Privacy Policy
This policy explains what personal data KeyForrest collects, why we collect it, who we share it with, how long we keep it and what rights you have. It is written to meet the requirements of the UK GDPR and the Data Protection Act 2018, and we have tried to make it genuinely readable rather than merely compliant.
- Effective from: 22 August 2026
- Last reviewed: 22 August 2026
- Version: 3.0
- Data controller: ESEO SERVICES LTD
The short version
- We collect only what we need to sell you software licences, deliver them, support you and meet our legal obligations.
- We never sell your personal data and we do not share it for anyone else’s marketing.
- Marketing emails are sent only where you have opted in or bought from us before, and every one has a one‑click unsubscribe.
- We never see or store your full card number — payments are handled by regulated providers.
- You can ask for a copy of your data, correct it, or ask us to delete it, and we respond within one month.
- You can complain to the UK Information Commissioner’s Office at any time, free of charge.
Contents
- Who we are and how to contact us
- Scope of this policy
- Personal data we collect
- Where we get your data from
- How and why we use your data
- Our legitimate interests explained
- Marketing and your choices
- Cookies and similar technologies
- Who we share your data with
- Sending data outside the UK
- How long we keep your data
- How we keep your data secure
- Automated decision-making and fraud screening
- Your rights
- How to exercise your rights
- Children
- Changes to this policy
- Complaints to the ICO
1. Who we are and how to contact us
ESEO SERVICES LTD, trading as KeyForrest, is the data controller for the personal data described in this policy. That means we decide what data is collected and why, and we are legally responsible for it.
We are registered in England and Wales under company number 13675404, with our registered office at 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom.
For any question about this policy or about how we handle your data, contact our privacy team at [email protected], marking your message “Data protection”, or write to us at the registered office address above.
2. Scope of this policy
This policy covers personal data we process when you visit keyforrest.co.uk, place an order, create an account, contact our support team, subscribe to marketing, or interact with us in any other way.
It does not cover the privacy practices of software publishers whose products we resell. When you activate a licence key, or receive a licence assigned to your own publisher account, you enter into a relationship directly with the publisher (for example Microsoft, Adobe or Autodesk) and their own privacy notice will apply to any data you give them. It also does not cover third‑party websites we link to.
3. Personal data we collect
| Category | What it includes | When we collect it |
|---|---|---|
| Identity data | First and last name, and company name if you buy as a business | At checkout or registration |
| Contact data | Email address, billing address, telephone number | At checkout, registration or when you contact us |
| Order data | Products bought, order number, order date, licence keys issued or licences assigned, invoices, delivery records, correspondence about the order | When you buy |
| Payment data | Payment method type, the last four digits and expiry of a card, the transaction reference and authorisation result. We do not receive or store your full card number or security code. | At checkout |
| Account data | Username, securely hashed password, saved addresses, wishlist, subscription status, communication preferences | If you create an account |
| Support data | Emails, contact form messages, chat transcripts, activation error reports and screenshots you send us | When you contact us |
| Technical data | IP address, browser type and version, device type, operating system, time zone, language settings | Automatically when you visit |
| Usage data | Pages viewed, products viewed, search terms, referring website, time spent, cart and checkout progress | Automatically, subject to your cookie choices |
| Marketing data | Whether you have consented to marketing, which emails you opened or clicked, and your unsubscribe status | When you subscribe or interact with our emails |
| Fraud prevention data | Risk scores from our payment providers, IP geolocation, billing and delivery mismatches, order pattern indicators | At checkout |
We do not deliberately collect any special category data — such as data about health, ethnicity, religion, political opinions, trade union membership, sex life or sexual orientation — and we ask that you do not send it to us. If you do include it in a support message we will delete it once the query is resolved.
4. Where we get your data from
- Directly from you, when you order, register, contact us, leave a review or subscribe.
- Automatically, through cookies and similar technologies when you use the site — see section 8.
- From our payment providers, who give us the outcome of a payment, a fraud risk indicator and limited card metadata.
- From analytics and advertising partners, in aggregated or pseudonymised form, and only where you have consented to those cookies.
5. How and why we use your data
UK data protection law requires us to have a lawful basis for everything we do with your data. The table below sets out each purpose, the data involved, the lawful basis we rely on, and how long the data is kept.
| What we do | Data used | Lawful basis | Retention |
|---|---|---|---|
| Process your order and deliver your licence | Identity, contact, order, payment | Performance of a contract with you | 6 years from the end of the tax year of purchase |
| Take payment and manage refunds | Payment, order, identity | Performance of a contract; legal obligation | 6 years |
| Issue and store invoices and keep accounting records | Identity, contact, order, payment | Legal obligation (Companies Act 2006 and UK tax law) | 6 years from the end of the accounting period |
| Provide customer support and handle claims under our returns policy | Support, order, identity, contact | Performance of a contract; legitimate interests | 3 years from the last contact |
| Manage your account | Account, identity, contact | Performance of a contract | Until you close the account, then 12 months |
| Manage subscriptions and take renewal payments | Account, payment, order | Performance of a contract | For the life of the subscription, then 6 years |
| Send service messages such as order confirmations, delivery emails and renewal reminders | Contact, order | Performance of a contract | As for the underlying order |
| Send marketing emails about similar products | Contact, marketing, order | Consent, or legitimate interests under the soft opt-in for existing customers | Until you unsubscribe, then a suppression record indefinitely |
| Prevent and detect fraud and unauthorised transactions | Fraud prevention, payment, technical, order | Legitimate interests; legal obligation | 6 years |
| Measure and improve how the website performs | Usage, technical | Consent, through analytics cookies | Up to 14 months in aggregated form |
| Advertise our products, including through Google Ads and Google Shopping | Usage, technical, marketing | Consent, through advertising cookies | Up to 13 months |
| Publish and moderate reviews | Identity, support | Consent; legitimate interests | Until you ask us to remove it |
| Keep our site and systems secure | Technical, account | Legitimate interests; legal obligation | Security logs, 12 months |
| Establish, exercise or defend legal claims | Any relevant category | Legitimate interests; legal obligation | 6 years from the end of the matter |
If we ever need to use your data for a purpose not described here, we will tell you and explain the lawful basis before we do so.
6. Our legitimate interests explained
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that our use is proportionate and would be within your reasonable expectations. In summary:
- Fraud prevention — digital licence keys are a frequent target for card fraud. Screening protects genuine customers from having their cards misused and protects us from loss.
- Customer support records — keeping a history of a query lets us resolve a repeat issue quickly and evidences how a claim was handled.
- Service improvement and security — understanding how the site is used and monitoring for attacks keeps it working and safe.
- Marketing to existing customers — telling a customer about a similar product, where they can opt out at any time and in every message.
You have the right to object to any processing based on legitimate interests. See section 14.
7. Marketing and your choices
We send marketing emails only if you have opted in, or if you have bought from us before and we are telling you about similar products. This is the “soft opt‑in” permitted by the Privacy and Electronic Communications Regulations 2003.
Every marketing email contains an unsubscribe link that works immediately. You can also update your preferences at Communication Preferences or in My Account, or email us. Opting out of marketing does not stop service messages such as order confirmations, delivery emails, renewal reminders or security notices — we have to send those to perform our contract with you.
When you unsubscribe we keep a minimal suppression record — normally just your email address and the date — so that we do not accidentally contact you again. That record is kept for as long as we operate.
8. Cookies and similar technologies
We use cookies and similar technologies to make the site work, to remember your basket, to understand how the site is used, and to measure our advertising. Only the strictly necessary cookies are required: everything else is optional, and you can refuse or remove those cookies at any time using the browser settings and opt‑out tools described in our Cookie Policy.
Full details of every category of cookie we use, who sets them, how long they last and how to control them are in our Cookie Policy.
9. Who we share your data with
We share personal data only with the categories of recipient below, only to the extent necessary, and always under a written contract that requires them to keep it secure and to use it only on our instructions.
| Recipient | Purpose | Data shared |
|---|---|---|
| Payment providers | Taking payment, processing refunds, fraud screening and 3‑D Secure authentication. Includes PayPal, Stripe, Revolut and Viva Wallet, each acting as an independent controller for their own compliance purposes. | Identity, contact, order, payment |
| Email delivery provider | Sending transactional and marketing email (Amazon Simple Email Service) | Contact, order |
| Hosting and infrastructure provider | Running and backing up the website and its database | All categories, at rest |
| Analytics, Google Ads, Google Shopping and free product listings, and reCAPTCHA bot protection — subject to your cookie choices | Usage, technical, marketing identifiers | |
| Accountants and auditors | Preparing statutory accounts and tax returns | Order, payment, invoice data |
| Software publishers and distributors | Verifying, replacing or reissuing a licence key, and assigning a licence to your account for products supplied that way (for example Autodesk and Microsoft 365) | Order reference and the key concerned; for an assigned licence, the account email address you gave us, and your name where the publisher requires it |
| Professional advisers and insurers | Legal advice, insurance and dispute resolution, where needed | Only what is relevant to the matter |
| Law enforcement and regulators | Where we are legally required to disclose, or where disclosure is necessary to prevent fraud or crime | Only what is legally required |
| A buyer of our business | If we sell or reorganise the business, data may transfer to the buyer, who must continue to protect it under this policy | Relevant customer records |
We do not sell your data
We have never sold, rented or traded personal data, and we do not share it with third parties for their own marketing. The only sharing that happens is what is listed above, for the purposes listed above.
10. Sending data outside the UK
Some of our providers are based outside the United Kingdom, or store data on servers outside it. Where personal data leaves the UK we make sure one of the following safeguards is in place, as required by Chapter V of the UK GDPR:
- the destination country is covered by UK adequacy regulations, for example the countries of the European Economic Area;
- the transfer is made under the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s Standard Contractual Clauses, supported by a transfer risk assessment;
- for transfers to the United States, the recipient is certified under the UK Extension to the EU‑US Data Privacy Framework (the “UK‑US data bridge”).
You can ask us for a copy of the safeguard applying to a particular transfer by emailing [email protected].
11. How long we keep your data
We keep personal data only for as long as we need it for the purpose we collected it, plus any period required by law. The retention column in section 5 gives the period for each purpose. The main drivers are:
- Six years for order, invoice and payment records, because tax and company law require accounting records to be retained and because that is the ordinary limitation period for a contract claim in England and Wales.
- Three years for support correspondence, so we can deal with a repeat issue or a later claim.
- Twelve months for security and server logs.
- Indefinitely for marketing suppression records, because deleting them would risk contacting you again.
When a retention period ends we delete the data or irreversibly anonymise it so that it can no longer identify you.
12. How we keep your data secure
We take appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include:
- encryption of all traffic to and from the website using TLS;
- encryption of data at rest and encrypted, access‑controlled backups;
- a web application firewall, malware scanning and intrusion monitoring;
- role‑based access control, so staff can only reach the data their role requires, and multi‑factor authentication on administrative accounts;
- passwords stored only as salted hashes, never in readable form;
- full card details never reaching our systems — card data is captured directly by our PCI DSS compliant payment providers;
- regular patching of the platform and its components, and vetting of suppliers before we appoint them.
We have procedures for dealing with a suspected personal data breach. Where a breach is likely to result in a risk to your rights and freedoms we will notify the Information Commissioner’s Office within 72 hours, and will tell you directly where the risk to you is high.
No system can be guaranteed completely secure. Please help us by using a strong, unique password and by never sharing your licence keys or account credentials.
13. Automated decision-making and fraud screening
Orders are automatically screened for signs of fraud, using risk indicators supplied by our payment providers together with information such as IP geolocation and mismatches between billing and account details. An order flagged as high risk is not rejected automatically — it is held for review by a member of our team, who decides whether to release it, request verification, or decline it.
Because a person makes the final decision, this is not a decision based solely on automated processing. If an order of yours is declined you may ask us to explain the reason, provide further information and have the decision reconsidered by emailing [email protected]. Any payment taken on a declined order is refunded in full.
We do not carry out profiling for any other purpose, and we do not make decisions with legal or similarly significant effects about you by automated means alone.
14. Your rights
Under the UK GDPR you have the following rights, free of charge in almost all cases.
| Right | What it means |
|---|---|
| Access | Ask for a copy of the personal data we hold about you, and information about how we use it. |
| Rectification | Ask us to correct data that is inaccurate, or complete data that is incomplete. |
| Erasure | Ask us to delete your data where we no longer need it. This right is limited where we must keep records for tax, accounting or legal reasons. |
| Restriction | Ask us to pause our use of your data, for example while we check its accuracy or consider an objection. |
| Portability | Receive the data you gave us in a structured, commonly used, machine‑readable format, or have it sent to another controller. |
| Object | Object to processing based on our legitimate interests. You can object to direct marketing at any time and we will always stop. |
| Withdraw consent | Withdraw consent at any time where we rely on it, such as for analytics and advertising cookies or marketing. This does not affect processing already carried out. |
| Automated decisions | Ask for human involvement in, and challenge, a decision made solely by automated means. See section 13. |
| Complain | Lodge a complaint with the Information Commissioner’s Office. See section 18. |
15. How to exercise your rights
Email [email protected] with “Data protection request” in the subject line, telling us which right you want to exercise. You do not need to use a particular form of words.
- We may ask for information to confirm your identity before we act, so that we do not disclose your data to someone else. The one‑month period starts once we have what we need.
- We respond within one month. If a request is complex or you have made several, we may extend by up to two further months and will tell you within the first month if so.
- Requests are handled free of charge. We may charge a reasonable fee, or refuse, only if a request is manifestly unfounded or excessive, and we will explain why.
- If we cannot do what you have asked, we will tell you why and explain your right to complain.
16. Children
Our website and products are intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it promptly.
17. Changes to this policy
We review this policy at least annually and update it when our processing changes or the law changes. The effective date at the top of this page shows when the current version took effect. Where a change materially affects how we use your data we will tell registered customers by email before it takes effect.
18. Complaints to the ICO
If you are unhappy with how we have handled your personal data, please tell us first at [email protected] so we have the chance to put it right. You also have the right to complain directly to the UK supervisory authority at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Helpline: 0303 123 1113
Website: ico.org.uk/make-a-complaint
Data controller details
- Trading name
- KeyForrest
- Legal entity
- ESEO SERVICES LTD
- Registered in
- England and Wales, company number 13675404
- Registered office
- 2 Frederick Street, Kings Cross, London, WC1X 0ND, United Kingdom
- Privacy contact
- [email protected]
- Telephone
- +44 731 280 5009
- Supervisory authority
- Information Commissioner’s Office (United Kingdom)
Related policies: Cookie Policy · Terms of Sale & Website Use · Returns, Cancellations & Refunds · Payment Policy
© 2026 ESEO SERVICES LTD trading as KeyForrest. This policy was last reviewed on 22 August 2026.