Privacy policy

How plogins.com handles contact, checkout, analytics, support and scanner data.

Last updated:

Controller

WPPoland, a sole proprietorship of Mariusz Szatkowski, ul. Starowiejska 16/2, 81-356 Gdynia, Poland, NIP 7393037445, is the controller for personal data collected on plogins.com. Contact for any data protection matter: [email protected]. We are not required to appoint a data protection officer and have not appointed one; requests go to the address above.

What we process, why, and on what legal basis

Correspondence you send us (email address, message content, any support context) is processed to answer you, on the basis of our legitimate interest in responding to enquiries, Art. 6(1)(f) GDPR, or to perform a contract where you are a customer, Art. 6(1)(b). PRO licence data (account email, licence key, site domain, payment status) is processed to deliver updates and support under the contract, Art. 6(1)(b), and to meet accounting duties, Art. 6(1)(c). URLs submitted to public tools such as the tracking scanner are processed to produce the requested result, Art. 6(1)(b). Server logs kept by our hosting provider are processed for security and availability, Art. 6(1)(f).

We run no analytics on this site

plogins.com loads no analytics or advertising script and builds no visitor profile. We do not track you across sites, we do not use advertising identifiers, and we do not sell or share personal data. The only third-party code the site loads is described in the cookies document.

How long we keep it

Correspondence is kept while the matter is open and for up to 24 months afterwards, so we can follow up on a recurring issue. Data on invoices and other accounting records is kept for 5 years from the end of the tax year in which the invoice was issued, as Polish tax law requires. Licence records are kept for the life of the licence and for as long as a claim under it can be made. Vulnerability reports are kept indefinitely in an internal log, because the history of a fix is itself a security record.

Who else sees the data

We use a small number of processors, each named with its role in the subprocessors document: our hosting and network provider, the checkout and licensing provider for PRO purchases, the platform hosting our public source repositories and issue trackers, and our mail provider Smarthost sp. z o.o. Payment card data is handled by the checkout provider and its payment partners and never reaches us. We disclose data to public authorities only where the law obliges us to.

Transfers outside the EEA

Some of these providers are established outside the European Economic Area or process data there. Where that happens, the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision, together with the provider's own supplementary measures. You can ask us at [email protected] which mechanism applies to a specific provider and we will tell you.

Your rights

You have the right of access, rectification, erasure, restriction, data portability, and objection to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of what happened before. Write to [email protected]; we answer without undue delay and within one month, and we will say so if a complex request needs the extension the GDPR allows. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzedu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or with the authority where you live or work.

No automated decision-making

We take no decisions about you by automated means alone and we do not profile you. Providing data is voluntary, but without an email address we cannot answer a message, and without licence data we cannot deliver PRO updates or support.

This document is product information and does not replace individual legal advice.