GDPR & Data Protection
Last updated: 30 September 2026
We take data protection seriously. This page explains our roles, what we promise as a data processor, our sub-processors and how to exercise your rights. It applies alongside our Privacy Policy.
1. Roles
- Controller: for account, contact and website-visitor data of people who deal with us directly.
- Processor: for data our customers ask us to monitor, scan, crawl or back up on their websites. The customer is the controller of that data.
2. Processing summary (for customers)
| Subject matter | Providing website monitoring, security, performance, SEO, backup and update services. |
|---|---|
| Duration | For as long as the customer uses the service, plus the retention periods in our Privacy Policy. |
| Nature and purpose | Collecting, storing, analysing and transmitting website data to detect problems, alert the customer, produce reports and, on request, copy or update the website. |
| Types of personal data | Names, email addresses and usernames of website administrators; contact details in site content; and, where backups are used, any personal data held in the website's database and files (for example customer, comment or order records). |
| Data subjects | The customer's staff and clients using the dashboard, and the customer's website users, customers and visitors. |
3. Our commitments as processor
- We process personal data only on the customer's documented instructions (the service configuration and these terms), unless the law requires otherwise.
- People who access the data are bound by confidentiality.
- We apply appropriate technical and organisational security measures (see Privacy Policy, section 7).
- We use only the sub-processors below and will give customers notice of changes so they can object.
- We help customers respond to data subject requests and carry out impact assessments, taking into account the nature of processing.
- We notify customers without undue delay after becoming aware of a personal data breach affecting their data.
- On termination we delete or return the customer's data, and delete existing copies unless the law requires storage. Customers can delete sites, and their backups, at any time.
- We make available the information needed to show compliance and allow for audits, on reasonable notice.
A signed data processing agreement (DPA) incorporating the EU standard contractual clauses where needed is available on request from support@urkavach.com.
4. Sub-processors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| [Hosting provider (HOSTING_PROVIDER)] | Hosting, database, storage of backups | All service data | [Hosting region (HOSTING_REGION)] |
| Payment provider | Subscription billing | Name, email, billing details, payment amounts | Per provider |
| Email delivery provider (SMTP) | Sending alerts and digests | Recipient address, alert text | Per provider |
| Google (PageSpeed Insights, Web Risk / Safe Browsing, Search Console) | Speed tests, malware reputation checks, search data | Website address (Search Console data only if connected) | Global |
| WPScan (if enabled) | Known-vulnerability lookups | Plugin, theme and WordPress version identifiers | Per provider |
| Slack, Discord, Google Chat (if configured by the customer) | Alert delivery | Alert text | Per provider |
5. International transfers
Where personal data is transferred outside the EEA or the UK to a country without an adequacy decision, we rely on standard contractual clauses or another lawful transfer mechanism.
6. Your rights and how to use them
You can ask to access, correct, delete, restrict, object to, or receive a portable copy of your personal data, and to withdraw consent. Signed-in users can export their account data and delete their account under Account. Otherwise email support@urkavach.com. We aim to respond within one month. If you think we have not handled your data properly you can complain to your supervisory authority.
7. Data protection contact
UrKavach, [Your postal address (LEGAL_ADDRESS)]
support@urkavach.com
India (DPDP Act 2023): for grievances about how we process your personal data, write to the contact above. We will acknowledge and address them within the time the Act requires.