GDPR and data protection policy – TSGuard
1. Purpose of this document
This document describes how TSGuard WordPress Security and TS-Plugins handle personal data in the context of Regulation (EU) 2016/679 (GDPR) and national data protection law. It addresses both customers who use the product and individuals whose data may be processed through your site (visitors, users, IPs, etc.).
2. Roles in processing
- You (the client / site administrator) are the controller for data processed on your own WordPress site (e.g. security logs, blocked IPs, login events). You must have a legal basis and, where applicable, information/consent for the data subjects.
- TS-Plugins acts as controller for data processed for the purpose of providing the licence, verifying the licence and support services (account, billing, communication). In certain scenarios (e.g. central API, aggregated statistics), we may act as controller or processor depending on the service architecture.
3. Data processed by TSGuard on your site
The TSGuard plugin, installed on your server, may process among other things:
- IP addresses – for blocking, rate limiting, security logs.
- Events – login attempts (success/failure), firewall events, panic mode activation, etc.
- Identifiers / user ID – where relevant for logs (e.g. who performed an action in admin).
- Metadata – timestamp, event type, severity.
Storage: this data is stored in your WordPress database (tables created or used by the plugin). You decide retention period and deletion policy at site level.
Legal basis (suggestion for your site): legitimate interest (security of the site and users), possibly legal obligations. For employees/collaborators, you may need to inform them about monitoring in your internal privacy policy.
4. Data sent to TS-Plugins
Depending on the features used, the following may be sent to our servers (ts-plugins.net / API):
- Licence verification: domain, licence key (or hash), plugin version – for licence validation and abuse prevention.
- Support / errors: messages and any files/logs you send to support.
- Statistics / improvements: only if applicable and described in documentation or settings (e.g. anonymous usage reports). We do not include personal data in such reports without legal basis and transparency.
Legal basis (us): contract performance, legitimate interest (security, service improvement), consent where applicable.
5. Your obligations as controller (your site)
- Legal basis: ensure that processing on your site (IPs, logs, blocks) has a legal basis (e.g. legitimate interest for security).
- Transparency: inform visitors/users (via your site's privacy policy) that you collect technical and security data (IP, events) and for what purposes.
- Retention period: set and apply a reasonable retention period for logs and IP lists; delete or anonymise after that period.
- Data subject rights: respond to requests for access, rectification, erasure, restriction, portability, objection, in accordance with GDPR. TSGuard provides tools to manage data (e.g. view/delete logs); implementing procedures remains your responsibility.
- Security: take appropriate technical and organisational measures (limited admin access, backups, updates).
6. What we (TS-Plugins) do in compliance with GDPR
- We process only the data necessary for providing the licence, verification, support and legal compliance.
- We use processors (hosting, email, tools) with contractual confidentiality and security commitments.
- We do not sell personal data.
- We respect rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) and respond to requests within a reasonable time (usually 30 days).
- We retain data only as long as necessary (contractual relationship, legal obligations, disputes).
- We report security breaches to the supervisory authority and, where applicable, to data subjects, in accordance with GDPR.
7. International transfers
If we use providers or servers outside the EEA, we ensure appropriate safeguards (adequacy decisions, standard contractual clauses, etc.) in accordance with GDPR.
8. Data subject rights
Data subjects (including you as data subject) have the right to: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority (in Romania: ANSPDCP – anspdcp.ro).
Requests to TS-Plugins: support@ts-plugins.net.
Requests regarding data on your site: must be addressed to you as controller of that site.
9. Documentation and updates
We recommend keeping a copy of the privacy policy and GDPR information you provide to your site users. We may update this GDPR policy. Significant changes will be communicated (on the site or by email). The "Last updated" date indicates the current version.
10. Contact
For questions about data processing and GDPR:
Email: support@ts-plugins.net
Website: https://ts-plugins.net
This document is for informational purposes and does not constitute legal advice. For concrete implementation and full compliance, consult a lawyer specialised in data protection and/or the supervisory authority.