Privacy Policy
Effective Date: 24/04/2026 • Last Updated: 22/08/2026
This Privacy Policy explains how GRAPHDAGGER LTD, a company incorporated in England and Wales with company number 17075289, whose registered office is at 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, Greater London, United Kingdom, W1T 6EB (“we”, “us”, “our” or “the Company”) collects, uses, discloses and protects the personal data of individuals who visit our website, purchase or use the GraphDagger desktop software application (the “Software”), or otherwise interact with us.
This Privacy Policy is issued on behalf of the Company. When we refer to “you” or “your” in this Privacy Policy, we mean the individual whose personal data we process. It should be read alongside our Terms of Use, which govern your use of the Software.
Our approach in summary. We are committed to protecting your privacy. GraphDagger is a local desktop application by design. The data you capture, scan, intercept or analyse using GraphDagger (for example, network traffic, files, or email content) stays on your device and is not transmitted to us. Our Software does not contain telemetry and does not send usage data to our servers. The only information the Software sends to us is a periodic licence validation check.
This Privacy Policy explains, in detail, what personal data we do process, why we process it, the lawful basis on which we rely, how long we keep it, who we share it with, and your rights in relation to it.
1. Who We Are and How to Contact Us
1.1 Data Controller. For the purposes of the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the data controller responsible for your personal data is GRAPHDAGGER LTD, company number 17075289, registered office at 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, Greater London, United Kingdom, W1T 6EB.
1.2 Privacy Contact. We have not appointed a statutory Data Protection Officer because we are not required to do so under Article 37 UK GDPR or Article 37 EU GDPR. However, we have designated a dedicated contact for privacy matters. If you have any questions about this Privacy Policy, about how we process your personal data, or if you wish to exercise any of your rights, please contact our Privacy Contact at:
Email: privacy@graphdagger.com
Post: Privacy Team, GRAPHDAGGER LTD, 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, Greater London, United Kingdom, W1T 6EB
1.3 EU Representative. We offer services to individuals in the European Economic Area (“EEA”). In accordance with Article 27 of the EU GDPR, we have appointed an EU Representative to act as our point of contact for individuals in the EEA and EEA supervisory authorities on matters relating to our processing of personal data. You can contact our EU Representative directly at:
[EU REPRESENTATIVE NAME]
[EU REPRESENTATIVE REGISTERED ADDRESS]
Email: [EU REPRESENTATIVE EMAIL]
When contacting our EU Representative, please reference GraphDagger Ltd so that the request is correctly routed.
1.4 Supervisory Authority. Our lead supervisory authority for UK data protection matters is the UK Information Commissioner’s Office (the “ICO”), whose contact details appear at Section 10 below. Individuals in the EEA may also raise concerns with their local EEA supervisory authority.
2. Scope of This Privacy Policy
2.1 This Privacy Policy applies to personal data we process when:
- you visit our website at graphdagger.com (the “Website”);
- you purchase a Subscription to the Software, or start a 14-day free trial, through our checkout;
- the Software performs a licence validation check with our licence management provider;
- you contact us by email or otherwise correspond with us; or
- you exercise any of your rights under applicable data protection law.
2.2 What this Privacy Policy does not cover. GraphDagger is, by design, a local desktop application. The data you capture, scan, intercept or analyse using the Software (including, for example, network packets, files on your device, email content, and geolocation data) is processed locally on your device and is not transmitted to us. Where you use GraphDagger to process personal data of third parties, you are the controller of that data, and this Privacy Policy does not govern it. You are responsible for ensuring that your use of the Software complies with all applicable data protection and other laws, in accordance with our Terms of Use.
3. Personal Data We Collect and Why
We are committed to transparency under Article 13 of the UK GDPR. The table below sets out, for each category of personal data we process, the specific purpose for which we process it, the lawful basis on which we rely, and the retention period. This table is the authoritative record of our processing activities that relate to you.
| Data Category | What We Collect | Purpose | Lawful Basis (UK GDPR Art. 6) | Retention |
|---|---|---|---|---|
| Customer identity | Email address; name and billing address (from Stripe) | To issue and deliver your licence key; to identify you as our customer; to provide customer support | Art. 6(1)(b) – performance of contract | Duration of Subscription + 6 years (UK tax/accounting retention) |
| Payment metadata | Billing country; transaction and subscription identifiers; payment status. Your card details are collected and held by Stripe; we never receive or store them | To process payment via Stripe; to issue receipts; to process refunds and chargebacks; to prevent fraud | Art. 6(1)(b) – performance of contract; Art. 6(1)(c) – legal obligation (tax/accounting); Art. 6(1)(f) – legitimate interests (fraud prevention) | 6 years from the end of the financial year to which the transaction relates (UK tax law) |
| Subscription and purchase history | Products purchased; subscription status; start and end dates; renewal history | To administer your Subscription; to manage renewals; to deliver service communications; to respond to support queries | Art. 6(1)(b) – performance of contract | 7 years, after which our billing records are pseudonymised (all customer identifiers removed) |
| Licence key and device data | Our systems hold pseudonymous licence records only (licence, payment and subscription identifiers, seat number, status). Device fingerprints, activation logs and the IP address at validation are processed by our licence provider, Keygen, when the Software validates a licence | To validate your licence; to enforce the one-device-per-licence rule; to enable self-service re-assignment; to detect and prevent licence misuse or fraud | Art. 6(1)(b) – performance of contract; Art. 6(1)(f) – legitimate interests (licence enforcement, fraud prevention) | Revoked licence records are deleted 12 months after revocation; active records last for the Subscription |
| Free trial data | Starting the 14-day free trial creates a Stripe customer record with your payment method on file, pseudonymous licence and billing records flagged as a trial, and up to four trial lifecycle emails (started, ending, converted, cancelled) | To provide the free trial, convert it into a paid Subscription, or wind it down if you cancel | Art. 6(1)(b) – performance of contract | Trial flags are cleared on conversion; a cancelled trial’s revoked licence records are deleted 12 months after revocation, and Stripe-held records follow the payment metadata row above |
| Website traffic data | IP address; requested URL, method, status and timing metadata, recorded in Cloudflare request logs. A request URL can briefly include a checkout session reference. We use no analytics or tracking services | To operate, secure and protect our Website and API; to diagnose faults; to detect and mitigate malicious activity | Art. 6(1)(f) – legitimate interests (website operation, security) | Held by Cloudflare for a short fixed window (a matter of days) and not exported elsewhere |
| Support and general correspondence | Email content and metadata of any message you send us; any attachments you choose to include; any identifying information you voluntarily provide in bug reports | To respond to your enquiry; to investigate and resolve support issues; to maintain a record of our correspondence; to improve the Software | Art. 6(1)(b) – performance of contract (support as part of your Subscription); Art. 6(1)(f) – legitimate interests (record-keeping, product improvement) | 3 years from last contact |
| Rights requests | Your identity; the nature of your request; any identifying information we require to verify your identity and handle your request | To receive, verify, process and respond to your data subject rights requests | Art. 6(1)(c) – legal obligation (compliance with UK GDPR) | 3 years from the date the request is closed |
3.1 No special category data. We do not intentionally collect, and we have no operational need to collect, any “special category” personal data (as defined in Article 9 UK GDPR), such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person’s sex life or sexual orientation. Please do not send us such data.
3.2 No children’s data. The Software is intended for adults only. We do not knowingly collect personal data from anyone under eighteen (18) years of age. If we discover that we have collected personal data from a person under eighteen, we will delete it as soon as reasonably practicable.
3.3 Data you process using the Software. GraphDagger is a local desktop application. Any personal data you process using the Software (for example, within captured network traffic, scanned files, or email scans) remains on your device. We do not collect, store, have access to, or process that data, and we do not appear as a controller or processor in respect of it. You are the controller of that data and are solely responsible for its lawful processing, in accordance with our Terms of Use.
4. How We Collect Your Personal Data
4.1 We collect personal data about you in the following ways:
- Directly from you — when you type your email address into our checkout page (it passes through our servers to Stripe and is not stored or logged by us), contact us by email, or submit a bug report or feedback.
- Automatically when you use our Website or Software — through Cloudflare request logs and the Software’s licence validation requests.
- From our service providers — we receive information from Stripe (payment details, billing location), Keygen (licence and device activation data), Postmark (email delivery status), and Cloudflare (website traffic data, and the cloud platform on which our services run). These providers act as our processors (or, in the case of payment processing, as independent controllers for regulatory and anti-fraud purposes).
5. Who We Share Your Data With
5.1 Service providers (processors). We use the following processors to deliver our Software and services. Each processor acts on our documented instructions under a written data processing agreement (“DPA”) that meets the requirements of Article 28 UK GDPR.
| Processor | Role | Data shared | Location | Safeguard |
|---|---|---|---|---|
| Stripe Payments UK Ltd | Payment processing and billing | Name, email, billing address, card details (tokenised), transaction metadata, subscription status | United Kingdom; with onward transfers to Ireland and the United States (Stripe group) | Stripe DPA; UK Extension to the EU-US Data Privacy Framework for US transfers |
| Keygen, Inc. | Licence key management, device activation, validation | Pseudonymous payment and subscription identifiers only; we never send Keygen your email address. Device fingerprints and validation requests reach Keygen directly from the Software when it validates a licence | United States (AWS) | Keygen DPA; EU SCCs with the UK Addendum |
| ActiveCampaign, LLC (Postmark) | Transactional email delivery | Customer email address; email subject and body; delivery and bounce metadata | United States | Postmark DPA; UK Extension to the EU-US Data Privacy Framework |
| Cloudflare, Inc. | Cloud hosting and security platform on which our Website and back-end services run, including content delivery, WAF and DDoS protection, and request logging | Visitor IP address and request metadata in request logs; pseudonymous payment and licence identifiers held in our systems on Cloudflare’s platform; customer email addresses transiently while transactional emails are sent (never persisted by us) | Cloudflare’s global network, with primary operations in the United States | Cloudflare DPA; UK Extension to the EU-US Data Privacy Framework |
Operational health alerts about our billing systems may additionally be delivered to a team messaging service. These alerts contain aggregate counts only and never include personal data.
5.2 Other recipients. We may also share your personal data with:
- Professional advisers — our accountants, lawyers, auditors, insurers, and similar professional advisers where disclosure is necessary for them to advise us. Shared on the basis of legitimate interests.
- Law enforcement, courts, and regulators — where we are required to do so by law, court order, or binding regulatory request, or to protect our legal rights, the safety of our users, or the integrity of our Software. Shared on the basis of legal obligation or legitimate interests.
- Successors in a business transaction — if we sell, merge, restructure, or transfer all or part of our business, your personal data may be disclosed to a prospective buyer, merger partner, or investor, subject to appropriate confidentiality protections.
5.3 We do not sell your personal data. We do not sell, rent, trade or otherwise disclose your personal data to third parties for their own marketing purposes.
6. International Transfers of Your Data
6.1 We are based in the United Kingdom, but some of our processors listed in Section 5 are located outside the UK and the EEA — principally, in the United States. Where personal data is transferred outside the UK or the EEA to a country that is not the subject of an adequacy decision, we ensure that appropriate safeguards are in place as required by Article 46 UK GDPR and Article 46 EU GDPR.
6.2 Safeguards we rely on. Depending on the destination and the processor, we rely on the following safeguards:
- the UK Extension to the EU-US Data Privacy Framework, for US recipients certified under the framework. Stripe, ActiveCampaign (Postmark) and Cloudflare are certified;
- the European Commission’s Standard Contractual Clauses (2021/914/EU) together with the UK International Data Transfer Addendum, supported by a transfer risk assessment, for US recipients that are not certified. Keygen relies on this safeguard; or
- an adequacy decision by the UK Secretary of State or the European Commission, where one applies to the destination country.
6.3 You may request further details of the safeguards we use in relation to any transfer by contacting our Privacy Contact at the address set out in Section 1.
7. Cookies and Similar Technologies
7.1 Our approach. We have deliberately designed our Website to minimise the use of cookies. We do not use advertising cookies, marketing cookies, third-party tracking, or cross-site profiling.
7.2 No analytics. We do not use any analytics or tracking service, cookieless or otherwise. The only record of a visit is the Cloudflare request log described in Section 3.
7.3 Strictly necessary cookies. Our Website, which is served via Cloudflare, may set a small number of cookies that are classified as “strictly necessary” under Regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”). In particular, Cloudflare may set the __cf_bm cookie for bot-management and security purposes, with a short lifespan (typically 30 minutes). Strictly necessary cookies do not require your consent but we disclose them here in the interests of transparency.
7.4 Local storage. The Website stores a small amount of functional data in your browser’s local storage: a cached copy of our public price list, the open or closed state of the documentation sidebar, and cached documentation layout data. None of it contains personal data or identifiers, none of it leaves your browser, and all of it is strictly necessary for the Website to work as you left it, so it is exempt from consent under PECR. We use no other cookies or similar technologies; if that changes we will update this Privacy Policy and, where required, implement a consent mechanism first.
8. Marketing Communications
8.1 We do not send marketing. We do not currently send marketing communications of any kind, we have no newsletter, and we do not collect marketing preferences or consent records. If we introduce marketing in the future, we will do so only with the consent or soft opt-in mechanics that PECR requires, including a clear way to opt out before the first message is sent, and we will update this Privacy Policy first.
8.2 Transactional communications. The only email we send is transactional, necessary to administer your Subscription: licence key delivery, renewal and payment notices, payment failure notifications, trial started, trial ending, trial converted and trial cancelled notices, cancellation and revocation notices, and material changes to our Terms of Use or this Privacy Policy.
9. Your Rights
9.1 Under the UK GDPR and, where applicable, the EU GDPR, you have the following rights in relation to your personal data. We explain each right and how to exercise it below.
9.2 Right of access. You have the right to obtain a copy of the personal data we hold about you and certain information about how we process it. (Articles 15 UK GDPR / EU GDPR.)
9.3 Right to rectification. You have the right to ask us to correct inaccurate personal data and to complete incomplete personal data. (Article 16.)
9.4 Right to erasure (“right to be forgotten”). You have the right to ask us to delete your personal data in certain circumstances, for example where it is no longer necessary for the purposes for which it was collected. When we action an erasure, it is executed by a queued batch job, normally within one to two days of approval and always well inside the one-month statutory window. The erasure revokes your licences, deletes our licence and email records, removes every customer identifier from our billing records, deletes the associated durable processing state, and removes your address from our email provider’s suppression list. This right is not absolute: records held by Stripe are retained under Article 17(3)(b) to meet tax and accounting obligations, short-lived technical duplicates expire automatically within 30 days, and Cloudflare request logs expire within days. (Article 17.)
9.5 Right to restrict processing. You have the right to ask us to restrict our processing of your personal data in certain circumstances, for example while we verify the accuracy of contested data. (Article 18.)
9.6 Right to data portability. Where we process your personal data on the basis of consent or performance of a contract, and where that processing is carried out by automated means, you have the right to receive the personal data you provided to us in a structured, commonly-used and machine-readable format, and to have it transmitted to another controller where technically feasible. (Article 20.)
9.7 Right to object. You have the right to object to our processing of your personal data on the basis of legitimate interests, including for direct marketing purposes. You can object to direct marketing at any time, and we will stop processing your data for that purpose. (Article 21.)
9.8 Right to withdraw consent. Where we process your personal data on the basis of consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before you withdrew consent. (Article 7(3).)
9.9 Rights in relation to automated decision-making. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. (Article 22.)
9.10 How to exercise your rights. To exercise any of these rights, please email our Privacy Contact at privacy@graphdagger.com with the subject line “Data Rights Request” and explain which right you are exercising and the details of your request.
9.11 Our response timeline. We will acknowledge your request within seven (7) days of receipt, and we will respond substantively within one (1) month of receipt, in accordance with Article 12(3) UK GDPR. Where your request is complex or where we have received several requests from you, we may extend this period by up to a further two (2) months. We will inform you of any such extension, and the reasons for it, within one month of receipt of your request.
9.12 Identity verification. To protect your personal data, we may need to ask for further information to verify your identity before we can action your request. We will not ask for more information than is necessary to verify you.
9.13 No fee. You will not normally have to pay a fee to exercise your rights. However, where your request is manifestly unfounded or excessive (in particular because of its repetitive character), we may either charge a reasonable fee or refuse to act on the request, in each case in accordance with Article 12(5) UK GDPR.
10. Complaints
10.1 Complain to us first. We would prefer to address any concerns you have about our processing of your personal data directly, and under the Data (Use and Access) Act 2025 you are asked to raise your complaint with us before going to the regulator. To complain, email our Privacy Contact at privacy@graphdagger.com with the subject line “Data Protection Complaint”. We will acknowledge your complaint within thirty (30) days of receipt, look into it without undue delay, and tell you the outcome and the steps we have taken or will take.
10.2 UK complaints. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (the ICO):
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: https://ico.org.uk
10.3 EEA complaints. If you are in the EEA, you have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available on the European Data Protection Board’s website: https://edpb.europa.eu.
11. How We Keep Your Data Secure
11.1 Technical and organisational measures. We have put in place appropriate technical and organisational measures to protect your personal data against unauthorised access, unlawful processing, accidental loss, destruction or damage, in accordance with Article 32 UK GDPR. These measures include:
- encryption of personal data in transit (TLS 1.2 or higher) and at rest with our processors;
- access controls, multi-factor authentication, and role-based permissions on our internal systems and processor accounts;
- minimisation of the personal data we collect, and segregation of data across processors based on purpose;
- use of reputable, contractually-bound sub-processors with published security certifications (where applicable, SOC 2, ISO 27001, PCI DSS);
- regular review of our processing activities and supplier security posture; and
- procedures to detect, investigate, respond to, and learn from suspected personal data breaches.
11.2 No absolute guarantee. While we take security seriously, no system or transmission of data over the internet can be guaranteed to be completely secure. We cannot and do not guarantee absolute security, but we apply appropriate measures to protect your personal data and we continuously improve them.
12. Personal Data Breaches
12.1 ICO notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of it, in accordance with Article 33 UK GDPR.
12.2 Notification to affected individuals. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 UK GDPR. The notification will describe, in clear and plain language, the nature of the breach, the likely consequences, the measures taken or proposed, and how you can contact us for more information.
12.3 EEA notifications. Where an EEA supervisory authority is competent under the EU GDPR, our EU Representative will support the notification process to that authority on our behalf.
13. How Long We Keep Your Data
13.1 Retention principle. We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including to satisfy legal, regulatory, accounting, or reporting requirements. The specific retention periods for each category of data are set out in the table in Section 3 above.
13.2 Long-term retention for accounting records. The core customer record (identity, Subscription history, payment metadata, invoices) is held by Stripe and in our pseudonymous billing records to comply with our statutory obligations under the Companies Act 2006 and UK tax legislation, and to defend against potential legal claims within the statutory limitation periods. Our billing records are pseudonymised after seven (7) years.
13.3 Specific periods applied automatically. Our systems apply these periods on a weekly schedule: billing event records lose every customer identifier after 7 years; revoked licence records are deleted 12 months after revocation; reconciliation telemetry (which contains no personal data) is deleted after 90 days; queued email retry records are deleted after 90 days; identifiers in administrative command records are redacted after 12 months; and short-lived technical duplicates expire within 30 days. What remains after pseudonymisation is accounting data that no longer points at you from our systems, though corresponding records may still exist at Stripe under its own retention obligations.
14. Changes to This Privacy Policy
14.1 We may update this Privacy Policy from time to time to reflect changes in our practices, our processors, or applicable law. When we do, we will update the “Last Updated” date at the top of this Privacy Policy.
14.2 Where the changes are material, we will provide you with reasonable advance notice by email (to the address associated with your Subscription) or via a prominent notice on the Website, at least thirty (30) days before the changes take effect.
14.3 Your continued use of the Software or the Website after the effective date of any update constitutes your acknowledgement of the revised Privacy Policy. If you do not agree with the revised Privacy Policy, you should stop using the Software and, if applicable, exercise your right to cancel your Subscription in accordance with our Terms of Use.
15. Contact Information
If you have any questions about this Privacy Policy or our processing of your personal data, please contact us:
Privacy Contact (UK):
GRAPHDAGGER LTD
4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London, Greater London, United Kingdom, W1T 6EB
Email: privacy@graphdagger.com
EU Representative (for EEA enquiries):
[EU REPRESENTATIVE NAME]
[EU REPRESENTATIVE REGISTERED ADDRESS]
Email: [EU REPRESENTATIVE EMAIL]
— END OF PRIVACY POLICY —