Legal
Privacy Policy
Effective April 5, 2026
1. Overview
Indelible Systems Inc., DBA IT First Aid Kit (“Company”) provides this Privacy Policy to explain how we collect, use, disclose, and protect information in connection with the IT First Aid Kit software and control plane.
This Policy applies to account administrators, IT professionals who deploy the Software, and end users on whose machines the Software is executed.
2. Data We Collect
Account and Billing Data
Name, business email, company name, billing address, and payment metadata (last four digits, card type, expiry). Full card numbers are processed exclusively by Stripe and never stored by us.
Basis: Contract performance. Retained: subscription term + 7 years.
License Validation Data
When the Software validates a license, it transmits:
| License key hash | SHA-256 hash of the license key | No |
| Client ID (hardware fingerprint) | One-way hash of MAC + CPU ID + Windows MachineGuid — raw values never leave the endpoint | Pseudonymous |
| Software version | Version string (e.g. 1.0.0) | No |
| Timestamp | UTC timestamp of validation | No |
Basis: Contract performance. Retained: subscription term + 2 years.
Telemetry Data
After each execution, the Software transmits:
| Hardware fingerprint hash | See above | Pseudonymous |
| Operation | remediate, dry_run, or rollback | No |
| Success | Boolean outcome | No |
| Duration | Execution time in milliseconds | No |
| OS version | Windows version string | No |
Basis: Legitimate interest. Retained: 90 days, then automatically deleted.
Data That Never Leaves the Endpoint
The following is generated and stored only on the endpoint machine — never transmitted to us:
- Audit logs — full operation record, ACL-restricted to local Administrators
- Rollback snapshots — registry state, identity cache references, AppX state
- Credential Manager — the Software deletes entries by name only; credential secrets (passwords, tokens) are never read, stored, or transmitted
3. How We Use Data
| Purpose | Data Used | Basis |
|---|---|---|
| License validation & seat enforcement | Key hash, client ID, version | Contract |
| Billing & payment | Account data, payment metadata | Contract |
| Customer support | Account data, validation records | Contract |
| Service reliability & diagnostics | Telemetry, validation logs | Legitimate interest |
| Fraud & abuse prevention | Validation patterns, seat counts | Legitimate interest |
| Product improvement | Aggregated, anonymized telemetry | Legitimate interest |
| Marketing (opt-in only) | Email address | Consent |
We do not sell, rent, or trade personal data to third parties.
5. International Data Transfers
Our Control Plane is hosted in AWS us-east-1 (USA). If you are in the EEA, UK, or Switzerland, transfers are protected by:
- EU Standard Contractual Clauses (Decision 2021/914, Module 2)
- UK International Data Transfer Agreement (IDTA) for UK transfers
Enterprise customers requiring a Data Processing Addendum (DPA) should contact legal@itfirstaidkit.com.
6. Your Data Rights
If you are in the EEA, UK, or a jurisdiction with applicable data protection rights, you may exercise the following rights by contacting privacy@itfirstaidkit.com:
| Access | Obtain a copy of your personal data |
| Rectification | Correct inaccurate personal data |
| Erasure | Request deletion (subject to legal retention obligations) |
| Restriction | Limit how we process your data |
| Portability | Receive your data in machine-readable format |
| Objection | Object to legitimate-interest processing |
| Withdraw consent | For consent-based processing (e.g. marketing) |
We respond within 30 days. Identity verification may be required.
7. Retention
| Account and billing data | Subscription term + 7 years |
| License validation records | Subscription term + 2 years |
| Telemetry events | 90 days |
| Audit logs (endpoint-local) | Controlled by Account administrator |
| Support correspondence | 3 years after last interaction |
8. Security
We protect personal data with:
- TLS 1.2+ for all data in transit
- AES-256 encryption at rest (AWS-managed)
- Least-privilege IAM — no standing production access
- License keys stored as SHA-256 hashes — plaintext never persisted server-side
- AWS Secrets Manager for all secrets
- DynamoDB PITR for backup and recovery
In the event of a personal data breach, we will notify affected customers within 72 hours of becoming aware. To report a security vulnerability, contact security@itfirstaidkit.com.
9. Changes to This Policy
We will provide at least 30 days’ notice of material changes via email and website notice. The “Effective” date above reflects the most recent revision.
10. Contact
Privacy inquiries: privacy@itfirstaidkit.com
If you believe we have not addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.