Skip to content
WPAgently
EN/DE
Back to home

Legal

Privacy Policy

Last updated: 3 August 2026

This English text is a convenience translation. The German version is authoritative to the extent permitted by law.

1. Controller

The controller within the meaning of the General Data Protection Regulation is:

Finn Hillebrandt
Am Brandberg 10
21401 Thomasburg
Germany
Telephone: +49 171 7344291
Email: info@blogmojo.de

2. Principles and scope

This Privacy Policy describes the processing of personal data when visiting wpagently.com, directly downloading Free, purchasing or requesting support, voluntarily activating a paid licence, and using plugin updates.

Customer website content, WordPress databases and credentials are not transmitted to Finn Hillebrandt or a WPAgently application server during normal product operation. Free does not require a Polar connection. This is distinct from connections to Polar after voluntary activation of a paid licence and to wpagently.com for updates, which are described below.

If a Customer uses the optional integrated WordPress chat, their WordPress installation sends the entered messages and the site data retrieved through read-only Abilities for the response directly to the AI provider selected under Settings > Connectors. This data flow does not pass through Finn Hillebrandt, Polar, or a WPAgently application server. The Customer selects, configures, and uses the AI provider under their own provider agreement. The Customer should use this feature only for data they are permitted to send to the selected AI provider.

3. Visiting the website

wpagently.com is a static website hosted by Vercel Inc., 440 N Barranca Avenue #4133, Covina, California 91723, USA, and delivered through services provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, California 94107, USA.

The following data may be processed when the website is accessed:

  • IP address
  • date and time of the request
  • requested address and HTTP method
  • status code and transferred data volume
  • referrer, if supplied by the browser
  • browser, operating system and user agent
  • technical security and error data

The purposes are secure, stable and efficient website delivery, attack prevention and error analysis. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of the website.

We do not use website analytics, profiling, advertising or marketing tracking on wpagently.com. Vercel Analytics is not integrated.

Vercel and Cloudflare act as processors to the extent that they provide hosting and delivery services on our behalf. Their data processing terms incorporate Standard Contractual Clauses. Where an effective certification exists and covers the specific processing, a transfer to the USA may additionally rely on the EU-US Data Privacy Framework. Further information is available in the Vercel DPA, the Cloudflare DPA, and the privacy policies of Vercel and Cloudflare.

4. Waitlist and email communication

4.1 Registration

When a person joins the waitlist, we process the email address entered, the registration page address, form and scenario identifiers, and technical request logs. The form sends this data to a mailer interface operated by Finn Hillebrandt under graduallyai.com. The interface runs as a Cloudflare Worker and stores contact, list, consent and delivery data in a Neon Postgres database supplied by Neon Inc. Emails are delivered through Amazon Simple Email Service, Amazon SES, in AWS region eu-central-1 in Frankfurt, Germany.

4.2 Double opt-in

Registration only becomes effective when the recipient selects the confirmation link in the double opt-in email. Registration, delivery and confirmation are logged with timestamps. The purposes are to provide the requested product launch notification and to document consent.

The legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time with future effect through the unsubscribe link or by emailing info@blogmojo.de. This does not affect the lawfulness of earlier processing.

4.3 Recipients and international transfers

Cloudflare processes form data to operate the Worker. Neon Inc. processes the data stored in the mailer database. Amazon Web Services EMEA SARL and relevant AWS entities process the email address and delivery data for Amazon SES. Emails are sent through the Frankfurt region. Daily backups of the mailer database are also stored locally and in the controller's Google Drive account.

Access from the USA cannot be entirely excluded due to provider, group and support structures. Restricted transfers are covered by the providers' contractual safeguards, particularly Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Further information is available in the data processing terms of AWS, Cloudflare, Neon and Google, and in the providers' privacy policies.

5. Purchase, customer portal and transactional emails

5.1 Polar as seller and independent controller

Purchases are concluded through Polar Software, Inc., 3500 South DuPont Highway, Dover, Delaware 19901, USA, as merchant of record and authorised reseller. Polar processes identity, contact, order, payment, invoice, tax, fraud-prevention and subscription data under its own responsibility. The Polar Privacy Policy applies to that processing.

5.2 Data received in connection with a purchase

Polar provides the Provider, through its dashboard, notifications and a signed webhook, with the order data required for product delivery, customer support and assignment. This may include the email address, name, product and order identifiers, order status, language or locale, and subscription status. We do not receive full card or bank account details.

A successfully completed purchase is sent through a separate Polar webhook to the mailer interface under graduallyai.com. The email address, any name supplied, product, order and subscription identifiers, language, price, discount, tax and total amounts, the status of the required Terms and EULA field, and a WPAgently customer tag are stored in the Neon Postgres database. The mailer sends a contract confirmation containing the Terms, EULA and withdrawal notice that applied when the order was placed. It stores the delivery time, Amazon SES message identifier and SHA-256 hashes of the legal-text versions sent as delivery evidence. The purposes are customer assignment, product delivery, evidence of the incorporated terms and transactional communication. This does not provide a legal basis for marketing emails without separate consent.

The legal basis for provision, licensing and support is Article 6(1)(b) GDPR. Article 6(1)(c) GDPR applies where data is required to comply with commercial, tax or consumer-protection law. Secure assignment and abuse prevention may additionally rely on Article 6(1)(f) GDPR.

5.3 Online withdrawal function

When you submit the online withdrawal function, we process your full name, email address, Polar order number or contract identifier, language, the confirmed wording of the withdrawal declaration, the server-side receipt time, a random request identifier, and the status and identifiers of the receipt and forwarding emails. The declaration is stored in the Neon Postgres database, forwarded through Amazon SES to Polar and info@blogmojo.de, and sent to the specified email address as a confirmation of receipt. For abuse prevention, the IP address and normalised recipient address are each processed only as a SHA-256 hash in short-lived counters. The IP counter runs for ten minutes and the recipient counter for 24 hours. The counters are deleted after their time window and an additional cleanup period expire.

The purposes are to receive, forward, process and document the withdrawal. The legal bases are Article 6(1)(b) and (c) GDPR. Article 6(1)(f) GDPR additionally applies to protection against automated abuse. Our legitimate interest is protecting the public function and reliably delivering legally significant declarations.

6. Voluntary activation of a paid licence

Free works without a licence key and does not communicate with Polar. Only if a user voluntarily activates a paid licence key does the Companion plugin communicate directly with Polar's licence API for activation, daily validation and deactivation. Depending on the operation, it transmits:

  • the licence key
  • WPAgently's fixed Polar organisation identifier
  • the Polar activation identifier
  • the normalised home URL of the WordPress website
  • on activation, the website URL as the activation label and metadata

The purposes are to provide the purchased licence, assign an activation, enforce the site limit and block expired or revoked licences. The legal basis is Article 6(1)(b) GDPR. Polar processes API data under the roles and terms applicable to its licensing service. Where Polar processes data on the Provider's behalf, Polar's data processing terms apply. Polar acts as an independent controller for its own customer-facing activities.

The plugin stores the licence key, activation identifier, validation timestamps and necessary licence status in the Customer's WordPress database. Its public status route never returns the licence key. The Customer can deactivate the site in the plugin or Polar customer portal.

The licence requests do not transmit WordPress content, database content, usernames or WordPress application passwords to Polar.

7. Static update channel

The two WordPress plugins periodically retrieve a static update manifest from wpagently.com. When an update is installed, the associated package is also downloaded from wpagently.com. This causes Vercel and Cloudflare to process the connection and server-log data described in Section 3, particularly the IP address, timestamp, requested manifest or package URL, and user agent. WordPress content and WordPress credentials are not transmitted.

The purpose is to supply functional and security updates securely. The legal basis is Article 6(1)(b) GDPR during the contract term and Article 6(1)(f) GDPR for secure technical delivery.

8. Support and contact

When you contact us by email or telephone, we process, depending on the contact method, your email address or telephone number, the contact information you provide, the content of your request and the technical details required to answer it. Emails sent to info@blogmojo.de are processed in Google Workspace. Google Ireland Limited and relevant Google entities process email content, sender and recipient data, and technical delivery and log data. Do not send passwords, API keys, complete database exports or other secrets by email.

Google Workspace is subject to the Cloud Data Processing Addendum and its incorporated transfer terms. Access from third countries cannot be entirely excluded due to group and support structures. Further information is available in the Google Privacy Policy.

The legal basis is Article 6(1)(b) GDPR for contract-related enquiries. Article 6(1)(f) GDPR applies to other enquiries. Our legitimate interest is answering and documenting the communication.

9. Cookies and local storage

wpagently.com does not set analytics, marketing or profiling cookies and does not use browser local storage for those purposes. Hosting or security providers may use strictly necessary cookies or comparable identifiers in a specific threat situation, for example to prevent bots or abuse. Where access to a user's device is strictly necessary, Section 25(2) of the German Telecommunications Digital Services Data Protection Act applies. Any subsequent processing of personal data relies on the legal bases stated in Section 3.

When a user opens Polar Checkout or the Polar customer portal, they leave wpagently.com. Polar is responsible for its own cookies and comparable technologies on those services.

10. Recipients

Depending on use, personal data may be received by:

  • Vercel Inc., website hosting and static update channel
  • Cloudflare, Inc., website delivery and mailer Worker
  • Amazon Web Services EMEA SARL and relevant AWS entities, email delivery
  • Neon Inc., mailer database
  • Google Ireland Limited and relevant Google entities, support communications in Google Workspace and time-limited mailer database backups in Google Drive
  • telecommunications providers, where technically required for telephone contact
  • Polar Software, Inc., sales, customer portal, licence service and subscription management
  • lawfully authorised authorities, courts, tax advisers or other professional advisers where required

Finn Hillebrandt does not sell personal data or disclose it for third-party advertising.

11. Retention

We retain personal data only for as long as required for its purpose or by statutory duties and the establishment, exercise or defence of legal claims.

  • Server-log retention follows the configured periods of Vercel and Cloudflare. Logs are then deleted or anonymised unless they are required for longer to investigate a security incident.
  • Unconfirmed waitlist registrations are not used for newsletters or marketing. Pending list memberships that remain unconfirmed for seven days are deleted automatically. If the associated contact belongs to no other list and is still marked only as pending, the contact record is deleted as well. Confirmed records are retained until consent is withdrawn or the recipient unsubscribes. Evidence of consent may be retained until the regular limitation period expires.
  • Customer and licence assignments, contract confirmations and their delivery records are retained for the contract term. Necessary evidence may then be retained until statutory limitation periods expire.
  • Online withdrawal declarations and their delivery records are automatically deleted after the end of the third calendar year following receipt. Statutory retention duties or the establishment, exercise or defence of specific legal claims may require longer retention in an individual case.
  • Support communications are normally deleted no later than three years after the end of the calendar year in which the request was closed, unless a longer statutory duty or ongoing dispute applies.
  • Accounting records are generally retained for eight years, certain business correspondence for six years and annual accounts for ten years where those records arise at the Provider. Polar, as seller, primarily retains the end customer's purchase records.
  • Daily mailer database backups are normally limited to the latest 14 backup sets. If daily backup and pruning complete successfully, deleted data will therefore normally age out of local and Google Drive backups within 14 days. A temporary backup or pruning failure may extend that period. Backups are used only for restoration and security purposes.

12. Data subject rights

Subject to the GDPR, you have in particular the following rights:

  1. access under Article 15 GDPR
  2. rectification under Article 16 GDPR
  3. erasure under Article 17 GDPR
  4. restriction under Article 18 GDPR
  5. data portability under Article 20 GDPR
  6. objection to processing under Article 6(1)(e) or (f) GDPR in accordance with Article 21 GDPR
  7. withdrawal of consent with future effect under Article 7(3) GDPR
  8. complaint to a supervisory authority under Article 77 GDPR

To exercise rights against Finn Hillebrandt, email info@blogmojo.de. For data Polar processes under its own responsibility, you may additionally contact privacy@polar.sh.

The supervisory authority responsible for Finn Hillebrandt is:

The State Commissioner for Data Protection of Lower Saxony
Prinzenstraße 5
30159 Hannover
Germany
Website: https://www.lfd.niedersachsen.de

13. Requirement to provide data and automated decisions

Data marked as required for a purchase, paid licence activation or support request must be supplied if the relevant service is to be used. Free does not require this data. Polar cannot assign a purchase and paid access without an email address. A plan-bound licence cannot be activated or validated without the data stated in Section 6.

Finn Hillebrandt does not make decisions producing legal or similarly significant effects solely through his own automated profiling. Polar may use automated payment and fraud-prevention procedures. Details are available in the Polar Privacy Policy.

14. Changes

We update this Privacy Policy when processing operations, providers or the legal framework change. The version published on wpagently.com describes the current procedures actually used there.

Imprint Privacy Terms Withdraw from contract EULA Cancel subscription
info@blogmojo.de WPAgently is built and operated by Finn Hillebrandt. © 2026 WPAgently