helloLOG is operated by GoBird OÜ (registry code 17311365), Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia ("we", "us"). This page describes how we handle personal data. It covers two different roles, because they carry different obligations under the GDPR:
- Data controller — for your own account: the email and payment details you give us to sign up and pay for helloLOG.
- Data processor — for the WordPress activity data your sites send us. That data belongs to you (or your client), and we only process it on your instructions, as described in the Data Processing Agreement.
Account data we control
To run your account and bill you, we hold:
- Name and email address
- Billing details, handled by our payment processor (Stripe) — we do not store full card numbers
- Login credentials: a hashed password, or an identifier from Google/GitHub if you sign in with OAuth, or a passkey credential
- Support correspondence you send us
Legal basis for processing
For account data, we rely on:
- Contract (GDPR Art. 6(1)(b)) — creating your account, running your subscription, billing, and providing the service you signed up for.
- Legitimate interest (Art. 6(1)(f)) — securing the service (fraud and abuse prevention, keeping the login flow working), and responding to support requests.
- Legal obligation (Art. 6(1)(c)) — keeping the financial records tax law requires us to keep.
For activity-log data, the legal basis is between you (the controller) and your own users or site visitors — we process it only as your processor, on your instructions.
Activity-log data we process on your behalf
When your WordPress plugin is connected, it sends event data to our backend. We process this strictly as a processor, per your configuration:
- Event metadata — what happened, when, on which site, and its severity
- WordPress usernames and user IDs associated with the event
- IP addresses, unless you turn on IP anonymization in the plugin's Filters tab
- The WordPress site domain the event came from
We do not sell this data, and we do not use it for anything other than delivering the service back to you (search, retention, the dashboard).
Retention
Event data is retained according to your plan, then deleted:
- Free plan: 7 days
- Starter, Growth, Scale: 90 days
- Enterprise: per your contract
Account data (billing, correspondence) is kept as long as your account is active, plus whatever period we're legally required to retain financial records for. If you ask us to delete your account, we remove what we're not legally required to keep.
Cookies
The hellolog.io marketing site you're reading this on does not set analytics or advertising cookies. The dashboard at app.hellolog.io uses a single essential session cookie to keep you signed in — it's required for the dashboard to work and isn't used for tracking, so it isn't subject to cookie consent under the ePrivacy rules.
Subprocessors
We use the following subprocessors to run the service:
| Subprocessor | Purpose | More detail |
|---|---|---|
| Hosting / infrastructure provider | Runs the backend that stores and serves event data | Details available on request |
| Stripe | Payment processing and billing | See stripe.com/privacy |
| hellohost.io | Transactional email delivery over SMTP (account, billing, security notices) | See hellohost.io |
International transfers
We haven't made data-residency or "EU-only storage" commitments — if that matters for your compliance needs, contact us before connecting a site so we can confirm current details with you directly, rather than relying on an assumption either way. Where a subprocessor processes data outside the EEA, we rely on the EU Standard Contractual Clauses as the transfer safeguard.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. You can also lodge a complaint with your local data protection authority — in Estonia, the Andmekaitse Inspektsioon. For your own account data, contact us directly. For activity-log data on a site you don't administer, the request should go to that site's owner (the controller) — we act on their instructions as the processor.
Security
We use encryption in transit, access controls on the backend, and the retention limits above to minimize how long data is kept. A fuller security overview is available on request.
Changes to this policy
We may update this policy as the product changes. We'll update the date above and, for material changes, let account holders know by email.
Contact
Questions about this policy or a data request: [email protected] (legal: [email protected]).