GDPR information — Maca Development
Version: 3.0
Last updated: 2026-07-06
Applies to: maca WP Plugin Demo (https://demo.maca.se/)
1. Purpose of this document
Here we provide the information required by the GDPR when we collect personal data via the website — without you needing to request it separately.
This document fulfills the information obligation under GDPR Articles 13 and 14 when personal data is collected via the website.
2. Data controller
| | |
|—|—|
| Name | Maca Development |
| Email | web@maca.se |
| Website | https://demo.maca.se/ |
3. Processing activities
Web server and operational logs
- Data: IP address, time, URL, browser, referrer
- Purpose: Operation, troubleshooting and security
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: Web hosting — normally 30–90 days in access logs
- Recipients: Web hosting provider
- Transfer outside the EU/EEA: May occur depending on where the server is located
Comments
- Data: Name, email, IP address, comment text
- Purpose: Publish and moderate comments
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: As long as the comment remains on the website
- Recipients: Web hosting provider
maca DownList
- Source: maca DownList
- Data: Email and, if applicable, name in email gate, download log (file, time, IP address may be logged)
- Purpose: Provide file downloads and track downloads according to the site owner’s settings
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: Download log according to plugin settings; email gate session temporarily
- Recipients: Website staff
- Transfer outside the EU/EEA: Normally processed within the EU/EEA via your web host
WPForms
- Source: WPForms Lite
- Data: Form content according to configured fields
- Purpose: Collect inquiries, bookings or registrations
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: According to plugin settings and internal retention routine
- Recipients: Website staff
- Transfer outside the EU/EEA: May occur if WPForms cloud services are used
- Provider’s privacy policy: https://wpforms.com/privacy-policy/
4. Purpose and legal basis
Each processing activity must have a valid legal basis under GDPR Article 6. Below we describe the bases we use on the website:
Legal bases
- Legitimate interest (Art. 6(1)(f)) — for security, operation, troubleshooting, spam protection and responding to general inquiries, following a balancing test where your interests do not override ours.
- Consent (Art. 6(1)(a)) — for optional cookies, newsletters and marketing when consent is required. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. Source of data
We normally collect data directly from you (forms, orders, account, email) and automatically during visits (technical logs, cookies according to your consent). Data may also come from payment or delivery partners when you shop with us.
6. Retention period
We store personal data only as long as necessary for the purpose or as required by law. After that, the data is deleted or anonymized securely.
7. Recipients
Data may be shared with providers such as hosting, CDN, email, payment, analytics and support tools. These may only process data under contract (data processing agreement) and our instructions. A list of processing activities is shown above.
8. Your rights under GDPR
You have the following rights under GDPR when we process your personal data:
Your rights
- Right of access (Art. 15) — obtain confirmation and a copy of your data
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure (Art. 17) — request deletion where there is a legal basis
- Restriction (Art. 18) — request restricted processing in certain situations
- Objection (Art. 21) — object to processing based on legitimate interest or direct marketing
- Data portability (Art. 20) — receive data in a structured, machine-readable format when processing is based on contract or consent
- Withdraw consent (Art. 7(3)) — when processing is based on consent
- Complaint (Art. 77) — to a supervisory authority
To exercise your rights, contact us at web@maca.se.
We respond to requests regarding your rights without undue delay and no later than within one month (may be extended by an additional two months in complex cases under Art. 12(3)).
Supervisory authority
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, phone 08-657 61 00, website imy.se — if you believe the processing violates GDPR.
9. Information obligation and automated decision-making
We generally do not use automated decision-making or profiling that has legal effects or similarly significantly affects you. If this changes, the policy will be updated.
10. Cookies
Information about cookies and consent can be found in our cookie policy. A full description of processing can be found in the privacy policy.
