Makion

Privacy Notice — Checkout Purchases

makion.dev · Version 1.0-launch-minimum · Effective 2026-08-16

These are the authoritative English-language terms. The Paddle Buyer Terms govern the sale itself (Paddle is the Merchant of Record); this document is provided for transparency. This notice covers checkout purchases; the separate website privacy policy covers the contact form.

The public-facing Privacy Notice for checkout buyers. The internal inventory behind it is.

Scope note: this notice covers the data Licensor holds around a checkout purchase — the consent-evidence log and the refused-order log. It does not cover data processed inside the Software on the Licensee's own infrastructure, which never reaches Licensor (EULA §14), nor content sent to an AI Provider (EULA §14.3), nor Paddle's own processing under Paddle's own privacy terms.


1. Who is responsible for your data (controller), and how to reach us

2. Data we collect directly from you

From the checkout and licence flow, as specified in :

We do not collect your IP address on any record. Acceptance is proved by the document hash + timestamp + Paddle order_id.

3. Data we receive from Paddle

When you buy through the checkout, the seller is Paddle (the Merchant of Record). Under the Paddle Data Sharing Addendum, the Shared Personal Data available to us as Supplier includes:

This notice serves as the information owed to you about that Paddle-sourced data (GDPR Article 14 — a duty the Data Sharing Addendum places on the Data Receiver). See also §10.

Apart from Paddle acting as Merchant of Record, Makion does not share buyer personal data with any other processor for this checkout flow.

4. Why we process this data, and on what legal bases

The purposes: delivering and operating your licence (delivery, redemption, updates); proving what was agreed and disclosed at your purchase; handling refunds, chargebacks and disputes; preventing fraud and purchase-and-refund abuse; keeping the tax records required of a Ukrainian private entrepreneur; and operating the geofence (EU/EEA + Switzerland + UK).

The legal bases:

5. Legitimate interests we rely on

Where the basis is legitimate interest (Art. 6(1)(f)), the interests are: proving the contract and the disclosures made; defending refund, chargeback and consumer claims; preventing fraud and purchase-and-refund abuse; keeping the records required by Ukrainian tax law; and demonstrating that the geofence is enforced. Each is supported by a documented balancing test (LIA) and a defined retention period (§8).

6. Who receives your data (processors and recipients)

7. International transfers and safeguards

Personal data submitted directly by you to Makion is processed by a Ukrainian controller subject to the applicable extraterritorial requirements of EU or UK data-protection law. Personal data disclosed by Paddle to Makion is a controller-to-controller transfer governed by the Paddle Data Sharing Addendum, including the applicable EU Standard Contractual Clauses (Module 1) and the UK Approved Addendum. The parties and applicability of those safeguards must be verified before launch.

Separately, where Makion transfers personal data out of Ukraine to its own service providers (for example non-Ukrainian hosting or email providers), that outbound transfer is governed by the Ukrainian Law No. 2297-VI cross-border-transfer regime (Art. 29) as well as by the relevant EU/UK safeguards — see §9a. The Paddle→Makion disclosure above is inbound to Makion and is not governed by Art. 29.

8. How long we keep data (retention by category)

Retention periods are purpose-derived, not indefinite:

9. Your rights, and how to complain

You have the rights mandatory data-protection law gives you — including access, rectification, erasure, restriction, portability and objection, where they apply — exercisable at [email protected]. You also have the right to lodge a complaint with a supervisory authority:

9a. Ukrainian data-protection law (Law No. 2297-VI)

Makion's controller is a Ukraine-registered private entrepreneur, so the Ukrainian Law No. 2297-VI "On Personal Data Protection" applies in parallel with the GDPR / UK GDPR, not instead of it. Under that law:

10. The Paddle data source, stated plainly

The seller for your purchase is Paddle, under the Paddle Buyer Terms. Paddle is the source of the Transaction data described in §3, and Paddle processes your data as an independent controller under its own privacy terms. Statutory withdrawal and refund rights are determined and processed under the Paddle Buyer Terms, the Paddle Refund Policy in effect at the time of the Transaction, and applicable mandatory law (Refund Policy §1).

← Back to Legal