Privacy Policy
What data WPDeeply collects, why, and how to have it removed.
This policy covers wpdeeply.com/ and the WPDeeply Risk Monitor plugin. Contact for anything below: legal@wpdeeply.com.
Who is responsible
WPDeeply operates this website and the Risk Monitor plugin, and acts as data controller for the personal data described here. All privacy requests are handled at legal@wpdeeply.com.
Data collected on this website
- Contact and waitlist forms — the name, email address and message you submit. Used to answer you or to send one launch email. Not sold, not shared, not added to a marketing list you did not ask for.
- Server logs — your IP address, browser user agent, requested URL and timestamp, recorded by the web server for security and abuse prevention, retained for a short period.
- Cookies — a session cookie if you log in, and a form-protection token. There are no advertising or cross-site tracking cookies, and no analytics scripts that build a profile of you.
Data collected by the plugin
A scan transmits component slugs and version numbers, your WordPress version and your PHP version. It does not transmit post content, user accounts, email addresses, customer or order data, database contents or file contents. Free scans are not retained on our side; paid monitoring retains scan histories so it can report changes, deleted 30 days after a licence ends.
Legal bases
- Consent — waitlist emails, which you can withdraw at any time.
- Contract — providing paid monitoring and services you have purchased.
- Legitimate interests — answering enquiries, security logging, preventing abuse.
- Legal obligation — retaining invoices where tax law requires it.
Processors
We use a web host, an email provider and, once paid plans launch, a payment processor. Each processes data only to deliver its service, under a data processing agreement. Payment card details are never seen or stored by WPDeeply.
Your rights
Under the GDPR you may request access, correction, deletion, restriction, portability, or object to processing, and you may withdraw consent at any time. Email legal@wpdeeply.com and we will respond within one month. You may also complain to your national data protection authority.
Retention
- Contact enquiries: deleted once the enquiry is closed.
- Waitlist addresses: deleted after the launch email, or immediately on request.
- Server logs: short-term, for security purposes only.
- Invoices: retained as long as tax law requires.
Children
This site is not directed at children and we do not knowingly collect their data.
Changes
Material changes will be noted on this page with a new date. Last updated: 8 August 2026.