Privacy Policy
Last updated: July 8, 2026 · Version 1.2
This Privacy Policy explains how [protected] ([protected]), established in Romania ("we", "us"), collects and processes personal data when you use the Webkio platform ("Service"). It is written to comply with the EU General Data Protection Regulation (GDPR) and applicable national law.
1. Controller & Two Roles
Our role depends on whose data is involved:
- We are the controller of personal data about you, our account holder and website visitor - your account, billing, support, and usage data.
- We are a processor of personal data about the End Users of websites you build and publish (e.g. people who submit your data, subscribe, book, or buy from your store). For that data you are the controller; our handling is governed by the Data Processing Agreement.
This policy is about the first role. For your rights as a data subject, see our GDPR page.
2. Data We Collect
- Account data - your name, email address, hashed password, and (if you enable it) your two-factor authentication secret.
- Content & projects - the websites, pages, media, and settings you create.
- Billing data - your subscription plan, plan dates, and a payment-provider customer identifier. Card/payment details are entered into and held by Creem; we do not receive or store full card numbers.
- Usage & analytics - page views and traffic on your projects and our marketing site, including IP address, approximate country (derived from IP via a local geolocation database), referrer, and browser/user-agent.
- Security & audit logs - records of key actions, login attempts, and IP addresses, used to secure accounts and detect abuse.
- Communications - messages you send us via the contact form (name, email, message) or support, and our email correspondence.
3. Why We Process It & Legal Bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and maintaining the Service, your account, and your projects | Performance of a contract |
| Processing subscriptions, invoices, and refunds | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention, audit logging | Legitimate interests; legal obligation |
| Content safety & moderation - screening content and links processed through the Service for malware, phishing, and unlawful material, and cooperating with authorities where required | Legitimate interests; legal obligation |
| Product analytics and improving the Service | Legitimate interests (and consent for non-essential cookies) |
| Responding to your enquiries and support | Legitimate interests; performance of a contract |
| Marketing communications (where applicable) | Consent; legitimate interests |
| Complying with legal/accounting obligations | Legal obligation |
4. Service Providers & Recipients
We do not sell your personal data. We share it only with vetted providers ("sub-processors") who process it on our behalf to run the Service:
| Provider | Purpose |
|---|---|
| Creem | Subscription billing & payments (Merchant of Record) |
| Stripe | Payment processing for stores you operate on Published Sites |
| Amazon Web Services (RDS, S3) | Cloud hosting, database, and file/media storage |
| Amazon Web Services (SES) | Transactional & notification email delivery |
| Twilio SendGrid | Fallback transactional email delivery when our primary provider is unavailable |
| Google (Analytics) | Marketing-site analytics (only with your cookie consent) |
| Google (reCAPTCHA) | Spam/bot protection on forms |
| Google (Sign-in) | Authenticating you if you choose "Sign in with Google" |
| Google (Fonts, Safe Browsing) | Web fonts; URL safety checks |
| OpenAI | AI features and automated content moderation. Sent: your instruction, the website text being written or checked, and a screenshot of the page for design features. Not sent: your contacts, form submissions, orders, or uploaded files. |
| MaxMind (GeoLite2) | Offline IP-to-country geolocation |
| Content delivery networks (jsDelivr, cdnjs) | Serving static assets (fonts, scripts); receive your IP as part of the request |
We may also disclose data to comply with the law, enforce our terms, or protect rights, safety, and property. See our Cookie Policy for cookies set by some of these services.
5. International Transfers
Some providers are located outside the EEA (e.g. in the United States). Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and/or recognised adequacy frameworks.
6. Retention
We keep personal data only as long as necessary for the purposes above: account and content data for the life of your account; billing records for the period required by tax/accounting law; security and analytics logs for a limited period. When you delete your account, we run a cascading deletion of your projects, pages, leads, subscribers, bookings, payments, themes, and settings, subject to any legal retention obligations and routine backups, which are overwritten on a rolling basis.
7. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), password hashing, optional two-factor authentication, role-based access controls, rate limiting, audit logging, and available IP allow-listing for administrative access. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a personal data breach where legally required.
8. Your Rights
Subject to applicable law you may access, rectify, erase, restrict, or object to processing of your personal data, withdraw consent, and request data portability. You can manage much of your data directly in your account settings, including deleting your account. For requests or complaints, contact us (Section 10). You also have the right to lodge a complaint with your data protection authority - in Romania, this is the national supervisory authority (for Romania, the ANSPDCP). Full details are on our GDPR page.
9. Cookies & Children
We use cookies and similar technologies as described in our Cookie Policy; non-essential cookies are set only with your consent. The Service is not directed at children under 16, and we do not knowingly collect their data without appropriate consent.
10. Contact
For privacy questions or to exercise your rights:
[protected]
[protected], Romania
Privacy: [protected]
11. Changes
We may update this policy; we will post changes here and update the "Last updated" date, and notify you of material changes where required.
This document is provided for transparency and general information. It is not legal advice; please have it reviewed by qualified counsel for your jurisdiction before relying on it.