Terms of Service
Data Processing Agreement
Version 3, 4 September 2026. Applies to WP-AllBackup Storage and the licence portal operated by Fixit d.o.o.
This agreement is part of the Terms of Service. It applies whenever you use WP-AllBackup Storage, and it describes what we do with the personal data we handle to run your licence. Where the plugin sends backups to storage you own (your Dropbox, Google Drive, S3 bucket, server), we do not process that data at all and this agreement does not apply to it. It is written in plain language on purpose; if a term here conflicts with a law that protects you, the law wins.
1. Who is who
You are the controller of the content of your backups: the files and database of your WordPress site, including whatever personal data of your own users those contain. Fixit d.o.o. ("we") is the processor of that content when you store it on WP-AllBackup Storage. For the data we need to run your licence and account (your email address, licence key, order and subscription records, the addresses of activated sites) we are the controller, and the Privacy Policy describes that. The providers listed in section 8 are our subprocessors.
2. What we process, and why
Subject matter: backup archives your site uploads to WP-AllBackup Storage, and the manifests that list them. Nature and purpose: storing them so that you can restore, migrate or download them; measuring how much space each licence uses, because that is what the allowance is enforced against and what a paid package is billed on; deleting them on the schedule in section 6. Categories of data: whatever your site contains. We do not know what that is and we do not look. Data subjects: you and the users of your site. Duration: for as long as your licence carries storage, plus the retention period in section 6.
3. What we do, and do not do, with your backups
- We store them and hand them back to your site, or to another site of yours that presents the same licence, when asked.
- We measure the size of each licence's directory. That is the only reading we do of your data, and it reads a number, not a file.
- We do not open, read, index, scan, analyse or share the contents of an archive. Not for support, not for statistics, not for anything, unless you ask us in writing to look at a specific file to help you, in which case we do only what you asked and tell you what we did.
- We process only on your instructions, which are the ones built into the product: store, list, return, measure, delete on the published schedule. If a law requires us to process differently, we tell you first unless the law forbids it.
- If you switch on Encryption in the plugin, what we hold is ciphertext under a key that only you have. We cannot read it, and we cannot recover the key for you if you lose it.
4. Security measures
What is actually in place, stated as it is rather than as a list of adjectives:
- In transit: your site talks to the storage server over SFTP and to the portal over HTTPS. The plugin verifies the storage server's host key against the fingerprints the portal publishes for it, so nobody is ever asked to accept a key they cannot check.
- Isolation: each licence has its own account on the storage server, confined to its own directory. No licence can reach another licence's directory. Sites on the same licence write only into their own subdirectory, and may read each other's for a migration.
- Credentials: the credentials your site holds are issued by the portal for six hours at a time and renewed on request; the underlying password on the storage server is changed every week, and at once when a copied site is caught using the original's identity.
- Copies you cannot lose to a stolen credential: the storage server keeps seven daily snapshots that no customer credential can list, delete or reach.
- At rest: Encryption in the plugin, when you switch it on, seals every archive on your server before it is uploaded (AES-256-GCM). Without it, archives are stored as the plugin wrote them, on disks operated by our storage provider in Germany.
- People: only Fixit d.o.o. staff who operate the service can reach the storage server as its main account, under a duty of confidentiality, and only to operate it: measure usage, apply the deletion schedule, or recover a directory from a snapshot at your request.
- Portal: passwords hashed; two-factor authentication required for every staff account (the admin console does not open without it) and offered to customers; sensitive reveals behind a fresh password confirmation; request rate limits.
5. Helping you meet your own obligations
If a person exercises a data-protection right that touches the contents of a backup, we cannot find or change anything inside an archive; the answer is a restore on your side or a deletion of the backup. We will delete a restore point or a licence's whole storage on your written request within five working days. We will answer a reasonable question about our processing within a month, and we will give you what you need for a data-protection impact assessment on request.
6. Retention and deletion
While your licence is active, archives stay until you delete them. If the licence lapses or you disconnect the storage, they are kept, readable, for 60 days, with warning emails during that period and one when the deletion has happened; renewing at any point stops the clock. After deletion the storage server's daily snapshots let go of the data within a further seven days. On your written request we delete sooner. Deletion means the files are removed from the storage server; we do not keep another copy of an archive anywhere.
7. If something goes wrong
If we become aware of a personal data breach that affects your backups (unauthorised access to, loss of, or disclosure of an archive or of the credentials that reach it), we will tell you by email within 48 hours of becoming aware, with what we know, what we have done, and what we suggest you do, and we will keep telling you as we learn more.
8. Subprocessors
We use these companies to provide the service. Each is bound by a written agreement to protect your data at least as well as this agreement requires. If we add or replace one we will note it here with a new version and date at least 30 days before it starts handling data, and you may end your storage subscription if you object.
| Who | What they do for us | Where | What of yours they see |
|---|---|---|---|
| Hetzner Online GmbH | Runs the storage server (Storage Box) that holds WP-AllBackup Storage archives | Falkenstein, Germany (EU) | Your backup archives, as your site uploaded them; encrypted ones only as ciphertext |
| Microsoft Ireland Operations Ltd (Azure) | Hosts the licence portal and the OAuth relay | North Europe region (Ireland, EU) | Your account and licence records; never a backup archive |
| Paddle.com Market Ltd | Merchant of record for purchases: checkout, invoices, VAT, refunds | United Kingdom | Your name, email address and payment details, under Paddle's own privacy policy (Paddle is a controller for these) |
| SMTP2GO Limited | Delivers transactional email (account invitations, password resets, storage warnings) | New Zealand (an EU adequacy country); delivery infrastructure in several regions | Your email address and the text of those emails; never a backup archive |
| Cloudflare, Inc. | The human check (Turnstile) on the portal's login and forgot-password forms | United States, serving from data centres worldwide including the EU; certified under the EU-US Data Privacy Framework | The IP address and technical browser characteristics of whoever opens those two pages; never an account record or a backup archive |
| Google LLC | Sign in with Google on the portal, only for accounts that choose it | United States; certified under the EU-US Data Privacy Framework | That you signed in to our portal; we receive your Google account id, name and email address |
9. Where your data is
Backup archives are held in Germany and are not moved out of the European Union by us. Account and licence records are held in the EU (Ireland). Payment records sit with Paddle in the United Kingdom, which the EU recognises as providing adequate protection. Transactional email is delivered by SMTP2GO, whose infrastructure may sit outside the EEA; those messages carry your email address and the text of the notice, nothing from a backup. The human check on the portal’s sign-in forms and, if you choose it, Sign in with Google are provided from the United States by Cloudflare and Google under the EU-US Data Privacy Framework; each sees the sign-in request and nothing from a backup.
10. Audits and information
You may ask us, in writing and no more than once a year unless there has been an incident, to demonstrate what this agreement says. We answer with documentation first: this page, the user guide, and the technical description of the storage design, which we keep current. If that is not enough for a supervisory authority, we will cooperate with an audit at a reasonable time and at your cost.
11. Ending
When your storage subscription ends, section 6 applies: readable for 60 days, then deleted, then gone from snapshots within seven more days. You can download every archive from your site's restore points list before then. We keep no copy afterwards. Licence and order records are kept as the Privacy Policy describes, for as long as tax and accounting rules require.
12. Changes and versions
We change this agreement by publishing a new version here with its number and date. A change that reduces your protection takes effect 30 days after it is published; any other change takes effect when published. The current version is stated at the top of this page.
- Version 3, 4 September 2026. Two subprocessors added for signing in to the portal: Cloudflare (the human check on the login and forgot-password forms) and Google (Sign in with Google, only for accounts that choose it). Neither touches a backup archive. No change to the processing of archives, retention or the security measures.
- Version 2, 31 August 2026. The free build named as Okleone Backups alongside the premium build. No change to processing, subprocessors or retention.
- Version 1, 17 August 2026. First published, together with archive encryption in plugin 3.8.0, weekly credential rotation and daily storage snapshots. Amended the same evening: two-factor authentication became mandatory for staff accounts on the portal.
13. Contact
Fixit d.o.o., wp-allbackup-support@fixit.biz. Requests under this agreement are handled by the same address; put "DPA" in the subject line.