Privacy Policy
What personal data Webforta processes, why, and your rights.
Controller
[Legal entity name - to be confirmed], [Registered address - to be confirmed]. Contact for privacy matters: support@webforta.com. [Appoint/identify a data protection contact or DPO if required.]
Data we process
- Account data: name, email address, password hash (never the password itself), email verification status.
- Organization data: organization name, memberships and roles, invitations.
- Website data you add: hostnames, verification records, scan results, monitoring measurements, DNS and HTTP header snapshots, incidents and reports.
- Security and usage data: session records (with a truncated browser user-agent and a keyed hash of your IP address), audit log entries, rate-limit counters (hashed identifiers), API key metadata.
- Billing data: subscription status, plan and payment-provider customer ID. Card details are processed by the payment provider and are not received by us.
- Support messages you send through the contact form.
- If you connect Cloudflare: an encrypted API token you create, zone identifiers and settings, and imported security events without client IP addresses.
- If you use Webforta Shield: request metadata needed to filter traffic (path, method, country, user agent) for blocked, challenged or would-block requests, with visitor IP addresses stored only as keyed hashes; aggregated hourly traffic counts. Hashed IPs whose attacks are blocked on sites of at least two different customers are shared across Shield sites as threat intelligence (based on the last 6 hours of events; requests a browser was made to send by another website are never counted).
- If you install the Webforta Connector WordPress plugin: WordPress, PHP, plugin and theme versions; administrator usernames and registration dates; security settings; file paths, line numbers and hashes of files that fail integrity or malware checks (never file contents); and a WordPress activity log of logins, failed logins and account/plugin changes including the usernames and IP addresses involved.
- If you add chat or webhook alert channels: the channel name and its webhook URL (stored encrypted), the delivery status of each alert, and for signed webhooks an encrypted signing secret. Alert texts are sent to the service you chose (Slack, Discord, Microsoft or your own endpoint).
- Domain registration data for verified websites: the registered domain, its expiry date and registrar name, obtained from the public RDAP service of the domain's registry.
- If you set branding: the brand name, accent colour and logo image you upload, shown on your downloadable reports and public status pages.
- If you turn on a public status page: the website name, hostname, current availability, uptime percentages and availability incidents are published at a random address you can share, replace or remove at any time.
Purposes and legal bases
- Providing the Service under our contract with you (Art. 6(1)(b) GDPR).
- Securing the Service, preventing abuse and keeping audit records (legitimate interests, Art. 6(1)(f)).
- Billing and tax record-keeping (legal obligation, Art. 6(1)(c)).
- Service emails such as verification, password reset and the alerts you configure (contract).
Processors and recipients
- Cloudflare, Inc. - application hosting, database (D1), queues and bot protection (Turnstile).
- Email provider (Brevo or Resend, as configured) - delivery of transactional emails and alerts.
- Slack, Discord, Microsoft (Teams) or your own endpoint - only if you add them as alert channels; they receive the alert texts you choose.
- Stripe - payment processing and invoicing.
- OpenCVE (opencve.io) - receives the names and slugs of WordPress software being checked for known vulnerabilities (for example "contact-form-7"), never your hostname or account details.
- Public DNS resolvers (Cloudflare 1.1.1.1, Google Public DNS), Certificate Transparency search (crt.sh) and the RDAP registration services of domain registries (via the rdap.org directory) receive hostnames or domain names you add when we check them.
- [List data processing agreements and international transfer mechanisms, e.g. Standard Contractual Clauses or the EU-US Data Privacy Framework, after verification.]
Retention
See the Data Retention and Deletion policy for retention periods.
Your rights
You may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interests. You can delete your account yourself in the account settings. You may lodge a complaint with your supervisory authority.
Cookies
We use only strictly necessary cookies. See the Cookie Policy.
Other policies: Terms of Service · Privacy Policy · Cookie Policy · Acceptable Use Policy · Security Testing Authorization Terms · Data Retention and Deletion Policy · Responsible Disclosure Policy ·