Privacy policy
Last updated 2 September 2026
This describes what this website actually collects, which is less than you might expect. Where a section says we do not hold something, it is because the code genuinely does not store it.
The data controller is Vertex Infosolutions. Buying from us means your data is processed in India, outside the EEA and the UK — what that means for you is set out under International transfers below.
What we collect when you shop
- Your basket. A cookie holds a random token and nothing else — no prices, no products, no identity. The basket itself lives on our server against that token and expires after 30 days.
- Your market — India or international — so prices and tax can be shown correctly. Stored against the basket and in one cookie, not against you.
- Your order. Email address, phone number, and the billing details your invoice is made out to. There is no delivery address, because nothing is delivered anywhere but an inbox.
- Your GSTIN, if you are an Indian business and choose to give one, so it can appear on the tax invoice.
- What you bought, kept for as long as tax law requires, because an invoice has to be reproducible years later.
- Your IP address, but only when a sign-in fails. It is recorded with the address that was typed, and deleted an hour later or the moment a sign-in succeeds — whichever comes first. It is there to slow down somebody guessing passwords, and it is not kept for successful sign-ins, so this is not a record of when or where you logged in.
What we never collect
- Card numbers, CVVs or PayPal credentials. These are entered on the payment provider's own page and never reach this website. We could not disclose them if we were asked to.
- Analytics or advertising identifiers. There are no trackers on this site.
- Anything about you from a third-party data broker.
Why we are allowed to hold it
- To perform the contract — we cannot issue a licence without an email address, or invoice you without a name and a country.
- To comply with a legal obligation — GST invoices, export records and the sanctions screening every order goes through.
- Legitimate interests — preventing fraud, and answering you when you contact us.
We do not rely on consent for any of it, because we do not do the things consent would be needed for.
Who else sees it
- The payment provider, which needs the order amount and reference to take the payment.
- The publisher — Microsoft, Adobe or Autodesk — for a licence that has to be registered or assigned to a named end user. They receive the email address the seat is assigned to and nothing more.
- Microsoft Azure, which hosts this website and its database on our behalf.
Nobody else. We do not sell personal data, we do not share it for advertising, and we have never done either.
International transfers
Your data is processed in India. If you are in the EEA or the UK, that is a transfer to a country without an adequacy decision, and we rely on the Standard Contractual Clauses for it. Ask us and we will send you a copy of the safeguards in place.
How long we keep it
- Baskets: 30 days.
- Orders and invoices: eight years, which is what Indian tax law requires for GST records and export documentation.
- Support correspondence: three years from the last message.
Your rights
Wherever you live, you can ask us what we hold about you, ask for it to be corrected, ask for a copy in a portable format, or ask for it to be deleted. If you are in the EEA or the UK you also have the right to object to processing and to complain to your local supervisory authority. If you are in California you may ask what we disclosed and to whom, and the answer is the list above.
Deletion applies to everything except records that tax law requires us to keep — we will tell you exactly what has to stay and why. We answer within 30 days.
Email our contact address to make any of these requests, or see contact & complaints.
Cookies
Two: one holding the basket token, one remembering whether you chose INR or USD. Both are strictly necessary for the store to work and there is no tracking cookie to consent to. Detail in the cookie policy.
Security
The site is served over HTTPS, the database is encrypted at rest and reachable only from the application, and the basket cookie is HTTP-only so no script on the page can read it. If we ever suffer a breach that puts you at risk, we will tell you and the relevant regulator within 72 hours.


