Privacy policy
Version in force since 28 August 2026.
1. Who processes your data
The data controller is UKTO — Sébastien DUBOIS, sole trader registered in France, SIRET 501 724 132 00037, 59 rue de Ponthieu, Bureau 326, 75008 Paris.
For any question, or to exercise your rights: ukto@lyonpoker.com.
Given its size and the nature of its processing, UKTO is not required to appoint a data protection officer. Requests are handled directly by Sébastien DUBOIS.
This English text is a translation provided for convenience. In the event of any discrepancy, the French version at ukto.fr/confidentialite.php prevails.
2. What we never receive
This is the most important point for users of our plugin.
The Invoice Sync for Pennylane plugin runs on your own server. Your order, customer and invoice data travels directly from your shop to your Pennylane account. It does not pass through our servers and we have no access to it.
The only information the plugin sends us is your licence key and your site address, to check that the licence is valid and to deliver updates. Nothing else.
Towards your own customers, you are therefore the data controller and Pennylane your processor. We are neither.
3. The processing we carry out
| Context | Data | Purpose and legal basis | Retention |
|---|---|---|---|
| Contact form | Name, email address, message content | Answering your enquiry — pre-contractual steps or legitimate interest in responding | 3 years after the last exchange |
| Pro version purchase | Name, email address, company, billing address, country, VAT number, transaction amount and date | Performing the sales contract; issuing and keeping invoices — performance of the contract and legal obligation | Accounting records: 10 years (art. L123-22 of the French Commercial Code) |
| Licence management | Licence key, email, name, country, VAT number, status, expiry date, Stripe customer and subscription identifiers | Delivering updates and support for the subscribed period — performance of the contract | Term of the contract, then 3 years |
| Activation on a site | WordPress site address, first activation date, last check date | Checking licence validity and enforcing the one-site limit — performance of the contract and legitimate interest in preventing key sharing | Term of the contract, then 3 years |
| Licence server technical log | Event type (activation, download, refusal…), key concerned, IP address, timestamp | Security, abuse prevention, diagnostics — legitimate interest | 12 months |
| Host access logs | IP address, pages visited, timestamp | Security and correct operation of the website — legitimate interest | Standard period applied by the host |
We carry out no profiling and no automated decision-making producing legal effects concerning you.
4. Cookies and analytics
This website sets no cookies for analytics, advertising or tracking. No consent banner is therefore needed.
The payment page and the customer portal, however, are hosted by Stripe on its own domains: Stripe sets there the cookies necessary for payment and fraud prevention, under its own policy.
5. Who else sees this data
We do not sell, rent or trade any personal data. The only third parties involved are our technical providers, strictly within their remit:
- Stripe Payments Europe, Limited (Ireland) — payment collection, subscriptions, invoicing and customer portal. Card details are processed by Stripe alone: we never have access to them.
- IONOS SARL (7 place de la Gare, BP 70109, 57201 Sarreguemines Cedex, France) — hosting of the website and of the licence server, in France.
Data may further be disclosed to our accountant and, upon a lawful request, to the tax authorities or a judicial authority.
6. Transfers outside the European Union
The website, the licence server and the database are hosted in France. We make no transfers outside the EU ourselves.
Stripe, as part of its global payment business, may transfer certain data to third countries, including the United States. Such transfers are framed by the mechanisms set out in Chapter V of the GDPR (standard contractual clauses and, where applicable, the EU–US Data Privacy Framework). Details are in Stripe's own privacy policy.
7. Security
Exchanges with the website and the licence server are encrypted over HTTPS. The licence database is not reachable from the web, the administration console is protected by a secret token, and payment notifications are authenticated by cryptographic signature before being accepted. We store no card data.
8. Your rights
Under the conditions set out in the GDPR, you have rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions on the fate of your data after your death.
To exercise them, write to ukto@lyonpoker.com. We reply within one month. Some data cannot be erased before its legal retention period ends: invoices, in particular, must be kept for ten years.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
9. Changes
This policy may change, in particular if a new processing activity or a new provider appears. The version date is shown at the top of the page. Licensed customers are informed by email of any significant change affecting them.