Patch DNA
OverviewFeaturesSoundsDemoPricingFAQ
LoginBuy Now
Back to Patch DNA

PATCH DNA LEGAL

Implemented Personal Data Protection Measures

Public information about the organisational and technical measures PatchDNA implements to protect personal data.

Version 1.3 · effective 10 August 2026
Contents
  • 1. Purpose
  • 2. Organisational measures
  • 3. Regional separation
  • 4. Access and secret protection
  • 5. Payments and analytics
  • 6. Logging, backups and assurance
  • 7. Retention, deletion and requests
  • 8. Incident response
  • 9. Separate choices
  • 10. Contact

Version: 1.3
Effective date: 10 August 2026

1. Purpose

This public statement describes the organisational and technical measures PatchDNA implements to protect personal data. It supplements the Privacy Policy, does not replace internal policies and deliberately omits secrets, IP addresses, keys, detailed topology and other information that could reduce security.

The controller and Russian-law operator is Individual Entrepreneur Igor Grigoryevich Molka, INN 772377040614, OGRNIP 321774600446241. Privacy and security contact: support@patchdna.ai.

2. Organisational measures

The operator defines processing purposes and data categories and maintains records of systems, legal bases, recipients and retention. Applicable procedures cover access, backups, deletion, incident response and data-subject requests.

Access is limited to work-related need. Administrative functions are separated from ordinary user functions. Infrastructure-provider accounts use multi-factor authentication where supported; server administration uses individual SSH keys. Sharing credentials or secrets in plain text is prohibited.

Processors are reviewed before use and receive only the data required under an agreement, processing instruction or other lawful arrangement. Their authority, confidentiality, safeguards, incident notice and return or deletion obligations must be documented.

3. Regional separation

The apex patchdna.ai address performs ordinary request routing only and does not provide Accounts, checkout or the License API. ru.patchdna.ai and global.patchdna.ai are separate stateful services with separate applications, databases and host-only cookies.

The stateful Russian application and API, PostgreSQL, operational logs and rotating backups run in Joint Stock Company Selectel infrastructure in the Russian Federation. New Russian Account data is not written to the Bulgarian international database by default. The exact data-centre address is being confirmed from Selectel contractual records and must be entered in the operator's internal inventory and regulator notification before final approval; no assumed address is used.

The separate international service at global.patchdna.ai and its database are hosted by VPSBG in Bulgaria. Their existence does not itself transfer a Russian user's data. Application controls verify the region of each Account, order and License, and a session from one regional host is not accepted by the other.

Residual legacy Russian records and old backup generations on the former Bulgarian system are subject to verified isolation, deletion and rotation after migration validation. Until completion, they are not used as an active database or failover system for Russian users.

4. Access and secret protection

Public network connections use TLS. Same-origin and expected-host controls limit cross-site and misdirected requests. Sensitive operations apply rate limits and verify the session, role and data region.

Passwords are stored as cryptographic hashes. Raw Device identifiers and licensing IP addresses covered by the event model are replaced with HMAC values. Recoverable License keys are encrypted and License responses are signed. Secrets are separated from source code and ordinary logs and are exposed only to processes that need them.

Session cookies use Secure, HttpOnly, SameSite=Lax and Path=/ and omit Domain. A ru.patchdna.ai cookie is therefore not sent to global.patchdna.ai. A customer session lasts up to 30 days and an administrative session up to 12 hours; either may be revoked earlier.

5. Payments and analytics

Full card credentials are entered with the Payment Provider and are not stored by PatchDNA. The Russian checkout provides Robokassa only the data needed for the order, payment and receipt. Payment completion relies on a signed callback with amount, order, region and replay controls.

Yandex Metrica remains off until separate optional-analytics consent and is excluded from authentication, Account, checkout, License-claim and other sensitive routes. Session Replay is disabled. The current URL is reduced to origin plus pathname and the referrer to origin; URL credentials, query parameters, fragments, email, Account identifiers and License keys are intentionally excluded by the integration.

6. Logging, backups and assurance

Limited events are recorded for sign-in, licensing, payment callbacks, administrative changes, transactional email and errors. Passwords, secrets and full card details must not be logged. Log access is limited to security, diagnosis and transaction-evidence purposes.

The Russian database is backed up daily under the current 14-day local rotation. Copies are isolated from ordinary use and are restore-tested in a disposable environment. Automated checks monitor application and container health, disk use, backup age and TLS certificate expiry.

Components are updated with regard to security fixes. Material changes to architecture, recipients, processing purposes or analytics require renewed assessment, document updates and any required notice or consent.

7. Retention, deletion and requests

Category-specific rules are set out in the Privacy Policy. Once a purpose ends and no mandatory basis remains, data is deleted, anonymised or isolated from ordinary processing. A deleted record expires from rotating backups at the end of their cycle unless a legal hold or incident investigation requires otherwise.

Requests for access, correction, blocking or deletion may be sent to support@patchdna.ai. PatchDNA may reasonably verify identity and Account control before disclosure or change.

8. Incident response

The response procedure covers detection, containment, evidence preservation, assessment, remediation, restoration and documentation. Where an incident infringes personal-data rights, the operator notifies Roskomnadzor within applicable Russian deadlines: an initial notice within 24 hours and investigation results within 72 hours, and informs affected persons where law requires.

9. Separate choices

The Privacy Policy and this statement are notices, not consent. Acceptance of the offer, acknowledgement of the Privacy Policy, immediate digital-delivery instruction, optional analytics consent and any separate personal-data consent required by law are distinct actions and do not replace one another.

10. Contact

Controller: Individual Entrepreneur Igor Grigoryevich Molka
INN: 772377040614
OGRNIP: 321774600446241
Website: https://patchdna.ai
Email: support@patchdna.ai

Current statement: https://global.patchdna.ai/en/data-protection

Patch DNA

AI Bass Preset Machine for Serum 2.

Product

OverviewFeaturesSoundsDemo

Legal

TermsRefundsPrivacyCookies

Account & Support

LoginDownloadsFAQContactInstall on macOSInstall on WindowsSystem requirements
Digital product seller: Individual Entrepreneur Igor Grigoryevich MolkaINN 772377040614OGRNIP 321774600446241support@patchdna.ai

macOS and the Apple logo are trademarks of Apple Inc. Windows and the Windows logo are trademarks of Microsoft Corporation. Serum and Serum 2 are trademarks of Xfer Records. Ableton Live, FL Studio, Logic Pro, Cubase, Studio One, Bitwig Studio and REAPER, together with their names and logos, are trademarks of their respective owners.

All product names, logos, brands and trademarks are property of their respective owners. Their use is for compatibility identification only. Patch DNA is not affiliated with, endorsed by, or sponsored by those companies.

© 2026 Patch DNA. All rights reserved.