← Merlin VA

Merlin VA — Privacy Policy

Version 1.0 — effective 28 August 2026

Cinedon, enterprise number 0688.849.161, registered in Belgium, is the data controller for the processing described here. Contact: [email protected].

Purchases are made from our merchant of record, Stripe, trading as Link, an independent controller for the sale — shown to you at checkout as "Sold through Link". We do not receive or store your card details, and we do not invoice you.

This policy explains what we do and do not collect. It is short because we collect very little.


1. The Software does not send us your work

Merlin VA processes your footage, audio, transcripts, projects and timelines entirely on your own computer. Transcription, vision analysis, embedding, search and planning all run locally through models you install yourself. None of this material reaches us or any third party through the Software.

Licence verification is offline. The Software checks your Licence Key using a cryptographic signature on your own machine. It does not contact us to do so, it works with no network connection, and it does not report to us that you launched the application, what you did with it, or how often.

There is no analytics or telemetry in the Software. The status readouts inside the application — memory pressure, transfer rates, model residency — are computed locally and displayed to you. They are not transmitted.


2. What we do collect

2.1 When you buy a licence

Purchases are handled by our merchant of record, Stripe, trading as Link, which is the seller of record and an independent controller for the sale. The transaction is acquired by one of Stripe's acquiring affiliates — Stripe Technology Europe, Limited (Ireland) or Stripe Payments Company (United States) — depending on the transaction, and the entity for your purchase is named on your receipt. They collect what a sale requires — name, email address, billing country, and the tax and payment details needed to complete and invoice it.

We never see or store your card details.

From them we receive, and we store:

Data Why Legal basis
Email addressTo issue and re-send your Licence Key, and to notify you of updates and security issuesPerformance of a contract (Art. 6(1)(b) GDPR)
NameTo personalise the Licence Key and your invoicePerformance of a contract
CountryTax and compliance recordsLegal obligation (Art. 6(1)(c) GDPR)
Order reference, product, amount, dateAccounting, refunds, supportLegal obligation; performance of a contract
The Licence Key we issued youSo we can re-send it when you lose itPerformance of a contract

2.2 When you use our website

Our website is served from a static host behind Cloudflare. Cloudflare processes IP addresses transiently to deliver the site and protect it from attack, on the basis of our legitimate interest in keeping the site available and secure.

We do not use advertising cookies, tracking pixels, or third-party analytics.

2.3 When you sign in to your account

If you use the account area, signing in uses a magic link sent to your email address. We do not ask for, or store, a password. The session cookie is strictly necessary to keep you signed in and is exempt from consent requirements.

2.4 When you contact support

We keep the correspondence and anything you attach to it, for as long as needed to resolve your issue and to handle any follow-up. Legal basis: performance of a contract and our legitimate interest in supporting our product.

If you send us a diagnostic report, you choose to send it. The Software never transmits one by itself. Before sending, please check that it does not contain material you would rather not share — file paths can reveal client names.


3. Who we share it with

Only with processors who help us run the business, under contract and only for that purpose:

Processor Purpose Where
Stripe, trading as LinkPayment processing, invoicing, EU VATIreland (Stripe Technology Europe, Limited) or the United States (Stripe Payments Company), depending on the transaction
ResendSending your Licence Key and account emailsEU / US
CloudflareWebsite hosting, DNS, licence issuing infrastructureGlobal CDN

We do not sell your personal data. We do not share it for advertising. We disclose it otherwise only where legally required.

Where a processor transfers data outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.


4. How long we keep it

Data Retention
Purchase and invoice records7 years — Belgian accounting law requires it
Licence Key and the email it is tied toFor the life of the licence, which is perpetual, so that we can re-issue it
Support correspondence2 years after the issue is closed
Account sessionsUntil expiry, at most 30 days
Website logs (Cloudflare)As per Cloudflare's retention, typically days

5. Your rights

Under the GDPR you may access your data, have it corrected, have it erased, restrict or object to its processing, and receive it in a portable format. You may withdraw consent where processing rests on consent.

Write to [email protected]. We will respond within one month.

Two honest limits:

Your copy of the Software keeps working — verification is offline and does not depend on us — but if you later lose the key we will have no way to prove it was yours. Keep your own copy.

You may lodge a complaint with the Belgian Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels — <https://www.gegevensbeschermingsautoriteit.be>.


6. Security

Licence Keys are signed with an Ed25519 private key held in secrets storage that is not reachable from the website or the application. The Software contains only the public half and has no code path capable of signing anything.

The website is served over HTTPS with HSTS, a strict Content Security Policy, and no inline scripts. The account area is never cached and is excluded from search indexing.

If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.


7. Children

The Software is not directed at children and we do not knowingly collect data from anyone under 16.


8. Changes

We will post any change here with a new version number and effective date, and email you if the change is material.