Privacy Policy

Reading Time: 13 minutes

Effective date: 2 October 2026
Last updated: 2 October 2026

This Privacy Policy explains how Ermada (“WPservice“, “we“, “us“, “our“) collects, uses, shares and protects personal data when you:

  • visit wpservice.pro (the “Website“);
  • buy or use our professional services: WordPress speed optimisation, maintenance, expert analysis and related work (“Professional Services“);
  • use our WordPress plugins, including the Dr. Speed product line (such as Dr. Speed: AI Assets Scanner), Speed Analyzer WP and Code Unloader (the “Plugins“);
  • use the online services our Plugins connect to, such as the Dr. Speed scanning service, API keys, credits and licences (the “Cloud Services“); or
  • take part in our affiliate programme.

1. Summary

  • We collect only what we need to run the Website, sell and deliver our services, and operate the Cloud Services.
  • We do not sell your personal information.
  • Analytics and advertising cookies are used only if you allow them in our cookie banner.
  • Our Plugins send nothing to us until you enter or validate an API key. After that, they send only what the Cloud Services need (mainly your site’s domain and the URLs you choose to scan).
  • The Cloud Services analyse web pages, not people. They do not send your data to any third-party artificial-intelligence or large-language-model service.
  • You can access, correct, delete or export your data, and object to certain uses. See Section 11 (EEA/UK) and Section 12 (United States).
  • Questions: [email protected]

2. Who we are

The controller responsible for your personal data is:

Ermada, obrt za računalne usluge, vl. Dalibor Družinec
Stonska ulica 1, 10000 Zagreb, Croatia
Company registration / OIB: 65391314985
VAT ID: HR65391314985 (not in the Croatian VAT system)
Email: [email protected]

We are a small business and are not required to appoint a Data Protection Officer. Please send all privacy questions and requests to [email protected].


3. When we are a controller and when we are a processor

We are the controller for personal data we decide how to use: Website visitors, customers’ account, order and billing data, support conversations, affiliates, and the account, key, credit and security data of the Cloud Services.

We are a processor acting on your instructions:

  • when we work on your website during Professional Services and can see personal data stored there (for example your site’s users, customers or orders); and
  • when pages you ask the Cloud Services to scan contain personal data (for example an author’s name published on a page).

In those cases you are the controller of that data and responsible for your own website’s privacy notice. We process it only to deliver the service, under our Data Processing Addendum, which forms part of our Terms and Conditions.


4. What we collect, why, and our legal basis

The legal bases below are those of the EU and UK GDPR (Art. 6(1)): contract (to provide what you asked for), legal obligation, legitimate interests (balanced against your rights), and consent (which you can withdraw at any time).

4.1 Visiting the Website

DataWhyLegal basis
IP address, browser and device type, pages requested, referrer, date and timeTo deliver the Website and keep it secure (firewall, bot and attack protection, caching)Legitimate interests
Cookie and similar identifiersSee Section 6Consent, except strictly necessary cookies
Approximate country (from IP address)To show prices in your local currencyLegitimate interests

4.2 Contacting us

When you use our contact form or email us, we receive your name, email address, message and anything else you choose to tell us. The contact form is protected by Cloudflare Turnstile, which checks technical browser and device signals to tell humans from bots.

Why: to answer you and, if you ask, prepare an offer. Legal basis: steps at your request before a contract, and legitimate interests.

4.3 Buying from us and your customer account

  • Order and billing data: name, email, billing address, company name and VAT number (if you give them), country, order contents, currency, amount and payment status.
  • Payment data: payments are handled by our payment providers (see Section 7). We do not receive or store your full card number or PayPal password.
  • Account data: email, username and password (stored by WordPress only in hashed form). If an account is created automatically when you buy, we email you your login details.
  • Sign in with Google: if you use it, Google gives us your name, email address and profile picture.

Why: to process orders, deliver what you bought, issue invoices, provide support and prevent fraud. Legal basis: contract, legal obligation (accounting and tax records) and legitimate interests (fraud prevention).

4.4 Professional Services

  • Access credentials you give us (WordPress admin, hosting panel, FTP/SFTP, CDN or DNS). We use them only for the agreed work and ask you to change or remove them when we finish.
  • Project information and communications: contact persons, instructions, reports and correspondence.

Legal basis: contract. Any personal data we see on your website is processed on your behalf as a processor (see Section 3).

4.5 Dr. Speed Cloud Services (scanning service, API keys and credits)

How it works. A Dr. Speed plugin on your WordPress site talks to our API at wpservice.pro and to our scanning service. The scanning service opens the pages you select in an automated browser, on desktop and mobile, to find out which scripts and styles each page really needs. It then returns rules to your plugin. The scanning service identifies itself in its browser “user agent” with a link to wpservice.pro/bot.

What we process:

DataDetails
Free key registrationYour site’s domain and the plugin version, sent when you click Validate your key. We do not ask for your name or email for a free key. Each free key is tied to one domain and holds a small number of starter credits.
API keyWe store only a one-way hash of your key plus its last 8 characters (so you can recognise it). The full key is shown to you, or emailed to you, when it is issued. We cannot recover a lost key, but you can regenerate it in My Account.
CreditsBalance, purchases, charges and automatic refunds (a credit ledger).
Scan jobsDomain; the list of page URLs you choose to scan; number of pages; one-time job tokens; credits reserved, used and refunded; a summary of the caching and optimisation plugins detected on your site; scan status and result counts.
Page contentOur automated browser loads each page as a visitor would, including images, scripts and third-party resources embedded in the page. Page content and screenshots are compared in memory and are not saved to disk.
Staging login (optional)If your site is password-protected (HTTP Basic Auth) and you enter a username and password in the plugin, they are stored encrypted in your WordPress database and kept encrypted in our scanning queue. They are used only to load your pages.
Misuse reportsIf someone tries to misuse the scanner’s access token on your site, the plugin may report a short one-way hash computed from that visitor’s IP address, browser user agent and requested path, never the IP address itself. We treat this hash as pseudonymised personal data and use it only to detect abuse.
Rate limitingIP addresses of servers calling our API are used briefly to limit abuse. They are not stored in our database, and the temporary counters expire within an hour.
Service telemetryTechnical measurements about scans (timings, error types, counts). Host names are pseudonymised with a keyed hash before they leave the scanning service.

Why: to provide the scanning service you requested (including the free tier), bill and refund credits, prevent abuse (for example, one free key per domain), keep the service secure, and fix and improve it. Legal basis: contract, and legitimate interests (security, abuse prevention and service improvement).

Mostly technical data. Most of this is information about websites, not people. It becomes personal data when it relates to an identifiable person, for example a sole trader’s domain, a URL containing a name, or personal information published on a scanned page.

No third-party AI, and no automated decisions about people. The scanning service decides by testing pages (for example, whether a page still displays and works without a given script). These are decisions about website files, not about individuals, and have no legal or similarly significant effect on anyone (Art. 22 GDPR). We do not send your data to third-party artificial-intelligence or large-language-model services. If this ever changes, we will update this policy first.

4.6 Our WordPress plugins

Our Plugins run on your server. Apart from what is described here, they do not send personal data to us.

  • Dr. Speed: AI Assets Scanner sends nothing to us until you save or validate an API key. After that it sends only the data described in Section 4.5. It stores its settings (including your API key and the encrypted staging login) in your site’s database and deletes them when you delete the plugin. Your key and remaining credits stay in our system so you can restore them later.
  • Speed Analyzer WP (premium licences): licence key, the domain(s) where it is activated, activation status and expiry date. The plugin sends your site’s URL to wpservice.pro to check that the licence is valid for that site. Nothing else is sent.
  • Code Unloader: runs entirely on your site and sends no data to us.
  • Future Dr. Speed products. Before we release a new product or feature that sends data to us, we will describe that data flow in this policy and in the product’s documentation.
  • Plugins you download from WordPress.org are distributed by WordPress.org, not by us. Downloads and update checks are covered by the WordPress.org privacy policy.

4.7 Affiliate programme

  • Affiliates: name, email, website, payout details (for example your PayPal email address), tax information if the law requires it, and referral statistics (clicks, referred orders and commissions). Legal basis: contract.
  • Referred visitors: when you follow an affiliate link, a referral cookie (valid for up to 60 days) records which affiliate referred you, so we can pay the correct commission. Legal basis: consent where the law requires it, otherwise legitimate interests.

4.8 Blog comments and testimonials

  • Comments: name, email, website (optional), comment text, and IP address and browser user agent for spam detection.
  • Testimonials: we publish your name, company, photo and statement only with your permission.

Legal basis: consent and legitimate interests.

4.9 Emails we send

We send transactional and service emails: order confirmations, API keys, login details, security notices, and important changes to our services or terms. We do not send marketing emails.


5. Where your data comes from

  • From you: forms, checkout, your account, emails, and the plugin settings you enter.
  • From your WordPress site, through our Plugins, once you enter or validate an API key.
  • From Google, if you use Sign in with Google.
  • From payment providers: payment status and fraud signals.
  • From affiliates: referral information.
  • From public websites you ask the Cloud Services to scan.

6. Cookies

Cookies are small files your browser stores. Some are strictly necessary for the Website to work (for example your login, basket and cookie choices) and are set without consent. All others (analytics, advertising, affiliate tracking) are used only if you accept them in our cookie banner. You can Accept all, Reject all or Customise, and change your choice at any time through the Cookie settings link at the bottom of every page.

CookieProviderPurposeCategoryLifetime
cookieyes-consentCookieYes (on our behalf)Remembers your cookie choicesNecessary1 year
cf_clearanceCloudflareSecurity and bot protectionNecessaryup to 1 year
wordpress_*, wordpress_logged_in_*, wp-settings-*WordPress (our site)Login session and account preferencesNecessarysession to 1 year
woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*WooCommerce (our site)Basket and checkoutNecessarysession to 2 days
swpm_sessionSimple Membership (our site)Member login sessionNecessarysession
g_state, googlesitekit_auth_nonceGoogleSign in with GoogleFunctionalsession to 180 days
_ga, _ga_*Google Analytics 4Visitor statisticsAnalytics (consent)up to 2 years
_gcl_* and other Google Ads cookiesGoogle AdsMeasuring which ads lead to purchasesAdvertising (consent)up to 90 days
_vk_vid, _vk_session_id, _vk_referrer, _vk_landing, _vk_attr_firstVisibilityKitVisitor statistics and traffic-source attributionAnalytics (consent)session to 1 year
slicewp_aff, slicewp_visitSliceWP (our site)Affiliate referral attributionMarketing (consent)up to 60 days

Google Consent Mode. We use Google’s Consent Mode. If you decline analytics or advertising cookies, Google tags set no cookies but may send limited, cookieless signals (for example, that a page was viewed). Google uses these only in aggregated form.

Global Privacy Control. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a refusal of advertising cookies and as an opt-out of “sale” or “sharing” for that browser.


7. Who we share data with

We share personal data only as described here.

7.1 Service providers (processors)

They act on our instructions under data processing agreements.

ProviderServiceData involvedLocation / transfer safeguard
Hostinger International Ltd.Hosting of wpservice.pro, its database and emailAll Website, customer and Cloud Services account dataGermany (Frankfurt), EU
Cloudflare, Inc.Content delivery, security, Turnstile bot protectionIP addresses, request dataUSA / EU–US Data Privacy Framework and SCCs
Railway CorporationHosting of the Dr. Speed scanning service and its temporary job queueScan jobs, URLs, page content (processed temporarily), encrypted staging login, server IP addresses, technical logsUSA (US West) / EU–US Data Privacy Framework and SCCs
Google Ireland Ltd. / Google LLCAnalytics, Ads measurement, Sign in with Google, Site KitCookie identifiers, usage data, sign-in dataEU / USA, EU–US Data Privacy Framework and SCCs
Complete Web Resources LLC (Visibility Kit)Website analytics: measuring visits that come from AI tools and other traffic sourcesCookie identifiers, pages visited, traffic sourceUSA / SCCs
CookieYes LimitedCookie consent managementConsent records (anonymised consent ID, choices, date)United Kingdom / UK adequacy decision
Defiant, Inc. (Wordfence)Website firewall and securityIP addresses, request dataUSA / SCCs
WooPayments (WooCommerce Ireland Ltd. and Automattic Inc., with Stripe Payments Europe, Ltd. as payment processor)Card payments and currency conversionOrder and payment dataIreland and USA / SCCs; Stripe also under the EU–US Data Privacy Framework

7.2 Independent controllers

They process data under their own privacy policies.

  • PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, and for US customers, PayPal, Inc. including Venmo) processes your payment.
  • Google, when you use Sign in with Google, under Google’s own privacy policy for your Google account.
  • WordPress.org, for plugin downloads and updates.

7.3 Others

  • Professional advisers (accountants, lawyers, auditors) under a duty of confidentiality.
  • Authorities (for example the Croatian Tax Administration, courts or police) when the law requires it.
  • A buyer or successor of our business or of a product line (for example the Dr. Speed products), if it is sold, merged or transferred. The recipient must keep protecting your data in line with this policy, and we will tell you before your data becomes subject to a different privacy policy.

8. International transfers

Some of our providers are located outside the European Economic Area, mainly in the United States. When we transfer personal data outside the EEA or UK, we rely on:

  • an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified companies) or of the UK government; or
  • the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant), plus additional safeguards where needed.

You can ask us for a copy of the relevant safeguards at [email protected].


9. How long we keep your data

DataRetention
Website server, CDN and firewall logsUp to 30 days
Contact enquiries12 months after our last contact, unless they lead to a contract
Customer accountWhile your account exists; deleted or anonymised within 30 days after you ask us to close it, except the records below
Orders, invoices and payment records11 years, as required by Croatian accounting and tax law
Professional Services access credentialsDeleted when the engagement ends
Professional Services project records3 years after the engagement ends (the limitation period for claims)
Scanning service: page resultsUp to 4 hours
Scanning service: job status dataUp to 2 hours (up to 24 hours for paused scans)
Scanning service: job records in the queue (URL list, tokens, encrypted staging login)Kept in a rolling buffer of the most recent 100 completed and 50 failed scan jobs across all customers, and overwritten as new scans run
Scan history (domain, pages, credits, result counts)Shown in your account; older entries are archived once more than 5,000 scans are stored in total, and archives are deleted after 12 months
Cloud Services event logsSecurity events 1 year; billing and credit events 2 years; operational events 30 days
Cloud Services telemetry30 days
Scanning service technical logsUp to 30 days
API key hash, credit balance and credit ledgerWhile the key or account exists (paid credits do not expire). You can ask us to delete it at any time, and any unused credits are then lost.
Affiliate dataWhile you are an affiliate; payout records 11 years
Analytics data (Google Analytics)14 months
Cookie consent records1 year
Blog commentsUntil you ask us to remove them

When a retention period ends, we delete or irreversibly anonymise the data.


10. Security

We protect personal data with appropriate technical and organisational measures, including:

  • HTTPS encryption;
  • storing API keys and job tokens only as one-way hashes;
  • encrypting optional staging logins;
  • pseudonymising identifiers in logs and telemetry;
  • a web application firewall;
  • access restricted to people who need it; and
  • regular updates.

No system is perfectly secure. If a personal data breach puts your rights at risk, we will notify the Croatian data protection authority within 72 hours where required, and notify you without undue delay when the risk is high.

Please treat your API key like a password. If you think it has been exposed, regenerate it in My Account or contact us.


11. Your rights (EEA, UK)

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:

  • access your personal data and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (“right to be forgotten”);
  • restrict our processing;
  • data portability: receive the data you gave us in a machine-readable format, or have it sent to another provider;
  • object at any time to processing based on legitimate interests, and always to direct marketing;
  • withdraw consent at any time, without affecting processing already carried out; and
  • lodge a complaint with a supervisory authority. In Croatia this is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, azop.hr. You can also contact the authority where you live or work (in the UK, the Information Commissioner’s Office, ico.org.uk).

How to use your rights: email [email protected]. We may ask you to confirm your identity (for example, from the email address linked to your account or key). We reply within one month. For complex requests this can be extended by two further months, and we will tell you if so. Requests are free unless they are manifestly unfounded or excessive.

If we process data on behalf of a customer (see Section 3), please contact that customer. We will help them respond.


12. US privacy rights

This section applies to residents of the United States. It covers the California Consumer Privacy Act (as amended by the CPRA) and the privacy laws of other states such as Virginia, Colorado, Connecticut, Utah, Texas and Oregon. We extend these rights to all US residents, whether or not a particular state law applies to us.

12.1 Categories of personal information we collect (last 12 months)

CategoryExamplesCollected
IdentifiersName, email, IP address, account username, API key (hashed), cookie IDsYes
Customer records (Cal. Civ. Code § 1798.80)Billing address, company, payment statusYes
Commercial informationOrders, credits purchased and used, licencesYes
Internet or network activityPages visited, interactions with the Website, scan job dataYes
GeolocationApproximate country (from IP address)Yes (approximate only)
Professional informationCompany name, role (if you tell us)Yes
Sensitive personal informationAccount login and password, used only to provide your accountYes (limited)
Biometric, health, precise geolocation, and other sensitive categories—No
Inferences / profiling—No

Sources, purposes and recipients: see Sections 4, 5 and 7. We disclose personal information for business purposes only to the service providers and parties listed in Section 7. Retention: see Section 9.

12.2 Sale, sharing and targeted advertising

We do not sell personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16.

We do not “share” personal information for cross-context behavioural advertising and do not use it for targeted advertising.

We use sensitive personal information only to provide the services you request, so the “right to limit” does not apply.

12.3 Your rights

Depending on your state, you have the right to:

  • know and access the personal information we have collected about you;
  • delete it;
  • correct inaccurate information;
  • obtain a portable copy of it;
  • opt out of the sale or sharing of personal information, targeted advertising and profiling; and
  • not be discriminated against for exercising your rights.

How to submit a request: email [email protected]. We operate exclusively online, so email is our request channel. We will verify your request by matching it to information we already hold, usually your account email.

Authorised agents may submit a request with your signed permission. We may still ask you to confirm your identity directly.

We respond within 45 days, or up to 90 days if we tell you we need more time.

Appeals: if we decline your request, you can appeal by replying with “Appeal” in the subject line within 60 days. We will answer within 60 days (45 days in some states). If you are not satisfied, you can contact your state Attorney General.

12.4 Other US notices

  • Do Not Track: browsers’ “Do Not Track” signals have no common standard, so we do not respond to them. We do honour Global Privacy Control (see Section 6).
  • California “Shine the Light”: we do not disclose personal information to third parties for their own direct marketing.
  • Nevada: we do not sell covered information as defined by Nevada law.

13. Children

Our Website and services are intended for businesses and adults. They are not directed at children under 16 (or under 13 in the United States), and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.


14. Links and third-party services

The Website links to third-party websites and services (for example WordPress.org, Trustpilot or PayPal). Their privacy practices are their own responsibility. Please read their privacy policies.


15. Changes to this policy

We will update this policy when our services or the law change, and show the new “Last updated” date at the top. If we make material changes, we will notify you in advance by email, in the Plugin, or with a notice on the Website. Earlier versions are available on request.


16. Contact

Ermada, Stonska ulica 1, 10000 Zagreb, Croatia
Email: [email protected]