Privacy Policy

PRIVACY POLICY

Effective Date: 23.02.2026


1. Identity of the Data Controller

WooLinker.com is operated by:

TER22 AREA S.R.L.
Trade Register Number: J2018001796222
Unique Registration Code (CUI): RO39590977
European Unique Identifier (EUID): ROONRC.J2018001796222
Registered Office: Iași, Strada Vasile Lupu nr. 25, ap. 16, Romania
Email: [email protected]

TER22 AREA S.R.L. acts as Data Controller under Regulation (EU) 2016/679 (GDPR).


2. Nature of the Services

WooLinker.com sells exclusively digital products, including WordPress and WooCommerce plugins distributed under software license agreements.

No physical goods are shipped.


3. Categories of Personal Data Processed

Depending on how you interact with our website, we may process the following categories of data:

3.1 Account and Purchase Data

  • Name and surname
  • Email address
  • Billing information
  • VAT number (for B2B transactions)
  • Order history

3.2 License Validation Data

In order to activate and validate plugin licenses, our systems process:

  • The domain name where the plugin is installed
  • The license key

For update verification:

  • The license key is transmitted to our licensing server.

We do not collect telemetry, usage statistics, or behavioral tracking data from within the plugins.

3.3 Payment Data

Payments are processed securely via Stripe.
We do not store full payment card information on our servers.

3.4 Technical Data

  • IP address
  • Browser type
  • Device information
  • Security-related metadata

This data may be processed via hosting infrastructure and Cloudflare security services.

3.5 Support Data

Information submitted through our ticket support system, including:

  • Name
  • Email
  • Content of communication

We process personal data based on:

  • Contract performance (Art. 6(1)(b)) – order processing, license activation, support.
  • Legal obligation (Art. 6(1)(c)) – accounting, tax compliance (including VAT OSS and B2B reverse charge).
  • Legitimate interest (Art. 6(1)(f)) – fraud prevention, license protection, IT security, abuse prevention.
  • Consent (Art. 6(1)(a)) – marketing cookies or tracking tools, where applicable.

5. License Data and Legitimate Interest

License validation data is retained to:

  • prevent fraud
  • prevent license abuse
  • maintain software security
  • verify entitlement to updates and support

Expired license records may be retained indefinitely under legitimate interest for fraud prevention and audit purposes.


6. Payment and Invoicing

Payments are processed via Stripe.
Invoices are generated automatically via Nexus CRM, an external invoicing and CRM system.

VAT OSS and B2B reverse charge mechanisms are applied in accordance with EU tax regulations.


7. Hosting and Infrastructure

Our website is hosted in Romania by:

Cyber_Folks Romania (cyberfolks.ro)

We use Cloudflare for security and DDoS protection, including bot management and “Under Attack” mode when necessary.

Cloudflare may process IP addresses and connection metadata for security filtering.


8. Google Services and Advertising

We use:

  • Google Ads
  • Google Merchant Center

These services may process limited data for advertising performance and conversion tracking, subject to your cookie consent preferences.

We do not operate newsletter campaigns.


9. Data Retention

We retain personal data as follows:

  • Account data: 1 year after account inactivity
  • Accounting and invoicing data: as required by Romanian fiscal law (minimum 10 years)
  • Expired license data: retained for fraud prevention and audit purposes
  • Support communications: retained as necessary to provide ongoing support
  • Technical backups: maintained for operational security and business continuity

Backups are securely stored and automatically overwritten according to internal security policies.


10. International Transfers

Some service providers (e.g., Stripe, Google, Cloudflare) may process data outside the European Economic Area.

Where applicable, such transfers rely on:

  • Standard Contractual Clauses (SCC)
  • Adequacy decisions
  • Additional safeguards implemented by providers

11. Data Security

We implement appropriate technical and organizational measures, including:

  • SSL/TLS encryption
  • Restricted internal access
  • Server-level security controls
  • Anti-malware and firewall protections
  • Regular software updates

However, no online system can be guaranteed 100% secure.


12. Your GDPR Rights

You have the right to:

  • Access your data
  • Rectify inaccurate data
  • Request erasure (where legally applicable)
  • Restrict processing
  • Object to processing based on legitimate interest
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with your national supervisory authority

To exercise your rights, contact:
📩 [email protected]


13. Minors

WooLinker.com does not knowingly collect data from individuals under 16 years of age.


14. Cookies

WooLinker.com uses essential cookies for functionality and security, as well as advertising-related cookies where consent is given.

For detailed information, please consult our separate Cookie Policy.