Privacy Policy

Last updated: 2026-08-18

helloLOG is operated by GoBird OÜ (registry code 17311365), Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia ("we", "us"). This page describes how we handle personal data. It covers two different roles, because they carry different obligations under the GDPR:

  • Data controller — for your own account: the email and payment details you give us to sign up and pay for helloLOG.
  • Data processor — for the WordPress activity data your sites send us. That data belongs to you (or your client), and we only process it on your instructions, as described in the Data Processing Agreement.

Account data we control

To run your account and bill you, we hold:

  • Name and email address
  • Billing details, handled by our payment processor (Stripe) — we do not store full card numbers
  • Login credentials: a hashed password, or an identifier from Google/GitHub if you sign in with OAuth, or a passkey credential
  • Support correspondence you send us

For account data, we rely on:

  • Contract (GDPR Art. 6(1)(b)) — creating your account, running your subscription, billing, and providing the service you signed up for.
  • Legitimate interest (Art. 6(1)(f)) — securing the service (fraud and abuse prevention, keeping the login flow working), and responding to support requests.
  • Legal obligation (Art. 6(1)(c)) — keeping the financial records tax law requires us to keep.

For activity-log data, the legal basis is between you (the controller) and your own users or site visitors — we process it only as your processor, on your instructions.

Activity-log data we process on your behalf

When your WordPress plugin is connected, it sends event data to our backend. We process this strictly as a processor, per your configuration:

  • Event metadata — what happened, when, on which site, and its severity
  • WordPress usernames and user IDs associated with the event
  • IP addresses, unless you turn on IP anonymization in the plugin's Filters tab
  • The WordPress site domain the event came from

We do not sell this data, and we do not use it for anything other than delivering the service back to you (search, retention, the dashboard).

Retention

Event data is retained according to your plan, then deleted:

  • Free plan: 7 days
  • Starter, Growth, Scale: 90 days
  • Enterprise: per your contract

Account data (billing, correspondence) is kept as long as your account is active, plus whatever period we're legally required to retain financial records for. If you ask us to delete your account, we remove what we're not legally required to keep.

Cookies

The hellolog.io marketing site you're reading this on does not set analytics or advertising cookies. The dashboard at app.hellolog.io uses a single essential session cookie to keep you signed in — it's required for the dashboard to work and isn't used for tracking, so it isn't subject to cookie consent under the ePrivacy rules.

Subprocessors

We use the following subprocessors to run the service:

Subprocessor Purpose More detail
Hosting / infrastructure provider Runs the backend that stores and serves event data Details available on request
Stripe Payment processing and billing See stripe.com/privacy
hellohost.io Transactional email delivery over SMTP (account, billing, security notices) See hellohost.io

International transfers

We haven't made data-residency or "EU-only storage" commitments — if that matters for your compliance needs, contact us before connecting a site so we can confirm current details with you directly, rather than relying on an assumption either way. Where a subprocessor processes data outside the EEA, we rely on the EU Standard Contractual Clauses as the transfer safeguard.

Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can also lodge a complaint with your local data protection authority — in Estonia, the Andmekaitse Inspektsioon. For your own account data, contact us directly. For activity-log data on a site you don't administer, the request should go to that site's owner (the controller) — we act on their instructions as the processor.

Security

We use encryption in transit, access controls on the backend, and the retention limits above to minimize how long data is kept. A fuller security overview is available on request.

Changes to this policy

We may update this policy as the product changes. We'll update the date above and, for material changes, let account holders know by email.

Contact

Questions about this policy or a data request: [email protected] (legal: [email protected]).