GDPR, data residency and how long we keep things
Who operates WP Safer, which servers your data physically sits on, every other company that processes something, what we hold per connected site, and how to exercise your rights.
If you look after WordPress sites for clients, sooner or later one of them asks where their data goes and who else touches it. This article answers that in one place. The document that governs is the Privacy Policy; this page is the practical summary, and where the two disagree the Privacy Policy wins.
Who you are dealing with
WP Safer is operated by Limon Software Solutions, Kuşdili Caddesi No:18, Kadıköy / Istanbul, Türkiye. Privacy questions and requests go to info@wpsafer.com. Given the size of the company no data protection officer is formally designated; requests are handled through that address.
Where the data physically is
- Application, database, server logs, screenshots — Hetzner, Germany. This is where your account, your site list and the site access keys live.
- Backup archives — DigitalOcean Spaces, Amsterdam, Netherlands (
ams3), private bucket. Files and database dumps of your connected sites.
Both locations are inside the EEA. DigitalOcean is a US-based company operating the Amsterdam region, which is why the Privacy Policy sets out the safeguards relied on for transfers.
Who else processes something
- Polar.sh — payments and subscriptions. Card details stay with Polar; we receive transaction and subscription data only.
- Resend — delivery of transactional email (alerts, reports, billing, password resets).
- Trustpilot (Denmark) — a single review invitation after a completed purchase, sent from a copy of the order confirmation.
- Google Analytics — usage measurement on wpsafer.com, and only after you consent in the cookie banner.
- wpvulnerability.net — the public vulnerability database we query by plugin, theme and core version. Your site addresses are not sent there.
What we hold about a connected site
Per site: the address, the administrator username you enter, the site access key that signs our commands, the inventory we read back (WordPress, plugin, theme and user lists), uptime and performance history, screenshots, and the backup archives themselves. Optional FTP/SFTP details only if you enter them.
The archives are the part that matters most for a client conversation: a full backup can contain anything stored on that site, including personal data belonging to your client’s own visitors, customers or members. Deciding what that site collects and telling its visitors about it stays with you and your client; what we do with the archive once it reaches us is described in Where your backups are stored.
How long things are kept
The retention periods we commit to — account data after closure, backups after a site is disconnected, payment records, server logs — are listed in section 5 of the Privacy Policy. Two points that are easy to get wrong in practice:
- Removing a site is not the same as erasing its key. A removed site can be restored, so its record is kept for that purpose. If the point of removing it is that the access should end — a client relationship finishing, a key that may have leaked — change the key on the site itself, or delete the plugin there. That is what actually stops a command from being accepted.
- Deleted archives sit in Trash until they are emptied. Use Delete permanently in Trash when a client asks you to remove their data now, rather than waiting for the automatic clean-up.
Exercising your rights
Under the GDPR you can ask for access to your data, correction, erasure, restriction of processing, portability, and you can object to processing; you can also complain to your supervisory authority. Email info@wpsafer.com from the address on the account and we answer within one month.
Being straightforward about the current state: there is no self-service data export or account deletion button in the panel. Closing an account and getting a copy of your data are both handled by email today.
There is also no separate data processing agreement document at the moment — the Privacy Policy, the Terms of Service and, for consumer purchases, the distance sales agreement are what cover the relationship. If a client of yours requires a signed DPA, write to us and say so.
Cookies and email
- wpsafer.com sets essential cookies for sign-in and security; these cannot be turned off without breaking the service. Analytics cookies are set only after consent, and you can change your choice at any time from Cookie preferences in the footer. Details are in the Cookie Policy.
- The newsletter is double opt-in: nothing is sent until you confirm the address by clicking the link in the first email, and every issue carries a one-click unsubscribe.
- Service email — downtime alerts, reports, billing — is part of the service and is not marketing; it stops when the account is closed.