Privacy and Cookie Policy
Privacy and Cookie Policy
Personal data, service providers, international processing, cookies and marketing choices
Version 1.0. Effective date: 3 August 2026.
Operator: Omnexa OÜ
Brand: Printex Vault
Registry code: 17525014
Registered address: Pärnu mnt 105, 11312 Tallinn, Estonia
Email: info@printexvault.com
Website: printexvault.com
Part I – Privacy
1. Scope
This Policy applies to the Printex Vault Website, customer and creator accounts, orders, downloads, support, marketing, content reports and related interactions. It does not govern independent third parties acting as separate controllers, such as a payment provider processing data under its own legal obligations and privacy notice.
2. Data we collect
- Identity and account data, such as name, username, age or eligibility confirmation, company details, account identifiers and login records.
- Contact data, such as email address and other details supplied for support, orders, creator onboarding or legal notices.
- Order and transaction data, such as products, licence type, price in EUR, payment status, order time, refunds, chargebacks and transaction references. We do not need to store complete card credentials when they are handled by a payment provider.
- Creator data, such as identity or business verification, payout details, submitted products, rights information, sales statements and communications.
- Content and communications, such as reviews, uploaded previews, support messages, copyright notices, appeals and survey responses.
- Technical and usage data, such as IP address, device and browser information, cookie identifiers, log data, downloads, pages viewed, security events and approximate location inferred from network data.
- Marketing and preference data, such as newsletter status, consent records, interests inferred from use and communication preferences.
- Information received from providers and partners, such as payment status, fraud signals, delivery events, identity-verification results and referral information.
3. Why we use personal data and legal bases
Provide the service and fulfil contracts. Examples include accounts, checkout, payment status, delivery, licences, downloads, creator submissions, support and refunds. Typical legal basis: performance of a contract or steps requested before a contract.
Operate safely and prevent abuse. Examples include authentication, logs, fraud and chargeback prevention, security monitoring, infringement prevention and enforcement of terms. Typical legal basis: legitimate interests in security and protection of users, rights and the service, and legal obligations where applicable.
Comply with law and resolve disputes. Examples include required records, authority requests, legal claims, complaints, takedowns and preservation of evidence. Typical legal basis: legal obligation and legitimate interests in establishing, exercising or defending legal claims.
Improve and analyse the service. Examples include aggregate statistics, product performance, feature testing and diagnostics. Typical legal basis: legitimate interests for necessary low-impact analytics and consent where required for device storage or non-essential tracking.
Marketing and personalisation. Examples include newsletters, promotions, advertising and preference-based recommendations. Typical legal basis: consent where required, or legitimate interests for limited communications where permitted, with an easy opt-out.
Corporate operations. Examples include accounting, audits, professional advice, business transactions and internal administration. Typical legal basis: legal obligations and legitimate interests in managing the business.
4. Payment processing
We may make available any lawful payment method and use different payment providers. Information necessary to initiate, authenticate, settle, refund and dispute a payment may be sent to and received from those providers. A provider may process some information as our processor and some as an independent controller under financial, fraud-prevention or legal requirements.
5. Cookies and similar technologies
We use cookies, local storage, pixels and similar technologies for essential functions and, where enabled, preferences, analytics and advertising. Non-essential technologies are used on the basis of consent where consent is required. Details and current controls are described in Part II of this Policy and the Website’s consent interface.
6. Recipients and service providers
We may disclose personal data to categories of recipients that need it for the relevant purpose, including:
- payment, fraud-prevention and transaction providers;
- hosting, cloud, content-delivery, storage, backup, security and technical infrastructure providers;
- email, customer-support, communications, analytics, advertising and consent-management providers;
- identity, business, sanctions or payout-verification providers used for creator onboarding or risk controls;
- creators where necessary to provide product support or address a rights claim, with unnecessary customer details withheld;
- professional advisers, auditors, insurers, banks and corporate transaction participants under appropriate duties;
- courts, law-enforcement bodies, regulators and other authorities where disclosure is required or legally justified;
- a buyer, successor or group company in a merger, financing, reorganisation or transfer of the service, subject to applicable safeguards.
We select and manage providers using contractual, organisational and technical measures appropriate to their role. The specific providers may change as the service evolves.
7. International processing and transfers
Our providers and contractors may process data in different countries. Where personal data is transferred from the European Economic Area to a country that is not recognised as providing adequate protection, we use an available lawful transfer mechanism, such as approved standard contractual clauses, and supplementary safeguards where appropriate, or another legally permitted basis.
8. Retention
We keep personal data only as long as reasonably necessary for the purpose for which it was collected, including service delivery, the guaranteed download period, account operation, security, fraud prevention, support, legal claims and mandatory accounting or record-keeping duties. Retention periods vary by category and may be extended where records are needed for an active dispute, investigation or legal hold.
- Account data is generally kept while the account is active and for a reasonable period afterward to complete closure, prevent abuse and resolve claims.
- Order, licence and transaction records are kept for the period required to evidence the contract, meet legal record duties and handle disputes.
- Technical logs are kept for security and operational periods appropriate to their risk and usefulness.
- Marketing data is kept until consent is withdrawn, an objection is made, or the data is no longer useful, subject to keeping a minimal suppression record.
- Rights complaints and takedown records may be kept to document decisions, prevent repeat infringement and defend legal claims.
9. Security
We use measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure or access. Measures may include access controls, authentication, encryption in transit, backups, logging, monitoring, provider due diligence and incident-response procedures. No system is completely secure, and users should protect credentials and devices.
10. Automated tools and fraud prevention
We and our providers may use automated signals to detect fraud, payment risk, abuse, malware or account compromise. These tools may delay or flag a transaction for review. We do not intend to make solely automated decisions producing legal or similarly significant effects unless the decision is authorised by law and the required safeguards are available.
11. Marketing choices
You can unsubscribe from marketing emails using the link in the message or by contacting us. Service messages about orders, security, licences, policy changes or support are not marketing and may still be sent where needed. Withdrawing consent does not affect processing carried out before withdrawal.
12. Your rights
Subject to applicable conditions and exceptions, you may have the right to:
- receive information about processing and access your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a structured, commonly used and machine-readable format and transmit it to another controller;
- withdraw consent at any time;
- request human intervention and contest a qualifying automated decision;
- complain to a competent data-protection authority.
To exercise a right, email info@printexvault.com. We may need to verify identity and clarify the request. We normally respond within one month, subject to lawful extensions for complex or numerous requests.
13. Supervisory authority
You may complain to the Estonian Data Protection Inspectorate or another supervisory authority competent for your habitual residence, workplace or the alleged infringement. We encourage you to contact us first so we can try to resolve the matter.
14. Children
The Website is not intended for purchases or creator accounts by persons under 18. We do not knowingly create such accounts for children. If you believe a child has provided personal data contrary to this rule, contact us so we can review and take appropriate action.
15. Third-party links and independent services
The Website may link to external sites or integrate services that act independently. Their privacy practices are governed by their own notices. We are not responsible for an independent third party’s processing, but we aim to choose appropriate providers for service functions under our control.
16. Changes to this Policy
We may update this Policy to reflect service, provider or legal changes. The current version is published with an effective date. We will provide additional notice where required for a material change.
17. Contact
Privacy questions and requests: info@printexvault.com. Postal contact: Omnexa OÜ, Pärnu mnt 105, 11312 Tallinn, Estonia.
Part II – Cookies and Similar Technologies
1. Scope
This Part explains how Omnexa OÜ uses cookies and similar technologies on the Printex Vault Website. It should be read together with Part I of this Policy.
2. What these technologies are
Cookies are small files stored on a device. Similar technologies include local storage, software development kits, tags and pixels. They can remember a session, protect the Website, store preferences, measure use or support advertising. Some are set by us and some by providers whose technology is integrated into the Website.
3. Categories we may use
Strictly necessary. Used for checkout, account login, security, load balancing, fraud prevention, consent records and core Website functions. Duration is limited to the session or the period reasonably needed for the function. These technologies may be used without optional consent where permitted.
Preferences. Used to remember language, display settings, saved choices and other convenience settings. Duration may range from the session to several months. Consent is requested where required.
Analytics. Used to understand visits, downloads, performance, errors and aggregated usage. Duration may be a session or a limited persistent period. These technologies are used only after consent where required.
Advertising and measurement. Used to measure campaigns, limit repetition, attribute referrals and show more relevant advertising. Duration varies by campaign and provider. These technologies are used only after consent where required.
4. Current cookie details
The precise names, providers, purposes and lifetimes of active non-essential technologies may change when we update infrastructure or providers. The current Website consent interface or cookie settings panel should display the available categories and, where technically supported, the current detailed list. We do not treat the use of a particular provider as permanent.
5. Consent and withdrawal
Where consent is required, non-essential technologies are not activated until you make a choice. You can accept or reject categories through the consent interface. You can change or withdraw consent at any time through the cookie settings link on the Website. Withdrawal does not affect prior lawful processing, and some data may remain in backups or records for a limited period.
6. Browser and device controls
Most browsers allow you to delete or block cookies. Blocking strictly necessary cookies may prevent login, checkout, security or other requested functions. Device and browser settings are separate from our consent interface and may not communicate all choices to us.
7. Global privacy signals
Where required or technically supported, we may recognise legally binding browser-based privacy signals. Because standards and legal requirements evolve, the Website’s consent interface remains the primary method for recording choices unless stated otherwise.
8. Personal data
Identifiers and usage information collected through these technologies may be personal data. Purposes, legal bases, recipients, international transfers, retention and rights are described in Part I of this Policy.
9. Changes and contact
We may update this Policy when technology, providers or law changes. Questions may be sent to info@printexvault.com.