GDPR & Data Protection
EU General Data Protection Regulation (GDPR) NoticeThis notice explains how Birtikta ("we", "us") processes personal data of the users of our services ("you", "data subject") in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
1. Controller and Processor RolesBirtikta acts as the data controller for the personal data of its own account holders. For the data of your clients and their end-customers that you manage through Birtikta as an agency, you are the data controller and Birtikta acts solely as a data processor, processing such data only on your documented instructions and never for our own purposes.
2. Data We ProcessDepending on your use of the service, the following categories of personal data may be processed:
- Identity and contact data (name, e-mail, phone)
- Account and membership data (username, password hashes, subscription and billing details)
- Technical and usage data of the WordPress sites you connect
- Transaction security data (IP address, session and log records)
Your personal data is processed to provide and operate the service, create and manage your account, ensure security, improve system performance, fulfil legal obligations and communicate with you.
4. Lawful Bases (Art. 6 GDPR)We process your data on the following lawful bases: performance of a contract, compliance with a legal obligation, our legitimate interests (provided they are not overridden by your rights and freedoms) and, where required, your explicit consent.
5. Data Storage and SecurityAll data is stored and processed on secure servers located within the European Union (Europe-based data centers). We do not transfer your personal data outside the EU/EEA unless an adequate level of protection and appropriate safeguards are in place. We apply administrative and technical measures such as encryption, access control and logging to prevent unauthorized access. Personal data is retained for as long as your account is active and for the legal retention periods required by applicable law, after which it is deleted, destroyed or anonymized.
6. No Sharing with Third PartiesYour personal data is never sold or shared with third parties for marketing purposes. Data is only shared with the technical infrastructure providers strictly necessary to deliver the service, with competent public authorities where required by applicable law, or where you have given your explicit consent.
7. Your Rights (Art. 15–22 GDPR)You have the right to access your personal data, to rectify inaccurate data, to erase your data ("right to be forgotten"), to restrict or object to processing, to data portability and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.
8. ContactTo exercise any of these rights, please contact us at privacy@birtikta.com. We respond to requests within the time limits set out in the GDPR.
