Privacy Policy
Last updated: 5 September 2026
Majware collects very little personal data, and none of the clinical data you process with our tools. This policy explains exactly what we hold, who else touches it, and how to get it removed.
1. Who is responsible for your data
TODO — registered legal entity name, trading as Majware, is the data controller for the personal data described in this policy.
TODO — street address, TODO — city, region, postcode, TODO — country
Privacy contact: privacy@majware.com
One important exception: for payment data, Paddle.com Market Ltd is the merchant of record and acts as an independent controller of the payment and tax data you give it at checkout. That data is governed by Paddle's privacy notice as well as this policy. See section 4.
2. Information we collect
Email address — when you subscribe to the newsletter, request a free resource, unlock an export format in one of the browser tools, or contact us.
Name and message content — when you submit the contact form. The form asks for your name, email, an optional company name and your message.
Purchase information — name, email, billing address and the tax identifiers needed to invoice you, collected by Paddle at checkout and shared with us in a limited form (see section 4). We never receive or store your card number, CVC or bank details.
Licence activation data — when you activate a desktop product, our licensing service receives your licence key, a non-reversible machine fingerprint used to bind the licence to one computer, the product name and version, and the time of activation.
Usage data — anonymised analytics via Google Analytics 4: pages visited, session duration, approximate region and referring source. This is aggregated and is not used to identify you.
Server logs — our web server records IP address, user agent, requested URL and timestamp for security and troubleshooting.
What we do not collect: we do not collect special-category health data, we do not build advertising profiles, and we do not buy personal data from third parties.
3. Your DICOM, HL7 and FHIR data — never sent to us
This is the part most healthcare IT readers came for, so it is stated plainly.
Browser tools (DICOM Header Validator, DICOM Anonymizer, HL7 Message Viewer, HL7 to FHIR Converter, Diagram Builder) process files entirely in your browser using client-side JavaScript. Files are read into memory, processed, and discarded when you close or reload the page. No file, and no fragment of one, is transmitted to a Majware server.
Desktop software (DICOM Anonymizer Pro, DICOM Migration Engine) reads and writes files on your own machine. The only network request it makes is the licence activation call described in section 2, which carries the licence key and machine fingerprint and nothing else. There is no telemetry, no crash upload containing file data, and no cloud processing.
Consequently Majware has no access to any patient identifiable information (PHI) contained in the files you process, and there is no data set on our side that a breach could expose. This is a deliberate architectural choice, not a policy promise.
4. Payments, Paddle and tax data
When you buy a product on majware.com, checkout is operated by Paddle.com Market Ltd (Judd House, 18–29 Mora Street, London, EC1V 8BT, United Kingdom) as merchant of record.
- Paddle collects your payment details, billing address, country and any tax identification number directly. These go to Paddle, not to us. We never see your card details.
- Paddle uses that data to take payment, calculate and remit sales tax or VAT, issue your invoice, and run fraud and sanctions screening — obligations it carries as the seller of record.
- Paddle passes us a limited record of the order: your name, email address, the product purchased, the amount, the country for tax purposes and the order reference. We use this to issue your licence key, provide support and keep the accounting records the law requires.
- Refunds, chargebacks and invoice corrections are processed by Paddle.
Paddle's own privacy notice is at paddle.com/legal/privacy. Billing enquiries can be raised at https://paddle.net.
Some documentation toolkits are sold through our Gumroad storefront, in which case Gumroad performs the same role for that order under its own privacy policy.
5. How we use your information
We use personal data to:
- Deliver the product, licence key or free resource you asked for
- Provide support and answer your enquiries
- Send the newsletter and product updates you subscribed to
- Issue and validate software licences, and prevent licence abuse
- Keep the financial and tax records we are legally required to keep
- Understand in aggregate how the site is used, so we write about what people actually read
- Protect the site and our systems against abuse, fraud and attack
We do not sell, rent or trade your personal data. We do not share it with third parties for their own marketing.
6. Legal bases for processing (UK/EU GDPR)
Where the UK or EU GDPR applies, we rely on:
- Contract — to deliver a product you bought, issue and validate your licence, and provide support.
- Consent — for marketing email. You give it by subscribing and can withdraw it at any time via the unsubscribe link in every email.
- Legal obligation — to retain invoices and tax records, and to comply with sanctions screening.
- Legitimate interests — for site security, server logs, fraud and licence-abuse prevention, aggregate analytics, and responding to enquiries you initiate. We have balanced these against your rights and consider the impact minimal because the data involved is limited and is not used to make decisions about you.
7. Email communications
If you give us your email address you may receive a welcome message with any resource you requested, a short onboarding sequence, and our periodic newsletter of technical content and product updates.
You can unsubscribe from any of it at any time using the link in every email. Unsubscribing is immediate and we do not ask why.
Transactional email — your licence key, order confirmation, a reply to your support request — is not marketing and cannot be unsubscribed from, because it is how you receive what you paid for.
Our email platform is Kit (formerly ConvertKit). Your email address, subscription tags and engagement data are stored on Kit's systems under their privacy policy.
9. Third-party services we use
- Paddle.com Market Ltd — merchant of record: payment processing, tax, invoicing, fraud screening (privacy notice)
- Gumroad — payment and delivery for documentation toolkits sold through store.majware.com
- Kit (ConvertKit) — newsletter and email delivery
- Google Analytics 4 — anonymised site analytics
- Our SMTP provider — delivery of contact-form messages and licence emails
- Our VPS host — hosting of majware.com and the licensing service
Each has its own privacy policy. We share the minimum data each needs to do its job, and none of them is authorised to use it for their own marketing.
10. International transfers
Some of these providers are based outside the UK and European Economic Area, principally in the United States. Where personal data is transferred there, it is protected by the safeguards those providers rely on — standard contractual clauses, the EU–US and UK–US Data Privacy Framework, or equivalent measures set out in their own privacy documentation.
You can ask us at privacy@majware.com for details of the safeguards applying to a specific transfer.
11. Data retention
- Newsletter subscribers — retained while you remain subscribed. After you unsubscribe we remove you from the active list within 30 days, keeping only a suppression record so we do not email you again by mistake.
- Contact form messages — retained for up to 24 months, so we can follow up on a prior conversation.
- Order and invoice records — retained for 7 years, or longer if tax law in the relevant country requires it.
- Licence and activation records — retained for the life of the licence, since a perpetual licence has to remain verifiable.
- Server logs — retained for up to 90 days.
- Analytics data — retained according to the GA4 property setting, currently 14 months.
12. Security
The site and the licensing service run over TLS. The licensing database is not publicly reachable; the service listens on the local interface only and is proxied. Signing keys are held on the server with restricted file permissions and are never distributed with the software or published in any repository.
Access to subscriber and order data is limited to the people who need it to run the business.
No system is perfectly secure, but the amount of personal data we hold is deliberately small — and, as section 3 explains, none of it is patient data.
13. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and receive a copy of it
- Have inaccurate data corrected
- Have your data deleted
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent for marketing at any time
- Not be subject to a decision based solely on automated processing (we do not make any)
California residents additionally have the rights to know, delete and correct, and to opt out of the "sale" or "sharing" of personal information under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, and we do not offer financial incentives for data.
To exercise any right, email privacy@majware.com or use the contact form. We respond within 30 days and will not charge you or treat you differently for asking.
For payment data held by Paddle, requests can also be made directly to Paddle.
If you are in the UK or EU and are unhappy with our response, you may complain to your national supervisory authority — in the UK, the Information Commissioner's Office at ico.org.uk.
14. Children
Majware sells professional healthcare IT tools. The site and products are not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, email privacy@majware.com and we will delete it.
15. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of the page shows when it last changed. Where a change materially affects how we handle your data, we will say so in the newsletter as well as here.
16. Contact
TODO — registered legal entity name, trading as Majware
TODO — street address, TODO — city, region, postcode, TODO — country
- Privacy and data rights: privacy@majware.com
- General: hello@majware.com
- Payment data held by our merchant of record: https://paddle.net