PATCH DNA LEGAL
Privacy Policy
How PatchDNA processes account, order, licensing, activation, support and security data.
Version 1.9 · effective 5 October 2026Version: 1.9
Application: This version applies to Stripe purchases whose order records version 1.9. Earlier purchases retain their recorded terms.
This Policy explains personal-data processing for the international Patch DNA service at global.patchdna.ai, including purchases with or without a pre-existing Account, Product activation, email and support. It describes the Developer's technical service, Account, licensing and support processing and the conditions for any future case-specific disclosure to the Seller. The Seller can access buyer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. It should be read together with the Terms and Cookie Policy. The Russian service has its own applicable notices; its infrastructure is described here only where needed to explain regional separation.
1. General
The Developer processes personal data lawfully, fairly and only for its stated technical-service purposes, including orders, Accounts, licensing, security, support and legal compliance. Stripe provides the Seller with the payer and transaction information available in its merchant account. If a future individual refund, dispute, accounting matter or legal obligation requires disclosure to the Seller, only the minimum necessary information may be disclosed with a lawful basis under section 15.
2. Responsible parties and their roles
International Seller: ASIA M AND T CO., LTD., registered in Thailand under number 0105567191935, at 11/2 P23 Building, Level 11, Soi Sukhumvit 23, Sukhumvit Road, Khongtoey Nua, Wattana, Bangkok 10110, Thailand. The Seller can access buyer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. The Stripe merchant account provides payment and payer information for the Seller's sales. The Developer does not provide a routine feed of Account or License information. Any future case-specific receipt of personal data is limited to the conditions in section 15. Seller privacy and commercial requests: mttraidinglmt@gmail.com.
Developer and technical-service controller: Individual Entrepreneur Igor Grigoryevich Molka, INN 772377040614, OGRNIP 321774600446241. The Developer operates the Patch DNA Website, Accounts, License service, delivery infrastructure, technical support and optional Website analytics and remains the controller and, where Russian law applies, the personal-data operator for that technical processing. Technical privacy and Account requests: support@patchdna.ai. Developer business contact: admin@patchdna.ai.
The Seller's role does not transfer Product ownership or technical-service control to it. The Developer does not provide the Seller with a routine feed of Account or License data; Stripe provides the transaction information available in the Seller's merchant account. Any future disclosure must be limited to the minimum necessary information for an individual refund, dispute, accounting matter or legal obligation and supported by a lawful basis. The Seller's commercial role does not itself grant access to source code, passwords, License-key secrets, raw Device identifiers or server administration. References to Patch DNA in the technical sections below identify the Developer-operated service, not an additional legal entity.
3. Scope
3.1. This Policy covers the international Website, Account, checkout, License server, official technical support and transactional email operated by the Developer. It also describes the payer and transaction information available to the Seller through Stripe and the conditions for any additional case-specific disclosure under section 15.
3.2. An external Payment Provider, email provider or third-party website may process information under its own policy. This Policy does not make PatchDNA the controller of an independent provider's processing.
3.3. This Policy does not cover personal data that a User independently places in a music project or Third-Party Software and that is never sent to PatchDNA.
3.4. The apex address patchdna.ai performs stateless regional routing for ordinary page requests. It does not provide an Account, checkout or License API and does not set a PatchDNA session cookie. Stateful Russian service functions are provided at ru.patchdna.ai; stateful international service functions are provided separately at global.patchdna.ai.
4. Data categories
Depending on the interaction, the Developer-operated service processes the categories below. The Seller can access the payer and transaction information available in its Stripe merchant account, but has no Patch DNA database access. Any future case-specific disclosure is subject to section 15:
- checkout-routing data: the selected regional service, host and time of the purchase request; the international provider-hosted purchase flow does not ask PatchDNA for a citizenship declaration;
- Account data: email address, cryptographic password hash where set, email-verification or post-payment claim status, preferred email language, role and Account timestamps;
- Order data: product, order identifier, status, amount, currency, provider references and purchase timestamps;
- License data: encrypted license key, non-secret key prefix, Product, plan, status, activation allowance and relevant dates;
- Activation data: HMAC-protected Device identifier, Device name supplied by the system, operating system, Product version, activation status and timestamps;
- security and request data: HMAC-protected IP information in license events, user agent, event type, rate-limit and integrity results, session version, one-time Account-claim token status and expiry, and limited diagnostic metadata. Claim and password-reset token secrets are not stored in reusable plain form;
- support data: messages, attachments, order references and troubleshooting information you choose to provide;
- email-delivery data: recipient, message kind, language, delivery state, attempts, provider message identifier and timestamps;
- payment data: payment status, amount, currency, payer email, Stripe Checkout Session and Payment Intent references, Product and offer identifiers, and provider-reconciliation results. Stripe and its payment partners may collect additional payment, wallet, bank, anti-fraud or compliance data under their own notices. PatchDNA does not receive or store full card credentials;
- consent evidence: accepted document type, version, content hash, time, source, related order, user agent and HMAC-protected IP information;
- preferences: selected Website language and any future cookie choice.
Neither the Seller nor the Developer intentionally requests special-category data, government identity documents, payment-card secrets or biometric data for ordinary Product use.
5. Sources
Data comes directly from you, including the order email and payment selection made in the Payment Provider environment, later personal confirmation choices and technical-support correspondence; from your browser, Device and Product when they communicate with the Developer-operated service; from a Payment Provider confirming a transaction; from the email-delivery provider; and from security systems that generate integrity and abuse-prevention events. Stripe makes payer and transaction information available to the Seller in its merchant account. Other technical-service flows do not provide a routine Account or License feed to the Seller. Any future individual-case disclosure to the Seller, including information needed to resolve a purchaser's request, must satisfy section 15.
Neither the Seller nor the Developer purchases data-broker profiles or enriches Accounts with advertising datasets.
6. Purposes
The Developer-operated service processes data to:
- record and reconcile a provider-hosted paid but unclaimed Order, create or match the restricted Account identity needed to secure it, verify control of the payer email through a secure claim link or a verified Account using that same email, and, only after the required personal confirmation choices, create the corresponding Account entitlement and deliver the License;
- accept and fulfil orders;
- issue, activate, validate, deactivate, refund or revoke Licenses;
- provide downloads, Updates and transactional notices;
- respond to support and legal requests;
- prevent piracy, fraud, credential abuse, chargebacks and attacks;
- diagnose availability and compatibility incidents;
- keep accounting, tax, acceptance and compliance records;
- establish, exercise or defend legal claims;
- send marketing only where a lawful basis and required choice exist.
Data collected for one purpose is not reused for an incompatible purpose without an additional lawful basis and notice.
7. Legal bases
Depending on the jurisdiction and activity, the Developer's processing is based on the grounds below. Any future individual-case disclosure to the Seller requires its own applicable lawful basis and compliance with section 15:
- contract and requested pre-contract steps: the provider-hosted purchase and secure claim requested by the payer, payment reconciliation, restricted Account-identity creation or matching, post-claim Account access, delivery, licensing, activation, download and support;
- legal obligation: tax, accounting, consumer, security and lawful-authority requirements;
- legitimate interests: service security, fraud and piracy prevention, limited operational logging, claim protection and reliable delivery, balanced against User rights;
- consent: optional marketing, optional analytics or another activity where consent is required. Consent can be withdrawn without affecting prior lawful processing;
- establishment or defence of claims: where recognised by applicable law.
Where Russian law requires written or separate consent for a specific operation, it is requested separately rather than inferred from this Policy.
8. Payments
8.1. Payment details are entered in the environment of the Payment Provider selected at checkout. PatchDNA normally receives the transaction status, amount, currency and provider references needed to match and fulfil the order.
8.2. The Payment Provider may independently perform fraud, sanctions, identity or compliance checks under its own legal duties and policy.
8.3. Before a provider-hosted claim is completed, PatchDNA stores payment and paid-order evidence but no Terms or immediate-delivery acceptance. If the claim is completed, PatchDNA stores the accepted document version and hashes, acceptance time and source, related order, and protected request evidence needed to fulfil the purchase, handle a refund or chargeback and defend a claim.
8.4. For Russian orders, Robokassa receives the payer email, merchant and order identifiers, Product description, amount, currency, receipt data, interface language and technical information needed to initiate, secure and confirm the payment. Robokassa independently processes card credentials, anti-fraud and payment-compliance data under its own privacy terms. PatchDNA verifies a signed result callback and does not treat a browser return alone as payment confirmation.
8.5. For international orders routed through Stripe, Stripe receives the selected Product, amount, currency, internal Order reference and the payer email and payment details supplied in its hosted checkout. For a verified Account upgrade, the service supplies the verified Account email. Stripe and its payment partners independently process card, wallet, anti-fraud, identity and payment-compliance data under their own terms and notices. The Seller can view the payer and transaction information available in its Stripe merchant account. For payment notifications, Patch DNA verifies Stripe's signature before processing the notification. The service confirms the Checkout Session and Payment Intent directly through authenticated server-side Stripe API requests, both for notified payments and protected operator reconciliation. The return page displays a status message and does not confirm or fulfil payment.
8.6. Before checkout, the Developer records a pending Order with the selected Product, amount and currency. A guest email is collected in Stripe rather than in a Patch DNA pre-payment form. Following server-verified payment confirmation, the service checks the exact Session, Payment Intent, Product, saved offer, quantity, amount, currency and test/live mode. It records a paid but unclaimed Order and creates or matches the restricted Account identity needed to secure that Order, without issuing a Product License. A time-limited one-time access link is sent to the payer email. The payer proves email control through that link or an already verified Account using the same checkout email. Only after the Customer personally accepts the Order's Terms, acknowledges this Policy and separately requests immediate digital delivery with the applicable withdrawal acknowledgement does the service issue that Order's License and entitlement. Sign-in or payment alone does not fulfil a new Order. Expired or unused links do not expose keys or installers. Mismatches, refunds and disputes restrict automatic fulfilment and are recorded for reconciliation, support or refund review.
9. Licensing and Activation
9.1. Activation identifies an authorised Device through a stable value protected with keyed cryptographic hashing. The raw identifier is not stored in the operational License record.
9.2. Device name, operating system, app version, Activation status and last-check timestamps let the User recognise and manage Devices and let PatchDNA enforce the licensed allowance.
9.3. The license server may issue signed, time-limited evidence allowing offline continuity after a successful check. This does not create a behavioural advertising profile.
9.4. Deactivating a Device changes the license state but does not immediately erase evidence needed for Account security, audit and dispute handling.
10. Technical logs and security
10.1. Requests may generate server and application logs containing time, route, response status, network information, user agent and security outcome. Production license events store a protected IP value rather than plain IP where the implemented event model provides for it.
10.2. Logs are used for rate limiting, incident investigation, availability, webhook integrity, session revocation, license protection and detection of unusual activation patterns.
10.3. The Developer does not use licensing logs to advertise to you or infer musical taste.
11. Support and correspondence
The Developer processes technical-support messages to authenticate the order, reproduce a defect and maintain a reasonable history of the resolution. Those messages are not routinely shared with the Seller. If a future individual refund or dispute requires the Seller's involvement, only the minimum necessary information may be disclosed with a lawful basis under section 15. Send only relevant files and remove unrelated personal or confidential information before attaching diagnostics.
12. Analytics
Yandex Metrica counter 111201464 is started only after the visitor separately and affirmatively accepts optional analytics and only on non-sensitive public pages. Before that choice, PatchDNA does not load the Yandex library or initiate an analytics request to Yandex. After consent, Yandex may process a sanitised page address and title, sanitised referrer, browser and Device characteristics, approximate network location, link interactions and clicks. The PatchDNA integration sends the current page as origin plus pathname and the referrer as origin only; it does not intentionally send URL credentials, query parameters, fragments, email, Account identifier or License key. PatchDNA uses the resulting information to assess Website performance and improve public pages. Session Replay (Webvisor) is disabled, and analytics is not used to issue a License or create a third-party advertising profile.
On Account, authentication, checkout, License-claim and other designated sensitive routes, the counter is not started and an existing counter is stopped. Consent can be rejected or withdrawn through Cookie settings without disabling the Product, Account or purchasing functions. Withdrawal stops the counter and removes accessible Yandex identifiers where technically possible. The factual technologies and durations are listed in the Cookie Policy.
13. Marketing
Registration, security, purchase, License, support and material legal-change emails are necessary service communications and are not promotional newsletters.
Marketing email will be sent only where an appropriate legal basis exists and will include an effective opt-out. Opting out of marketing does not disable required Account or transaction messages.
14. Cookies
Each regional Website uses its own secure, host-only HttpOnly session cookie for Account authentication and host-only first-party preferences. No cookie Domain attribute is set, so a session issued by ru.patchdna.ai is not sent to global.patchdna.ai and vice versa. The apex regional router does not set these cookies. After analytics consent, Yandex Metrica may use cookies, localStorage and sessionStorage. The PatchDNA Cookie Policy contains the factual register, purposes, durations and preference control.
15. Recipients and processors
15.1. Access to the Developer-operated technical service is limited to authorised persons who need it for administration, technical support, security or legal compliance. ASIA M AND T CO., LTD. can access payer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. The Developer does not provide a routine feed of Account or License information to the Seller. A future disclosure may occur only for a specific refund, dispute, accounting matter or legal obligation, where a lawful basis exists and the information is necessary for that individual case. The disclosure must be limited to the minimum required data and does not grant database, Account-administration or server access. Source code, passwords and License-key secrets are not disclosed for the Seller's commercial role.
15.2. Russian hosting and database: Joint Stock Company Selectel provides infrastructure located in the Russian Federation for ru.patchdna.ai. The Russian service runs its stateful application and API, PostgreSQL database, operational logs and rotating backups in that Russian infrastructure. Selectel acts within the hosting and infrastructure instructions agreed with PatchDNA. The exact data-centre address is not stated here until it is confirmed in the operator's Selectel documents.
15.3. International hosting and database: VPSBG infrastructure in Bulgaria hosts the separate international service at global.patchdna.ai and its international database. It is not the primary database for Russian Accounts.
15.4. Email: Yandex 360 / Yandex Mail for Domain carries transactional and support messages where the required contractual and data-processing terms are in place.
15.5. Russian payments: Robokassa independently receives and processes the limited order and payment data described in section 8 for payments started through the Russian checkout.
15.6. International payments: Stripe and its payment partners process the order, payer and payment data described in section 8. The Seller can access payer and transaction information through its Stripe merchant account for payment administration, refunds, disputes and required commercial records. The provider and available payment method are displayed before the Customer completes payment.
15.7. Optional analytics: Yandex receives Website analytics data only after separate consent to Yandex Metrica and subject to the minimisation in section 12. Session Replay is disabled.
15.8. Professional advisers, infrastructure contractors or authorities receive data from the Developer only where needed under confidentiality, contract or law. If the Seller lawfully receives information for a future individual case under clause 15.1, it may use or disclose that information only as necessary for that case and its applicable legal obligations.
15.9. Neither the Seller nor the Developer sells personal data or discloses it for third-party cross-context behavioural advertising.
16. International transfers and Russian localisation
16.1. Initial collection, recording, systematisation, accumulation, storage, clarification and retrieval of personal data for a Russian Account occur in the Russian service and its database in the Russian Federation. New Russian Account, order, License and Activation records are not written to or routinely copied into the Bulgarian international database by default.
16.2. The existence of the independent international service does not by itself constitute a transfer of a Russian Account. A Russian user is not silently authenticated against, or failed over to, the international database. Separate host-only cookies and regional data markers enforce this separation.
16.3. If a Russian Account's personal data is later sent to a foreign recipient, PatchDNA will first complete the notification, recipient assessment and other safeguards required for that transfer. The Russian service is not configured to use the Bulgarian database as an ordinary backup or replica.
16.4. During the controlled regional migration, any residual legacy Russian records or backup generations on the former Bulgarian system are isolated from new Russian processing and removed through a verified migration and backup-rotation procedure. They are not used to create a second active Russian Account.
16.5. The international technical service and database remain hosted in Bulgaria. The Developer operates the technical service from the Russian Federation and may access necessary international Account, order, licensing and technical-support data there. The Seller in Thailand can access payer and transaction information in its Stripe merchant account, but has no access to the Patch DNA database. Any future individual-case disclosure requires the lawful basis and minimisation described in section 15. These roles do not relocate the international database or merge it with the Russian service.
16.6. Where EEA personal data in the international service is transferred to a country without an applicable adequacy decision, the responsible party will use an approved transfer mechanism and supplementary safeguards where required. The location and commercial role of a recipient do not themselves provide an exception to an applicable transfer requirement.
17. Retention
The Developer-operated technical service applies the following operational retention rules. The Seller can retain the payer and transaction information available in its Stripe merchant account for payment administration and applicable commercial obligations. If it lawfully receives minimum necessary information for a future individual case under section 15, retention must be limited to that case and the applicable accounting, legal-obligation or claim period, with use restricted accordingly. A legal hold or a longer mandatory period prevails only for the affected record.
| Record | Normal retention rule |
|---|---|
| Customer session cookie | up to 30 days; ends sooner on logout or revocation |
| Administrative session cookie | up to 12 hours; ends sooner on logout or revocation |
| Email-verification token | valid for up to 24 hours; an old token is replaced when a new one is issued and consumed or expired tokens are removed under cleanup |
| Password-reset token | valid for up to 30 minutes; an old token is replaced when a new one is issued and consumed or expired tokens are removed under cleanup |
| Post-payment Account-claim token | valid only for the configured short claim period; it is single-use, replaced on reissue and removed or invalidated after use or expiry |
| Cookie preference | up to 1 year unless changed or deleted sooner |
| Pending unpaid Stripe checkout | contains the reservation and provider references; Patch DNA collects no guest email before payment confirmation. Verified Account attempts can also reference that Account. Records are restricted to reconciliation and applicable transaction, accounting or claim purposes. |
| Paid but unclaimed provider-hosted Order and restricted Account identity | retained while secure claim, reissue, pre-delivery refund, payment reconciliation or dispute handling remains available; expiry of one claim link does not erase the payment or create a License; after claim or refund, only the Account, transaction and legal records justified by the applicable rule are retained |
| Account and License | while the Account or purchased entitlement remains active; afterwards only for a documented legal, fraud-prevention or claim purpose |
| Orders, payment confirmations, acceptances, refunds and chargebacks | for the applicable tax, accounting, consumer and claim period; access is restricted after ordinary Account deletion |
| Security events and technical logs | for the documented operational period proportionate to incident investigation and repeated-abuse prevention, then deleted or irreversibly aggregated |
| Support correspondence | while the request is active and afterwards only for continuity and claim protection; unnecessary attachments are removed earlier |
| Russian local database backups | daily rotating copies retained for 14 days under the current production schedule, isolated from ordinary use and restore-tested |
When a purpose ends and no mandatory basis remains, data is deleted, anonymised or isolated from ordinary processing. Backup expiry follows its rotation cycle rather than an immediate per-record deletion.
A paid but unclaimed Order is never converted into acceptance or a License merely because time passes. PatchDNA periodically reviews such Orders so secure access can be reissued or a pre-delivery refund can be arranged. A payer may contact support from the checkout email at any time before claim completion.
The 30-day guest rule removes the reversible buyer identity from the unresolved attempt; it does not delete the underlying transaction and contract evidence where a tax, accounting, consumer, dispute or reconciliation period applies. Access to that retained evidence is restricted to those purposes. It is not reused to recreate the buyer identity, market to the payer or issue a License after pseudonymisation.
18. Security
Measures include regional database separation, role-based access, encrypted transport, cryptographic password hashing, HMAC protection of Device and licensing IP identifiers, encryption of recoverable license keys, signed license responses, host-only secure cookies, same-origin checks, rate limits, administrative event logging, Russian rotating backups and restore tests, secret isolation and dependency updates. Public information about these measures is available at https://global.patchdna.ai/en/data-protection.
No system is absolutely secure. If an incident occurs, PatchDNA will contain and investigate it, restore integrity and provide legally required notices to users and authorities.
19. Your rights
Subject to the law that applies to you, you may request access and a copy; correction; deletion; restriction; portability; objection; withdrawal of consent; and information about processing. You may also complain to a competent data-protection authority or court.
Requests concerning Accounts, licensing, technical support, Website analytics or the Developer's technical records should be sent to support@patchdna.ai. If the Seller lawfully receives personal data for a future individual case under section 15, requests about those particular records should be sent to mttraidinglmt@gmail.com. A recipient may reasonably verify identity and order or Account ownership before disclosing or changing data and will respond within the applicable statutory period. No automatic transfer of a request or its underlying buyer data to the Seller takes place; any necessary case-specific disclosure requires a lawful basis and minimum-data handling under section 15.
If processing is based on legitimate interests, you may object on grounds relating to your situation. If processing is based on consent, withdrawal does not affect processing before withdrawal.
20. Account deletion
20.1. Send an Account deletion request from the verified Account email to support@patchdna.ai. Before deletion, deactivate Devices and retain any installers or records you lawfully need.
20.2. Deletion removes ordinary Account access and personal data no longer needed. It does not automatically refund a purchase.
20.3. Order, acceptance, payment, refund, security and claim records may be isolated and retained for the mandatory or justified period, with access restricted to those purposes.
21. Minors
Patch DNA Products are intended for persons who can enter into the purchase agreement themselves or act with their legal representative's authorisation. Neither the Seller nor the Developer knowingly solicits data from children below the applicable digital-consent age. If such data is identified without a lawful basis, the responsible party will delete it unless law requires retention.
22. Automated security measures
The service may automatically reject or temporarily limit a request, session or Activation after an invalid signature, revoked session, exceeded allowance, rate-limit event or credible attack indicator. These measures protect the service, do not make marketing or credit decisions, and can be reviewed by a person through support.
23. Changes
A revised Policy is published with a new version and effective date. Material changes affecting current Users will be communicated through the Website, Account, Product or email. A new purpose that requires consent will not begin until the required choice is obtained.
24. Contact
Seller, authorised distributor and advertiser: ASIA M AND T CO., LTD.
Company registration number: 0105567191935
Registered address: 11/2 P23 Building, Level 11, Soi Sukhumvit 23, Sukhumvit Road, Khongtoey Nua, Wattana, Bangkok 10110, Thailand
Sales, payment, refund and seller privacy contact: mttraidinglmt@gmail.com
International website: https://global.patchdna.ai
Technical-service controller: Individual Entrepreneur Igor Grigoryevich Molka
INN: 772377040614
OGRNIP: 321774600446241
Technical privacy and Account contact: support@patchdna.ai
Developer business contact: admin@patchdna.ai
Current Policy: https://global.patchdna.ai/en/privacy
