Privacy Policy
PRIVACY POLICY
Effective Date: 23.02.2026
1. Identity of the Data Controller
WooLinker.com is operated by:
TER22 AREA S.R.L.
Trade Register Number: J2018001796222
Unique Registration Code (CUI): RO39590977
European Unique Identifier (EUID): ROONRC.J2018001796222
Registered Office: Iași, Strada Vasile Lupu nr. 25, ap. 16, Romania
Email: [email protected]
TER22 AREA S.R.L. acts as Data Controller under Regulation (EU) 2016/679 (GDPR).
2. Nature of the Services
WooLinker.com sells exclusively digital products, including WordPress and WooCommerce plugins distributed under software license agreements.
No physical goods are shipped.
3. Categories of Personal Data Processed
Depending on how you interact with our website, we may process the following categories of data:
3.1 Account and Purchase Data
- Name and surname
- Email address
- Billing information
- VAT number (for B2B transactions)
- Order history
3.2 License Validation Data
In order to activate and validate plugin licenses, our systems process:
- The domain name where the plugin is installed
- The license key
For update verification:
- The license key is transmitted to our licensing server.
We do not collect telemetry, usage statistics, or behavioral tracking data from within the plugins.
3.3 Payment Data
Payments are processed securely via Stripe.
We do not store full payment card information on our servers.
3.4 Technical Data
- IP address
- Browser type
- Device information
- Security-related metadata
This data may be processed via hosting infrastructure and Cloudflare security services.
3.5 Support Data
Information submitted through our ticket support system, including:
- Name
- Content of communication
4. Legal Basis for Processing (Art. 6 GDPR)
We process personal data based on:
- Contract performance (Art. 6(1)(b)) – order processing, license activation, support.
- Legal obligation (Art. 6(1)(c)) – accounting, tax compliance (including VAT OSS and B2B reverse charge).
- Legitimate interest (Art. 6(1)(f)) – fraud prevention, license protection, IT security, abuse prevention.
- Consent (Art. 6(1)(a)) – marketing cookies or tracking tools, where applicable.
5. License Data and Legitimate Interest
License validation data is retained to:
- prevent fraud
- prevent license abuse
- maintain software security
- verify entitlement to updates and support
Expired license records may be retained indefinitely under legitimate interest for fraud prevention and audit purposes.
6. Payment and Invoicing
Payments are processed via Stripe.
Invoices are generated automatically via Nexus CRM, an external invoicing and CRM system.
VAT OSS and B2B reverse charge mechanisms are applied in accordance with EU tax regulations.
7. Hosting and Infrastructure
Our website is hosted in Romania by:
Cyber_Folks Romania (cyberfolks.ro)
We use Cloudflare for security and DDoS protection, including bot management and “Under Attack” mode when necessary.
Cloudflare may process IP addresses and connection metadata for security filtering.
8. Google Services and Advertising
We use:
- Google Ads
- Google Merchant Center
These services may process limited data for advertising performance and conversion tracking, subject to your cookie consent preferences.
We do not operate newsletter campaigns.
9. Data Retention
We retain personal data as follows:
- Account data: 1 year after account inactivity
- Accounting and invoicing data: as required by Romanian fiscal law (minimum 10 years)
- Expired license data: retained for fraud prevention and audit purposes
- Support communications: retained as necessary to provide ongoing support
- Technical backups: maintained for operational security and business continuity
Backups are securely stored and automatically overwritten according to internal security policies.
10. International Transfers
Some service providers (e.g., Stripe, Google, Cloudflare) may process data outside the European Economic Area.
Where applicable, such transfers rely on:
- Standard Contractual Clauses (SCC)
- Adequacy decisions
- Additional safeguards implemented by providers
11. Data Security
We implement appropriate technical and organizational measures, including:
- SSL/TLS encryption
- Restricted internal access
- Server-level security controls
- Anti-malware and firewall protections
- Regular software updates
However, no online system can be guaranteed 100% secure.
12. Your GDPR Rights
You have the right to:
- Access your data
- Rectify inaccurate data
- Request erasure (where legally applicable)
- Restrict processing
- Object to processing based on legitimate interest
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your national supervisory authority
To exercise your rights, contact:
📩 [email protected]
13. Minors
WooLinker.com does not knowingly collect data from individuals under 16 years of age.
14. Cookies
WooLinker.com uses essential cookies for functionality and security, as well as advertising-related cookies where consent is given.
For detailed information, please consult our separate Cookie Policy.