GDPR Compliance
Last updated: 14 September 2026
This page describes how Job Done Marketing LLC, the company behind Serverpacemaker, handles personal data of European Union data subjects under the General Data Protection Regulation (GDPR).
Data controller
Job Done Marketing LLC
1209 Mountain Road Pl NE, Ste 12681
Albuquerque, NM 87110
United States of America
Email: privacy@serverpacemaker.com
What personal data we process
We process the minimum necessary for running the business:
- Customer email addresses — for delivering purchase confirmations, download links, and support replies.
- Purchase records — transaction IDs and dates from our payment provider, for accounting and license verification.
- Support correspondence — emails you send us and our replies.
We do not process: names, addresses, phone numbers, payment card data, IP addresses (beyond what nginx logs temporarily for operational purposes), browsing behavior, or any other personal data.
Legal basis for processing
- Contractual necessity (Article 6(1)(b)) — processing your email to deliver the product you purchased, provide support, and send release notifications.
- Legal obligation (Article 6(1)(c)) — retaining transaction records for tax and accounting purposes.
- Legitimate interest (Article 6(1)(f)) — preventing fraud, ensuring license compliance.
Data retention
- Purchase records: retained for as long as required by tax law (typically 7 years).
- Email correspondence: retained until you ask us to delete it.
- Download logs: not retained. We don't track downloads.
Data location
Our email is hosted by Proton (Switzerland, which has an EU adequacy decision). Our website is hosted on a VPS in Denmark (EU). Purchase records are stored by our payment provider in their EU data centers.
Third parties
- Proton — email hosting (Switzerland)
- Payment provider — payment processing (EU data centers)
- Webdock — VPS hosting (Denmark, EU)
We do not share your data with anyone else. We do not sell it. We do not use it for advertising.
Your rights under GDPR
As an EU data subject, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate data.
- Erasure — request deletion of your data (subject to legal retention requirements).
- Restriction — request that we limit how we process your data.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Complaint — lodge a complaint with your national data protection authority.
Exercising your rights
Email privacy@serverpacemaker.com. We respond within 30 days.
Data breaches
In the unlikely event of a data breach affecting your personal data, we will notify affected individuals and the relevant supervisory authority within 72 hours, as required by GDPR Article 33.
International transfers
Serverpacemaker is operated by a US company. Personal data may be transferred to the US for processing. We rely on Standard Contractual Clauses and the Swiss-US Data Privacy Framework for transfers between the EU and the US.
Changes
If this statement changes, the "Last updated" date at the top will change. Material changes will be announced on the blog.
Contact
For GDPR inquiries: privacy@serverpacemaker.com