Merlin VA — Privacy Policy
Version 1.0 — effective 28 August 2026
Cinedon, enterprise number 0688.849.161, registered in Belgium, is the data controller for the processing described here. Contact: [email protected].
Purchases are made from our merchant of record, Stripe, trading as Link, an independent controller for the sale — shown to you at checkout as "Sold through Link". We do not receive or store your card details, and we do not invoice you.
This policy explains what we do and do not collect. It is short because we collect very little.
1. The Software does not send us your work
Merlin VA processes your footage, audio, transcripts, projects and timelines entirely on your own computer. Transcription, vision analysis, embedding, search and planning all run locally through models you install yourself. None of this material reaches us or any third party through the Software.
Licence verification is offline. The Software checks your Licence Key using a cryptographic signature on your own machine. It does not contact us to do so, it works with no network connection, and it does not report to us that you launched the application, what you did with it, or how often.
There is no analytics or telemetry in the Software. The status readouts inside the application — memory pressure, transfer rates, model residency — are computed locally and displayed to you. They are not transmitted.
2. What we do collect
2.1 When you buy a licence
Purchases are handled by our merchant of record, Stripe, trading as Link, which is the seller of record and an independent controller for the sale. The transaction is acquired by one of Stripe's acquiring affiliates — Stripe Technology Europe, Limited (Ireland) or Stripe Payments Company (United States) — depending on the transaction, and the entity for your purchase is named on your receipt. They collect what a sale requires — name, email address, billing country, and the tax and payment details needed to complete and invoice it.
We never see or store your card details.
From them we receive, and we store:
| Data | Why | Legal basis |
|---|---|---|
| Email address | To issue and re-send your Licence Key, and to notify you of updates and security issues | Performance of a contract (Art. 6(1)(b) GDPR) |
| Name | To personalise the Licence Key and your invoice | Performance of a contract |
| Country | Tax and compliance records | Legal obligation (Art. 6(1)(c) GDPR) |
| Order reference, product, amount, date | Accounting, refunds, support | Legal obligation; performance of a contract |
| The Licence Key we issued you | So we can re-send it when you lose it | Performance of a contract |
2.2 When you use our website
Our website is served from a static host behind Cloudflare. Cloudflare processes IP addresses transiently to deliver the site and protect it from attack, on the basis of our legitimate interest in keeping the site available and secure.
We do not use advertising cookies, tracking pixels, or third-party analytics.
2.3 When you sign in to your account
If you use the account area, signing in uses a magic link sent to your email address. We do not ask for, or store, a password. The session cookie is strictly necessary to keep you signed in and is exempt from consent requirements.
2.4 When you contact support
We keep the correspondence and anything you attach to it, for as long as needed to resolve your issue and to handle any follow-up. Legal basis: performance of a contract and our legitimate interest in supporting our product.
If you send us a diagnostic report, you choose to send it. The Software never transmits one by itself. Before sending, please check that it does not contain material you would rather not share — file paths can reveal client names.
3. Who we share it with
Only with processors who help us run the business, under contract and only for that purpose:
| Processor | Purpose | Where |
|---|---|---|
| Stripe, trading as Link | Payment processing, invoicing, EU VAT | Ireland (Stripe Technology Europe, Limited) or the United States (Stripe Payments Company), depending on the transaction |
| Resend | Sending your Licence Key and account emails | EU / US |
| Cloudflare | Website hosting, DNS, licence issuing infrastructure | Global CDN |
We do not sell your personal data. We do not share it for advertising. We disclose it otherwise only where legally required.
Where a processor transfers data outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
4. How long we keep it
| Data | Retention |
|---|---|
| Purchase and invoice records | 7 years — Belgian accounting law requires it |
| Licence Key and the email it is tied to | For the life of the licence, which is perpetual, so that we can re-issue it |
| Support correspondence | 2 years after the issue is closed |
| Account sessions | Until expiry, at most 30 days |
| Website logs (Cloudflare) | As per Cloudflare's retention, typically days |
5. Your rights
Under the GDPR you may access your data, have it corrected, have it erased, restrict or object to its processing, and receive it in a portable format. You may withdraw consent where processing rests on consent.
Write to [email protected]. We will respond within one month.
Two honest limits:
- - We cannot erase invoice records before the 7-year statutory period expires.
- - Erasing your email address means we can no longer re-send your Licence Key.
Your copy of the Software keeps working — verification is offline and does not depend on us — but if you later lose the key we will have no way to prove it was yours. Keep your own copy.
You may lodge a complaint with the Belgian Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels — <https://www.gegevensbeschermingsautoriteit.be>.
6. Security
Licence Keys are signed with an Ed25519 private key held in secrets storage that is not reachable from the website or the application. The Software contains only the public half and has no code path capable of signing anything.
The website is served over HTTPS with HSTS, a strict Content Security Policy, and no inline scripts. The account area is never cached and is excluded from search indexing.
If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.
7. Children
The Software is not directed at children and we do not knowingly collect data from anyone under 16.
8. Changes
We will post any change here with a new version number and effective date, and email you if the change is material.