Privacy Policy — Maca Development
Version: 3.0
Last updated: 2026-07-06
Applies to: maca WP Plugin Demo (https://demo.maca.se/)
1. Introduction
We care about your privacy. This privacy policy describes which personal data we process, why, on what legal basis, how long the data is stored, who may access it, and what rights you have.
This policy describes how Maca Development («we», «us») processes personal data when you visit or use our website, in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
- The Data Protection Act (2018:218) supplementing the GDPR in Sweden
- Act (2003:389) on Electronic Communication (LEK) to the extent that it regulates cookies and similar technology (see also our cookie policy)
2. Data Controller
| | |
|—|—|
| Organization | Maca Development |
| Website | https://demo.maca.se/ |
| Email (privacy) | web@maca.se |
The data controller determines the purposes and means of the processing. We may engage data processors (e.g. hosting, email and analytics tools) that process data according to our instructions and written agreements.
3. Scope and target group
The policy applies to visitors, customers and others who interact with the website. It does not cover processing that takes place entirely offline or in other systems unless otherwise stated.
4. What data do we process?
We process only personal data that is adequate, relevant and necessary for the purposes stated below. Processing identified on the website based on installed plugins and integrated services is described per activity.
Web server and operational logs
- Data: IP address, time, URL, browser, referrer
- Purpose: Operation, troubleshooting and security
- Legal basis: Legitimate interest (GDPR art. 6.1 f)
- Retention period: Web hosting — normally 30–90 days in access logs
- Recipients: Web hosting provider
- Transfer outside the EU/EEA: May occur depending on where the server is located
Comments
- Data: Name, email, IP address, comment text
- Purpose: Publish and moderate comments
- Legal basis: Legitimate interest (GDPR art. 6.1 f)
- Retention period: As long as the comment remains on the website
- Recipients: Web hosting provider
maca DownList
- Source: maca DownList
- Data: Email and, if applicable, name in email gate, download log (file, time, IP address may be logged)
- Purpose: Provide file downloads and track downloads according to the site owner’s settings
- Legal basis: Legitimate interest (GDPR art. 6.1 f)
- Retention period: Download log according to plugin settings; email gate session temporarily
- Recipients: Website staff
- Transfer outside the EU/EEA: Normally processed within the EU/EEA via your web host
WPForms
- Source: WPForms Lite
- Data: Form content according to configured fields
- Purpose: Collect inquiries, bookings or registrations
- Legal basis: Legitimate interest (GDPR art. 6.1 f)
- Retention period: According to plugin settings and internal retention routine
- Recipients: Website staff
- Transfer outside the EU/EEA: May occur if WPForms cloud services are used
- Provider’s privacy policy: https://wpforms.com/privacy-policy/
Forms on the website
- maca DownList email gate — fields: email, possibly name
- WPForms — fields: fields according to configured form
Required fields in forms are needed so that we can handle your inquiry or order.
5. Where does the data come from?
We normally collect data directly from you (forms, order, account, email) and automatically during visits (technical logs, cookies according to your consent). Data may also come from payment or delivery partners when you shop with us.
6. Legal basis for processing
Each processing activity must have a valid legal basis under GDPR Article 6. Below we describe the bases we use on the website:
Legal bases
- Legitimate interest (art. 6.1 f) — for security, operation, troubleshooting, spam protection and responding to general inquiries, following a balancing test where your interests do not outweigh ours.
- Consent (art. 6.1 a) — for optional cookies, newsletters and marketing when consent is required. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
7. Retention period
We store personal data only as long as necessary for the purpose or as required by law. Thereafter the data is deleted or anonymized securely.
Specific retention periods are stated per processing activity in section 4. When data is no longer needed, it is deleted or anonymized, unless statutory retention is required (e.g. the Accounting Act).
8. Recipients and data processors
Data may be shared with providers such as hosting, CDN, email, payment, analytics and support tools. These may only process data under agreement (data processing agreement) and our instructions. A list of processing is shown in the activities above.
9. Cookies and similar technology
We use cookies, pixels and similar technology. Necessary cookies may be stored without consent. Non-necessary cookies (e.g. statistics and marketing) are activated only after your consent via our cookie banner.
See our cookie policy for a complete list, categories and consent management.
10. Security
We take appropriate technical and organizational measures under art. 32 GDPR to protect personal data against unauthorized access, loss, destruction and unlawful disclosure.
We continuously work with access control, updates, backups and incident management to a reasonable extent for the size and risk profile of the business.
11. Automated decision-making and profiling
We generally do not use automated decision-making or profiling that has legal effect or similarly significantly affects you. If this changes, the policy will be updated.
12. Your rights
You have the following rights under the GDPR when we process your personal data:
Your rights
- Right of access (art. 15) — obtain confirmation and a copy of your data
- Rectification (art. 16) — correct inaccurate or incomplete data
- Erasure (art. 17) — request deletion where there is a legal basis
- Restriction (art. 18) — request restricted processing in certain situations
- Objection (art. 21) — object to processing based on legitimate interest or direct marketing
- Data portability (art. 20) — receive data in a structured, machine-readable format when processing is based on contract or consent
- Withdraw consent (art. 7.3) — when processing is based on consent
- Complaint (art. 77) — to the supervisory authority
To exercise your rights, contact us at web@maca.se.
We respond to requests regarding your rights without undue delay and no later than within one month (may be extended by an additional two months in complex cases under art. 12.3).
Supervisory authority
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, phone 08-657 61 00, website imy.se — if you believe the processing violates the GDPR.
13. Children
The website is not directed to children under 16 years of age. We do not knowingly collect personal data from children without the consent of a guardian.
14. Changes to the policy
We may update this policy when the website, our tools or legal requirements change. Always check the date of the latest update.
In the event of material changes affecting your consent, we may ask you to confirm your choices again via the cookie banner.
Manual review
The following plugins are active but lack detailed policy text in maca Polly — review manually:
- All-in-One WP Migration and Backup (all-in-one-wp-migration)
- Easy WP SMTP (easy-wp-smtp)
- Maca Co (maca-co)
- maca Hold (maca-hold)
- maca Hub Connector (maca-hub-connector)
- maca Restu Pro (maca-menulist-pro)
- maca Sec (maca-sec)
- Plugin Check (PCP) (plugin-check)
- SVG Support (svg-support)
