Privacy Statement

SoftSDC / Maas Cyber Labs LLC
Last updated: 3 August 2026

Maas Cyber Labs LLC respects your privacy and is committed to protecting personal data processed through the SoftSDC website, customer accounts, licensing services, software support services, and related communications.

This Privacy Statement explains what personal data we collect, how and why we use it, when we disclose it, how long we retain it, and the rights that may be available to you.

1. Who We Are

The controller responsible for the personal data covered by this Privacy Statement is:

Maas Cyber Labs LLC
251 Little Falls Drive
Wilmington, Delaware 19808
United States of America

Email: info@softsdc.com

In this Privacy Statement, “SoftSDC,” “Maas Cyber Labs,” “we,” “us,” and “our” refer to Maas Cyber Labs LLC.

For website accounts, licensing, direct purchases, support administration, and our own business operations, Maas Cyber Labs generally acts as the controller of personal data.

Where we process personal data solely on behalf of a customer, taxpayer, POS operator, reseller, or another organisation and according to that organisation’s instructions, we may act as a processor or service provider. In such cases, the relevant customer agreement or data processing agreement may also apply.

2. Scope of This Privacy Statement

This Privacy Statement applies to personal data processed through:

  • the SoftSDC website;
  • SoftSDC customer accounts;
  • trial and software download services;
  • licence purchase, activation, renewal, and administration services;
  • the SoftSDC support portal and support communications;
  • SoftSDC software and connected services, to the extent that Maas Cyber Labs receives or controls the relevant personal data;
  • email and other business communications with us; and
  • interactions with authorised SoftSDC support partners where we are responsible for the processing.

This Privacy Statement does not govern websites, payment pages, POS systems, government portals, tax authority systems, or other services operated independently by third parties. Those organisations process personal data under their own privacy statements and legal responsibilities.

3. Personal Data We Collect

Depending on how you interact with SoftSDC, we may collect the following categories of personal data.

3.1 Account and identity data

This may include:

  • email address;
  • full name;
  • business or company name;
  • telephone number;
  • country, address, or time zone;
  • username, account identifiers, and authentication credentials;
  • account status and preferences; and
  • information showing that you accepted applicable terms, licence agreements, or notices.

3.2 Purchase and licence data

This may include:

  • products and licence plans ordered;
  • order number and transaction reference;
  • purchase and renewal history;
  • company and billing details;
  • licence number, activation code, licence status, and expiry date;
  • payment status and payment method category;
  • reseller or customer reference; and
  • records required for accounting, taxation, fraud prevention, and contractual administration.

Payment card information is generally collected and processed directly by the payment service provider shown during checkout. Maas Cyber Labs does not normally receive or store complete payment card numbers or card security codes.

3.3 Device, software, and technical data

When you access our website, activate a licence, use connected SoftSDC functionality, or request support, we may collect:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • date and time of access;
  • pages, functions, and downloads requested;
  • session and cookie identifiers;
  • application version and software environment;
  • device or installation identifiers used for licensing;
  • licence activation and reactivation information;
  • connectivity, error, performance, and security records;
  • hardware configuration relevant to licensing or support; and
  • information about connected components, such as card readers, where necessary for troubleshooting.

3.4 Support and communication data

When you contact us or open a support ticket, we may collect:

  • your contact details;
  • licence number;
  • ticket number and communication history;
  • description of the issue;
  • software version and environment;
  • screenshots, files, or other attachments;
  • troubleshooting and diagnostic logs;
  • operating system and hardware information;
  • correspondence with SoftSDC personnel or local support partners; and
  • information required to investigate and resolve the request.

You should not include personal data, confidential business information, payment card data, passwords, PINs, or fiscal transaction data in a support request unless it is genuinely necessary and we have specifically requested it through an appropriate secure channel.

3.5 Fiscalization-related data

SoftSDC is designed to support fiscalization processes and communication between a POS environment and the relevant tax authority system.

Depending on the country, configuration, and applicable fiscal rules, the software may process information contained in fiscal invoices, taxpayer identifiers, secure element information, transaction references, audit data, or related technical records.

The taxpayer, merchant, POS operator, or relevant tax authority may be the controller of this information. Maas Cyber Labs processes such information only to the extent necessary to provide, secure, support, maintain, or legally operate the SoftSDC service, or where the customer has instructed us to do so.

Information transmitted directly from the customer’s environment to a tax authority is also subject to the tax authority’s legal powers, technical specifications, and privacy practices.

3.6 Information received from other sources

We may receive personal data from:

  • your employer or organisation;
  • resellers and authorised representatives;
  • local support partners;
  • payment service providers;
  • POS providers and system integrators;
  • publicly available business sources; and
  • government or tax authorities where permitted or required by law.

4. How We Use Personal Data

We may use personal data to:

  • create and administer customer and support accounts;
  • provide access to trials, downloads, documentation, and customer services;
  • process licence orders, renewals, and wire transfer requests;
  • issue, activate, validate, renew, and protect software licences;
  • provide updates, upgrades, maintenance, and customer support;
  • diagnose software, device, installation, and connectivity problems;
  • communicate about licence expiry, renewals, service notices, security matters, and contractual changes;
  • process payments and reconcile transactions;
  • maintain financial, tax, contractual, and audit records;
  • prevent fraud, misuse, unauthorised access, and security incidents;
  • protect our rights, systems, customers, personnel, and property;
  • investigate suspected violations of our terms or licence agreements;
  • improve the reliability, usability, compatibility, and security of our website and services;
  • comply with legal, regulatory, tax, fiscalization, court, and law-enforcement obligations;
  • establish, exercise, or defend legal claims; and
  • send marketing communications where you have requested them or where otherwise permitted by applicable law.

We will not use personal data for a materially different purpose without providing additional information and, where required, obtaining consent.

6. Payments

Payments may be handled by an independent payment service provider or merchant of record displayed during the checkout process.

The payment provider may collect your name, company information, billing address, tax information, payment details, IP address, device information, and information needed to verify and complete the transaction.

The payment provider processes this information under its own privacy statement and contractual terms. We may receive transaction confirmation, order details, contact and billing information, payment status, fraud indicators, and transaction references, but we do not normally receive complete payment card credentials.

Where you request payment by wire transfer, we may process contact details, order details, company information, invoice information, bank transaction references, and related correspondence.

7. Cookies and Similar Technologies

Our website may use cookies and similar technologies for the following purposes:

Strictly necessary cookies

These cookies support essential functions such as account login, authentication, session management, security, checkout navigation, and protection against fraudulent or malicious activity.

Preference cookies

These cookies may remember choices such as the “Remember me” setting, language, region, or other user preferences.

Analytics cookies

Where enabled, analytics technologies may help us understand how visitors use the website, identify errors, and improve website performance.

Marketing cookies

We will not use non-essential marketing or behavioural advertising cookies unless they are disclosed and, where required, you have been given an appropriate choice or consent mechanism.

You can manage cookies through the cookie controls through your browser settings. Disabling strictly necessary cookies may prevent some parts of the website from functioning correctly.

Where legally required, non-essential cookies will not be placed before valid consent is obtained.

8. When We Disclose Personal Data

We may disclose personal data to the following categories of recipients:

Service providers

These may include providers of:

  • website and infrastructure hosting;
  • cloud storage and backup;
  • email delivery;
  • authentication and cybersecurity;
  • software development and maintenance;
  • customer support and ticket management;
  • payment processing and merchant-of-record services;
  • accounting, auditing, and professional services; and
  • analytics services, where used.

Service providers may process personal data only for the agreed service and subject to appropriate contractual and confidentiality obligations.

Local support partners

Where you request local or on-site support, or where local assistance is necessary to resolve your request, we may share relevant contact, licence, installation, and support information with an authorised local support partner.

We limit such disclosure to information reasonably necessary for providing the requested assistance.

Tax authorities and public bodies

Information may be transmitted or disclosed to the relevant tax authority or another public body where required by fiscalization rules, technical specifications, licences, legal obligations, or a lawful government request.

Resellers, representatives, and business customers

Where an organisation, reseller, or authorised representative purchases or administers licences on your behalf, we may provide information necessary to administer the account, order, licence, renewal, or support relationship.

Professional advisers

We may disclose information to lawyers, accountants, auditors, insurers, and other professional advisers where reasonably necessary.

Corporate transactions

Personal data may be disclosed in connection with a merger, acquisition, reorganisation, financing, sale of assets, or similar corporate transaction, subject to appropriate confidentiality and legal protections.

Legal and security disclosures

We may disclose personal data where we reasonably believe this is necessary to:

  • comply with law, regulation, court order, or lawful government request;
  • investigate fraud, security incidents, or misuse;
  • enforce our agreements;
  • protect the safety and rights of SoftSDC, our customers, users, personnel, or others; or
  • establish, exercise, or defend legal claims.

We do not sell personal data for monetary consideration. Unless we clearly disclose otherwise, we do not share personal data for cross-context behavioural advertising or use it for automated profiling that produces legal or similarly significant effects.

9. International Data Transfers

Maas Cyber Labs is based in the United States and provides services to customers in multiple countries.

Your personal data may therefore be processed in the United States, in the country where you use SoftSDC, in the country where the relevant tax authority or support partner is located, or in another country where an approved service provider operates.

Privacy and data protection laws in those countries may differ from the laws in your country.

Where required by applicable law, we use appropriate safeguards for international transfers. These may include contractual protections, data processing agreements, approved standard contractual clauses, transfer risk assessments, access controls, encryption, and other legally recognised mechanisms.

You may contact us for additional information about safeguards relevant to your personal data.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Statement.

Retention periods depend on factors including:

  • the duration of the account, licence, or customer relationship;
  • the period during which support, maintenance, or warranty services may be required;
  • accounting, taxation and recordkeeping obligations;
  • licence enforcement and fraud prevention requirements;
  • applicable limitation periods;
  • pending disputes, investigations, or legal claims;
  • security and incident-response requirements; and
  • whether you have requested deletion.

Account and licence information may be retained while an account or licence remains active and for a reasonable period afterwards.

Purchase, invoice, tax, and accounting records may be retained for the period required by applicable financial and tax laws.

Support tickets and diagnostic information are retained for the period reasonably necessary to resolve the issue, maintain an appropriate support history, improve service reliability, and protect against legal claims.

When personal data is no longer required, we delete, anonymise, or securely isolate it, unless continued retention is required or permitted by law.

11. Data Security

We use reasonable and appropriate technical and organisational safeguards designed to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

These safeguards may include:

  • access restrictions based on business need;
  • authentication and account security controls;
  • encryption during transmission;
  • network and system monitoring;
  • logging and incident detection;
  • backups and recovery measures;
  • confidentiality obligations;
  • supplier and service-provider controls; and
  • procedures for handling security incidents.

No website, internet transmission, or storage system can be guaranteed to be completely secure. You are responsible for using a strong, unique password and protecting your account credentials, secure element credentials, and PINs.

Where required by law, we will notify affected individuals and competent authorities of qualifying personal data breaches.

12. Your Privacy Rights

Depending on your location and applicable law, you may have the right to:

  • receive information about our processing of your personal data;
  • confirm whether we process your personal data;
  • access or obtain a copy of your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • restrict certain processing;
  • object to processing based on legitimate interests;
  • object to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent;
  • opt out of the sale of personal data, targeted advertising, or certain automated profiling;
  • obtain information about categories of third parties receiving personal data;
  • appeal a decision concerning your privacy request;
  • use an authorised agent where permitted by law; and
  • submit a complaint to a competent privacy or data protection authority.

These rights are subject to legal conditions and exceptions. For example, we may need to retain information to complete a transaction, provide a requested service, comply with law, protect security, or establish or defend legal claims.

We will not unlawfully discriminate against you for exercising a privacy right.

13. Exercising Your Rights

To submit a privacy request, contact:

Email: info@softsdc.com
Suggested subject line: Privacy Request

Please describe the right you wish to exercise and identify the account, order, licence, or interaction concerned.

We may request additional information to verify your identity and protect your account. We will use verification information only for handling the request.

You are not required to create a new account to submit a privacy request. Where you already have an account, we may ask you to use it as part of secure identity verification.

We will respond within the period required by applicable law. If we cannot fulfil all or part of a request, we will explain the reason unless prohibited from doing so.

Where applicable, you may appeal our decision by replying to our response with the subject line Privacy Request Appeal.

Individuals in the European Economic Area or United Kingdom may also complain to the data protection authority responsible for their place of residence, workplace, or the location of the alleged infringement.

Residents of a U.S. state with an applicable comprehensive privacy law may contact the relevant state privacy regulator or Attorney General.

14. Marketing Communications

We may send service-related communications concerning your account, licence, payment, renewal, security, support request, or important changes. These communications are necessary for providing the service and are not treated as optional marketing.

Where permitted, we may also send information about SoftSDC products, services, updates, or offers.

You may opt out of marketing emails by using the unsubscribe method provided in the message or by contacting us. Opting out of marketing does not prevent us from sending necessary transactional or service communications.

15. Children’s Privacy

SoftSDC is a business and fiscalization solution and is not intended for children.

We do not knowingly collect personal data directly from individuals under the age of 16. Where a higher minimum age applies under local law, we apply that higher age.

If you believe a child has provided personal data to us, contact us so that we can investigate and take appropriate action.

16. Third-Party Websites and Services

Our website may contain links to payment providers, support partners, tax authorities, software providers, or other third-party websites.

We do not control the privacy or security practices of independent third parties. You should review their privacy statements before providing personal data.

The presence of a link does not mean that this Privacy Statement applies to the linked service.

17. Changes to This Privacy Statement

We may update this Privacy Statement to reflect changes to our services, technology, business practices, service providers, or legal obligations.

The updated version will be posted on the SoftSDC website with a revised “Last updated” date.

Where changes materially affect your rights or the way we use personal data, we will provide additional notice where required, such as through the website, customer account, or email.

18. Contact Us

Questions, complaints, and privacy requests may be sent to:

Maas Cyber Labs LLC
251 Little Falls Drive
Wilmington, Delaware 19808
United States of America

Email: info@softsdc.com