Segurium
Privacy Policy
Last revised: 6 August 2026
This Privacy Policy explains what data the Segurium WordPress plugin (the “Plugin”) transmits to the Segurium cloud service at cti.segurium.com (the “Service”), why we process it, how long we keep it, who we share it with, and the rights you have under European data-protection law. It also explains, in §4, how we handle the contact data of businesses we approach about a partnership — data we did not get from you, but from your company’s own public website.
This Policy is the public, long-form version of the External Service Disclosure that the Plugin shows you after activation. Where the two documents describe the same processing, they must say the same thing; if there is a discrepancy, the description here controls.
cti.segurium.com. It also sends the contents of individual files when a hash alone cannot classify them, or when a clean replacement is needed. We don’t collect visitor analytics, posts, comments, or media. The data is processed inside the European Economic Area, you can ask for a copy or deletion at any time, and the contact for that is privacy@segurium.com. Separately, if we wrote to you about a partnership without you having contacted us first, §4 tells you where we got your address and how to make us stop — one reply is enough, and we do not ask why.
1. Who is the controller
The data controller for the personal data described in this Policy is Dmytro Tkachuk, an individual sole developer trading as “Segurium”, established in Tiana, Barcelona province, Spain, contactable at privacy@segurium.com. Because we are established in an EU member state, our processing falls under Article 3(1) GDPR and no representative under Article 27 is required. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD). We have not appointed a data protection officer: our processing does not meet the conditions in Article 37(1) that would make one mandatory. If you need a postal address for a formal data-protection request, ask at the address above and we will provide it.
2. Scope of this Policy
This Policy applies to:
- data the Plugin transmits to
cti.segurium.comwhile protecting your WordPress installation (each, a “Site”); - data we hold about Pro-tier customers for billing and licensing purposes (collected through Freemius);
- data collected when you visit segurium.com, including the quote form on the pricing page;
- contact data of representatives of businesses we approach about a partnership, taken from those businesses’ own public websites (§4). This is the only category in this Policy that we did not obtain from the person it concerns.
It does not cover data collected by your own WordPress installation (visitor analytics, posts, user accounts, etc.). For data on your Site you are the controller; we are not. It also does not cover data collected by third parties whose terms apply when you interact with them (e.g. Freemius for payments, your hosting provider, the WordPress.org plugin directory).
3. Data we collect from your Site
The Plugin sends the following categories of data to the Service. The list mirrors the External Service Disclosure shown after activation.
3.1 File metadata
For each file in scope of a scan: SHA-256 hash, path relative to your WordPress installation, size in bytes, and last-modified timestamp. The path is a relative path inside your WordPress directory (for example, wp-content/plugins/example/file.php) and may incidentally contain a username or site name if your installation uses one in the directory layout.
3.2 File contents (occasional)
When classification by hash alone is not conclusive — that is, when the hash is not in our knowledge base — the Plugin uploads the file body so the Service can analyse it and return a verdict. The Plugin also uploads file bodies when generating a clean replacement during cleanup. File bodies are not uploaded for files whose hash is already known to the Service: in that case, only the hash leaves your server.
3.3 Installation identifier and basic Site information
A randomly generated installation identifier (the “IID”) is created the first time you enable cloud scanning. The IID is not derived from any personal identifier. Together with the IID we record: your Site URL, the Site’s name as set in WordPress, the WordPress version, and the Plugin version. This is what lets the Service associate requests with your Site.
3.4 Scan, cleanup, and settings events
Operational telemetry needed to keep cloud and Site state in sync: scan start and finish events, per-file actions (cleaned, ignored, restored), and snapshots of Plugin settings (for example, which protection modules are on, the cleanup policy). These events include the IID and timestamps.
3.5 Firewall events
Records of network requests blocked by the Plugin’s firewall: the source IP address, the attack pattern that triggered the rule, and a timestamp. We use these events in aggregate to adapt protection across all Sites running Segurium. The blocked IP and attack pattern are personal data of the third party that originated the request, not of you.
3.6 Account, billing, and support data
If you buy a Pro license, Freemius collects the data needed to process the payment (name, email address, billing address as required for tax) and shares with us a license record (license key, plan, validity period, the email address you registered with) so we can grant Pro entitlements to your IID. If you write to support@segurium.com we receive your email address and the content of your message.
3.7 Marketing site (segurium.com)
The marketing site uses session cookies only on /pricing for CSRF protection of the quote form (a server-side token, no third-party tracking). The quote form sends what you type in it — site count, contact name, email address, message — to support@segurium.com via SMTP. The site does not use third-party analytics or advertising trackers.
4. Contact data of businesses we approach
We look for partners — web agencies, freelancers, and hosting providers who maintain WordPress sites for their own clients. To do that we read the public websites of such companies and write to a small number of them by hand. If you received a message from us and never contacted us first, this section is for you. It is the notice required by Article 14 GDPR, which applies whenever personal data is collected from somewhere other than the person it belongs to.
4.1 Where we got your data
From your company’s own public website — the contact, team, or about page, as published by your company. We do not buy contact lists, we do not use data brokers or contact-enrichment services, and we do not scrape social networks or personal profiles. Nothing is collected automatically in bulk: a person opens the site and reads it.
4.2 What we hold
- the contact name published on the site, where one is given;
- the business email address published on the site;
- the company name and the website address;
- a short free-text note on why the company looked relevant (for example, “maintains WordPress sites for clients”), and the date and outcome of any message we sent.
That is the whole record. We do not add data from other sources, we do not build profiles, and no decision about you is made by automated means.
4.3 Why we process it, and on what legal basis
The purpose is a manually written, business-to-business message proposing a partnership, plus any conversation that follows if you reply. If you do not reply we may follow up, at most four times, spaced out and never in quick succession; after that you are marked do-not-contact and we stop for good. Any reply that says no ends it immediately, whatever the count.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR: as a small independent developer, finding partners for a professional product is how the business reaches the customers it is built for. We weighed this against your interests before starting, and the balance rests on narrow limits we hold ourselves to — we contact people only in their professional role and only at the address their company published for that purpose, we write about a product relevant to that professional role, we do not send bulk campaigns, and we stop immediately on request. This is a separate legitimate interest from the one claimed in §6 for operating the Service; the two do not overlap.
Note that we treat every address this way, whether or not it names a person. An address such as info@example.com is not personal data in law, but we apply the same limits and the same right to object to it anyway.
4.4 How long we keep it
Twelve months from the last message exchanged, then deletion. If you reply and we begin working together, the record stops being outreach data: it becomes ordinary business correspondence, kept while the relationship lasts and for as long afterwards as Spanish accounting and limitation rules require. If you object, see §4.5 — deletion in that case is immediate and does not wait for the twelve months to pass.
4.5 Your right to object — absolute, no reason needed
You can tell us to stop contacting you, and we must stop. Article 21(2) GDPR gives you this right for direct marketing without qualification: there is no balancing test, you do not have to explain yourself, and we have no grounds we can weigh against it.
To use it, either reply to our message with anything that says no — a single word is enough — or write to privacy@segurium.com. We act on it within five working days and we do not reply asking you to reconsider.
The same address handles every other right in §10, including asking for a copy of your record or its deletion, and you can complain to the Agencia Española de Protección de Datos (aepd.es) or to the authority where you live or work.
4.6 What happens after you object
We delete the record described in §4.2. One thing survives it: a one-way SHA-256 hash of your email address, which we keep on a suppression list and check before writing to anyone. The hash cannot be turned back into your address; it can only be used to recognise that address if it ever comes up again, so that you are not contacted a second time.
We keep that hash for as long as we do any outreach at all. Deleting it would defeat its only purpose — the record of “do not contact” is the very thing that has to outlive the deletion of everything else. This is the narrow exception in Article 17(3)(b) and (e) GDPR: keeping it is what lets us honour your objection. If you would rather we did not keep even the hash, write to privacy@segurium.com and we will remove it, but then we can no longer guarantee that a future check will catch your address.
4.7 Who else sees it
Nobody outside the providers already listed in §8. The messages are sent from a mailbox hosted by Zoho, so Zoho processes them as our email provider. The records themselves are held by us. We do not share, sell, or rent this data, and it never enters the Service’s threat database.
5. Data we do not collect
The Plugin does not transmit any of the following to cti.segurium.com:
- visitor analytics or personal data of users who visit your Site;
- your WordPress database content — posts, pages, comments, user accounts, options, secrets;
- media files (images, video, audio, PDFs);
- files whose hash is already known to the Service — only the hash leaves your server in that case.
6. Purposes and lawful bases
We process the data above for the following purposes, on the legal bases shown. The lawful bases are those of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”).
| Purpose | Lawful basis |
|---|---|
| Detecting malware on your Site by comparing file hashes against our verdict database, and producing scan results. | Performance of the contract between you and us (Art. 6(1)(b) GDPR) and our legitimate interest in operating the Service (Art. 6(1)(f)). |
| Uploading and analysing file contents when a hash is not enough, and generating clean replacements during cleanup. | Your explicit consent given when you enable cloud scanning (Art. 6(1)(a)). You can withdraw consent at any time; see §10. |
| Aggregating firewall events across all Sites to refine threat intelligence and adapt protection rules. | Our legitimate interest in keeping the Service effective for all customers (Art. 6(1)(f)). The originating IP belongs to the attacker, not to you. |
| Billing and license management for Pro purchases. | Performance of the contract (Art. 6(1)(b)) and compliance with our legal accounting obligations (Art. 6(1)(c)). |
| Responding to support, abuse, or privacy requests. | Our legitimate interest in supporting the Service (Art. 6(1)(f)) and, for privacy requests, compliance with our legal obligations (Art. 6(1)(c)). |
| Sending the optional daily security digest (only if you enabled it in Plugin settings). | Your explicit consent (Art. 6(1)(a)). You can disable it from the Plugin’s alert settings at any time. |
| Writing to businesses whose public websites suggest they maintain WordPress sites for clients, to propose a partnership (§4). | Our legitimate interest in finding partners for a professional product (Art. 6(1)(f)), weighed against the recipient’s interests as described in §4.3. You can object at any time and we stop — see §4.5. |
| Keeping a hashed suppression list so that a person who objected is never contacted again. | Our legitimate interest, and yours, in making an objection stick (Art. 6(1)(f)), read with Art. 17(3)(b) and (e). |
We do not use this data for advertising or for automated decision-making with legal effect.
7. Retention
We keep data only as long as needed for the purpose it was collected for, and then delete it or fully anonymise it. The current periods are:
- File samples uploaded for analysis — up to 365 days, after which they are deleted by an automated nightly purge. Analysts may delete a sample sooner once triaged.
- Verdict records (per file hash) — kept while the verdict is in active use by the Service. Some verdicts (for example, neutral/clean verdicts produced by short-lived analysis paths) expire after 7 days and are re-evaluated on the next encounter.
- Per-file cleanup and integrity-fix events — 90 days.
- Verdict audit log (administrative changes to verdicts) — 730 days, retained for forensic review of the threat database.
- Operational logs of the Service — rotated and purged after 30 days.
- Pro license records — for the duration of the license plus the period required by accounting and tax law (typically up to 5 years, in line with Spanish accounting rules).
- Support correspondence — up to 24 months after the conversation closes, then deleted unless we need it for an open issue.
- Outreach contact data (§4) — 12 months from the last message exchanged, then deleted. Deleted immediately on objection.
- Hashed suppression list — kept for as long as we do any outreach. It holds one-way hashes only, and its sole purpose is to make sure an objection is never overridden by mistake (§4.6).
If you ask us to delete the IID and operational data tied to it, we will do so within 30 days, except where we are required to retain specific records (for example, a paid invoice for tax purposes) or where the data has already been irreversibly aggregated into threat statistics.
8. Recipients and subprocessors
We do not sell or rent personal data. We share it only with the providers we rely on to run the Offering:
- Freemius, Inc. — payment processing and license management for Pro purchases. Freemius is the merchant of record for Pro transactions and processes billing data on its own terms.
- Zoho Corporation — our email provider. It relays transactional and security email sent from
support@segurium.com(account, alert digests, quote-form submissions), and hosts the mailbox used for the partnership outreach described in §4. - Our hosting provider — the data centre that physically hosts
cti.segurium.com. The hosting provider has no operational access to the data stored on the server. - Service providers strictly necessary for the operation of segurium.com itself — the FTP/CDN provider that serves the public website.
We may also disclose data when required by law, to protect our rights, or in connection with a merger, acquisition, or asset sale, in which case we will inform affected users in advance where practicable.
9. International transfers
The Service’s servers are located within the European Economic Area (EEA). Some of our subprocessors are headquartered or operate outside the EEA — in particular Freemius (United States) and Zoho (United States and India). When personal data is transferred to those countries we rely on the safeguards permitted under Chapter V GDPR, including, where applicable, the European Commission’s Standard Contractual Clauses, and we limit transfers to what is strictly necessary.
10. Your rights
If you are a natural person whose personal data we process, the GDPR gives you the following rights, which you can exercise free of charge:
- Access — ask for a copy of the data we hold about you.
- Rectification — ask us to correct data that is inaccurate or incomplete.
- Erasure — ask us to delete data when one of the grounds in Article 17 GDPR applies.
- Restriction — ask us to suspend processing while a dispute is resolved.
- Portability — receive the data you provided to us, in a structured, machine-readable format, where the processing is based on consent or on a contract with you.
- Objection — object to processing based on our legitimate interests, including objection to firewall-event aggregation if you can show overriding personal grounds.
- Objection to direct marketing — a separate and stronger right. If we contacted you about a partnership, you can stop it with no reason given and nothing to prove; we have no grounds to weigh against you. See §4.5.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Disabling cloud scanning in the Plugin withdraws the consent given for §6.
- Complain to a supervisory authority — in particular the Spanish data-protection authority, the Agencia Española de Protección de Datos (AEPD), aepd.es, or the authority of the EU member state where you live or work.
To exercise any of these rights, write to privacy@segurium.com. We will respond within one month and may ask you to confirm your identity if the request is unclear.
11. Children
The Offering is intended for adults administering WordPress sites. It is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@segurium.com and we will delete it.
12. Cookies on segurium.com
The marketing site does not use third-party analytics, advertising, or tracking cookies. The only cookie set is a session cookie on /pricing that holds a CSRF token used by the quote form. The cookie is strictly necessary, expires when you close the browser, and is not shared with third parties; under Article 5(3) of the ePrivacy Directive (and its national implementations), strictly necessary cookies do not require consent.
13. Security
We protect data in transit with TLS, isolate the Service’s database on a dedicated server, restrict administrative access to the production environment, log administrative changes to the verdict database, and keep operational logs only as long as needed. Files submitted for analysis are stored in a content-addressed, access-controlled directory and purged on schedule. No system is impenetrable; we encourage you to keep your WordPress installation up to date and to use strong administrator credentials.
14. Data breach notification
If a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware of it, in line with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (Article 34 GDPR).
15. Changes to this Policy
The current version of this Policy is always at segurium.com/privacy with a “Last revised” date. For changes that materially affect your rights or the categories of data we process, we will notify you in the Plugin’s admin UI or by email at least 30 days before the change takes effect.
16. Contact
For privacy questions, GDPR data-subject requests, or to withdraw consent, write to: privacy@segurium.com.
For all other questions about Segurium: support@segurium.com.