GDPR and your data rights
Last updated 29 September 2026
If you are in the European Economic Area or the UK, the GDPR gives you control over your personal data. This page explains those rights and how to use them.
Our role
For your account and how you use Sitefar, Where Design SRL is the controller of your personal data. What we collect and why is in our privacy policy.
Your WordPress sites may hold personal data about your own visitors or customers. Sitefar reads only what it needs to manage plugins, themes and updates (inventories, versions and activity), and does not read your site's content or user database. If you are a business that needs a data processing agreement (DPA) with us, email contact@sitefar.com.
Your rights
- Access. Get a copy of the personal data we hold about you.
- Rectification. Have inaccurate or incomplete data corrected.
- Erasure. Have your data deleted, for example by deleting your account.
- Restriction. Ask us to pause using your data while a concern is resolved.
- Portability. Receive the data you gave us in a common, machine-readable format.
- Objection. Object to processing we base on our legitimate interests.
- Withdraw consent. Where we rely on consent, such as analytics cookies, withdraw it any time using "Cookie settings" in the footer, with no effect on what happened before.
- No automated decisions. We do not make decisions about you by automated means that have legal or similarly significant effects.
How to use them
- Yourself, in the app. Delete your account from Settings (confirmed by email) to remove your sites, stored credentials and activity. Disconnect a site, or revoke a connected AI app, in Settings at any time.
- By email. Write to contact@sitefar.com saying which right you want to use. We may ask you to confirm your identity first, so we don't give your data to someone else.
We reply within one month. If your request is complex we may extend that by up to two more months, and we will tell you why. There is no charge, unless a request is clearly unfounded or excessive.
Legal bases we rely on
Contract for running your account and the features you use, legitimate interests for security, abuse prevention and keeping the service working, and consent for analytics cookies. The full table is in section 2 of the privacy policy.
Where your data goes
Our servers are in EU. Our processors are listed in the privacy policy. Where data is processed outside the EEA we use adequacy decisions or the European Commission's Standard Contractual Clauses.
How we protect it
- WordPress application passwords are encrypted at rest and never returned to the browser.
- Account passwords are salted and hashed, and checked against known breaches.
- Two-step verification and passkeys are available for every account.
- Sign-in and other sensitive actions are rate limited, and sessions expire.
- AI assistants connect with scoped permissions that you choose, limited to the sites you choose, and you can pause all of them with one switch.
- We limit who can access our systems, and only for running and supporting the service.
If something goes wrong
If a personal data breach is likely to put you at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and tell you without undue delay where the risk to you is high.
Complaints
We would like the chance to fix a problem first, so please write to us. You always have the right to complain to a data protection authority, in the EU country where you live, work or think a breach happened, or to EU.