Last Updated: September 7, 2026
This statement outlines the comprehensive data protection framework, privacy principles, and regulatory compliance standards maintained by FastrSoft (https://fastrsoft.com) in compliance with the General Data Protection Regulation (GDPR – EU & UK), the California Consumer Privacy Act as amended by CPRA (CCPA/CPRA), and international e-commerce and merchant standards (IBC Policy).
1. Regulatory Roles: Controller vs. Processor
Understanding our data protection posture requires distinguishing between how fastrsoft.com operates and how our self-hosted software plugin (Pixel Ultimate Pro) functions.
A. FastrSoft as a Data Controller (Our Website & Licensing)
FastrSoft acts as a Data Controller with respect to personal information you submit directly to us (e.g., your account username, email address, support tickets, and license activation tokens).
B. Pixel Ultimate Pro as Self-Hosted On-Premise Software
- Zero Centralized Telemetry on Customer Orders: Pixel Ultimate Pro is an on-premise, self-hosted WordPress plugin installed directly on your web server.
- Direct Server-to-Server: When the plugin dispatches Server-Side Conversions API (CAPI) events to Meta, Google, TikTok, or Pinterest, the data travels directly from your WordPress server to the ad platform API endpoints.
- FastrSoft Never Intercepts Store Data: FastrSoft does NOT route, proxy, inspect, store, or sell your end customers’ checkout details, names, or order values on any FastrSoft central server. Your store’s end-customer data remains 100% under your sovereign control as the store’s Data Controller.
C. Paddle as Merchant of Record & Independent Data Controller
Our online reseller, Paddle.com (Paddle Payments Limited / Paddle.com Inc.), acts as an authorized Merchant of Record and an independent Data Controller for the purpose of processing customer payments, conducting anti-fraud screening, issuing invoices, and remitting statutory sales taxes.
2. Lawful Bases for Processing Under GDPR
FastrSoft processes personal data strictly under valid lawful bases established in Article 6 of the GDPR:
- Performance of a Contract (Art. 6(1)(b)): Processing necessary to execute transactions, deliver license keys, provide software downloads, verify domain activations, and deliver customer support.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary to ensure website security, protect against malicious license fraud, debug software errors, and improve product performance.
- Compliance with Legal Obligations (Art. 6(1)(c)): Retaining financial transaction tokens and tax records to comply with statutory accounting requirements.
- Consent (Art. 6(1)(a)): Processing non-essential analytics or promotional newsletters only when affirmative, explicit consent has been granted.
3. Data Subject Rights & How to Exercise Them
Under European (GDPR), United Kingdom (UK GDPR), and California (CCPA/CPRA) regulations, consumers possess statutory privacy rights:
| Statutory Right | Description | How FastrSoft Honors This Right |
|---|---|---|
| Right of Access | Request confirmation of data processing and a complete copy of stored personal data. | Provided within 30 days upon email request. |
| Right to Rectification | Correct inaccurate or incomplete personal information. | Editable directly via your FastrSoft Account or by contacting support. |
| Right to Erasure (“Forgotten”) | Request deletion of your account and personal records. | Account and activation telemetry permanently purged, excluding statutory tax records. |
| Right to Restrict Processing | Restrict how your personal data is utilized during disputes. | Implemented immediately upon formal verified request. |
| Right to Data Portability | Receive your data in a structured, commonly used JSON or CSV format. | Dispatched to your verified email within 30 days. |
| Right to Object | Object to processing based on legitimate interests or direct marketing. | One-click unsubscribe links in all marketing emails; instant objection handling. |
| Right to Non-Discrimination | Exercise privacy rights without denial of service or unfair pricing. | Guaranteed: equal pricing, service, and support regardless of rights exercised. |
To submit a data subject privacy request, email our compliance desk at support@fastrsoft.com with the subject line Data Privacy Request.
4. International Data Transfers & Standard Contractual Clauses (SCCs)
Because FastrSoft serves software users globally, personal data may be processed in countries outside the European Economic Area (EEA).
Where cross-border data transfers occur:
- Transfers to Paddle and our cloud infrastructure providers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
- Encryption in transit (TLS 1.3) and encryption at rest (AES-256) are strictly enforced.
5. Third-Party Sub-Processors
| Sub-Processor | Role / Function | Location / Safeguard |
|---|---|---|
| Paddle.com | Merchant of Record, Payment Gateway, Invoicing, Tax Remittance | UK / USA (PCI-DSS Level 1, SCCs) |
| Cloud Hosting Infrastructure | Web Server Hosting, Automated License Validation API | Global Edge (SOC 2, ISO 27001) |
| Transactional Email Services | Order confirmation and license delivery notifications | USA / EU (GDPR Compliant, SCCs) |
6. Contact Data Protection & Compliance
If you have questions regarding our GDPR posture, international compliance, or consumer data rights, please contact our compliance officer:
- Company Name: FastrSoft
- Website: https://fastrsoft.com
- Compliance Email: support@fastrsoft.com
- Official Phone: +8801619-009211
- Physical Business Address: Kawkhali – Pirojpur, 1205, Bangladesh
- Paddle Data Protection Officer: dpo@paddle.com