Last updated 11 August 2026
Draft — pending legal review
This document describes how the platform actually works, but it has not yet been reviewed or approved by Sea Star's counsel. Passages marked [TO CONFIRM: …] need a decision from Sea Star before this can be relied on.
This policy explains what personal data Licenceo collects, why, who it is shared with, and the rights you have over it.
The controller is [TO CONFIRM: registered company name, number and address]. Contact for privacy matters: [TO CONFIRM: privacy contact address]. [TO CONFIRM: whether a data protection officer or an EU/UK representative is required and, if so, who.]
We share only what a provider needs to do its job:
We do not sell personal data.
[TO CONFIRM: hosting regions, which providers process data outside the UK/EEA, and the transfer mechanism relied on for each.]
How long depends on what the data is for. Transaction records — offers, agreements, payments and the audit log — are retained after an account closes, because we are required to keep records of concluded business and may need them to defend a claim.
Consent records are retained even after erasure. This is deliberate. A record that you accepted a particular version of these documents, at a particular time, is the evidence that the agreement was formed, and it is of no value if it can be deleted by one of the parties. We rely on the exemptions for compliance with a legal obligation and for establishing or defending legal claims.
[TO CONFIRM: specific retention periods per category — verification documents, support messages, audit log, technical logs.]
Subject to the limits below you can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time.
Two of these work in a specific way on Licenceo, and it is fairer to say so plainly:
To exercise a right, use your account settings where the tool exists, or contact [TO CONFIRM: privacy contact address]. You can also complain to your data protection authority. [TO CONFIRM: name the relevant supervisory authority.]
Access to member and deal data is restricted to staff whose role requires it, and every administrative action is recorded with the actor, their role and what they acted on. Passwords are stored hashed. Two-factor authentication is available on your account. Master files are served only through single-use, time-limited links tied to the requesting account and network address, and only within the licence window.
No system is perfectly secure. If a breach affects your data and the law requires it, we will notify you and the relevant authority.
This policy is versioned in the same way as our Terms. When we publish a new version we ask you to accept it and record that acceptance with the version, the time in UTC and the network address.