Software Pac Logo
Software Pac Logo
Legal

Privacy Policy

Effective August 25, 2026·Version 1.0

What we collect

Identity, account, billing, support, usage, and recruitment data — and the third-party sources it can come from.

How we use it

The purposes and GDPR / UK GDPR legal bases for processing, plus our position on selling data and automated decisions.

Your rights & choices

Access, correction, deletion, portability, and opt-out rights under GDPR / UK GDPR and U.S. state laws, and how to use them.

SoftwarePac LLC ("SoftwarePac LLC", "we", "us", or "our") provides information technology (IT) services, software-as-a-service (SaaS) products, and licensed software products supplied for installation in our customers' own environments (collectively, the "Services"). We are committed to protecting the privacy and security of personal data. This Privacy Policy describes what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights available to you.

This Policy applies to our website, our SaaS platforms, our IT and consulting engagements, and our sales, marketing, and recruitment activities. It does not apply to third-party websites or services that we do not control.

1. Our Role: Controller and Processor

Our role under data protection law depends on the context in which we handle personal data:

  • Controller: We act as a controller for personal data we determine the purposes and means of processing for — for example, information about website visitors, prospects, customer contacts, billing contacts, job applicants, and our own personnel.
  • Processor: We act as a processor (or "service provider" under U.S. state privacy laws) for personal data contained within Customer Data that our customers upload to, or that we access in the course of servicing, their systems. In those cases our customer is the controller and determines the purposes of processing. Our processing is governed by our Data Protection Policy and Data Processing Addendum, and by the applicable customer agreement.
  • Neither, for self-hosted software: Where a customer licenses our software and installs it in its own environment, that customer is the sole controller of the personal data the software processes. We do not have access to that data and do not process it, except where the customer grants us access for support or professional services — at which point we act as processor for that limited purpose, and our Data Processing Addendum applies. We do receive limited licence activation data as described in Section 2.2.

If you are an end user of a customer's system and wish to exercise your rights over data held by that customer, please contact that customer directly. We will assist our customer in responding to your request.

2. Personal Data We Collect

2.1 Information you provide to us

CategoryExamplesSource
Identity & contact dataName, job title, employer, email address, telephone number, postal addressYou / your employer
Account dataUsername, password (hashed), account preferences, permissions and role assignmentsYou
Billing & transaction dataBilling contact, billing address, purchase order details, invoice history, tax identifiers, partial payment card detailsYou / payment processor
Support & correspondence dataSupport tickets, service requests, email and chat correspondence, call notes, feedback and survey responsesYou
Customer DataAny content, files, records, or data you submit to our SaaS products or that we access while delivering IT servicesYou
Recruitment dataCV, employment and education history, references, right-to-work informationYou / recruiters

2.2 Information collected automatically

  • Usage data: Pages and features accessed, actions taken, session duration, timestamps, referring pages, and in-product navigation.
  • Device and connection data: IP address, browser type and version, operating system, device type, screen settings, language, and time zone.
  • Log and security data: Authentication events, access logs, error and diagnostic logs, and records of suspected security events.
  • Licence and activation data: Where you install our licensed software, the product may transmit product version, installation identifier, licence key status, deployment counts, and basic environment characteristics to us or our licensing provider. This is used solely to manage entitlements, validate licences, and verify compliance with the agreed licence metric. It does not include the business data you process using the software.
  • Support diagnostics: Log files, crash dumps, configuration exports, and screenshots that you choose to send us when raising a support request. These may incidentally contain personal data, and we ask that you redact or minimise them where practicable.
  • Cookies and similar technologies: Cookies, pixels, local storage, and SDKs. See our separate Cookie Policy for full details and your choices.

2.3 Information from third parties

  • Payment processors, which confirm transactions and provide limited card details (such as brand and last four digits).
  • Identity and single sign-on providers you choose to authenticate with.
  • Third-party applications you connect to our SaaS products, subject to the permissions you grant.
  • Business partners, resellers, referral sources, and publicly available business directories used for B2B marketing.
  • Fraud prevention, credit reference, and sanctions-screening providers, where lawful and proportionate.

2.4 Sensitive data

We do not seek to collect special categories of personal data (such as health, biometric, racial or ethnic origin, or trade union membership) in the ordinary course of providing the Services. You should not upload such data to our SaaS products unless expressly agreed in writing with us and covered by an appropriate Data Processing Addendum.

3. How and Why We Use Personal Data

Where the GDPR or UK GDPR applies, we rely on the legal bases identified below. Where they do not apply, the purposes below still describe our use of personal data.

PurposeLegal basis (GDPR / UK GDPR)
Providing, operating, and maintaining the Services; provisioning accounts and delivering contracted IT workPerformance of a contract
Processing payments, issuing invoices, and collecting amounts duePerformance of a contract; legal obligation
Providing customer support and responding to enquiriesPerformance of a contract; legitimate interests
Licence activation, entitlement management, and verifying compliance with agreed licence metricsPerformance of a contract; legitimate interests (protecting our intellectual property)
Sending service, security, and administrative noticesPerformance of a contract; legal obligation
Monitoring, troubleshooting, securing, and improving the ServicesLegitimate interests (operating a reliable and secure service)
Product analytics, aggregated reporting, and service developmentLegitimate interests; consent where required for analytics cookies
Direct marketing to business contacts and prospectsLegitimate interests; consent where required by local law
Preventing fraud, abuse, and unauthorised accessLegitimate interests; legal obligation
Complying with law, responding to lawful requests, and establishing or defending legal claimsLegal obligation; legitimate interests
Corporate transactions such as financing, merger, or sale of assetsLegitimate interests
Recruitment and hiringLegitimate interests; steps prior to entering a contract

Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests are not overridden by your rights and freedoms. You may request further information about that assessment by contacting us.

4. Automated Decision-Making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, including profiling. Where any automated processing is introduced that would meet this threshold, we will provide notice and, where required, obtain consent and offer the ability to request human review.

5. Marketing Communications

We may send marketing communications about our Services to business contacts and prospects. Every marketing email includes an unsubscribe link, and you may opt out at any time by using that link or by emailing info@softwarepac.com. Opting out of marketing does not stop transactional or service messages such as billing notices, security alerts, and Service change notifications, which are necessary to our relationship with you.

6. Disclosure of Personal Data

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under U.S. state privacy laws. We disclose personal data only as described below.

  • Service providers and sub-processors: Hosting and cloud infrastructure, payment processing, email delivery, analytics, customer support tooling, error monitoring, and professional advisers. Each is bound by written contract to process personal data only on our instructions and to maintain appropriate safeguards.
  • Within our group and personnel: Access is limited to personnel who need it to perform their role, subject to confidentiality obligations and role-based access controls.
  • Corporate transactions: In connection with a merger, acquisition, reorganisation, financing, or sale of assets, subject to appropriate confidentiality protections.
  • Legal and regulatory disclosure: Where required to comply with applicable law, court order, subpoena, or governmental request, or to establish, exercise, or defend legal claims. Where legally permitted, we will notify the affected customer before disclosing their Customer Data.
  • Protection of rights and safety: To protect the rights, property, or safety of SoftwarePac LLC, our customers, our personnel, or the public, including to investigate suspected fraud or security incidents.
  • With your direction or consent: Where you instruct us to share data — for example, by enabling a third-party integration — or where you have otherwise consented.

A current list of sub-processors used to deliver our SaaS products is available on request to customers, and we provide advance notice of material changes as set out in our Data Processing Addendum.

7. International Data Transfers

We are established in the United States and our primary processing takes place there. Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, we implement an appropriate transfer mechanism, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or transfers to a jurisdiction subject to an adequacy decision. Where required, we carry out a transfer impact assessment and apply supplementary technical measures such as encryption in transit and at rest. You may request a copy of the relevant safeguards by contacting us at info@softwarepac.com.

8. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, or reporting requirements. The following retention periods apply as a general guide.

CategoryRetention period
Customer Data in SaaS productsFor the term of the subscription, then deleted or returned within 30 to 90 days of termination as specified in the customer agreement
Account and contact dataDuration of the relationship, plus up to 24 months
Billing, invoice, and tax records7 years from the end of the relevant financial year
Licence and entitlement recordsDuration of the licence, plus 7 years for perpetual licences
Support tickets and correspondenceUp to 3 years from closure of the ticket
Security, audit, and access logs12 to 24 months, unless required longer for an investigation
Marketing contact dataUntil opt-out, or 24 months of inactivity, whichever is earlier
Unsuccessful job applicationsUp to 12 months, unless you consent to a longer period

Backups containing personal data are retained on a rolling cycle and are overwritten in the ordinary course. Where deletion from an active system has occurred, residual copies in backups are deleted on expiry of that cycle.

9. Information Security

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encryption in transit and at rest, role-based access control, multi-factor authentication for administrative access, network segmentation and firewalling, vulnerability management and patching, logging and monitoring, secure development practices, vendor due diligence, personnel confidentiality obligations and security training, and a documented incident response process. Further detail on our technical and organisational measures is set out in our Data Protection Policy.

No system can be guaranteed to be completely secure. You are responsible for safeguarding your account credentials and for promptly notifying us of any suspected unauthorised access.

10. Data Breach Notification

We maintain procedures to detect, investigate, and respond to personal data breaches. Where we act as a controller and a breach is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, and will notify affected individuals where the breach is likely to result in a high risk to them. Where we act as a processor, we will notify the affected customer without undue delay after becoming aware and will provide reasonable cooperation and information to support their own notification obligations.

11. Your Privacy Rights

11.1 Rights under the GDPR and UK GDPR

If you are located in the EEA, the UK, or Switzerland, you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete personal data.
  • Erase personal data in certain circumstances (the 'right to be forgotten').
  • Restrict processing in certain circumstances.
  • Object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office.

11.2 Rights under U.S. state privacy laws

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another state with comparable legislation, you may have the right to:

  • Know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom it is disclosed.
  • Request deletion of personal information, subject to statutory exceptions.
  • Request correction of inaccurate personal information.
  • Opt out of the sale or sharing of personal information, and of targeted advertising. We do not sell or share personal information as those terms are defined by these laws.
  • Limit the use and disclosure of sensitive personal information. We do not use sensitive personal information for purposes requiring such a limitation.
  • Appeal a refusal to act on your request, where your state provides an appeal right. We will inform you of the appeal process in our response.
  • Be free from discrimination for exercising any of these rights. We will not deny you Services, charge different prices, or provide a different level of service because you exercised a privacy right.

11.3 How to exercise your rights

Submit a request to info@softwarepac.com with enough information for us to verify your identity and locate your data. We will not disclose personal data in response to an unverified request. We will respond within the period required by applicable law — generally one month under the GDPR and 45 days under most U.S. state laws — and may extend that period where permitted, in which case we will tell you why. An authorised agent may submit a request on your behalf with written proof of authorisation.

12. Children's Privacy

The Services are business tools intended for use by organisations and are not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn that we have collected personal data from a child without appropriate consent, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at info@softwarepac.com.

13. Third-Party Websites and Integrations

The Services may link to or integrate with third-party websites and applications that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third party before providing personal data to it.

14. Changes to This Policy

We may update this Policy to reflect changes in our practices, technology, or legal requirements. The revised version will be posted with an updated Effective Date and version number. Where changes are material, we will provide additional notice, such as by email or an in-product notification, before they take effect. We encourage you to review this Policy periodically.

15. Contact Us

If you have questions, concerns, or complaints about this Policy or our handling of personal data, please contact us:

SoftwarePac LLC

4727 Valley View Blvd. NW #1096

Roanoke, VA 24012, United States

Email: info@softwarepac.com

We take privacy complaints seriously and will investigate and respond. If you are not satisfied with our response, you may escalate to your local supervisory authority or applicable regulator.