GDPR Compliant

GDPR Compliance Policy

This document outlines how Bitree WP handles personal data across all our WordPress plugins and services, in full compliance with the General Data Protection Regulation (EU) 2016/679.

v2.4 Updated July 15, 2026 Kuala Lumpur, Malaysia
01

Introduction

Bitree WP ("we," "our," or "us") is committed to protecting the privacy and personal data of all individuals who interact with our WordPress plugins, websites, and services. This GDPR Compliance Policy outlines our approach to data protection in accordance with the General Data Protection Regulation (EU) 2016/679.

As a WordPress plugin development company, we understand the trust you place in us when you install our plugins on your website. We take that responsibility seriously and have implemented robust technical and organizational measures to safeguard personal data.

Data Protection Officer (DPO): If you have any questions about this policy or our data practices, contact our DPO at [email protected].

02

Data We Collect

Our plugins are designed with data minimization as a core principle. We only collect data that is strictly necessary for the functionality of our plugins:

Data Category Examples Purpose Retention
Account Data Name, email, username License verification & support Duration of license
Usage Data Plugin version, WP version Compatibility & updates 12 months
Payment Data Processed via Stripe/PayPal Transaction processing As required by law
Support Data Ticket messages, logs Technical support 24 months

We do not collect, store, or process any sensitive personal data (health, biometric, political views, etc.) through our plugins.

03

Legal Basis for Processing

Under GDPR, we rely on the following legal bases for processing personal data:

Consent

Explicit opt-in for newsletters, marketing, and non-essential data collection.

Contractual Necessity

Data required to deliver plugin functionality, license management, and support.

Legal Obligation

Retention of financial records and compliance with applicable laws.

Legitimate Interest

Improving our plugins, security monitoring, and fraud prevention.

04

Your GDPR Rights

As a data subject, you have the following rights under GDPR. Bitree WP has implemented automated systems to handle all of these requests efficiently.

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

Request deletion of your personal data when it's no longer needed.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Right to Restrict Processing

Limit how we process your data under certain circumstances.

📧 To exercise any of these rights, email us at [email protected] — we respond within 72 hours.

05

Security Measures

We implement industry-leading security measures to protect your data:

AES-256 Encryption at Rest
TLS 1.3 in Transit
Regular Security Audits
24/7 Intrusion Detection
Automated Patch Management
Access Control (RBAC)
06

Third-Party Data Processors

We work with carefully selected third-party processors who are also GDPR-compliant:

Stripe
Payment processing • PCI-DSS Level 1
✅ Compliant
PayPal
Payment processing • GDPR certified
✅ Compliant
Amazon Web Services (AWS)
Cloud hosting • DPA in place
✅ Compliant
SendGrid
Email delivery • GDPR compliant
✅ Compliant
HelpScout
Support ticket system • DPA signed
✅ Compliant
07

Data Breach Response Protocol

In the unlikely event of a data breach, Bitree WP has a structured response plan:

< 1 hour

Detection & Containment

Automated systems detect and isolate the breach immediately.

< 24 hours

Investigation & Assessment

Security team investigates scope, impact, and affected data.

< 48 hours

Notification

Supervisory authority and affected individuals notified per GDPR Art. 33-34.

< 7 days

Remediation & Report

Root cause analysis, patches deployed, and full incident report filed.

08

Contact Information

If you have any questions, concerns, or requests regarding your personal data, please reach out:

Kuala Lumpur, Malaysia
bitreewp.com/gdpr