Legal

Privacy Policy

How WPControl collects, uses and protects data — yours, your clients' and the sites you connect. Written to be read, not to be survived. Questions about any section: support@wpcontrol.com.

Last updated: Mar 3, 2026

1. What this policy covers

This policy explains what WPControl collects, why it collects it, and what happens to it afterwards. It covers the console, the WordPress connector, the plain-language command layer and the reports the service sends on your behalf.

Two roles run through the whole document. For your own account data — your name, email and billing details — WPControl is the controller. For the data that flows through your connected sites, including personal data belonging to your clients or their customers, you are the controller and WPControl acts as processor under the DPA described in section 5.

2. The data we collect about you

Account data: your name, email address, password hash, workspace, role and the language you browse in. Billing data: your plan, subscription state and the identifiers the payment provider returns — full card numbers never reach us.

Operational data: sign-in events with IP address and user agent, the commands you issue, the operations you run, and an audit record of every AI-initiated write action. These exist so an account owner can see who did what, and so we can investigate abuse.

3. Site data the connector reports

Each connected site reports operational metadata to WPControl: site name and URL, WordPress and PHP versions, installed plugins and themes with their versions and update state, uptime checks, response times and a health score computed from them.

The connector does not send us your posts, pages, media or database contents. It performs only the operations you initiate, and you can revoke it at any moment by deleting the plugin or rotating its per-site key.

4. WooCommerce data and field-level scoping

When a connected site runs WooCommerce, the service reads store metrics — order counts, revenue totals, product and customer counts, and the currency each store captured them in — so the console can show them and reports can include them.

Those reads are field-level scoped: the connector requests only the fields a feature actually needs, and order-level personal data — customer names, postal addresses, email addresses and phone numbers — is not pulled into the console for display. Revenue is always reported in the currency it was captured in and is never silently summed across currencies.

You can see exactly which stores are connected, and what is read from each of them, on the WooCommerce surface inside the console.

5. AI processing, the DPA and the off-switch

The plain-language command layer sends the text of your command, together with operational metadata about the sites it resolves against, to a third-party model provider so the request can be turned into per-site actions. WPControl holds a Data Processing Agreement with that provider covering exactly this processing.

Our GDPR and AI commitments, in plain terms

  • A Data Processing Agreement under GDPR Art. 28 is available to every account, on every plan, from the billing settings — no enterprise tier required.
  • Your commands, site metadata and WooCommerce metrics are processed to execute your requests — never to train models, ours or the provider's.
  • The AI command layer has an off-switch. An account owner can disable it for the entire workspace at any time, and every other part of the console — sites, updates, bulk operations, uptime and reports — keeps working with it off.
  • Personal data is redacted from tool results before they reach the model: names, email addresses, phone numbers, postal addresses and IP addresses in connector and WooCommerce responses are stripped or masked.
  • The AI resolves and proposes; destructive or large-scale write actions require an explicit human confirmation and are written to an audit log you can read.

As the EU AI Act requires, we state plainly that command resolution is automated. It is a drafting and dispatch aid, not an automated decision about a person, and it never acts on your sites without the confirmation described above.

6. PII redaction in tool results

Redaction happens on our side, before any model call. When the connector or a WooCommerce read returns a payload, the service strips or masks the fields most likely to carry personal data — customer and billing names, email addresses, phone numbers, postal addresses and IP addresses — and caps the size of what is passed on.

Redaction is defence in depth, not a licence to route personal data through the command layer. Do not paste your clients' personal data into a command: the console has no use for it, and the commitments in section 5 are easier to keep when it never arrives in the first place.

7. Sharing, subprocessors and transfers

We do not sell personal data and we do not share it for advertising. WPControl shares data only with the subprocessors that make the service run — hosting and database, the model provider, email delivery, error monitoring and the payment provider — each under its own data-processing agreement.

The current subprocessor list, including where each one processes data, is published in the documentation, and we give 30 days' notice before adding or replacing one. Where data leaves the EEA or the UK we rely on Standard Contractual Clauses.

8. Retention and deletion

Account data is kept for as long as the account exists. Uptime checks and operational history are kept for 12 months, audit records of AI write actions for 24 months, and generated reports until you delete them.

When you close an account we revoke every connector key immediately and delete your account data within 30 days, except records we are required to keep for legal, tax or accounting reasons. A lapsed trial is held for 30 days before deletion so that nothing is lost by accident.

9. Your rights

If you are in the EEA, the UK, or another jurisdiction with comparable law, you can ask us for access to your personal data, for correction or deletion, for a portable copy, or for processing to be restricted — and you can object to processing, withdraw consent where processing rests on it, and complain to your local supervisory authority.

Most of this you can do yourself from the console. For anything else, write to support@wpcontrol.com and we answer within 30 days. Where a request concerns data held on your clients' sites, you are the controller and we support you as your processor.

10. Cookies, changes and contact

We use only the cookies needed to run the console — session, locale and security. There are no advertising cookies and no third-party trackers on the public site. When this policy changes we update the date at the top of the page and notify account owners by email at least 14 days before the change takes effect.

Questions, DPA requests and data-subject requests: support@wpcontrol.com.