Patch DNA
OverviewFeaturesSoundsDemoPricingFAQ
LoginBuy Now
Back to Patch DNA

PATCH DNA LEGAL

Privacy Policy

How PatchDNA processes account, order, licensing, activation, support and security data.

Version 1.3 · effective 10 August 2026
Contents
  • 1. General
  • 2. Controller
  • 3. Scope
  • 4. Data categories
  • 5. Sources
  • 6. Purposes
  • 7. Legal bases
  • 8. Payments
  • 9. Licensing and Activation
  • 10. Technical logs and security
  • 11. Support and correspondence
  • 12. Analytics
  • 13. Marketing
  • 14. Cookies
  • 15. Recipients and processors
  • 16. International transfers and Russian localisation
  • 17. Retention
  • 18. Security
  • 19. Your rights
  • 20. Account deletion
  • 21. Minors
  • 22. Automated security measures
  • 23. Changes
  • 24. Contact

Version: 1.3
Effective date: 10 August 2026

This Policy explains how PatchDNA processes personal data when you visit patchdna.ai, create an Account, purchase or activate a Product, receive email or contact support. It should be read together with the Terms and Cookie Policy.

1. General

PatchDNA processes personal data lawfully, fairly and only for stated purposes. We seek to collect no more information than is reasonably needed to operate Accounts, orders, licensing, security, support and legal compliance.

2. Controller

The controller and, for Russian law, the personal-data operator is:

Individual Entrepreneur Igor Grigoryevich Molka
INN: 772377040614
OGRNIP: 321774600446241
Website: https://patchdna.ai
Privacy contact: support@patchdna.ai

3. Scope

3.1. This Policy covers the Website, Account, checkout, license server, official support and transactional email operated for current and future PatchDNA Products.

3.2. An external Payment Provider, email provider or third-party website may process information under its own policy. This Policy does not make PatchDNA the controller of an independent provider's processing.

3.3. This Policy does not cover personal data that a User independently places in a music project or Third-Party Software and that is never sent to PatchDNA.

3.4. The apex address patchdna.ai performs stateless regional routing for ordinary page requests. It does not provide an Account, checkout or License API and does not set a PatchDNA session cookie. Stateful Russian service functions are provided at ru.patchdna.ai; stateful international service functions are provided separately at global.patchdna.ai.

4. Data categories

Depending on the interaction, we process:

  • Account data: email address, cryptographic password hash, email-verification status, preferred email language, role and Account timestamps;
  • Order data: product, order identifier, status, amount, currency, provider references and purchase timestamps;
  • License data: encrypted license key, non-secret key prefix, Product, plan, status, activation allowance and relevant dates;
  • Activation data: HMAC-protected Device identifier, Device name supplied by the system, operating system, Product version, activation status and timestamps;
  • security and request data: HMAC-protected IP information in license events, user agent, event type, rate-limit and integrity results, session version and limited diagnostic metadata;
  • support data: messages, attachments, order references and troubleshooting information you choose to provide;
  • email-delivery data: recipient, message kind, language, delivery state, attempts, provider message identifier and timestamps;
  • payment data: payment status and provider identifiers. Full card credentials are not stored by PatchDNA where entered directly with a Payment Provider;
  • consent evidence: accepted document type, version, content hash, time, source, related order, user agent and HMAC-protected IP information;
  • preferences: selected Website language and any future cookie choice.

We do not intentionally request special-category data, government identity documents, payment-card secrets or biometric data for ordinary Product use.

5. Sources

Data comes directly from you; from your browser, Device and Product when they communicate with PatchDNA; from a Payment Provider confirming a transaction; from the email-delivery provider; and from security systems that generate integrity and abuse-prevention events.

We do not purchase data-broker profiles or enrich Accounts with advertising datasets.

6. Purposes

We process data to:

  1. create, secure and operate Accounts;
  2. accept and fulfil orders;
  3. issue, activate, validate, deactivate, refund or revoke Licenses;
  4. provide downloads, Updates and transactional notices;
  5. respond to support and legal requests;
  6. prevent piracy, fraud, credential abuse, chargebacks and attacks;
  7. diagnose availability and compatibility incidents;
  8. keep accounting, tax, acceptance and compliance records;
  9. establish, exercise or defend legal claims;
  10. send marketing only where a lawful basis and required choice exist.

Data collected for one purpose is not reused for an incompatible purpose without an additional lawful basis and notice.

7. Legal bases

Depending on the jurisdiction and activity, processing is based on:

  • contract and pre-contract steps: Account registration requested for purchase, checkout, delivery, licensing, activation, download and support;
  • legal obligation: tax, accounting, consumer, security and lawful-authority requirements;
  • legitimate interests: service security, fraud and piracy prevention, limited operational logging, claim protection and reliable delivery, balanced against User rights;
  • consent: optional marketing, optional analytics or another activity where consent is required. Consent can be withdrawn without affecting prior lawful processing;
  • establishment or defence of claims: where recognised by applicable law.

Where Russian law requires written or separate consent for a specific operation, it is requested separately rather than inferred from this Policy.

8. Payments

8.1. Payment details are entered in the environment of the Payment Provider selected at checkout. PatchDNA normally receives the transaction status, amount, currency and provider references needed to match and fulfil the order.

8.2. The Payment Provider may independently perform fraud, sanctions, identity or compliance checks under its own legal duties and policy.

8.3. PatchDNA stores enough order and acceptance evidence to fulfil the purchase, handle a refund or chargeback, issue required records and defend a claim.

8.4. For Russian orders, Robokassa receives the payer email, merchant and order identifiers, Product description, amount, currency, receipt data, interface language and technical information needed to initiate, secure and confirm the payment. Robokassa independently processes card credentials, anti-fraud and payment-compliance data under its own privacy terms. PatchDNA verifies a signed result callback and does not treat a browser return alone as payment confirmation.

9. Licensing and Activation

9.1. Activation identifies an authorised Device through a stable value protected with keyed cryptographic hashing. The raw identifier is not stored in the operational License record.

9.2. Device name, operating system, app version, Activation status and last-check timestamps let the User recognise and manage Devices and let PatchDNA enforce the licensed allowance.

9.3. The license server may issue signed, time-limited evidence allowing offline continuity after a successful check. This does not create a behavioural advertising profile.

9.4. Deactivating a Device changes the license state but does not immediately erase evidence needed for Account security, audit and dispute handling.

10. Technical logs and security

10.1. Requests may generate server and application logs containing time, route, response status, network information, user agent and security outcome. Production license events store a protected IP value rather than plain IP where the implemented event model provides for it.

10.2. Logs are used for rate limiting, incident investigation, availability, webhook integrity, session revocation, license protection and detection of unusual activation patterns.

10.3. We do not use licensing logs to advertise to you or infer musical taste.

11. Support and correspondence

Support messages are processed to answer the request, authenticate the order, reproduce a defect and maintain a reasonable history of the resolution. Send only relevant files and remove unrelated personal or confidential information before attaching diagnostics.

12. Analytics

Yandex Metrica counter 111201464 is started only after the visitor separately and affirmatively accepts optional analytics and only on non-sensitive public pages. Before that choice, PatchDNA does not load the Yandex library or initiate an analytics request to Yandex. After consent, Yandex may process a sanitised page address and title, sanitised referrer, browser and Device characteristics, approximate network location, link interactions and clicks. The PatchDNA integration sends the current page as origin plus pathname and the referrer as origin only; it does not intentionally send URL credentials, query parameters, fragments, email, Account identifier or License key. PatchDNA uses the resulting information to assess Website performance and improve public pages. Session Replay (Webvisor) is disabled, and analytics is not used to issue a License or create a third-party advertising profile.

On Account, authentication, checkout, License-claim and other designated sensitive routes, the counter is not started and an existing counter is stopped. Consent can be rejected or withdrawn through Cookie settings without disabling the Product, Account or purchasing functions. Withdrawal stops the counter and removes accessible Yandex identifiers where technically possible. The factual technologies and durations are listed in the Cookie Policy.

13. Marketing

Registration, security, purchase, License, support and material legal-change emails are necessary service communications and are not promotional newsletters.

Marketing email will be sent only where an appropriate legal basis exists and will include an effective opt-out. Opting out of marketing does not disable required Account or transaction messages.

14. Cookies

Each regional Website uses its own secure, host-only HttpOnly session cookie for Account authentication and host-only first-party preferences. No cookie Domain attribute is set, so a session issued by ru.patchdna.ai is not sent to global.patchdna.ai and vice versa. The apex regional router does not set these cookies. After analytics consent, Yandex Metrica may use cookies, localStorage and sessionStorage. The PatchDNA Cookie Policy contains the factual register, purposes, durations and preference control.

15. Recipients and processors

15.1. Access within PatchDNA is limited to authorised persons who need it for administration, support, accounting, security or legal compliance.

15.2. Russian hosting and database: Joint Stock Company Selectel provides infrastructure located in the Russian Federation for ru.patchdna.ai. The Russian service runs its stateful application and API, PostgreSQL database, operational logs and rotating backups in that Russian infrastructure. Selectel acts within the hosting and infrastructure instructions agreed with PatchDNA. The exact data-centre address is not stated here until it is confirmed in the operator's Selectel documents.

15.3. International hosting and database: VPSBG infrastructure in Bulgaria hosts the separate international service at global.patchdna.ai and its international database. It is not the primary database for Russian Accounts.

15.4. Email: Yandex 360 / Yandex Mail for Domain carries transactional and support messages where the required contractual and data-processing terms are in place.

15.5. Russian payments: Robokassa independently receives and processes the limited order and payment data described in section 8 for payments started through the Russian checkout. Other Payment Providers receive only the information required for the route displayed before payment.

15.6. Optional analytics: Yandex receives Website analytics data only after separate consent to Yandex Metrica and subject to the minimisation in section 12. Session Replay is disabled.

15.7. Professional advisers, infrastructure contractors or authorities receive data only where needed under confidentiality, contract or law.

15.8. PatchDNA does not sell personal data or disclose it for third-party cross-context behavioural advertising.

16. International transfers and Russian localisation

16.1. Initial collection, recording, systematisation, accumulation, storage, clarification and retrieval of personal data for a Russian Account occur in the Russian service and its database in the Russian Federation. New Russian Account, order, License and Activation records are not written to or routinely copied into the Bulgarian international database by default.

16.2. The existence of the independent international service does not by itself constitute a transfer of a Russian Account. A Russian user is not silently authenticated against, or failed over to, the international database. Separate host-only cookies and regional data markers enforce this separation.

16.3. If a Russian Account's personal data is later sent to a foreign recipient, PatchDNA will first complete the notification, recipient assessment and other safeguards required for that transfer. The Russian service is not configured to use the Bulgarian database as an ordinary backup or replica.

16.4. During the controlled regional migration, any residual legacy Russian records or backup generations on the former Bulgarian system are isolated from new Russian processing and removed through a verified migration and backup-rotation procedure. They are not used to create a second active Russian Account.

16.5. Where EEA personal data in the international service is transferred to a country without an applicable adequacy decision, PatchDNA will use an approved transfer mechanism and supplementary safeguards where required.

17. Retention

PatchDNA applies the following operational retention rules. A legal hold or a longer mandatory tax, accounting, consumer or limitation period prevails only for the affected record.

RecordNormal retention rule
Customer session cookieup to 30 days; ends sooner on logout or revocation
Administrative session cookieup to 12 hours; ends sooner on logout or revocation
Email-verification tokenvalid for up to 24 hours; an old token is replaced when a new one is issued and consumed or expired tokens are removed under cleanup
Password-reset tokenvalid for up to 30 minutes; an old token is replaced when a new one is issued and consumed or expired tokens are removed under cleanup
Cookie preferenceup to 1 year unless changed or deleted sooner
Account and Licensewhile the Account or purchased entitlement remains active; afterwards only for a documented legal, fraud-prevention or claim purpose
Orders, payment confirmations, acceptances, refunds and chargebacksfor the applicable tax, accounting, consumer and claim period; access is restricted after ordinary Account deletion
Security events and technical logsfor the documented operational period proportionate to incident investigation and repeated-abuse prevention, then deleted or irreversibly aggregated
Support correspondencewhile the request is active and afterwards only for continuity and claim protection; unnecessary attachments are removed earlier
Russian local database backupsdaily rotating copies retained for 14 days under the current production schedule, isolated from ordinary use and restore-tested

When a purpose ends and no mandatory basis remains, data is deleted, anonymised or isolated from ordinary processing. Backup expiry follows its rotation cycle rather than an immediate per-record deletion.

18. Security

Measures include regional database separation, role-based access, encrypted transport, cryptographic password hashing, HMAC protection of Device and licensing IP identifiers, encryption of recoverable license keys, signed license responses, host-only secure cookies, same-origin checks, rate limits, administrative event logging, Russian rotating backups and restore tests, secret isolation and dependency updates. Public information about these measures is available at https://global.patchdna.ai/en/data-protection.

No system is absolutely secure. If an incident occurs, PatchDNA will contain and investigate it, restore integrity and provide legally required notices to users and authorities.

19. Your rights

Subject to the law that applies to you, you may request access and a copy; correction; deletion; restriction; portability; objection; withdrawal of consent; and information about processing. You may also complain to a competent data-protection authority or court.

Requests should be sent to support@patchdna.ai. We may reasonably verify identity and Account ownership before disclosing or changing data. We will respond within the applicable statutory period.

If processing is based on legitimate interests, you may object on grounds relating to your situation. If processing is based on consent, withdrawal does not affect processing before withdrawal.

20. Account deletion

20.1. Send an Account deletion request from the verified Account email to support@patchdna.ai. Before deletion, deactivate Devices and retain any installers or records you lawfully need.

20.2. Deletion removes ordinary Account access and personal data no longer needed. It does not automatically refund a purchase.

20.3. Order, acceptance, payment, refund, security and claim records may be isolated and retained for the mandatory or justified period, with access restricted to those purposes.

21. Minors

PatchDNA Products are intended for persons who can enter into the purchase agreement themselves or act with their legal representative's authorisation. We do not knowingly solicit data from children below the applicable digital-consent age. If such data is identified without a lawful basis, it will be deleted unless law requires retention.

22. Automated security measures

The service may automatically reject or temporarily limit a request, session or Activation after an invalid signature, revoked session, exceeded allowance, rate-limit event or credible attack indicator. These measures protect the service, do not make marketing or credit decisions, and can be reviewed by a person through support.

23. Changes

A revised Policy is published with a new version and effective date. Material changes affecting current Users will be communicated through the Website, Account, Product or email. A new purpose that requires consent will not begin until the required choice is obtained.

24. Contact

Controller: Individual Entrepreneur Igor Grigoryevich Molka
INN: 772377040614
OGRNIP: 321774600446241
Website: https://patchdna.ai
Privacy email: support@patchdna.ai

Current Policy: https://global.patchdna.ai/en/privacy

Patch DNA

AI Bass Preset Machine for Serum 2.

Product

OverviewFeaturesSoundsDemo

Legal

TermsRefundsPrivacyCookies

Account & Support

LoginDownloadsFAQContactInstall on macOSInstall on WindowsSystem requirements
Digital product seller: Individual Entrepreneur Igor Grigoryevich MolkaINN 772377040614OGRNIP 321774600446241support@patchdna.ai

macOS and the Apple logo are trademarks of Apple Inc. Windows and the Windows logo are trademarks of Microsoft Corporation. Serum and Serum 2 are trademarks of Xfer Records. Ableton Live, FL Studio, Logic Pro, Cubase, Studio One, Bitwig Studio and REAPER, together with their names and logos, are trademarks of their respective owners.

All product names, logos, brands and trademarks are property of their respective owners. Their use is for compatibility identification only. Patch DNA is not affiliated with, endorsed by, or sponsored by those companies.

© 2026 Patch DNA. All rights reserved.