may share personal data with the following categories of recipients:
- Service Providers:
- Stripe (payment processing) – acting as data processor for all payment and transaction data
- Email service providers (Beehiiv) – for marketing communications
- Cloud hosting providers – for data storage and processing
- Analytics providers – for service improvement
Stripe Data Processing: Stripe acts as an independent data controller for all payment and transaction data. All credit card information, payment details, and financial transaction records are processed and stored exclusively by Stripe in accordance with their privacy policy and PCI DSS compliance standards. We do not have access to or store any payment card information or detailed financial data.
- Business Partners:
- B2B clients may access their end customers' data as joint controllers
- Integration partners with appropriate data processing agreements
- Legal Requirements:
- Law enforcement and regulatory authorities when required by law
- Courts and legal advisors in connection with legal proceedings
- Professional advisors for business purposes
- Business Transfers:
- In case of merger, acquisition, or sale of business assets
8. INTERNATIONAL DATA TRANSFERS
- We may transfer personal data outside the European Economic Area (EEA) to:
- Service providers in countries with European Commission adequacy decisions
- Recipients covered by Standard Contractual Clauses (SCCs)
- US companies certified under the EU-US Data Privacy Framework
- We ensure appropriate safeguards are in place for all international transfers.
9. DATA RETENTION
- We retain personal data only for as long as necessary for the purposes outlined in this policy:
- B2B client data: Duration of subscription plus 7 years for legal compliance
- End customer data: Duration of license ownership plus 3 years
- Marketing data: Until consent is withdrawn or data subject requests deletion
- Legal and compliance data: As required by applicable laws
- When retention periods expire, we securely delete or anonymize personal data.
10. YOUR DATA PROTECTION RIGHTS
Under GDPR, you have the following rights:
- Right of Access (Article 15):
- Request information about personal data processing
- Obtain copies of your personal data
- Right to Rectification (Article 16):
- Correct inaccurate or incomplete personal data
- Right to Erasure (Article 17):
- Request deletion of personal data in certain circumstances
- Right to Restrict Processing (Article 18):
- Limit how we process your personal data
- Right to Data Portability (Article 20):
- Receive your data in a structured, machine-readable format
- Transfer data to another controller
- Right to Object (Article 21):
- Object to processing based on legitimate interest
- Object to direct marketing at any time
- Right to Withdraw Consent:
- Withdraw consent for consent-based processing at any time
To exercise these rights, contact us at ampstudiobg@gmail.com.
11. COOKIES AND TRACKING TECHNOLOGIES
- We use cookies and similar technologies for:
- Essential platform functionality
- Performance monitoring and analytics
- Marketing and advertising (with consent)
- User preferences and settings
-
You can manage cookie preferences through your browser settings or our cookie consent banner.
-
For detailed information about our cookie usage, please refer to our Cookie Policy.
12. DATA SECURITY
We implement appropriate technical and organizational measures to protect personal data:
- Technical Measures:
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Regular security assessments and monitoring
- Incident response procedures
- Organizational Measures:
- Staff training on data protection
- Data processing agreements with vendors
- Privacy by design and default principles
- Regular policy reviews and updates
13. DATA BREACH NOTIFICATION
- In case of a data breach likely to result in a high risk to individuals, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected individuals without undue delay
- Take measures to mitigate the breach
14. CHILDREN'S PRIVACY
Our Platform is not directed at children under 18. We do not knowingly collect personal data from children under 18 without parental consent. If we learn that we have collected personal data of a child under 18 without such consent, we will take steps to delete that information.
15. CHANGES TO THIS PRIVACY POLICY
- We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws.
- Material changes will be communicated through email or platform notifications.
- Continued use of the Platform after changes constitutes acceptance of the updated policy.
16. SUPERVISORY AUTHORITY
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP) or your local data protection authority if you believe we have violated your privacy rights:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Frederic Joliot-Curie Str., 1113 Sofia, Bulgaria
Email: kzld@cpdp.bg
Website: www.cpdp.bg
For any privacy-related questions or to exercise your rights, please contact us:
Email: ampstudiobg@gmail.com
Address: 9Zh Boris Rumenov Street, Entrance B
Lozenets District, Sofia 1421,
Sofia Municipality, Bulgaria
18. MULTI-TIER DATA PROCESSING
- Keyper operates as a multi-tier platform where:
- AMP Studio Ltd. acts as data controller for platform operations
- B2B clients act as data controllers for their customer relationships
- End customers may have rights against both controllers, depending on the data processing context
- B2B clients are responsible for:
- Obtaining appropriate consents from their customers
- Providing privacy notices to their customers
- Handling customer data subject rights requests
- Ensuring lawful and secure processing of customer data
- Joint controller arrangements may apply where both AMP Studio Ltd. and B2B clients jointly determine the purposes and means of processing personal data.
© 2025 AMP Studio Ltd. All rights reserved.