Legal Privacy

Privacy Policy

How Gorilla DSP collects, uses, and protects personal information across our website and audio plug‑ins.

Effective 2026-05-10Version 1.0

01 Section

Introduction

Gorilla DSP (“we”, “us”, “our”) respects your privacy. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data when you visit our website at gorilladsp.com (the “Website”) or use any of our software products, including the Lush Reverb and Old Vintage Fuzz audio plug‑ins (collectively, the “Services”).

This Privacy Policy is incorporated into, and forms part of, our End User License Agreement (“EULA”). Capitalized terms not defined here have the meanings given to them in the EULA. In the event of a conflict between the EULA and this Privacy Policy regarding data‑protection matters, this Privacy Policy controls.

02 Section

Who we are and how to contact us

Gorilla DSP is the data controller responsible for your personal information.

You can reach us at:

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent legislation, you may also use these channels to exercise the rights described in Section 09.

03 Section

Information we collect

3.1 Information you provide directly

When you purchase, register, or request support for our Services, we may collect:

  1. Your name and email address, used to issue your license code, deliver download links, and respond to support requests;
  2. Billing information necessary to complete a transaction. Card numbers and bank‑account details are entered directly into our payment processor’s hosted forms; we do not receive or store full card numbers;
  3. The contents of correspondence you send to us, including support tickets, feedback, and bug reports.

3.2 Information collected automatically when you visit the Website

When you visit the Website, our hosting and content‑delivery providers may automatically log:

  1. Your IP address;
  2. The type and version of your web browser and operating system;
  3. The pages you view and the time and date of your visit;
  4. The website that referred you, where applicable.

These logs are used to operate, secure, and improve the Website. The Website’s use of cookies is described in Section 12.

3.3 Information collected when you activate or use our software

When you activate or use the Lush Reverb plug‑in, the Old Vintage Fuzz plug‑in, or any of our other software products, the software transmits a limited set of technical data necessary for license verification. The categories of data transmitted are:

  1. A one‑way cryptographically hashed identifier of the computer running the software (“Machine ID Hash”);
  2. The platform identifier of the operating system on which the software is running (e.g. “Windows”, “macOS”, “Linux”);
  3. The host name of the computer running the software;
  4. Your license code.

The software does not transmit, collect, store, or process any audio content, project files, presets you author, plug‑in parameter values, or other creative work product.

The software performs license verification locally after the initial activation and does not require a continuous internet connection.

04 Section

How we use your information

We use the information described in Section 03 for the following purposes:

  1. To provide, operate, and maintain the Services, including delivering license codes, processing software activations, and enforcing license terms (such as the per‑license machine limit set out in the EULA);
  2. To process transactions and issue receipts and invoices;
  3. To communicate with you about your purchases, license codes, software updates, and support requests;
  4. With your express consent, to send occasional product announcements and marketing communications, which you may opt out of at any time using the unsubscribe link in those communications or by emailing us at the address in Section 02;
  5. To detect, prevent, and respond to fraud, abuse, security incidents, and other unlawful activity;
  6. To comply with our legal obligations, enforce our rights under the EULA, and defend against legal claims;
  7. To analyse, in aggregate and de‑identified form, how our Services are used so that we can improve them.

06 Section

Sharing your information

6.1 Service providers and sub‑processors

We share personal information with carefully selected third‑party service providers who process the information on our behalf and under written data‑processing agreements consistent with applicable data‑protection laws. The categories of service providers we use are:

  1. Cloud‑infrastructure providers, who host our license‑verification systems, our Website, and related back‑end services;
  2. Payment processors, who handle the financial transaction when you purchase a license;
  3. Email‑delivery providers, who deliver order confirmations, license codes, and support correspondence;
  4. Analytics providers, who, where enabled and where you have provided any required consent, help us understand how the Website is used in aggregate.

We do not sell, rent, or trade your personal information.

6.2 Legal disclosures

We may disclose personal information if required to do so by law, court order, or other valid legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request.

6.3 Business transfers

If Gorilla DSP is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of all or a portion of its assets, your personal information may be transferred as part of that transaction. We will notify you (for example, by email or by posting a notice on the Website) before your personal information becomes subject to a different privacy policy.

07 Section

International data transfers

We are based in the United States, and the personal information we collect may be processed in, or transferred to, the United States or other countries that may have data‑protection laws different from those in your country of residence.

Where personal information is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed by the relevant authorities to provide an adequate level of protection, we rely on appropriate safeguards permitted by applicable law, including the European Commission’s Standard Contractual Clauses and the United Kingdom Information Commissioner’s International Data Transfer Addendum, as applicable.

08 Section

Data retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including to provide ongoing customer support, comply with our legal, accounting, and reporting obligations, resolve disputes, and enforce our agreements.

Indicative retention periods:

  1. License records— including your license code, the cryptographically hashed identifiers of computers you have activated, activation timestamps, and the email address associated with the license — are retained for the duration of your license. Because the licenses we sell are perpetual, this means we retain these records indefinitely so that we can provide continuing customer support, including license‑code recovery, machine deactivation, license reissuance, and fraud prevention, unless and until you request erasure under Section 09 or we cease to support the relevant Service;
  2. Purchase and billing records— for the period required by applicable tax, accounting, and consumer‑protection law (typically up to seven (7) years from the end of the relevant tax year);
  3. Support correspondence— up to three (3) years after the ticket is closed;
  4. Marketing‑list membership— until you unsubscribe;
  5. Operational and web‑server logs— rolling periods consistent with industry practice and applicable law, after which they are deleted or anonymised.

When personal information is no longer needed for the purposes above, we delete or anonymise it. You may request erasure at any time under Section 09, subject to the exceptions permitted by applicable law.

09 Section

Your rights

9.1 Rights under the GDPR and UK GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights with respect to your personal information:

  1. Right of access— to obtain confirmation of whether we process your personal information and, where we do, a copy of that information;
  2. Right to rectification— to ask us to correct inaccurate or incomplete information;
  3. Right to erasure— to ask us to delete your personal information in certain circumstances;
  4. Right to restriction of processing— to ask us to limit the processing of your personal information in certain circumstances;
  5. Right to data portability— to receive a copy of the personal information you provided to us in a structured, commonly used, machine‑readable format, and to transmit it to another controller;
  6. Right to object— to object to processing based on our legitimate interests, and to object at any time to direct marketing;
  7. Right to withdraw consent— where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, contact us at the address in Section 02. We will respond within the time limits set by applicable law (one month under the GDPR, extendable by two further months where requests are complex or numerous).

You also have the right to lodge a complaint with your local data‑protection supervisory authority. A list of EU supervisory authorities is maintained by the European Data Protection Board.

9.2 California privacy rights

If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended, grants you certain rights with respect to your personal information. We do not sell or share your personal information for monetary or other valuable consideration, and we have not done so in the preceding twelve months. You may request to know the categories of personal information we have collected, to access the specific pieces collected, and to request deletion, subject to the exceptions permitted by law. To exercise these rights, contact us at the address in Section 02. We will not discriminate against you for exercising any of your rights under the CCPA.

10 Section

Children's privacy

The Services are not directed to children under the age of sixteen (16), and we do not knowingly collect personal information from children under sixteen. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us so that we can take appropriate action.

11 Section

Security

We use commercially reasonable administrative, technical, and physical safeguards designed to protect your personal information from unauthorised access, alteration, disclosure, or destruction. These include encryption of personal information in transit and at rest, access controls, and regular review of our security practices.

No method of transmission over the internet or electronic storage is one hundred percent secure, and we cannot guarantee absolute security. You are responsible for keeping your license codes and account credentials confidential.

12 Section

Cookies and similar technologies

The Website does not set or store cookies on your device. We do not use cookies for analytics, advertising, personalisation, or session tracking, and you do not need to accept any cookies in order for the Website to function.

If this changes in the future — for example, if we adopt non‑essential analytics — we will update this section, request your consent through a banner before any non‑essential cookies are set, and give you a way to manage your choices.

14 Section

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our Services, or applicable law. When we make a material change, we will notify you by posting the revised Privacy Policy on the Website and updating the Effective Date at the top. Where required by law, we will obtain your consent to the revised practices.

You should review this Privacy Policy periodically. Your continued use of the Services after a revised Privacy Policy takes effect constitutes your acceptance of the revised terms.

15 Section

Contact us

If you have questions, comments, or requests regarding this Privacy Policy or our handling of your personal information, please contact us at:

© 2026 Gorilla DSP · All rights reserved