01 Section
Introduction
Gorilla DSP (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data when you visit our website at gorilladsp.com (the “Website”) or use any of our software products, including the Lush Reverb and Old Vintage Fuzz audio plug‑ins (collectively, the “Services”).
This Privacy Policy is incorporated into, and forms part of, our End User License Agreement (“EULA”). Capitalized terms not defined here have the meanings given to them in the EULA. In the event of a conflict between the EULA and this Privacy Policy regarding data‑protection matters, this Privacy Policy controls.
02 Section
Who we are and how to contact us
Gorilla DSP is the data controller responsible for your personal information.
You can reach us at:
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent legislation, you may also use these channels to exercise the rights described in Section 09.
03 Section
Information we collect
3.1 Information you provide directly
When you purchase, register, or request support for our Services, we may collect:
- Your name and email address, used to issue your license code, deliver download links, and respond to support requests;
- Billing information necessary to complete a transaction. Card numbers and bank‑account details are entered directly into our payment processor’s hosted forms; we do not receive or store full card numbers;
- The contents of correspondence you send to us, including support tickets, feedback, and bug reports.
3.2 Information collected automatically when you visit the Website
When you visit the Website, our hosting and content‑delivery providers may automatically log:
- Your IP address;
- The type and version of your web browser and operating system;
- The pages you view and the time and date of your visit;
- The website that referred you, where applicable.
These logs are used to operate, secure, and improve the Website. The Website’s use of cookies is described in Section 12.
3.3 Information collected when you activate or use our software
When you activate or use the Lush Reverb plug‑in, the Old Vintage Fuzz plug‑in, or any of our other software products, the software transmits a limited set of technical data necessary for license verification. The categories of data transmitted are:
- A one‑way cryptographically hashed identifier of the computer running the software (“Machine ID Hash”);
- The platform identifier of the operating system on which the software is running (e.g. “Windows”, “macOS”, “Linux”);
- The host name of the computer running the software;
- Your license code.
The software does not transmit, collect, store, or process any audio content, project files, presets you author, plug‑in parameter values, or other creative work product.
The software performs license verification locally after the initial activation and does not require a continuous internet connection.
04 Section
How we use your information
We use the information described in Section 03 for the following purposes:
- To provide, operate, and maintain the Services, including delivering license codes, processing software activations, and enforcing license terms (such as the per‑license machine limit set out in the EULA);
- To process transactions and issue receipts and invoices;
- To communicate with you about your purchases, license codes, software updates, and support requests;
- With your express consent, to send occasional product announcements and marketing communications, which you may opt out of at any time using the unsubscribe link in those communications or by emailing us at the address in Section 02;
- To detect, prevent, and respond to fraud, abuse, security incidents, and other unlawful activity;
- To comply with our legal obligations, enforce our rights under the EULA, and defend against legal claims;
- To analyse, in aggregate and de‑identified form, how our Services are used so that we can improve them.
05 Section
Legal bases for processing (EU/UK users)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction subject to comparable data‑protection legislation, we rely on the following lawful bases for processing your personal information:
- Performance of a contract— to deliver the Services you have purchased and to perform our obligations under the EULA (Article 6(1)(b) of the EU General Data Protection Regulation, Regulation (EU) 2016/679, “GDPR”);
- Legitimate interests— to operate, secure, and improve our Services, to enforce license terms (including seat‑count limits), and to detect and prevent fraud, where such interests are not overridden by your fundamental rights and freedoms (Article 6(1)(f) GDPR);
- Consent— for optional marketing communications, which you may withdraw at any time (Article 6(1)(a) GDPR);
- Compliance with a legal obligation— to retain transaction records as required by tax, accounting, and consumer‑protection law (Article 6(1)(c) GDPR).
07 Section
International data transfers
We are based in the United States, and the personal information we collect may be processed in, or transferred to, the United States or other countries that may have data‑protection laws different from those in your country of residence.
Where personal information is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed by the relevant authorities to provide an adequate level of protection, we rely on appropriate safeguards permitted by applicable law, including the European Commission’s Standard Contractual Clauses and the United Kingdom Information Commissioner’s International Data Transfer Addendum, as applicable.
08 Section
Data retention
We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to provide ongoing customer support, comply with our legal, accounting, and reporting obligations, resolve disputes, and enforce our agreements.
Indicative retention periods:
- License records— including your license code, the cryptographically hashed identifiers of computers you have activated, activation timestamps, and the email address associated with the license — are retained for the duration of your license. Because the licenses we sell are perpetual, this means we retain these records indefinitely so that we can provide continuing customer support, including license‑code recovery, machine deactivation, license reissuance, and fraud prevention, unless and until you request erasure under Section 09 or we cease to support the relevant Service;
- Purchase and billing records— for the period required by applicable tax, accounting, and consumer‑protection law (typically up to seven (7) years from the end of the relevant tax year);
- Support correspondence— up to three (3) years after the ticket is closed;
- Marketing‑list membership— until you unsubscribe;
- Operational and web‑server logs— rolling periods consistent with industry practice and applicable law, after which they are deleted or anonymised.
When personal information is no longer needed for the purposes above, we delete or anonymise it. You may request erasure at any time under Section 09, subject to the exceptions permitted by applicable law.
09 Section
Your rights
9.1 Rights under the GDPR and UK GDPR
If you are located in the European Economic Area or the United Kingdom, you have the following rights with respect to your personal information:
- Right of access— to obtain confirmation of whether we process your personal information and, where we do, a copy of that information;
- Right to rectification— to ask us to correct inaccurate or incomplete information;
- Right to erasure— to ask us to delete your personal information in certain circumstances;
- Right to restriction of processing— to ask us to limit the processing of your personal information in certain circumstances;
- Right to data portability— to receive a copy of the personal information you provided to us in a structured, commonly used, machine‑readable format, and to transmit it to another controller;
- Right to object— to object to processing based on our legitimate interests, and to object at any time to direct marketing;
- Right to withdraw consent— where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at the address in Section 02. We will respond within the time limits set by applicable law (one month under the GDPR, extendable by two further months where requests are complex or numerous).
You also have the right to lodge a complaint with your local data‑protection supervisory authority. A list of EU supervisory authorities is maintained by the European Data Protection Board.
9.2 California privacy rights
If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended, grants you certain rights with respect to your personal information. We do not sell or share your personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months. You may request to know the categories of personal information we have collected, to access the specific pieces collected, and to request deletion, subject to the exceptions permitted by law. To exercise these rights, contact us at the address in Section 02. We will not discriminate against you for exercising any of your rights under the CCPA.
10 Section
Children's privacy
The Services are not directed to children under the age of sixteen (16), and we do not knowingly collect personal information from children under sixteen. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us so that we can take appropriate action.
11 Section
Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your personal information from unauthorised access, alteration, disclosure, or destruction. These include encryption of personal information in transit and at rest, access controls, and regular review of our security practices.
No method of transmission over the internet or electronic storage is one hundred percent secure, and we cannot guarantee absolute security. You are responsible for keeping your license codes and account credentials confidential.
13 Section
Third‑party links
The Website and our software may contain links to third‑party websites and services (for example, your DAW host, plug‑in distributor, or open‑source standards bodies). This Privacy Policy does not apply to those third‑party services, and we are not responsible for their privacy practices. We encourage you to review their privacy policies before providing them with any personal information.
14 Section
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our Services, or applicable law. When we make a material change, we will notify you by posting the revised Privacy Policy on the Website and updating the Effective Date at the top. Where required by law, we will obtain your consent to the revised practices.
You should review this Privacy Policy periodically. Your continued use of the Services after a revised Privacy Policy takes effect constitutes your acceptance of the revised terms.
15 Section
Contact us
If you have questions, comments, or requests regarding this Privacy Policy or our handling of your personal information, please contact us at:
© 2026 Gorilla DSP · All rights reserved