Privacy Policy

Your privacy and data security are fundamental to everything we do. This policy explains how ISO8583Studio handles your information with transparency and respect.

Overview & our commitment

At ISO8583Studio, we are committed to protecting your privacy and ensuring the security of your personal information. As a professional desktop application for financial transaction processing, we understand the critical importance of data protection in the financial technology sector.

Our commitment

We process only the minimum data necessary to provide our services, implement industry-leading security measures, and never sell your personal information to third parties.

This Privacy Policy applies to:

  • ISO8583Studio Desktop Application — our primary software product
  • Official Websitehttps://iso8583.studio
  • Support Services — customer support and technical assistance
  • Documentation & Resources — online guides and documentation

Information we collect

Information you provide directly

We collect information you voluntarily provide when using our services:

  • Account information: name, email address, company name, and contact details when you create an account or request support
  • License information: license key details, activation information, and subscription data
  • Feedback & surveys: your responses to surveys, feedback forms, and product improvement requests

Information collected automatically

Our application and website may automatically collect certain technical information:

  • Application usage data: feature usage statistics, performance metrics, and crash reports (anonymized)
  • System information: operating system version, hardware specifications, and software environment details
  • Website analytics: IP address, browser type, pages visited, and interaction patterns
  • Log data: application logs, error reports, and diagnostic information
Desktop application data

ISO8583Studio is primarily a desktop application. Most of your transaction data, configurations, and financial information remain on your local system and are not transmitted to our servers unless you explicitly use cloud features or request support.

Desktop application usage analytics (opt-in)

The ISO8583Studio desktop application can report anonymous usage analytics to Google Analytics 4. This is off by default. On first launch the application asks whether you wish to enable it, and nothing is transmitted unless you accept. You can change your choice at any time under Settings → Usage Analytics.

When you have opted in, the application sends:

  • Feature usage: which tools and simulators you open, how long sessions last, whether a calculation succeeded or failed, and the names of screens you visit
  • Environment: application version, operating system and version, CPU architecture, Java runtime version, language, timezone and screen resolution
  • Approximate location: city, region/state and country. To determine this, the application makes a request to a third-party IP geolocation service. Your IP address is used to resolve this location and to let Google resolve it; it is not stored by us as an analytics attribute, and precise GPS coordinates are never collected.
  • A random device identifier: generated on your machine, persisted between launches, and not derived from any hardware, account or network identifier. You can regenerate it at any time from Settings.
  • Error types: the class name of an unexpected error, without its message or stack trace
What is never collected

Card numbers (PANs), PINs or PIN blocks, cryptographic keys or key components, cryptograms, MACs, the contents of any ISO 8583 or HSM message, file paths, hostnames, IP addresses of systems you connect to, or the names you give your simulator profiles. Analytics carries only the identity of the tool or screen in use, timings, and the environment details listed above.

Financial & transaction data

Important clarifications regarding sensitive financial data:

  • Local processing: transaction data processed through ISO8583Studio remains on your local system by default
  • No data collection: we do not collect, store, or transmit your actual financial transaction data
  • Configuration data: gateway configurations and message templates are stored locally unless you use cloud sync features
  • Support cases: if you share configuration or log files for support purposes, we handle them with strict confidentiality

How we use your data

We use collected information for the following purposes:

Service provision & improvement

  • License management: verify licenses, manage subscriptions, and prevent unauthorized use
  • Technical support: provide customer support, troubleshoot issues, and resolve technical problems
  • Product development: improve our software, develop new features, and enhance user experience
  • Performance optimization: analyze usage patterns to optimize application performance and stability

Communication & updates

  • Product updates: notify you about software updates, security patches, and new releases
  • Support communications: respond to your support requests and provide technical assistance
  • Educational content: share documentation, tutorials, and best practices (with your consent)
  • Important notices: communicate critical security updates or service changes

Legal & compliance

  • Legal obligations: comply with applicable laws, regulations, and legal processes
  • Security protection: detect and prevent fraud, unauthorized access, and security threats
  • Terms enforcement: enforce our Terms and Conditions and protect our rights and property

Data sharing & disclosure

We do not sell, rent, or trade your personal information. We may share information only in the following limited circumstances:

Service providers

We may share data with trusted third-party service providers who help us operate our business:

  • Cloud infrastructure: hosting services for our website and support systems
  • Analytics services:Google Analytics 4 for website and application usage measurement, and Google Ads for advertising measurement
  • Support tools: customer support and ticketing systems
  • Payment processing: payment processors for license purchases (they handle payment data independently)
Important

All service providers are contractually required to protect your data and use it only for the specific services they provide to us. They cannot use your information for their own purposes.

Legal requirements

We may disclose information when required by law or to protect our rights:

  • In response to valid legal processes (subpoenas, court orders, etc.)
  • To comply with applicable laws and regulations
  • To protect our rights, property, or safety, or that of our users
  • To investigate potential violations of our Terms and Conditions

Business transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and the choices you may have.

Security measures

We implement comprehensive security measures to protect your information:

Technical safeguards

  • Encryption: data in transit is protected using TLS/SSL encryption
  • Access controls: strict access controls and authentication for our systems
  • Secure infrastructure: industry-standard security practices for our servers and databases
  • Regular updates: timely security patches and software updates

Operational safeguards

  • Employee training: regular security awareness training for all employees
  • Background checks: comprehensive background checks for personnel with data access
  • Incident response: established procedures for security incident detection and response
  • Regular audits: periodic security assessments and vulnerability testing

Application security

  • Local data protection: your local data remains on your system with standard OS protections
  • Secure communications: all network communications use encrypted channels
  • Code signing: our application is digitally signed to ensure authenticity and integrity
  • Regular security reviews: continuous security assessment of our codebase and infrastructure
Financial data security

Since ISO8583Studio processes financial transaction data, we follow industry best practices including PCI DSS guidelines, even though your transaction data typically remains on your local system.

Data retention

We retain your information only as long as necessary to provide our services and comply with legal obligations:

Account information

  • Active accounts: retained while your account is active and for service provision
  • Inactive accounts: deleted after 2 years of inactivity, unless legal obligations require longer retention
  • Support records: support tickets and communications retained for 3 years for quality and legal purposes

Technical data

  • Usage analytics: aggregated and anonymized usage data retained for 24 months
  • Log files: server logs retained for 90 days for security and operational purposes
  • Crash reports: anonymous crash reports retained for 12 months for product improvement

Legal & compliance data

  • Financial records: license and payment records retained for 7 years for tax and accounting purposes
  • Legal holds: data subject to legal proceedings retained until resolution
  • Regulatory requirements: data retained as required by applicable financial services regulations

Your rights

You have several rights regarding your personal information. The specific rights available to you may depend on your location and applicable laws:

Access & portability rights

  • Access: request a copy of the personal information we hold about you
  • Portability: receive your data in a structured, machine-readable format
  • Information: learn about how we process your data and with whom we share it

Control & correction rights

  • Correction: update or correct inaccurate personal information
  • Deletion: request deletion of your personal information (subject to legal obligations)
  • Restriction: limit how we process your information in certain circumstances
  • Objection: object to processing based on legitimate interests

Communication preferences

  • Marketing opt-out: unsubscribe from marketing communications at any time
  • Communication settings: choose how and when we contact you
  • Notification preferences: control which product updates and announcements you receive
How to exercise your rights

Contact us at admin@iso8583.studio with your request. We will respond within 30 days and may require identity verification for security purposes.

Cookies & tracking technologies

Our website uses cookies and similar technologies to improve your experience and understand how our services are used:

Types of cookies we use

  • Essential cookies: required for website functionality and security
  • Analytics cookies: help us understand website usage and improve performance
  • Functional cookies: remember your preferences and settings
  • Marketing cookies: used for targeted advertising (with your consent)

Third-party cookies

We may use third-party services that set their own cookies:

  • Google Analytics 4: website traffic analysis and usage insights. We also enable Google Signals, which allows Google to associate visits with signed-in Google accounts for cross-device measurement and aggregated demographic reporting.
  • Google Ads: advertising measurement and remarketing audiences, where a campaign is running
  • Support chat: customer support chat functionality
  • CDN services: content delivery and website performance optimization

Managing cookies

You can control cookies through your browser settings:

  • Block all cookies (may affect website functionality)
  • Block third-party cookies only
  • Delete existing cookies
  • Set preferences for future cookies
Note

The desktop application does not use web cookies, but may store local configuration files and preferences on your system for application functionality.

International data transfers

ISO8583Studio operates globally, and your information may be transferred to and processed in countries other than your own:

Legal basis for transfers

  • Adequacy decisions: transfers to countries with adequate data protection laws
  • Standard contractual clauses: EU-approved contracts ensuring data protection
  • Your consent: explicit consent for specific transfers when required
  • Necessity: transfers necessary for service provision or legal compliance

Safeguards for international transfers

  • Encryption: all data transfers use strong encryption
  • Access controls: strict limits on who can access transferred data
  • Contractual protections: legal agreements requiring equivalent protection
  • Regular reviews: ongoing assessment of transfer arrangements and protections

Children's privacy

ISO8583Studio is designed for professional use in financial services and is not intended for children under 16. We do not knowingly collect personal information from children.

If we become aware that we have collected information from a child under 16 without parental consent, we will take steps to delete that information promptly.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How we notify you of changes

  • Website notice: prominent notice on our website for 30 days
  • Email notification: email to registered users for material changes
  • In-app notification: notification within the desktop application
  • Version dating: clear dating of policy versions for transparency

Types of changes

  • Minor changes: clarifications, formatting, or contact information updates
  • Material changes: changes to data collection, use, or sharing practices
  • Legal changes: updates required by new laws or regulations
Your continued use

Continued use of our services after policy changes constitutes acceptance of the updated terms. If you disagree with changes, please discontinue use and contact us about data deletion.

Legal compliance & frameworks

ISO8583Studio complies with major data protection frameworks and regulations:

Regulatory compliance

  • GDPR: European General Data Protection Regulation compliance
  • CCPA: California Consumer Privacy Act protections
  • PIPEDA: Canadian Personal Information Protection Act compliance
  • Financial regulations: relevant financial services data protection requirements

Industry standards

  • ISO 27001: information security management best practices
  • PCI DSS guidelines: payment card industry security standards
  • SOC 2: security, availability, and confidentiality controls
  • Financial industry standards: sector-specific security and privacy requirements

Contact information

If you have any questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please get in touch.