legal
Privacy Policy
Last updated: 12 August 2026
1. Who we are
DashboardWP is operated by Kupiša, s. r. o., Budatínska 3230/16A, 851 06 Bratislava, Slovakia, Company ID: 55804951 ("we", "us"). For the personal data described in this policy we are the controller within the meaning of the EU General Data Protection Regulation (GDPR), except where section 3 says otherwise.
This policy covers the dashboardwp.com website, the application at app.dashboardwp.com and the DashboardWP Connector plugin installed on sites you connect (together, the "Service").
2. Data you give us
- Account data: your email address, display name, password (stored only as a secure hash) and timezone.
- Sign in with Google: if you use it, Google shares your name and email address with us to create or sign you into your account.
- Contact messages: what you send through the contact form or by email, together with your name and address, so we can reply.
- Billing data: payments are handled by a payment provider. We receive confirmation, invoicing and subscription-status data, never your full card number.
3. Data from your connected sites
To provide the Service we collect data from the sites you connect: the site URL and connection credentials (stored encrypted), inventories of installed plugins, themes and WordPress versions, the site's user accounts, activity records, uptime measurements, security and malware scan results, and (when you create them) backups, which can contain the whole site including its database.
Important: for personal data contained in your sites and backups (for example your site's users, customers or commenters), you or your client are the controller, and we act as a processor: we store and process that data only on your instructions, only to provide the Service, and we never use it for our own purposes. If you need a signed data processing agreement, contact us.
If you provide wp-admin credentials for the automatic Connector installation, they are used once for that installation and are not stored.
4. Data collected automatically
Like practically every web service, our servers keep technical logs: IP address, request URL, time and basic browser information. We use them for security, abuse prevention and debugging, and keep them only as long as those purposes need.
5. Why we process data, and on what legal basis
- To provide the Service you signed up for: creating your account, connecting sites, running the operations you request (performance of a contract, Art. 6(1)(b) GDPR).
- To keep the Service secure and prevent abuse (legitimate interest, Art. 6(1)(f)).
- To send transactional email: verification, password reset, and alerts you configure (performance of a contract).
- To meet legal obligations such as accounting and tax rules (Art. 6(1)(c)).
- With your consent where we ask for it, for example product news; you can withdraw consent at any time (Art. 6(1)(a)).
We do not sell personal data, do not show ads, and make no automated decisions with legal or similarly significant effects.
6. Emails and notifications
We send emails that are part of the Service: account verification, password resets, and notifications such as uptime alerts. Alert recipients are addresses you configure; if you add someone else's address, make sure you are allowed to. Any non-essential email will always have a way to opt out.
9. International transfers
Some providers may process data outside the European Economic Area. Where that happens, the transfer is protected by an adequacy decision of the European Commission or by the Commission's Standard Contractual Clauses.
10. How long we keep data
- Account and site data: for as long as your account exists; deleted within 30 days after you close it.
- Backups: until you delete them, remove the site they belong to, or close your account.
- Uptime history: individual checks are not stored, only daily summaries and incidents.
- Technical logs: kept briefly for security and debugging, then deleted.
- Invoicing records: for as long as tax and accounting law requires.
11. How we protect data
All traffic to the Service and between the Service and your sites is encrypted in transit, requests to the Connector are cryptographically signed, site credentials and secrets are encrypted at rest, and access to production systems is restricted. No method of transmission or storage is absolutely secure, but protecting the connection between the dashboard and your sites is the core of how the Service is built.
12. Your rights
Under the GDPR you can ask us for access to your personal data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time. Write to hello@dashboardwp.com and we will respond within a month.
You also have the right to lodge a complaint with a supervisory authority: in Slovakia, the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR, dataprotection.gov.sk), or the authority of the country where you live.
13. Children
The Service is not directed at children and requires users to be at least 18 years old. We do not knowingly collect personal data from children.
14. Changes to this policy
When the Service or the law changes, this policy will change with it. For material changes we will notify you by email or in the dashboard. The "Last updated" date above always reflects the current version.
15. Contact
The controller is:
- Kupiša, s. r. o.
- Budatínska 3230/16A, 851 06 Bratislava, Slovakia
- Company ID: 55804951
- Tax ID: 2122092764
- VAT ID: SK2122092764
- Registered in the Commercial Register of the Bratislava III Municipal Court, Section: Sro, Insert No. 172970/B
For anything related to personal data, contact hello@dashboardwp.com. Security reports go to security@dashboardwp.com.