Legal information
Privacy Policy
This policy explains what personal data Xeon Labs processes when operating Server5, why it is used, who may receive it and what rights individuals may exercise. Paddle maintains a separate notice for data it controls as reseller and merchant of record.
1. Scope
This policy covers the Server5 website, license delivery, product communications and support provided directly by Xeon Labs. It does not govern Paddle’s independent processing or third-party websites.
2. Data controllers
Xeon Labs is an independent controller for data it receives and uses to operate Server5. Privacy enquiries may be sent to xeonlabs.io@gmail.com.
Paddle independently controls data processed as authorized reseller and merchant of record under the Paddle Privacy Notice. Each party is responsible for its own purposes, means and obligations.
3. Data categories
Depending on the interaction, Xeon Labs may process:
- Identity and contact details, such as name and email address.
- Purchase data shared by Paddle, including product, edition, transaction reference, status, currency and amount.
- Information required to deliver, activate or validate a license.
- Support requests, correspondence and incident details.
- Basic technical logs, such as IP address, timestamp, requested route, user agent and security events.
- Preferences or consents expressly communicated by the individual.
Xeon Labs does not receive or store full card numbers, card security codes or payment-account credentials.
4. Sources
Data may come directly from a person using the site or requesting support; from Paddle when it confirms a transaction and shares fulfillment data; or automatically through technical logs needed for security and operation.
Buyers should provide accurate data and avoid including passwords, private keys or unrelated confidential information in communications.
5. Purposes
- Validate purchases and deliver the correct Server5 edition.
- Administer licenses and respond to product questions and incidents.
- Send transactional messages required for purchase and delivery.
- Protect the website, investigate abuse and prevent fraud.
- Meet legal duties and respond to valid authority requests.
- Improve the product using aggregated information or voluntary feedback.
- Send marketing only where a valid legal basis exists and opt-outs are respected.
6. Legal bases
Delivery, licensing and requested support are processed to perform the Server5 agreement or take requested pre-contract steps. Some data is retained to comply with legal obligations.
Security, fraud prevention and legal defense may rely on legitimate interests after considering individual rights. Marketing that requires consent is sent only after consent and stops when consent is withdrawn.
7. Payments and Paddle
Paddle collects payment data, calculates taxes, issues tax documents and supports the transaction. It may share the data Xeon Labs needs for fulfillment, fraud prevention and product support.
Card, charge, invoice, tax, withdrawal and refund requests should be submitted using the Paddle receipt or paddle.net. Requests concerning data controlled by Paddle may need to be made directly to Paddle.
8. Recipients and service providers
- Paddle: authorized reseller, merchant of record and independent transaction controller.
- Cloudflare: website hosting, delivery, networking and security.
- Resend: transactional email delivery.
- Professional advisers or authorities: where necessary to comply with law, defend rights or answer a valid request.
Providers receive only the data needed for their function and remain subject to contractual and legal duties.
9. International transfers
Some providers may process data outside the individual’s country. Where required, transfers rely on adequacy decisions, standard contractual clauses or another mechanism recognized by applicable data-protection law.
10. Retention
Data is retained as long as needed to deliver the product, administer the license, resolve issues and serve the stated purposes. It may then be restricted for periods required by law or potential legal claims.
Non-contractual enquiries are removed when no longer useful; technical logs are retained for reasonable security periods; and consent-based use ends when consent is withdrawn, without affecting earlier lawful processing.
11. Individual rights
Where applicable, individuals may request access, correction, deletion, restriction, objection or portability, and may withdraw consent at any time.
Requests should be sent to xeonlabs.io@gmail.com. Reasonable identity verification may be required. Individuals may also complain to the Spanish Data Protection Agency or the competent authority in their country.
12. Automated decisions
Xeon Labs does not make decisions with legal or similarly significant effects solely through automated profiling. Paddle may use automated checks for fraud prevention and payment authorization under its own notice.
13. Children
Server5 is not directed to children and is not intentionally offered for purchase by them. Data identified as belonging to a child without a valid basis may be removed after appropriate verification.
14. Cookies, logs and external links
The site does not set its own advertising cookies. Cloudflare may process essential technical data to deliver and protect the site. Paddle may use necessary technologies to operate checkout, maintain a session and prevent fraud.
External links lead to independently operated services governed by their own notices.
15. Security
Reasonable technical and organizational safeguards are used to reduce unauthorized access, loss, alteration and disclosure, including encrypted communications, access controls and data minimization. No internet-connected system can guarantee absolute security.
16. Changes and contact
This policy may change to reflect technical, legal or provider developments. Material changes will be communicated where required by law.
Privacy questions about Xeon Labs processing may be sent to xeonlabs.io@gmail.com.