§Legal
Privacy policy
- Summary
- Who is responsible
- What we process
- Your store's data
- Who receives data
- Transfers outside the EU
- Retention
- Cookies
- Security
- Your rights
- Changes
- Company details
1. Summary
FastOps for WooCommerce is a WordPress plugin that runs inside your own store. Webkonsulenterne A/S operates FastOps Cloud, the service that licenses it, delivers updates and receives basic health reports from connected sites. We process the minimum needed to do that: your account and billing details, technical metadata about each connected site, and the messages you send us. Your store's products, orders, customers and payment data never leave your server and are never transmitted to us. We do not sell personal data, we do not use it for advertising, and the public website sets no tracking cookies.
2. Who is responsible
The data controller for FastOps Cloud and this website is Webkonsulenterne A/S, a Danish company registered under CVR 45330710, with its registered office at Hadsundvej 112, 9550 Mariager, Denmark. Questions about this policy, and requests to exercise your rights, go to [email protected]. We have not appointed a data protection officer because the scale and nature of our processing do not require one; the same address reaches the people responsible.
For the data inside your WooCommerce store, you are the controller and FastOps is software you run; see section 4.
3. What we process, why, and on what basis
| Category | What it includes | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|---|
| Account data | Name, email address, password (stored only as a salted hash), two-factor and passkey credentials you enrol, sign-in timestamps and IP address. | Creating and securing your account; letting your team access licences and sites. | Contract (1(b)); legitimate interest in account security (1(f)). |
| Billing data | Billing email, chosen plan and term, subscription and invoice references, and the subscription and payment status events we receive from the payment provider you paid through. Card and bank details go directly to the payment provider and never reach our systems. | Selling and renewing licences; issuing and honouring subscriptions; bookkeeping. | Contract (1(b)); legal obligation under the Danish Bookkeeping Act (1(c)). |
| Licence and site data | Licence keys (stored hashed, with an encrypted copy so you can retrieve them), and for each connected store: its URL and name, a random installation identifier, environment (production or staging), plugin, WordPress, WooCommerce and PHP versions, database flavour, interface language, site health status, and counts of products, orders and subscriptions. | Activating licences, delivering signed updates, showing you the health of your sites, sizing plans, and alerting you when a site stops reporting. | Contract (1(b)). |
| Diagnostics | A bounded self-report each site sends with its health check: hosting readiness results, health statistics, uptime and which FastOps extensions are installed. It contains no product, order or customer content. | Support: resolving problems without asking you to export and send a report. | Contract (1(b)); legitimate interest in supporting the service (1(f)). |
| Enquiries | What you send through the demo form (name, work email, company, store URL, catalogue size, message) or by email. | Answering you, scheduling a demo, scoping a quote. | Pre-contractual steps at your request (1(b)); legitimate interest (1(f)). |
| Audit trail | Who did what in the dashboard (for example issuing a licence, revealing a key, changing a plan), with timestamp and IP address. | Security, accountability and dispute resolution. | Legitimate interest (1(f)); legal obligation for billing-related events (1(c)). |
| Service emails | Licence delivery, expiry reminders, plan-usage notices, site health alerts, update failures, invitations. | Operating the service you bought. These are not marketing emails and cannot be opted out of while the service is active. | Contract (1(b)). |
If a colleague invites you to a team, we receive your name and email address from that account holder; the invitation links to this policy. FastOps Cloud is a business service and is not directed at anyone under 18; we do not knowingly process children's data.
We do not profile you and make no automated decisions with legal or similarly significant effects. Plan-usage standing is computed from record counts your site reports and only ever pauses updates and support; it never touches your store.
4. Your store's data
Because it matters in this product category we say it plainly: data about your customers, such as orders, addresses, emails and payment details, and the content of your catalogue, is processed by your WordPress installation and by the plugin running there. It is never transmitted to FastOps Cloud, never stored by us, and never accessible to us. FastOps Cloud is not in the path of daily store operations; if it is unreachable, the plugin keeps working.
For that data you are the controller and Webkonsulenterne A/S is not a processor, because we neither receive nor access it. If you engage us for support that requires access to your site, that access is agreed separately and in writing. Where a site URL or site name identifies a natural person, for example a sole trader, we process it only as described in section 3. If we ever add a feature that receives customer or order content, we will offer a data-processing agreement before enabling it.
5. Who receives data
- Frisbii (Reepay), Denmark — payment and subscription processing for card and invoice payments. Frisbii is an independent controller for payment data under financial regulation.
- Stripe Payments Europe, Ireland — payment and subscription processing where Stripe is the configured provider. Stripe is an independent controller for payment data and may transfer data to Stripe, Inc. in the United States under the EU–US Data Privacy Framework and standard contractual clauses.
- Hosting and email delivery providers — processors acting on our documented instructions under data-processing agreements, used to run FastOps Cloud and to send service emails.
- Authorities — where the law requires it, for example the Danish tax authority for bookkeeping records.
We do not share personal data with advertisers, data brokers or anyone else, and we do not sell it. We do not send marketing email unless you have asked for it; every such email carries an unsubscribe link and our postal address, and opt-outs are honoured within ten business days.
California residents. We do not sell or share personal information as defined in the CCPA/CPRA, and we do not process sensitive personal information beyond what is needed to run your account. You may exercise access, deletion and correction rights by emailing [email protected], and we will not discriminate against you for doing so.
6. Transfers outside the EU/EEA
FastOps Cloud is operated from Denmark. Where a provider we use processes data outside the EU/EEA, the transfer rests on an adequacy decision or on the European Commission's standard contractual clauses with supplementary measures. You can ask us for details of the safeguards in place for a specific provider.
7. How long we keep it
| Data | Kept for |
|---|---|
| Account data | The life of the account, then deleted within 30 days of closure or of your request. |
| Licence, site and diagnostics data | The life of the installation; removed when the installation is deleted. Daily usage counts are kept for the life of the installation to show growth over time. |
| Update history | Twelve months, then pruned monthly, so a regression can still be traced to a release. |
| Billing records | Five years after the end of the financial year, as the Danish Bookkeeping Act requires. |
| Enquiries | Twelve months after our last exchange, unless they lead to a contract. |
| Audit trail | Two years. |
| Server logs | Thirty days. |
Closing your account from the dashboard stops updates and support and starts the deletion clock; nothing about your installed stores changes. Deletion of an account does not remove invoices and billing records we must keep under the Bookkeeping Act; these are stored with restricted access until the retention period ends. You can download everything we hold about an account as a JSON file from the Team page at any time.
8. Cookies
The public website and the legal pages set no cookies and load no third-party scripts, fonts or analytics. Signing in to the dashboard sets strictly necessary cookies only:
- Session cookie — keeps you signed in for the session.
- Security token cookie — protects forms against cross-site request forgery.
- Remember-me cookie — only if you tick "remember me", for up to five years or until you sign out.
Because none of these track you, no consent banner is shown. Your browser can delete them at any time; you will simply be signed out.
9. Security
Passwords are hashed, installation secrets and stored licence keys are encrypted at rest, communication between sites and FastOps Cloud is authenticated, and payment-provider notifications are verified before they are acted on. Plugin releases are signed, and the plugin verifies a signature before installing anything. Access to the dashboard supports two-factor authentication and passkeys, and staff actions are recorded in the audit trail.
10. Your rights
Under the GDPR you can ask us for access to the personal data we hold about you, for its correction or deletion, for restriction of or objection to processing, and for a portable copy. Where processing rests on legitimate interest you may object on grounds relating to your particular situation. Write to [email protected]; we answer within one month, in complex cases within up to three months and we will tell you why, and we may ask you to confirm your identity first.
You also have the right to complain to a supervisory authority. In Denmark that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk. We would appreciate the chance to resolve the matter first.
11. Changes to this policy
We change this policy when the service changes. Material changes are announced by email to account holders before they take effect, and every version states its effective date at the top. The previous version is available on request.
12. Company details
Webkonsulenterne A/S
CVR 45330710
Hadsundvej 112, 9550 Mariager, Denmark
+45 54 62 54 21
[email protected] · webkonsulenterne.dk