Licenceo
CatalogueBundlesHow it worksWhy us?
Sign inGet started
Back to home

Privacy Policy

Last updated 11 August 2026

Draft — pending legal review

This document describes how the platform actually works, but it has not yet been reviewed or approved by Sea Star's counsel. Passages marked [TO CONFIRM: …] need a decision from Sea Star before this can be relied on.

This policy explains what personal data Licenceo collects, why, who it is shared with, and the rights you have over it.

1. Who controls your data

The controller is [TO CONFIRM: registered company name, number and address]. Contact for privacy matters: [TO CONFIRM: privacy contact address]. [TO CONFIRM: whether a data protection officer or an EU/UK representative is required and, if so, who.]

2. What we collect

  • Account and contact details — name, email address, password (stored hashed), company name and location, and your notification preferences.
  • Verification documents — identity documents, company registration, tax documents and bank details that you upload, along with the outcome of our review and who reviewed it.
  • Listing and deal data — titles, synopses and assets you publish; offers, counter-offers and messages; the agreements generated and the signatures applied to them.
  • Payment records — amounts, currency, commission, the state of each payment, and the references our payment provider returns. We do not store your card details.
  • Consent evidence — each time you accept our Terms or this policy we record your account, the email address on it at that moment, which version you accepted, the exact time in UTC, your network address and your browser's user-agent string.
  • Support content — messages you send to Sea Star, and tickets raised on your behalf.
  • Delivery and access records — when a download link was issued and redeemed, and the network address it was used from.
  • Administrative records — an audit log of actions taken on the platform, including which staff member acted, in what role, on what.
  • Technical data needed to operate the service, including your network address on requests we log.

3. Why we use it, and on what basis

  • To provide the service — creating your account, running deals, generating agreements, taking payment and delivering content. Basis: performance of a contract.
  • To verify participants and prevent fraud and rights abuse, including reviewing your documents before approving a seller capability. Basis: legitimate interests, and legal obligation where one applies.
  • To keep records of transactions, consents and administrative actions, so a deal or a decision can be reconstructed and defended. Basis: legal obligation and legitimate interests, including establishing or defending legal claims.
  • To send transactional messages you need — offer activity, signature requests, payment and delivery updates, licence expiry reminders at 90, 30, 14 and 3 days before expiry. Basis: performance of a contract.
  • To send optional marketing, only where you have opted in. Basis: consent, withdrawable at any time in your account settings.
  • To secure the platform and investigate misuse. Basis: legitimate interests.

4. Who we share it with

We share only what a provider needs to do its job:

  • Our payment provider (Stripe) — to take payment, hold funds and pay sellers out, including the identity and bank information required for payout onboarding.
  • Our electronic signature provider — to present and record signatures on an agreement.
  • Our hosting and storage providers — to run the service and store uploaded media and documents. Media is held in S3-compatible object storage (Cloudflare R2) and application data in a PostgreSQL database.
  • Our email provider — to deliver transactional messages. [TO CONFIRM: provider name once selected.]
  • The other party to a deal — a buyer and a seller inevitably see each other's identity, company and deal terms; that is the nature of contracting.
  • Professional advisers and authorities where we are legally required, or where necessary to establish or defend legal claims.

We do not sell personal data.

5. Where it is processed

[TO CONFIRM: hosting regions, which providers process data outside the UK/EEA, and the transfer mechanism relied on for each.]

6. How long we keep it

How long depends on what the data is for. Transaction records — offers, agreements, payments and the audit log — are retained after an account closes, because we are required to keep records of concluded business and may need them to defend a claim.

Consent records are retained even after erasure. This is deliberate. A record that you accepted a particular version of these documents, at a particular time, is the evidence that the agreement was formed, and it is of no value if it can be deleted by one of the parties. We rely on the exemptions for compliance with a legal obligation and for establishing or defending legal claims.

[TO CONFIRM: specific retention periods per category — verification documents, support messages, audit log, technical logs.]

7. Your rights

Subject to the limits below you can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time.

Two of these work in a specific way on Licenceo, and it is fairer to say so plainly:

  • Access and portability — you can export your data from your account at any time, without asking us.
  • Erasure — we anonymise your personal data and deactivate your login. We do not delete records of concluded transactions: agreements, payments, offers, the audit log and your consent records remain, because we are obliged to keep them and may need them to defend a claim. After erasure those records no longer identify you, except the consent record, which necessarily retains the email address the account used at the time it accepted.

To exercise a right, use your account settings where the tool exists, or contact [TO CONFIRM: privacy contact address]. You can also complain to your data protection authority. [TO CONFIRM: name the relevant supervisory authority.]

8. Security

Access to member and deal data is restricted to staff whose role requires it, and every administrative action is recorded with the actor, their role and what they acted on. Passwords are stored hashed. Two-factor authentication is available on your account. Master files are served only through single-use, time-limited links tied to the requesting account and network address, and only within the licence window.

No system is perfectly secure. If a breach affects your data and the law requires it, we will notify you and the relevant authority.

9. Changes to this policy

This policy is versioned in the same way as our Terms. When we publish a new version we ask you to accept it and record that acceptance with the version, the time in UTC and the network address.

Licenceo

The licensing marketplace for vertical drama. Operated by Sea Star.

Platform

  • Catalogue
  • Create an account
  • How it works

Company

  • About Sea Star
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • Rights & takedown

Operated by Sea Star · © 2026

London