Last updated: 24 July 2026
This Privacy Policy explains how IDEA TERMINAL S.R.L. (“IDEA TERMINAL”, “MQLDevelopers”, “we”, “us” or “our”) processes personal data in connection with the MQLDevelopers website, user accounts, online shop, customer support, developer services and software licensing platform.
1. Data controller and contact details
The data controller is:
IDEA TERMINAL S.R.L.
Registered office: Str. Pantei, Nr. 40, 535600 Odorheiu Secuiesc, Harghita County, Romania
Unique Registration Code (CUI): RO34843319
Trade Register Number: J2015000234191
Email: office@mqldevelopers.com
Website: https://mqldevelopers.com/
IDEA TERMINAL has not appointed a Data Protection Officer. Privacy questions and data protection requests may be sent to the email address above.
2. Scope and our data protection roles
This Privacy Policy applies to personal data processed in connection with:
- requesting, activating and managing an MQLDevelopers account;
- purchasing products, subscriptions and services through the online shop;
- using customer, developer and licensing dashboards;
- validating and administering software licences;
- contacting customer support by support ticket or email;
- operating, securing, maintaining and improving the website and services.
For MQLDevelopers users, customers and external developers who create an account directly with us, IDEA TERMINAL generally acts as the data controller.
Where an external developer uses MQLDevelopers to license software for that developer’s own end users, the external developer generally determines the licensing method and purpose and acts as the data controller. IDEA TERMINAL generally processes the relevant end-user technical identifiers on the external developer’s behalf as a data processor. IDEA TERMINAL may act as an independent controller for limited security, abuse-prevention, service-integrity and legal-claim records processed for its own legitimate purposes.
3. Personal data we process, purposes and legal bases
3.1 Account registration and activation
Anyone may request a basic account by providing an email address and completing the required age and Terms and Conditions confirmations. We process:
- email address;
- registration and activation status;
- activation and password-setup tokens;
- registration, activation and acceptance timestamps;
- the accepted Terms and Conditions version and related acceptance record;
- limited technical and security data associated with the request.
The password-setup link is valid for 24 hours. If a new link is requested, previously issued password-setup links are invalidated. The account becomes usable only after the user successfully sets a password.
This processing is necessary to take steps requested by the user before entering into a contract, to create and perform the user-account agreement, and to protect the legitimate interests of IDEA TERMINAL and its users in account security and abuse prevention.
3.2 Passwords and authentication
User passwords are not stored in readable form. They are securely hashed by the WordPress authentication system. Authorised administrators cannot retrieve or view the user’s original password. A forgotten password must be reset rather than recovered.
3.3 Account management, roles and profile visibility
MQLDevelopers uses a single account system. Depending on the selected services, an account may receive customer, developer or other service-related permissions. Account data may include the email address, internal user identifier, role, permissions, account status, subscription status and security-related account events.
MQLDevelopers accounts and profile information are not publicly listed. Users cannot view the profiles or account information of other users. Account information is accessible only to the account holder, authorised members of IDEA TERMINAL’s management and authorised service providers where necessary.
Users may update certain account information, including their email address, through the account settings. A change of account email may also update the billing email associated with the customer account. Email addresses stored in completed historical orders are not changed retrospectively.
3.4 Orders, subscriptions, billing and invoicing
When a user purchases a product, subscription or service, we may process:
- customer type (individual or company);
- first and last name or contact-person name;
- company legal name;
- tax identification number, company registration number and EU VAT number where applicable;
- billing country, address, city, county/state and postcode;
- email address and voluntarily provided telephone number;
- order notes voluntarily submitted by the customer;
- products, subscriptions, prices, currency, discounts, taxes, order status and transaction history;
- invoice, refund, cancellation, dispute and chargeback information.
We process these data to conclude and perform the purchase or subscription contract, provide the purchased service, issue invoices, administer subscriptions and refunds, comply with accounting and tax obligations, prevent fraud and establish, exercise or defend legal claims.
3.5 Payment processing through Stripe
Payments are processed through Stripe. Payment information necessary to complete and authenticate the transaction is transmitted to Stripe. IDEA TERMINAL does not store the customer’s full payment-card number or card security code.
We may receive and store limited payment-related information, including the amount, currency, status, payment method type, transaction date, Stripe customer/payment identifiers, masked card details such as brand and last four digits, and information about failed payments, refunds, disputes or chargebacks.
Stripe processes personal data under its own privacy and data processing terms and may act as a processor or an independent controller depending on the relevant processing activity.
3.6 Licensing for software sold directly by IDEA TERMINAL
For software sold directly by IDEA TERMINAL, we may process account and licence information required to provide and validate the purchased licence, including:
- customer and internal account identifiers;
- licence, product and subscription identifiers;
- Account ID or Machine ID, depending on the selected licensing method;
- licence status, activation limit, activation, expiration, reset, suspension, deletion and modification records;
- timestamps, validation results and technical error information.
This processing is necessary to perform the contract, provide the licensed software, prevent unauthorised use and protect the legitimate interests of IDEA TERMINAL in administering and securing its licensing service.
3.7 Data processed for external developers’ end users
External developers determine whether their software uses Account ID or Machine ID based licensing:
- an Account ID is submitted by the external developer or the licensed software;
- a Machine ID is generated automatically on the end user’s device by the licensing module and used as a technical identifier.
The licensing API does not provide fields for an end user’s name, email address or billing information. Depending on the implementation, the platform may process:
- Account ID or Machine ID;
- developer, product, licence and subscription identifiers;
- licence configuration, status, limits and expiration;
- activation, reset, update, suspension and deletion records;
- timestamps, validation results, IP addresses, masked tokens, response codes and technical errors.
The external developer is responsible for selecting the licensing method, establishing a lawful basis, informing its end users and complying with applicable data protection obligations. IDEA TERMINAL processes the technical identifiers to provide, secure, maintain and document the licensing service.
3.8 Customer support and email communications
Support tickets may be submitted only by authenticated MQLDevelopers users. Persons without an account may contact us by email at office@mqldevelopers.com.
We may process the account identifier, email address, ticket or email content, subject, timestamps, status, related correspondence and information reasonably necessary to investigate and resolve the request. Support tickets are visible only to the user who submitted the ticket and authorised administrators. They are not accessible to other users.
Business, customer-service and support email is processed through Google Workspace. Email data may include sender and recipient details, subject, content, timestamps, technical email metadata and attachments voluntarily sent by email.
Support and email data is processed to perform or prepare a contract, provide the requested service, administer customer relationships, protect service security and pursue the legitimate interests of IDEA TERMINAL in documenting and resolving requests and disputes.
3.9 Customer relationship management
We use Jetpack CRM within our WordPress environment to organise customer and business relationships. WooCommerce customer and order information may be synchronised automatically with Jetpack CRM. CRM records may include contact and company details, billing and order information, transaction history, customer status and related administrative records.
Authorised administrators may add internal notes where reasonably necessary to document communications, requests, contractual matters, support history or other legitimate business interactions. Such notes are not public and must not be used to store passwords, full payment-card details or irrelevant sensitive information.
Jetpack CRM data is stored in the database connected to our WordPress website and follows the retention period applicable to the underlying customer, order, support or contractual record.
3.10 Technical, API, security and audit logs
We maintain logs to operate and secure the website and licensing platform, apply request limits, detect automated abuse and denial-of-service attacks, investigate unauthorised access, diagnose errors, document licence operations and establish, exercise or defend legal claims.
Logs may include:
- IP address, timestamp and requested resource or API endpoint;
- browser, user-agent, device and technical request information;
- developer, product, licence, Account ID or Machine ID references;
- masked developer, control or licence tokens;
- request and response information, response codes and technical error messages;
- account, licence and administrative security events.
Authentication tokens are masked so that the original token cannot reasonably be reconstructed from the log. Passwords, password-reset tokens, complete authentication secrets, complete payment-card details, card security codes and reCAPTCHA verification tokens are not intentionally recorded.
This processing is based on our legitimate interests in maintaining the confidentiality, integrity, availability, security and evidentiary reliability of the services.
3.11 Automated tax calculation
Where automated tax calculation is enabled, WooCommerce Tax services provided by Automattic may process information such as billing location, order contents and transaction amount to determine applicable taxes and administer the purchase. The processing is necessary to perform the transaction and comply with legal and tax obligations.
3.12 Website analytics
Where enabled, we may use Jetpack Stats, provided by Automattic, to understand website use and improve performance, content and services. Jetpack Stats may process information such as IP address, user agent, visited and referring URLs, event timestamp, browser language, country code and, where available, WordPress.com user identifiers.
Optional analytics is controlled through the website’s consent settings and is used only where the required consent has been provided. Automattic states that identifiable Jetpack Stats logs containing IP addresses and available WordPress.com usernames are retained for 28 days. We generally receive aggregated statistics rather than direct access to visitor IP addresses through the Stats interface.
3.13 Google reCAPTCHA
We use Google reCAPTCHA on selected forms and security-sensitive interactions to distinguish human users from automated access and to prevent spam, fraudulent registrations, credential attacks and other abuse.
When reCAPTCHA is loaded, Google may process technical and interaction data required for risk analysis, such as IP address, browser and device information, page and interaction information, and verification tokens. A protected form may be unavailable if reCAPTCHA cannot be loaded or successfully completed. Where consent is required for the relevant technology, reCAPTCHA is managed through the website’s consent settings.
3.14 Google Fonts
The website currently uses fonts loaded from Google Fonts servers. When a font is requested from Google, the visitor’s browser connects to Google domains such as fonts.googleapis.com and fonts.gstatic.com. This connection may transmit the visitor’s IP address, browser information, requested resource, referring page and request timestamp to Google. Google states that the Google Fonts Web API does not set or log cookies for this purpose.
Where required by applicable law, third-party font loading is managed through the website’s consent settings.
3.15 Cookies and similar technologies
We use necessary cookies and similar technologies to operate and secure the website and provide requested functions. Optional preference, statistics, marketing and third-party technologies are managed through the consent banner.
Detailed information about cookies, services, purposes and durations is available in our Cookie Policy (EU). Users can change or withdraw optional consent through the “Privacy settings” or “Manage consent” control available on the website.
4. Automated licence verification
The licensing service automatically verifies whether a submitted technical identifier corresponds to an active and valid licence. Use of licensed software may be automatically denied where, for example:
- the licence has expired, has been suspended or deleted;
- the permitted activation limit has been exceeded;
- the submitted Account ID or Machine ID does not match the licence configuration;
- the related subscription or contractual entitlement is no longer active.
These checks apply predefined technical and contractual rules. They are not used to evaluate personal characteristics or create behavioural profiles.
For software sold directly by IDEA TERMINAL, the customer may manage or reset supported licence identifiers through the available account interface. For software supplied by an external developer, the external developer controls the relevant licence settings and may update them through the developer dashboard or API. The external developer’s end user should contact that developer regarding licence changes or access problems.
MQLDevelopers support may investigate suspected technical errors, incorrect data or service malfunctions but does not routinely modify licence assignments manually outside the provided dashboard and API functions.
5. Recipients and service providers
Personal data may be disclosed only where necessary and proportionate to:
- Akamai Cloud (formerly Linode), for server hosting, infrastructure and backups. The primary server region is Frankfurt, Germany;
- Stripe, for payment processing, fraud prevention, refunds, disputes and chargebacks;
- Google Workspace, for business, customer-service and support email;
- Google, where Google reCAPTCHA or externally hosted Google Fonts are used;
- Automattic / Jetpack / WooCommerce services, where enabled for analytics, automated tax calculation or other connected functions;
- our external accountant, accounting service providers and tax advisers in Romania, for accounting, invoicing and tax compliance;
- legal, security, technical or professional advisers where necessary;
- courts, regulators, tax authorities, law-enforcement bodies or other competent authorities where disclosure is required by law or a legally binding request.
Service providers receive only the information necessary for their role and are subject to applicable contractual, confidentiality and data protection obligations.
6. International data transfers
The MQLDevelopers website, licensing platform, databases and associated backups are primarily hosted in Akamai Cloud’s Frankfurt, Germany region within the European Economic Area.
Some service providers, affiliates or subprocessors may process personal data outside the European Economic Area. Where required, international transfers are protected by an adequacy decision, the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, together with supplementary safeguards where appropriate.
7. Data retention
We retain personal data only for as long as necessary for the relevant purpose, contract, legal obligation, security requirement or legal claim. The following periods generally apply:
| Data category | General retention period |
|---|---|
| Unactivated account request | Deleted if activation is not completed within 30 days. A password-setup link expires after 24 hours. |
| Active user account | For as long as the account, service, subscription, licence, purchase entitlement or related contractual relationship remains active or is otherwise needed. |
| Inactive account without an active entitlement | Generally up to 3 years of complete inactivity. We may provide at least 30 days’ notice before deleting or anonymising account data. |
| Orders, invoices, accounting and tax records | For the period required by Romanian accounting and tax law, generally 5 years calculated from 1 July of the year following the financial year in which the records were created, or longer where another legal requirement or legal claim applies. |
| Support tickets and customer-service emails | Generally up to 3 years after closure or the last relevant communication. Records connected with an unresolved complaint, dispute or legal claim may be kept longer where necessary. |
| Detailed technical, access, API and debugging logs | Generally up to 90 days, unless a record is required for a detected incident, suspected fraud, abuse, dispute or legal claim. |
| Active licence records | For the duration of the licence, account, subscription or contractual relationship and as long as necessary to provide and administer the licence. |
| Deleted external end-user licence identifiers | A deleted licence is initially deactivated through soft deletion. The related Account ID or Machine ID may remain in active systems for up to 90 days for recovery, recent-dispute handling and misuse investigation, after which unnecessary end-user identifiers are deleted or irreversibly anonymised. |
| Limited licensing audit records | Up to 5 years where necessary to document previous operations, resolve disputes or establish, exercise or defend legal claims. Long-term audit records are minimised and should not retain unnecessary end-user identifiers. |
| Jetpack Stats identifiable logs | Automattic states that identifiable Stats logs are retained for 28 days. Aggregated statistics that do not directly identify a visitor may be retained for longer. |
| Backups | Personal data deleted from active systems may remain in backup copies for up to 12 months. Backups are used only for disaster recovery, security and system restoration and are deleted or overwritten within the applicable rotation cycle. |
If a backup is restored, previously completed deletions and retention rules are reapplied as soon as reasonably practicable. A legal hold, security incident, complaint, payment dispute or legal proceeding may require relevant records to be retained until the matter is finally resolved and for any additional applicable limitation period.
8. Data security and access control
We apply appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.
Access to personal data is restricted to authorised members of IDEA TERMINAL’s management and authorised service providers who require access for their responsibilities. Separate administrator accounts are used, and personal data must be handled confidentially and only for authorised purposes.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security, but we review and improve safeguards in light of the nature of the data, available technology and relevant risks.
9. Your data protection rights
Subject to the conditions and limitations of applicable law, you may have the right to:
- obtain confirmation whether we process your personal data and receive access to it;
- request correction of inaccurate or incomplete personal data;
- request deletion of personal data that is no longer required;
- request restriction of processing;
- receive eligible data in a structured, commonly used and machine-readable format and request portability;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- submit a complaint to a competent data protection authority.
Users may update certain account details through their account settings. Account deletion, access, portability and other privacy requests may be submitted through a support ticket or by emailing office@mqldevelopers.com, preferably from the email address associated with the account.
We may request information reasonably necessary to verify the requester’s identity and protect data against unauthorised disclosure or deletion. We generally respond without undue delay and within one month. Where permitted by law, this period may be extended for complex or multiple requests.
Deletion is not absolute. We may retain information where necessary to comply with legal obligations, perform an active contract, protect security, resolve disputes or establish, exercise or defend legal claims.
10. Age restriction
MQLDevelopers accounts, purchases and developer services are intended only for persons who are at least 18 years old and legally capable of entering into the applicable agreement. A person acting for a company must also be authorised to bind or represent that company.
We do not intentionally offer accounts or services to children and do not request a date of birth. If we become aware that an account was created in breach of this age restriction, we may suspend or delete the account and associated data, subject to legal retention obligations.
11. Service communications, marketing and sale of data
We currently send account activation, password reset, order, payment, subscription, licence, security and support communications necessary to provide and administer the services.
We do not currently operate a newsletter or send promotional marketing emails. If this changes, we will update this Privacy Policy and obtain consent where required before sending marketing communications.
IDEA TERMINAL does not sell or rent personal data and does not disclose personal data to third parties for their own independent marketing purposes.
12. Changes to this Privacy Policy
We may update this Privacy Policy when our services, providers, processing activities or legal obligations change. The current version will be published on this page with an updated revision date. Where a change materially affects users, we may also provide an account or email notice where appropriate.
13. Contact and complaints
For questions, requests or concerns regarding personal data, contact:
IDEA TERMINAL S.R.L.
Email: office@mqldevelopers.com
You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania
Website: https://www.dataprotection.ro/
Email: anspdcp@dataprotection.ro
