Privacy Policy

Last Updated: July 4, 2026

1. Introduction

This Privacy Policy explains how WordSec ("WordSec", "we", "us") collects, uses, shares, and protects personal data when you visit wordsec.net, create a license, or use the WordSec plugin and API. It applies to website visitors, free and paying customers, and administrators who install our plugin. We act as the data controller for the processing described here under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, for visitors in the European Economic Area and the United Kingdom, the General Data Protection Regulation ("GDPR"). You can reach us about any privacy matter at info@wordsec.net.

2. Data We Collect

We only collect the data we need to provide and secure the service. Depending on how you use WordSec, this may include:

  • Identity & contact data: your name and email address, provided when you contact us or register for a license key.
  • Billing data: paid subscriptions are processed by our payment provider (Paddle); we receive your subscription status and email, not your full card details.
  • Technical & usage data: IP address, browser and device information, and anonymous, cookieless usage analytics (page views).
  • License, site & environment data: your license key, the website domain where the plugin is activated, and configuration details of your environment (WordPress, PHP, database, and web-server versions) together with WordSec feature usage. While the plugin is active, this information is reported to us periodically (about once a day) to validate your license, deliver threat-data updates, and provide security diagnostics and product analytics.
  • Installed software inventory: the slugs and versions of plugins and themes on your site, checked against our vulnerability database to alert you to risks.
  • Communications: the contents of messages and support requests you send us.

3. Security Data Processed by the Plugin

As a security plugin, WordSec processes data about activity on your own website, such as attacker IP addresses, blocked requests, login attempts, traffic logs, and malware scan results. This raw security data is generated and stored on your own server within your WordPress installation, and we do not receive the underlying IP addresses or log entries unless you explicitly enable a cloud feature that requires it or share them with us for support. While the plugin is active, WordSec does include anonymous, aggregate security statistics (for example daily counts of blocked requests, login attempts, and scan findings, without the underlying IP addresses or logs) in the periodic diagnostics report described above, which we use to power threat intelligence and improve the product. You remain the controller of the personal data of your own site's visitors and users.

4. Cookies & Tracking

We deliberately keep tracking to a minimum and do not use advertising or cross-site tracking technologies, so no cookie-consent banner is required:

  • Strictly necessary: a functional cookie that remembers your language preference, plus anti-abuse and rate-limiting (including Cloudflare Turnstile on forms). These are required for the site to work.
  • Analytics: we use PostHog in a cookieless, anonymous mode: no cookies or local storage are written to your device, no personal profile is built, and we honor your browser's "Do Not Track" setting.
  • No advertising, profiling, or third-party marketing cookies are used at any time.

5. Legal Bases for Processing

We process personal data only where we have a lawful basis under the GDPR (Art. 6) and the KVKK (Art. 5):

  • Performance of a contract: to create your account, deliver license keys, and provide the service you request.
  • Legitimate interests: to secure our services, prevent abuse and fraud, and understand usage through anonymous analytics.
  • Legal obligation: to meet tax, accounting, and other statutory requirements.
  • Consent: where required by law; you may withdraw your consent at any time without affecting prior processing.

6. How We Use Your Information

We use the data we collect to:

  • Provide, operate, and maintain the service and deliver your license keys.
  • Process payments and manage your subscription.
  • Respond to your questions and support requests.
  • Detect, prevent, and investigate security incidents, fraud, and abuse.
  • Improve our products using aggregated, anonymous analytics.
  • Send service and administrative messages (and, only with your consent, product updates).

7. How We Share Data

We never sell your personal data. We share it only with service providers who process it on our behalf under appropriate agreements, and only as needed to run the service:

  • Paddle: payment processing as our Merchant of Record for paid plans.
  • Cloudflare: bot protection (Turnstile) and content delivery / network security.
  • PostHog: anonymous, cookieless product analytics.
  • Email provider (Zoho): delivery of transactional and contact emails.
  • Hosting and infrastructure providers that run our servers.
  • Public authorities, where we are legally required to disclose data.

8. International Transfers

Some of our service providers operate outside Türkiye and the European Economic Area. Where personal data is transferred abroad, we rely on appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, and your explicit consent where required by the KVKK, to ensure your data remains protected.

9. Data Retention

We keep personal data only for as long as necessary for the purposes described in this Policy: account and license data for the life of your account and as required afterward by law; billing records for the statutory retention period; contact messages for as long as needed to handle your request; and anonymous analytics on an aggregated basis. When data is no longer needed, we delete or anonymize it.

10. Your Rights

Under the KVKK (Art. 11) and the GDPR (Art. 15–22), you have the right to:

  • Learn whether your personal data is processed and request access to it.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of your data where the conditions are met.
  • Restrict or object to certain processing.
  • Receive your data in a portable format and, where applicable, have it transferred.
  • Withdraw consent at any time and lodge a complaint with the Turkish Data Protection Authority (KVKK) or your local EU/UK supervisory authority.

11. Data Security

We apply appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, hashed secrets, rate limiting, and bot protection. No method of transmission or storage is completely secure, but we work continuously to safeguard your information and will notify you and the relevant authority of a data breach where the law requires.

12. Children's Privacy

WordSec is a professional tool intended for website administrators and is not directed to children. We do not knowingly collect personal data from anyone under the age of 16 (or the minimum age set by local law). If you believe a child has provided us data, please contact us and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. We will revise the "Last Updated" date above and, for material changes, provide a more prominent notice. Your continued use of the service after an update means you accept the revised Policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:

Email: info@wordsec.net