# reitzwerk Privacy Policy
**Effective date:** 1 August 2026
**Data controller:** Frank Reitz, trading as **reitzwerk**
## 1. Scope
This Privacy Policy explains how we process personal data in connection with:
- the CreakBox/reitzwerk website at www.reitzwerk.com/;
- CreakBox V2 licensing and activation;
- purchase information received from Gumroad;
- signed offline-license issuance and license transfers;
- technical support and product communications; and
- security, fraud prevention and legal compliance.
It does not replace Gumroad's privacy notice. Gumroad independently processes checkout, payment, tax, account, fraud and platform data as merchant of record. Payment-card details are handled by Gumroad and its payment providers; we do not receive full card details.
## 2. Controller details
**Frank Reitz, trading as reitzwerk**
Bjelkevej 9, DK-5690 Tommerup
Privacy contact: frank@reitzwerk.com
Website: www.reitzwerk.com/
## 3. Personal data we process
### 3.1 Purchase and entitlement data
Gumroad may provide us with information needed to supply and administer the product, including:
- purchaser name where supplied;
- purchase email address;
- Gumroad sale or transaction ID;
- product name and product identifier;
- purchase date, price and currency;
- country or limited tax/location information where supplied;
- license key and use count;
- test-purchase status; and
- refund, chargeback, dispute or cancellation status.
We do not require or receive the customer's full payment-card number from Gumroad.
### 3.2 Online activation data
As currently designed, CreakBox V2 online validation sends the CreakBox Gumroad product identifier and the entered Gumroad license key to Gumroad over HTTPS. The response may contain whether the validation succeeded, purchase information needed to confirm entitlement, use count, and refund, chargeback or dispute status.
Gumroad, Cloudflare and ordinary internet infrastructure may also process network data such as IP address, timestamps, TLS and request headers. CreakBox does not intentionally transmit your audio, MIDI performance, DAW project, project filename, preset content or rendered music as part of license validation.
If a future release introduces materially different telemetry or device identification, this policy will be updated before that processing begins where required.
### 3.3 Offline-license data
To create and administer a signed offline license, we may process:
- purchase email address and name;
- product and license identifiers;
- Gumroad sale reference;
- issue and reissue date;
- transfer and NFR status;
- license format or schema version; and
- cryptographic signature and verification metadata.
The private signing key is security material, not customer personal data, and is not distributed to customers.
### 3.4 Support and communications
When you contact us, we process the information you provide, such as:
- name and email address;
- purchase and license evidence;
- message contents and attachments;
- operating system, DAW, processor, sample rate, buffer and version details;
- screenshots, logs, crash information and reproduction projects; and
- records of advice, fixes and resolution.
Do not send confidential music, third-party personal data or a full project when a minimal reproduction is sufficient.
### 3.5 Website and security data
Our hosting and security provider may process:
- IP address;
- browser and device information;
- requested URL and referring page;
- date, time and response status;
- security events, bot indicators and rate-limit information; and
- necessary cookie or challenge data.
If Cloudflare Web Analytics is enabled, it is intended to provide privacy-oriented aggregate traffic and performance information without using cookies or local storage. See the Cookie Policy.
### 3.6 Marketing data
We process newsletter or promotional contact details only where you have consented or another lawful basis clearly applies. You can unsubscribe at any time. Service, security, license and legally required update messages are transactional and may still be sent without marketing consent.
## 4. Purposes and legal bases
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Deliver the product and administer the license | Purchase, email, sale ID, product and license status | Performance of a contract; steps requested before contract |
| Validate online entitlement | Product ID, license key, validation and transaction status | Performance of a contract; legitimate interests in secure licensing and fraud prevention |
| Issue and reissue signed offline licenses | Identity, email, purchase and license records | Performance of a contract; legitimate interests in durable entitlement administration |
| Provide technical and licensing support | Contact, system, logs and support history | Performance of a contract; legitimate interests in support and product improvement |
| Process transfers, refunds and disputes | Identity, purchase, communications and status | Contract; legal obligation; legitimate interests in establishing and defending rights and preventing fraud |
| Maintain website and service security | Network, request and security-event data | Legitimate interests in availability, abuse prevention and information security; legal obligation where applicable |
| Accounting, tax and compliance | Transaction and legally required records | Legal obligation |
| Product and service improvement | Aggregated support trends and privacy-oriented analytics | Legitimate interests, balanced against user rights; consent where required for the technology used |
| Marketing | Email and consent record | Consent, or another lawful basis only where expressly permitted by law |
Where we rely on legitimate interests, those interests include delivering a secure licensed product, preventing key sharing and fraud, diagnosing defects, preserving evidence, improving reliability and protecting our systems. You may object where GDPR gives you that right.
## 5. Sources of data
We obtain data:
- directly from you at checkout, activation, support or transfer;
- from Gumroad as merchant of record and license-validation provider;
- from our website, hosting, email and security providers;
- from a current or proposed license-transfer party; and
- from payment, legal or public authorities where necessary to resolve fraud, disputes or legal obligations.
## 6. Recipients and service providers
We may disclose personal data only where relevant to:
- **Gumroad**, for purchase, delivery, license validation, invoice, refund, chargeback, dispute, tax and platform administration;
- **Cloudflare**, for hosting, content delivery, web security and any enabled privacy-oriented analytics;
- our email, backup and support-service providers;
- professional advisers such as accountants, auditors, insurers and lawyers;
- payment, fraud-prevention or technical specialists where required to investigate a case;
- public authorities, courts or law enforcement where legally required or necessary to establish, exercise or defend legal claims; and
- a buyer or successor of the CreakBox business, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal data. We do not disclose customer email addresses to unrelated advertisers for their own marketing.
## 7. International transfers
Some providers, including Gumroad and Cloudflare, may process data outside Denmark or the European Economic Area. Where GDPR requires a transfer mechanism, the relevant controller or processor must use an applicable safeguard, such as an adequacy decision, the EU Standard Contractual Clauses or another lawful mechanism, together with supplementary measures where required.
Provider privacy notices describe their own locations and safeguards. Contact frank@reitzwerk.com for information relevant to our processing.
## 8. Retention
We retain personal data only for as long as necessary for the stated purpose, including:
- transaction, tax and accounting records for the statutory retention period, normally at least five years after the end of the relevant financial year where Danish bookkeeping rules apply;
- license-entitlement, refund, chargeback and transfer records for the life of the entitlement and a reasonable period afterwards to provide support, prevent duplicate claims and establish or defend legal rights;
- support records normally for up to three years after the case is closed, unless a longer period is needed for an ongoing entitlement, recurring defect, security matter or legal claim;
- marketing data until consent is withdrawn or the data is no longer needed, subject to retaining a minimal suppression record to respect an opt-out; and
- website and security logs for the limited period configured or made available by the provider, unless an incident requires longer preservation.
We may retain anonymised or irreversibly aggregated information that no longer identifies a person.
## 9. Automated validation and human review
License validation is an automated technical decision: a key may be accepted, rejected or temporarily suspended based on the product and transaction status returned by the validation service.
Where an automated result affects a valid customer, you may request human review at frank@reitzwerk.com. We do not intentionally make a solely automated decision producing legal or similarly significant effects without the safeguards required by applicable law.
## 10. Your rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- receive information about processing;
- access your personal data;
- correct inaccurate data;
- erase data;
- restrict processing;
- receive portable data you provided in a structured format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent without affecting earlier lawful processing; and
- complain to a supervisory authority.
To exercise a right, contact frank@reitzwerk.com. We may request proportionate identity verification. We normally respond within the period required by law.
In Denmark, the supervisory authority is Datatilsynet. You may also contact the authority in the EU/EEA country where you live, work or believe an infringement occurred.
## 11. Security
We use proportionate technical and organisational measures intended to protect personal data, including encrypted transport, access control, secure handling of license-signing material, protected administrative credentials, backups and data minimisation.
No internet or storage system is completely risk-free. If a personal-data breach creates a legally reportable risk, we will notify the competent authority and affected individuals as required.
## 12. Children
CreakBox V2 is a professional music-production product and is not intentionally directed to young children. A minor must have any consent or contractual authority required under applicable law. Contact frank@reitzwerk.com if you believe a child has supplied data unlawfully.
## 13. Cookies and external links
The Cookie Policy explains website technologies. Clicking a Gumroad, social-media, video or other external link takes you to a service governed by that provider's own privacy and cookie practices.
## 14. Changes
We may update this policy to reflect product, provider, legal or security changes. The current version will show its effective date. Where a change materially affects existing processing or requires consent, we will provide notice and obtain consent where required.
## 15. Contact
Privacy questions and rights requests: **frank@reitzwerk.com**
Technical and license support: **frank@reitzwerk.com**
Postal address: **Bjelkevej 9, DK-5690 Tommerup**