Patch DNA
OverviewDemoFeaturesSoundsPricingFAQ
LoginBuy
Back to Patch DNA

PATCH DNA LEGAL

Implemented Personal Data Protection Measures

Public information about the organisational and technical measures PatchDNA implements to protect personal data.

Version 1.9 · effective 5 October 2026
Contents
  • 1. Purpose
  • 2. Organisational measures
  • 3. Regional separation
  • 4. Access and secret protection
  • 5. Payments and analytics
  • 6. Logging, backups and assurance
  • 7. Retention, deletion and requests
  • 8. Incident response
  • 9. Separate choices
  • 10. Contact

Version: 1.9
Application: This version applies to Stripe purchases whose order records version 1.9. Earlier purchases retain their recorded terms.

1. Purpose

This public statement describes the organisational and technical measures of the Developer-operated international Patch DNA service. It supplements the Privacy Policy, does not replace internal policies and deliberately omits secrets, IP addresses, keys, detailed topology and other information that could reduce security. Descriptions of the Russian service explain separation only; the international Seller does not become the seller or technical operator for Russian-service orders.

The technical-service controller and, where Russian law applies, the personal-data operator is Individual Entrepreneur Igor Grigoryevich Molka, INN 772377040614, OGRNIP 321774600446241. In this statement, the operator means this Developer, who remains responsible for technical Accounts, licensing, infrastructure and support. Privacy and security contact: support@patchdna.ai; Developer business contact: admin@patchdna.ai.

The international Seller, ASIA M AND T CO., LTD., registered in Thailand under number 0105567191935 at 11/2 P23 Building, Level 11, Soi Sukhumvit 23, Sukhumvit Road, Khongtoey Nua, Wattana, Bangkok 10110, Thailand, can access payer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. The Developer does not provide a routine Account or License data feed to it; Stripe makes payment and payer information available in its merchant account. Only a future individual refund, dispute, accounting matter or legal obligation may justify disclosure of the minimum necessary information, with a lawful basis as described in the Privacy Policy. Such disclosure does not grant database or technical-administration access. Seller privacy and commercial contact: mttraidinglmt@gmail.com. Its commercial role does not grant access to credentials, License-key secrets or source code.

2. Organisational measures

The operator defines processing purposes and data categories and maintains records of systems, legal bases, recipients and retention. Applicable procedures cover access, backups, deletion, incident response and data-subject requests.

Access is limited to work-related need. Administrative functions are separated from ordinary user functions. Infrastructure-provider accounts use multi-factor authentication where supported; server administration uses individual SSH keys. Sharing credentials or secrets in plain text is prohibited.

Processors are reviewed before use and receive only the data required under an agreement, processing instruction or other lawful arrangement. Their authority, confidentiality, safeguards, incident notice and return or deletion obligations must be documented.

3. Regional separation

The apex patchdna.ai address performs ordinary request routing only and does not provide Accounts, checkout or the License API. ru.patchdna.ai and global.patchdna.ai are separate stateful services with separate applications, databases and host-only cookies.

The stateful Russian application and API, PostgreSQL, operational logs and rotating backups run in Joint Stock Company Selectel infrastructure in the Russian Federation. New Russian Account data is not written to the Bulgarian international database by default. The exact data-centre address is being confirmed from Selectel contractual records and must be entered in the operator's internal inventory and regulator notification before final approval; no assumed address is used.

The separate international service at global.patchdna.ai and its database are hosted by VPSBG in Bulgaria. Their existence does not itself transfer a Russian user's data. Application controls verify the region of each Account, order and License, and a session from one regional host is not accepted by the other.

Residual legacy Russian records and old backup generations on the former Bulgarian system are subject to verified isolation, deletion and rotation after migration validation. Until completion, they are not used as an active database or failover system for Russian users.

4. Access and secret protection

Public network connections use TLS. Same-origin and expected-host controls limit cross-site and misdirected requests. Sensitive operations apply rate limits and verify the session, role and data region.

Passwords are stored as cryptographic hashes. Raw Device identifiers and licensing IP addresses covered by the event model are replaced with HMAC values. Recoverable License keys are encrypted and License responses are signed. Secrets are separated from source code and ordinary logs and are exposed only to processes that need them.

Session cookies use Secure, HttpOnly, SameSite=Lax and Path=/ and omit Domain. A ru.patchdna.ai cookie is therefore not sent to global.patchdna.ai. A customer session lasts up to 30 days and an administrative session up to 12 hours; either may be revoked earlier.

5. Payments and analytics

Full card credentials are entered with the Payment Provider and are not stored by PatchDNA. The Russian checkout provides Robokassa only the data needed for the order, payment and receipt. The international provider-hosted checkout is operated by Stripe, which collects the payer email and available payment details in its environment. The Developer-operated service receives the authenticated transaction, payer email, Product, offer, amount, currency and provider identifiers needed for reconciliation. For payment notifications, it verifies Stripe's signature before processing the notification. Successful payment is always confirmed by retrieving the Checkout Session and Payment Intent through authenticated server-side Stripe API requests. Protected operator reconciliation uses the same server-side payment checks. A confirmed payment records a paid but unclaimed Order without issuing its License. License issuance requires proof of control of the checkout email through a secure claim link or an already verified Account with that same email, followed by the Customer's two separate personal confirmation choices for the order. An existing Account retains its previous rights; verification or sign-in alone does not accept or fulfil a new order. The return page displays a status message and does not confirm payment or fulfil an order. The Seller can access payer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. The Developer does not routinely share Account or License information; the Seller can view payer and transaction information through Stripe. A future individual refund, dispute, accounting matter or legal obligation may require only the minimum necessary case-specific disclosure with a lawful basis, under the Privacy Policy; it does not provide a routine feed or database access.

Yandex Metrica remains off until separate optional-analytics consent and is excluded from authentication, Account, checkout, License-claim and other sensitive routes. Session Replay is disabled. The current URL is reduced to origin plus pathname and the referrer to origin; URL credentials, query parameters, fragments, email, Account identifiers and License keys are intentionally excluded by the integration.

6. Logging, backups and assurance

Limited events are recorded for sign-in, licensing, payment callbacks, administrative changes, transactional email and errors. Passwords, secrets and full card details must not be logged. Log access is limited to security, diagnosis and transaction-evidence purposes.

The Russian database is backed up daily under the current 14-day local rotation. Copies are isolated from ordinary use and are restore-tested in a disposable environment. Automated checks monitor application and container health, disk use, backup age and TLS certificate expiry.

Components are updated with regard to security fixes. Material changes to architecture, recipients, processing purposes or analytics require renewed assessment, document updates and any required notice or consent.

7. Retention, deletion and requests

Category-specific rules are set out in the Privacy Policy. Once a purpose ends and no mandatory basis remains, data is deleted, anonymised or isolated from ordinary processing. A deleted record expires from rotating backups at the end of their cycle unless a legal hold or incident investigation requires otherwise.

A paid but unclaimed hosted Order remains restricted: claim-link expiry creates neither acceptance nor a License. Support may reissue access after verification or arrange the pre-delivery refund. The operator reviews these Orders and retains identity only while required for claim, refund, reconciliation, accounting, consumer or dispute purposes.

Requests for access, correction, blocking or deletion of technical-service records may be sent to support@patchdna.ai. The operator may reasonably verify identity and Account control before disclosure or change. If the Seller lawfully receives minimum necessary personal data for a future individual case under the Privacy Policy, requests about those particular records should be sent to mttraidinglmt@gmail.com.

8. Incident response

The response procedure covers detection, containment, evidence preservation, assessment, remediation, restoration and documentation. Where an incident infringes personal-data rights and Russian notification law applies to the operator, the operator notifies Roskomnadzor within applicable Russian deadlines: an initial notice within 24 hours and investigation results within 72 hours. The responsible party also makes other authority and affected-person notifications where the applicable law requires them. These technical-service procedures do not establish or imply unconfirmed technical access by the Seller.

9. Separate choices

The Privacy Policy and this statement are notices, not consent. Acceptance of the offer, acknowledgement of the Privacy Policy, immediate digital-delivery instruction, optional analytics consent and any separate personal-data consent required by law are distinct actions and do not replace one another.

10. Contact

Seller, authorised distributor and advertiser: ASIA M AND T CO., LTD.
Company registration number: 0105567191935
Registered address: 11/2 P23 Building, Level 11, Soi Sukhumvit 23, Sukhumvit Road, Khongtoey Nua, Wattana, Bangkok 10110, Thailand
Sales, payment, refund and seller privacy contact: mttraidinglmt@gmail.com
International website: https://global.patchdna.ai

Technical-service controller: Individual Entrepreneur Igor Grigoryevich Molka
INN: 772377040614
OGRNIP: 321774600446241
Technical privacy, security and Account contact: support@patchdna.ai
Developer business contact: admin@patchdna.ai

Current statement: https://global.patchdna.ai/en/data-protection

Patch DNA

AI Bass Preset Machine for Serum 2.

Product

OverviewFeaturesSoundsDemo

Legal

TermsRefundsPrivacyCookies

Account & Support

LoginDownloadsFAQContactInstall on macOSInstall on WindowsSystem requirements
ASIA M AND T CO., LTD.11/2 P23 Building, Level 11, Soi Sukhumvit 23, Sukhumvit Road, Khongtoey Nua, Wattana, Bangkok 10110, ThailandPowered by Stripe

macOS and the Apple logo are trademarks of Apple Inc. Windows and the Windows logo are trademarks of Microsoft Corporation. Serum and Serum 2 are trademarks of Xfer Records. Ableton Live, FL Studio, Logic Pro, Cubase, Studio One, Bitwig Studio and REAPER, together with their names and logos, are trademarks of their respective owners.

All product names, logos, brands and trademarks are property of their respective owners. Their use is for compatibility identification only. Patch DNA is not affiliated with, endorsed by, or sponsored by those companies.

© 2026 Patch DNA. All rights reserved.