Data processing agreement

Article 28 GDPR terms between you (controller) and {{LEGAL_ENTITY_NAME}} (processor), effective when you use SpamGuard on a site you operate. Last updated 2026-08-11.

Subject matter

We process submissions from your website in order to judge whether they are spam, and for no other purpose.

Duration: for as long as your account is active, plus the retention period of your plan.

Categories of data and data subjects

Data subjects: visitors who submit a comment, registration or form on your site.

Data: submission content, name, email address, IP address, browser identification, referring page, and non-identifying measurements of form interaction.

No special categories of data are requested. If a visitor volunteers such data inside a comment, it is processed as part of the submission text and subject to the same non-storage rule.

Our obligations

We process only on your documented instructions, which for this service means: judging submissions you send us.

Everyone with access is bound by confidentiality.

We apply the measures in the security section below.

We assist you with subject access, erasure and impact assessments. The plugin’s integration with WordPress privacy tools is designed to make most of that self-service.

On termination we delete your data on the retention schedule, or sooner if you ask.

Sub-processors

Railway — application hosting, European Union.

Supabase — database hosting, Frankfurt, Germany.

We will give notice before adding a sub-processor, and you may object.

International transfers

None. Processing and storage take place within the European Union.

This is the reason to choose us over alternatives that transfer to the United States under standard contractual clauses.

Security

Transport encryption on every connection. API keys stored as peppered hashes, never in recoverable form. Database access restricted to the service role with row-level security enabled on every table.

Submission content is not stored by default — a one-way fingerprint and derived numbers are kept instead. Data minimisation is the primary security measure here, because data that was never stored cannot leak.

We will notify you without undue delay of any breach affecting your data.

Audit

We will provide the information needed to demonstrate compliance with this agreement, and allow audits on reasonable notice.

← SpamGuard