1. Introduction
MegaManager ("we," "our," "us") is operated by MegaManager, registered in the Republic of Bulgaria. We are committed to protecting your privacy and personal data in accordance with the General Data Protection Regulation (GDPR), applicable EU data protection laws, and other relevant legislation. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use our WordPress site management platform ("the Service"). For the purposes of this policy, MegaManager acts as the data controller for the personal data described herein, unless otherwise specified. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
We collect the following categories of information: • Account Information: Name, email address, and password when you create an account. • Site Data: WordPress site URLs, plugin lists, theme information, database metrics, performance data, server configuration, and other technical data from connected sites. • Usage Data: How you interact with our Service, including pages visited, features used, actions taken, and session duration. • AI Interaction Data: Conversations with the AI Copilot, task instructions, prompts, and generated analysis results. • Communication Data: Email addresses for notifications, alert preferences, and support correspondence. • Technical Data: Browser type, IP address, device information, operating system, referrer URLs, and cookies. • Billing Data: Subscription plan details, payment method identifiers, and transaction history (processed by our third-party payment provider).
3. How We Use Your Information
We process your personal data for the following purposes: • Provide, operate, maintain, and improve the Service • Monitor and analyze your WordPress sites' health, uptime, and performance • Send notifications, alerts, uptime reports, and security advisories • Power AI-driven features such as the Copilot, AI Task Bot, and automated task management • Process transactions, manage subscriptions, and handle billing • Communicate with you about updates, security alerts, product changes, and support requests • Detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents • Comply with legal obligations, enforce our Terms of Service, and protect our rights • Generate aggregated, anonymized analytics to improve our products and services
4. Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases: • Contract: Processing necessary for the performance of a contract — specifically, to provide and maintain the Service you have subscribed to. • Consent: Where you have given explicit, informed consent for specific processing activities (e.g., marketing communications). • Legitimate Interest: For improving our services, ensuring security, preventing fraud, and conducting internal analytics, where such interests are not overridden by your fundamental rights. • Legal Obligation: When processing is required to comply with applicable law, regulation, or governmental request.
5. Data Sharing & Third Parties
We may share your data with the following categories of recipients: • Service Providers: Cloud hosting and infrastructure providers, email delivery services (e.g., Brevo), payment processors, and analytics tools that help us operate, maintain, and improve the Service. • AI Providers: Third-party AI model providers who process data to power AI-driven features such as the Copilot and AI Task Bot. Data shared with AI providers is limited to what is necessary for the specific AI functionality. • Team Members: If you use team features, shared site data is accessible to invited team members as configured by you. • Legal Requirements: When required by law, court order, subpoena, or governmental or regulatory request. We do not sell your personal data to third parties. Where data is transferred to third-party processors located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent mechanisms recognized under applicable data protection law.
6. Data Retention
We retain your personal data for as long as your account is active or as reasonably needed to provide the Service and fulfill the purposes described in this policy. You can configure data retention periods (30–365 days) through the GDPR settings in your account. Upon account deletion, we will remove your personal data within 30 days, except where retention is required by law, necessary to resolve disputes, or needed to enforce our agreements. Backup copies may be retained temporarily for security and disaster recovery purposes and will be deleted in accordance with our standard backup rotation schedule. System logs and security-related records may be retained for a reasonable period to support debugging, incident investigation, and compliance obligations.
7. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights: • Access: Request a copy of the personal data we hold about you. • Rectification: Correct inaccurate or incomplete personal data. • Erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements. • Restriction: Request restriction of processing in certain circumstances. • Portability: Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller. • Objection: Object to processing based on legitimate interests or direct marketing. • Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal. • Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. You can exercise these rights through the GDPR settings in your account or by contacting us at info@wpmegamanager.com. We will respond to your request within 30 days, as required by law.
8. Data Security
We implement industry-standard technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to: • Encryption in transit (TLS/SSL) and at rest • Role-based access controls and least-privilege principles • Regular security audits and vulnerability assessments • Logging, monitoring, and automated incident detection systems • Secure storage of site connection secrets, which are never exposed to the client-side application While we strive to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, and you acknowledge that you provide your data at your own risk.
10. International Data Transfers
Your data is primarily processed on servers located within the European Union. However, certain data may be transferred to and processed in countries outside the EU/EEA — for example, when utilizing third-party AI providers, cloud infrastructure, or other service providers. Where such transfers occur, we ensure that appropriate safeguards are in place in accordance with GDPR requirements, including: • Standard Contractual Clauses (SCCs) approved by the European Commission • Adequacy decisions by the European Commission for the recipient country • Your explicit consent, where applicable By using the Service, you acknowledge and consent to the transfer of your data to jurisdictions that may have different data protection standards than your country of residence.
11. Children's Privacy
The Service is not intended for individuals under 16 years of age. We do not knowingly collect, solicit, or process personal data from children under 16. If we become aware that personal data has been collected from a child under 16 without parental consent, we will take reasonable steps to delete such data promptly. If you believe that a child has provided us with personal data, please contact us at info@wpmegamanager.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of any material changes via email or through the Service at least 14 days prior to the changes taking effect. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically.
13. Contact Us
For privacy-related inquiries, data access requests, or any questions regarding this Privacy Policy, please contact us at info@wpmegamanager.com. We will respond to all inquiries within 30 days, as required by applicable data protection law.
14. AI Data Processing
The Service incorporates AI-powered features, including the Site Copilot, AI Task Bot, and automated analysis tools. When you use these features, the following applies: • Data such as site metrics, user prompts, conversation history, and system logs may be transmitted to and processed by third-party AI model providers in order to generate responses, analyses, and recommendations. • AI-generated outputs are provided on an "as-is" basis and may not always be accurate, complete, or suitable for your specific situation. You are solely responsible for reviewing, verifying, and approving any actions suggested or initiated by AI features. • AI processing may involve the transfer of data to servers located outside the EU/EEA. Where such transfers occur, we ensure appropriate safeguards are in place as described in Section 10. • Your data is not used for training third-party AI models unless explicitly stated and consented to by you. • We retain AI interaction data in accordance with the data retention policies described in Section 6.
15. Data Processing Roles
Under applicable data protection law, MegaManager operates in the following capacities: • Data Controller: MegaManager acts as the data controller for all account data, billing information, communication preferences, usage analytics, and any personal data collected directly through the Service. • Data Processor: MegaManager acts as a data processor when processing data from your connected WordPress sites on your behalf. In this capacity, we process site data strictly in accordance with your instructions and the terms of this Privacy Policy. Where required, a Data Processing Agreement (DPA) is available upon request by contacting info@wpmegamanager.com.
16. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay, and in any case within 72 hours of becoming aware of the breach, in accordance with Article 33 and Article 34 of the GDPR and other applicable data protection laws. Notification will include the nature of the breach, the categories and approximate number of data subjects affected, likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
17. Logs and Monitoring
We collect and maintain logs related to the operation of the Service, including: • System logs: Server performance, errors, and infrastructure events. • API activity: Requests made to and from connected WordPress sites. • User actions: Feature usage, configuration changes, and management actions performed through the Service. • Site connection events: Connection status, heartbeat signals, and synchronization activity. These logs are collected for the purposes of security monitoring, debugging, performance optimization, incident investigation, and compliance. Logs are retained in accordance with our data retention policies and are accessible only to authorized personnel.
18. International Users
The Service is operated from the European Union, with primary infrastructure located within the EU. Your data may be transferred to and processed in jurisdictions outside the EU/EEA as described in Section 10. If you are accessing the Service from outside the European Union, you are responsible for ensuring that your use of the Service complies with the data protection and privacy laws applicable in your jurisdiction. By using the Service, you consent to the transfer and processing of your data as described in this Privacy Policy.
19. Regional Compliance Disclaimer
MegaManager is designed to comply with the data protection laws of the European Union, including the General Data Protection Regulation (GDPR). However, we do not represent or warrant that the Service is compliant with the data protection or privacy laws of every jurisdiction worldwide. Users located outside the EU who choose to use the Service do so at their own risk and are solely responsible for determining whether their use of the Service complies with applicable local laws. To the extent permitted by applicable law, MegaManager shall not be liable for any conflicts between this Privacy Policy and the laws of jurisdictions outside the EU.
20. Conflict with Local Laws
If any provision of this Privacy Policy conflicts with mandatory provisions of local law applicable to you, the local law provision shall prevail to the extent of the conflict, but only insofar as required by such local law. All other provisions of this Privacy Policy shall remain in full force and effect.