1. Definitions
- Controller — the customer (you) who uses WP Citadel to monitor WordPress installations.
- Processor — WP Citadel (trade name of Mike Pluijlaar), processing personal data on behalf of the Controller.
- Sub-processor — third parties engaged by the Processor to process personal data.
- Personal Data — any information relating to an identified or identifiable natural person, as defined in the GDPR.
- Processing — any operation performed on personal data, including collection, storage, use, and deletion.
- GDPR — the General Data Protection Regulation (EU) 2016/679.
2. Subject matter and duration
This DPA applies to all processing of personal data performed by the Processor on behalf of the Controller through the WP Citadel service. The agreement remains in effect for as long as the service is active.
3. Nature and purpose of processing
The Processor processes personal data solely for the purpose of:
- Monitoring WordPress installations connected by the Controller
- Collecting technical data (plugin versions, PHP version, WordPress version, uptime status, error logs)
- Providing reports and alerts to the Controller
- Ensuring security and availability of the service
4. Types of personal data
- Domain names and website URLs
- Server IP addresses
- Technical configuration data (WordPress version, PHP version, installed plugins)
- Error logs that may contain file paths or database names
- Uptime and performance metrics
5. Categories of data subjects
- End users of WordPress sites monitored by the Controller
- Administrators of WordPress installations
6. Obligations of the Processor
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process personal data are bound by confidentiality
- Implement appropriate technical and organisational measures (TLS encryption, Argon2id password hashing, access controls, SSRF protection)
- Engage sub-processors only with prior written consent
- Assist the Controller in responding to data subject rights requests
- Notify the Controller without undue delay of any personal data breach
- Delete or return all personal data at the end of the agreement, unless legal obligations require retention
- Make available all information necessary to demonstrate compliance
7. Sub-processors
The Processor engages the following sub-processors:
- Hetzner Online GmbH — hosting and infrastructure (Finland and Germany)
- Mailgun (Sinch) — transactional email delivery (EU–US Data Privacy Framework certified)
- LemonSqueezy — payment processing and license management
The Controller grants general authorisation for the engagement of sub-processors. The Processor will inform the Controller of any intended changes at least 30 days in advance. The Controller may object to the use of a new sub-processor within 14 days.
8. Data security measures
- All data is stored on Hetzner servers located in Finland and Germany (EU)
- HTTPS/TLS encryption for all data in transit
- Argon2id password hashing
- Laravel Sanctum API authentication
- Login throttling and SSRF protection
- Regular security updates and monitoring
9. International data transfers
All personal data is stored within the European Union. Sub-processors outside the EU (if any) are covered by the EU–US Data Privacy Framework or Standard Contractual Clauses.
10. Data subject rights
The Processor will assist the Controller in fulfilling requests from data subjects to exercise their rights under GDPR (access, rectification, erasure, restriction, portability, objection). Requests should be sent to contact@wpcitadel.com.
11. Data breach notification
The Processor will notify the Controller without undue delay (within 48 hours) after becoming aware of a personal data breach, providing:
- Nature of the breach
- Categories and approximate number of affected data subjects
- Likely consequences
- Measures taken or proposed to address the breach
12. Audit rights
The Controller has the right to audit the Processor's compliance with this DPA, subject to reasonable notice (at least 30 days) and confidentiality obligations.
13. Return and deletion of data
Upon termination of the service or upon request, the Processor will delete all personal data within 30 days, unless EU or Member State law requires continued storage.
14. Liability and indemnification
Each party's liability is limited as set out in the Terms of Service. The Processor is liable only for damage caused by processing that violates GDPR obligations specific to processors.
15. Governing law
This DPA is governed by Dutch law and the GDPR. Any disputes will be resolved in accordance with the Terms of Service.
16. Contact
For questions about this DPA or data processing practices, contact:
- Email: contact@wpcitadel.com
- Address: Netherlands