Privacy & Cookies Policy
This policy explains what personal data KEYFORREST collects when you visit or buy from keyforrest.eu, why we collect it, who we share it with, how long we keep it, and the rights you have over it. We sell worldwide, so it covers UK, EU and other international customers.
1. Who is responsible for your data
The data controller for personal data collected through this Site is:
- Company
- ESEO SERVICES LTD
- Company no.
- 13675404 (England & Wales)
- Registered office
- 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom
- Privacy contact
- [email protected]
- Telephone
- +44 731 280 5009
The Site, the storefront and our advertising and merchant accounts are operated by ESEO SERVICES LTD, the company named above, which is the data controller for personal data collected through the Site.
We are not required to appoint a Data Protection Officer, but all privacy questions are handled directly by our management team at the address above.
2. Personal data we collect
We only collect what we need to sell you a licence and run our business.
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity & contact | Name, email address, telephone number, billing address, country | You, at checkout or registration |
| Account | Username, password (stored encrypted), order history, saved preferences | You |
| Order & transaction | Products bought, price, currency, invoice number, licence keys issued, VAT or tax number for business orders | Generated when you order |
| Payment | Payment method type, the outcome of the transaction, and a masked reference. We never receive or store your full card number — card data goes directly to our payment provider | Payment provider |
| Technical | IP address, browser and device type, operating system, language, time zone | Collected automatically |
| Usage | Pages viewed, products viewed, items added to basket, referring site, how you move through the Site | Cookies and analytics |
| Communications | Messages you send us, support tickets, contact-form and live-chat content, reviews | You |
| Fraud prevention | Risk signals relating to an order, such as address and IP consistency and payment verification results | Generated during screening |
We do not knowingly collect special category data (such as health, race, religion or political opinions), and we ask you not to send it to us.
3. Why we use it and our legal basis
Under the UK GDPR and EU GDPR we must have a lawful basis for each use of your data.
| Purpose | Data used | Legal basis |
|---|---|---|
| Processing your order and delivering your licence key | Identity, contact, order, payment | Performance of a contract |
| Managing your account and order history | Account, order | Performance of a contract |
| Customer support, refunds and complaints | Contact, order, communications | Performance of a contract |
| Screening orders for fraud and protecting cardholders | Technical, payment, fraud prevention | Legitimate interests — preventing fraud and loss |
| Issuing invoices and keeping accounting and tax records | Identity, order, tax number | Legal obligation |
| Sending marketing emails and newsletters | Contact, usage | Consent, or legitimate interests for existing customers about similar products |
| Analytics and improving the Site | Technical, usage | Consent (via cookies) |
| Advertising and measuring campaign performance | Technical, usage | Consent (via cookies) |
| Site security and abuse prevention | Technical | Legitimate interests — keeping the Site secure |
| Establishing or defending legal claims | As relevant | Legitimate interests / legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and concluded they are not. You may object at any time — see section 10.
4. Marketing and your choices
- We send marketing only where you have opted in, or where you have bought from us and we are telling you about similar products. Every message includes a one-click unsubscribe link.
- You can withdraw consent at any time by using that link, by changing your communication preferences, or by emailing [email protected].
- Withdrawing consent does not affect processing carried out before you withdrew it.
- You will still receive service messages — order confirmations, licence delivery, invoices, refund notices and security alerts. These are part of the contract and cannot be switched off while you have an active order.
- We do not sell your personal data, and we do not share it with third parties for their own independent marketing.
5. Who we share data with
We share personal data only with service providers who help us run the business, and only to the extent they need it. They act on our instructions under a written contract and may not use your data for their own purposes.
| Recipient | Purpose | Data shared |
|---|---|---|
| PayPal (incl. card payments) | Processing payments and refunds | Name, email, billing address, order value |
| Our bank | Receiving and refunding bank transfers | Name, payment reference, amount |
| Software publishers & suppliers | Issuing, verifying or replacing a licence key | Order reference and, where the publisher requires it to create or assign a licence, your name and email address |
| Amazon SES & our mail provider | Sending order, delivery and support emails | Name, email, message content |
| Mailchimp | Newsletter and marketing email delivery | Name, email, engagement data |
| Google Analytics | Understanding how the Site is used | Technical and usage data, in most cases pseudonymised |
| Google Ads & Merchant Center | Advertising, conversion measurement and product listings | Technical and usage data, conversion events |
| Cloudflare (Turnstile) | Blocking bots and abuse | IP address, technical data |
| Our hosting provider | Running and backing up the Site | All Site data, stored securely |
| Accountants & professional advisers | Accounts, tax and legal advice | Invoice and transaction records |
We may also disclose data where the law requires it, to a regulator or law enforcement body, to enforce our Terms of Use, or to protect our rights, property or safety. If our business is sold or reorganised, data may transfer to the buyer, who must continue to protect it under this policy.
6. International transfers
We are based in the United Kingdom and sell worldwide, so your data may be transferred outside your country — including to the United States, where several of our service providers are located.
Where personal data leaves the UK or EEA, we rely on one or more of the following safeguards:
- an adequacy decision by the UK Government or the European Commission covering the destination country;
- Standard Contractual Clauses, with the UK International Data Transfer Addendum where applicable;
- your explicit consent, or the transfer being necessary to perform our contract with you.
You may request a copy of the safeguard we rely on by emailing [email protected].
7. How long we keep data
| Record | Retention period |
|---|---|
| Order, invoice and accounting records | 6 years after the end of the relevant financial year (UK tax law) |
| Account details | While your account is open, then 12 months after you ask us to close it |
| Licence keys issued to you | Kept with the order record so we can re-send or verify it |
| Support tickets and correspondence | 3 years from the last contact |
| Marketing contact details | Until you unsubscribe, then suppressed on a do-not-contact list |
| Fraud prevention records | Up to 6 years where needed to prevent repeat fraud |
| Analytics and cookie data | Up to 26 months, or as set out in section 9 |
When a retention period ends we delete the data or irreversibly anonymise it so it can no longer identify you.
8. How we protect your data
- The whole Site is served over encrypted HTTPS/TLS.
- Card details are entered directly with our PCI-DSS compliant payment provider and never pass through our servers.
- Passwords are stored using a one-way cryptographic hash — we cannot read them.
- Access to customer data is restricted to staff who need it, protected by individual accounts and strong authentication.
- We run a web application firewall, bot protection and regular software updates and backups.
No system can be guaranteed completely secure, but we take these measures seriously. If a data breach occurs that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and in any event within 72 hours of becoming aware of it where the law requires.
9. Cookies and similar technologies
Cookies are small files stored on your device. We use them to keep the Site working, remember your basket, and — with your consent — to understand usage and measure advertising.
| Type | What it does | Consent | Typical life |
|---|---|---|---|
| Strictly necessary | Sign-in, shopping basket, checkout, security and bot protection. The Site cannot work without these. | Not required | Session to 12 months |
| Functional | Remembers language, currency, region and display preferences. | Consent | Up to 12 months |
| Analytics | Google Analytics — counts visits and shows how the Site is used, so we can improve it. | Consent | Up to 26 months |
| Advertising | Google Ads and similar — measures conversions and may show you relevant ads on other sites. | Consent | Up to 24 months |
Managing cookies. Where a consent banner is shown you can accept or reject non-essential cookies and change your choice at any time. You can also delete or block cookies in your browser settings — see the help pages for Chrome, Safari, Firefox or Edge. Blocking strictly necessary cookies will stop the basket and checkout from working.
You can opt out of Google Analytics across all sites using Google’s browser add-on at tools.google.com/dlpage/gaoptout, and manage ad personalisation at myadcenter.google.com.
Some browsers send a “Do Not Track” or Global Privacy Control signal. We treat a Global Privacy Control signal as a valid opt-out of advertising cookies where the law requires us to.
10. Your rights
If you are in the UK, the EEA or another region with equivalent law, you have the following rights over your personal data:
- Access — get a copy of the data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — ask us to delete data where we no longer need it. We may need to keep invoice records to meet our tax obligations.
- Restriction — ask us to pause processing while a concern is investigated.
- Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another provider.
- Object — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Complain — lodge a complaint with your data protection authority.
To exercise any right, email [email protected] from the address linked to your account. We may ask for proof of identity to make sure we do not disclose your data to someone else. We respond free of charge within one month, and will tell you if we need longer because the request is complex.
11. Rights for US residents
If you live in California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and why, to request access to it or its deletion, to correct it, and not to be discriminated against for exercising those rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising in exchange for payment. Where you reject advertising cookies, or send a Global Privacy Control signal, we do not use your data for personalised advertising.
To make a request, email [email protected] with “Privacy Request” in the subject line. An authorised agent may act for you with written permission.
12. Children
The Site is intended for adults. We do not knowingly collect personal data from anyone under 18, and orders may only be placed by adults. If you believe a child has given us personal data, contact us and we will delete it promptly.
13. Automated decision-making
Orders pass through automated fraud screening that may flag a transaction as high risk and delay or decline it. This helps protect cardholders and our business. A person always reviews an order before it is finally declined, and no order is rejected on a purely automated basis without that review. If your order was declined and you believe this was wrong, contact us and we will look at it again.
14. Changes to this policy
We review this policy regularly and may update it to reflect changes in our services or the law. The “last updated” date at the top shows when it last changed. Where a change is material, we will tell you by email or by a prominent notice on the Site before it takes effect.
15. Contact and complaints
Please contact us first with any privacy question — we would rather put things right directly.
- [email protected]
- Telephone
- +44 731 280 5009
- Controller
- ESEO SERVICES LTD (company no. 13675404)
- Post
- 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom
If you are not satisfied with our response, you may complain to your data protection authority. In the United Kingdom this is the Information Commissioner’s Office (ico.org.uk, helpline 0303 123 1113). In the EEA you may complain to the supervisory authority in your country of residence.