Last updated: 9 October 2026
Privacy policy
This policy explains how we collect and use your personal data when you visit store.chaostech.net, create an account, buy from us or contact us. We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who is responsible for your data
The data controller is MIKOMI LTD (trading as ChaosTech), company number 12784226, registered office 4 Woodcock Way, South Elmsall, Pontefract, WF9 2TP, United Kingdom. Contact for all privacy questions: admin@chaostech.net.
2. What we collect
- Account and order data: name, email address, password (stored encrypted), billing address, company name and VAT number if you give them, order history, licences and downloads.
- Payment data: confirmation of payment, amount, date and transaction reference from our payment provider. We do not receive or store your full card number.
- Support and contact data: messages you send us and any site details you share so we can help you.
- Technical data: IP address, browser type, pages visited and cookies needed to run the shop (see our Cookie policy).
- Marketing preferences: whether you have subscribed to our newsletter.
3. Why we use it and our lawful basis
- To process your order, deliver downloads, provide licences, updates and support – performance of a contract.
- To keep accounting and tax records – legal obligation.
- To keep the shop secure, prevent fraud and improve our products – our legitimate interests.
- To answer messages sent through the contact form – our legitimate interests, or steps before entering a contract.
- To send our newsletter and marketing emails – your consent (or, for existing customers, similar products under the Privacy and Electronic Communications Regulations 2003 with an opt-out in every email). You can unsubscribe at any time.
- Non-essential cookies – your consent.
4. Who we share it with
We do not sell your data. We share it only with service providers (processors) who act on our instructions:
- Web hosting provider – stores the shop and its database.
- Payment provider – processes your payment and carries out fraud checks. For some payment methods the provider is an independent controller under its own privacy notice.
- Email service provider – sends order, account and support emails.
We may also share data with our professional advisers (such as accountants) and where the law requires it (for example HMRC or the police).
5. International transfers
Some providers may process data outside the UK. When they do, we make sure there is an adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
6. How long we keep it
- Order and accounting records: 6 years from the end of the financial year they relate to.
- Your account: while it is open; we delete or anonymise it within 2 years of your last activity, unless the records above must be kept.
- Support messages: up to 3 years after the conversation ends.
- Newsletter data: until you unsubscribe.
7. Your rights
You have the right to: access your data; have it corrected; have it erased; restrict or object to its use (including to direct marketing at any time); data portability; and withdraw consent at any time. Logged-in customers can download or request deletion of their data from My account > GDPR - Personal data, or you can email us. We will reply within one month.
8. Security
The shop uses HTTPS encryption, passwords are stored hashed, and access to data is limited to people who need it.
9. Complaints
Please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority: ico.org.uk/make-a-complaint.
10. Changes
We may update this policy; the date at the top shows the latest version.