How RDS CAL Store handles personal information

This Privacy Policy explains how RDS CAL Store collects, uses, stores, and protects personal information when you visit our website, contact us, or purchase Microsoft Remote Desktop Services Client Access Licenses from rdscal.com. Our approach is simple: we collect the minimum needed to deliver your license and invoice, we keep it only as long as the law requires, and we never give it to anyone for their own use.

Last updated: 18 July 2026
Privacy-first by design Two required fields — an email address and a name — are all we need to deliver your license. No phone number, no street address, no marketing lists, no advertising trackers, and no sharing of your data with anyone for their own purposes.

1. Who we are

RDS CAL Store operates the website rdscal.com and sells Microsoft Remote Desktop Services Client Access Licenses for Windows Server deployments. RDS CAL Store is the data controller responsible for the personal information described in this policy.

Address: 399 High St, London E15 4QZ, United Kingdom

Email: [email protected]

For the purposes of this Privacy Policy, “we”, “us”, and “our” refer to RDS CAL Store. “You” refers to website visitors, customers, and people who contact us for support or pre-sales assistance.

2. The information we collect — and what we refuse to collect

We practice data minimization. Checkout asks for exactly two required pieces of information, plus a small number of optional fields that exist only for your benefit.

Information you provide at checkout

  • Email address (required): used to deliver your license document, invoice, and order records, and to answer support requests about the order.
  • Name (required): used as the licensee name on your license document and on your invoice.
  • Company name (optional): if provided, it is used as the licensee name on your license document instead of your personal name. Leave it blank to license in your own name.
  • Country (optional, pre-filled): used to complete your invoice. You may change or clear it.

What we deliberately do not collect

  • No phone number. There is no phone field at checkout.
  • No street address. We deliver digitally and do not need to know where you live or work.
  • No payment card details. Payment is handled entirely by the payment provider. Your card number never reaches our website or our records.
  • No marketing profiles. We do not build profiles of you, and we do not maintain marketing lists.

Order and support information

  • Order information: products purchased, order number, invoice details, license type, Windows Server version, quantity, and any order notes you add.
  • Account information (optional): signing up for an account is optional. If you sign up, we hold your account email, the password you set, and your order history so you can view your orders and license documents online.
  • Support messages: if you contact us, we keep the correspondence for as long as needed to resolve the matter.

Information collected automatically

  • Security and fraud-prevention data: our web server and security tools process technical information such as IP address and browser type in short-lived security logs. Basic details of the device used to place an order (browser and operating system) are stored with the order record for fraud protection.
  • Cookies: by default we set only the strictly necessary cookies that make the cart, checkout, and account sessions work. See section 5.

3. How we use your information

We use personal information only for the purposes below. Depending on where you are located, our lawful bases include performance of a contract, legal obligations, and legitimate interests.

Purpose Information used Typical lawful basis
Process and fulfil your order Name, email, order details, optional company / country Contract performance
Deliver your license document and invoice Email address, order number, licensee name Contract performance
Provide support and process eligible license corrections Support messages, order details, CAL type and server version Contract performance and legitimate interests
Keep business, tax, and accounting records Order and invoice records Legal obligation
Protect the website and prevent fraud and abuse IP address, basic device data, security logs Legitimate interests
Send service messages about your order or account Email address, order details Contract performance
Understand site traffic (analytics) Aggregate usage data and device signals — only if you enable analytics cookies Consent (through the cookie banner)

We do not sell your personal information. We do not rent it, trade it, or share it with anyone for their own purposes. We do not use it for advertising, and we do not send marketing emails.

4. Orders, payments and licensee details

When you place an order, we use your details to confirm the purchase, create the order record, prepare and deliver your license document and invoice, and provide post-purchase support.

Payment processing

Payments are processed entirely by our payment provider (PayPal), on their own pages and under their own privacy notice. Your card or account details are entered directly with the provider and never pass through or get stored on our website. We receive back only what is needed to complete your order: a payment confirmation and transaction reference.

Licensee and client details

If you purchase for a company, a client, or a third-party organization, the licensee details you provide are used for exactly one thing: naming the licensee on the license document and invoice, and verifying eligible corrections to that order afterwards.

The company field is optional. Leave it blank and the license is issued in your own name — nothing else changes.

5. Cookies, security tools and contact forms

Cookies

By default, our website sets only strictly necessary cookies — the ones that keep the shopping cart, checkout, account sessions, and site security working. These cannot be switched off because the store cannot function without them.

We do not run advertisements and we do not use advertising, marketing, or cross-site tracking cookies — at all, for anyone.

We do use analytics to understand site traffic in aggregate — which pages are visited, how people find the site, and where the site can be improved. Analytics cookies are off by default and load only if you switch them on through the cookie banner. Rejecting them is one click and changes nothing about how the store works for you; your purchase is never conditioned on being measured. You can change or withdraw your choice at any time through the cookie settings on our website or by clearing cookies in your browser.

Security and spam protection

We use security services such as firewalls, bot protection, and form verification to protect the website. These tools process technical information such as IP address, browser data, and challenge tokens, solely to keep the site and your data safe.

Contact forms

If you submit a contact form, we use the information you provide only to respond to your request. Providing contact details beyond an email address is always your choice, never a requirement.

6. Who can access your information

No third party receives your personal information for their own purposes. Not for advertising, not for analytics products, not for “partners”, not for sale — not for anything.

The only parties that touch your data are the infrastructure services every online store needs to run, acting strictly on our instructions and only to the extent necessary:

  • Our payment provider (PayPal) — processes your payment directly with you; we do not pass them your details.
  • Our website hosting and security providers — store and protect the website and its database.
  • Our email delivery service — transmits your license, invoice, and support emails to you.
  • Our analytics provider — receives usage data only if you enable analytics cookies, and only to produce the aggregate traffic statistics we see; we keep its advertising and data-sharing features switched off.
  • Our accountant and professional advisers — may access invoice records where required for tax compliance, under confidentiality obligations.

Requests from legal authorities

We disclose customer information to public authorities only when we are required to do so by a valid and binding legal demand (such as a court order). When that happens, we verify the demand, disclose the minimum information legally required, and we will inform you before we disclose anything, unless the law expressly prohibits us from telling you. We do not volunteer customer data to any authority, and we have no arrangements giving any authority routine or direct access to our systems.

7. How long we keep information and how we protect it

Retention

We keep personal information only as long as it is genuinely needed, then delete or anonymize it:

  • Order, invoice, and license records: kept for 6 years to meet UK tax and accounting obligations — this also lets us re-issue a lost license document years later — after which they are deleted or anonymized.
  • Account information: kept while your account is active; you may ask us to close it at any time.
  • Support messages: kept for up to 24 months after the matter is resolved, unless they form part of an order record we must keep longer.
  • Security and server logs: kept for a short period, typically no more than 12 months, and used only for security and fraud prevention.

Security

We use technical and organizational measures to protect personal information from unauthorized access, loss, misuse, alteration, or disclosure, and we limit access to the people who need it to run the store. No online service can promise perfect security, but holding less data in the first place is the strongest protection there is — and it is the one we have designed for.

8. Your privacy rights

Depending on where you are located, you have rights over your personal information, including the right to:

  • request a copy of the personal information we hold about you;
  • ask us to correct inaccurate or incomplete information;
  • request deletion of your information (note that invoice records required by tax law must be retained for the statutory period);
  • restrict or object to certain processing;
  • receive information you provided in a portable format, where applicable;
  • withdraw consent where we rely on consent; and
  • complain to a data protection authority.

To make a privacy request, email [email protected]. Requests are free. We may need to verify that you control the email address on the records, and we aim to respond within one month, in line with UK GDPR.

9. Marketing, children and updates

No marketing emails

We do not send marketing or promotional emails. The only emails you will ever receive from us are the ones needed to deliver and support your purchase: your license and invoice, order confirmations, account emails you explicitly request (such as a set-password link), and replies to your own messages.

Children

Our website and products are intended for business and adult customers. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy to reflect changes in our website, services, or legal obligations. The updated version will be posted on this page with a new “Last updated” date. If a change ever reduces the privacy commitments on this page, we will announce it clearly on the website before it takes effect — not just quietly edit this text.

10. Contact and complaints

If you have questions about this Privacy Policy or how we handle personal information, contact us by email.

RDS CAL Store
399 High St, London E15 4QZ, United Kingdom

Email: [email protected]

If you are in the UK and are not satisfied with how we have handled your information, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EU, you may complain to your local data protection authority. We would appreciate the chance to address your concerns directly before you do so.