Privacy Policy
Version 1 · published 3d ago
Privacy Policy
Effective from: the date this version was published — see the version stamp at the top of this page. Controller: Koya Labs, a registered business name of the legal entity identified on the [Company information](company-information.md) page Legal entity, registered address, and registration numbers: see [Company information](company-information.md) Privacy contact: [email protected]
1. Introduction
This Privacy Policy explains how Weblooks collects, uses, stores, shares, and otherwise processes personal data in connection with the Weblooks website, applications, platform, staging environments, support channels, integrations, and related services.
This Policy also explains your privacy rights and choices.
If you do not agree with this Policy, do not use the Service.
2. Scope
This Policy applies to personal data we process as a controller in connection with:
- visitors to our website
- users of our platform
- administrators and collaborators invited to workspaces or projects
- client reviewers invited through review links
- people who contact support, request demos, or otherwise interact with us
- recipients of our communications
Where a customer uses Weblooks to build and publish a website, that customer is the controller for the personal data in their content and for their site's visitors, and we act as their processor. That processing is governed by the Data Processing Agreement, not by this Policy. If you are a visitor to a site built with Weblooks and want to exercise your rights over data that site holds, contact the site's operator.
This Policy does not govern third-party services that you connect to or use through Weblooks. Those services have their own privacy notices and practices.
3. Where your data is processed
Our application servers, primary database, and cache run on infrastructure located in Germany. Error monitoring is processed in the European Union.
Content delivery, edge serving, and object storage run on a global network operated by our infrastructure provider; object placement is automatic across that provider's regions. Transactional email and secret management are operated by providers in the United States; secret management holds platform credentials only and no personal data.
The full list, with each provider's role and processing location, is published at Subprocessors.
4. Categories of personal data we collect
Depending on how you use Weblooks, we may collect the following categories of personal data.
Account and profile information
- name
- email address
- authentication identifiers
- account role
- organization or workspace information
- language and region preferences
Authentication and security data
- sign-in events
- passkey or authentication metadata
- device or browser-related security signals
- IP address
- session identifiers
- MFA status and related security settings
- audit logs and security event logs
Project and usage data
- project names and settings
- collaboration events
- comments and review actions
- deployment events
- staging access events
- metadata and governance settings
- issue and checklist states
- interaction events within the Service
Content and files
- content, files, images, assets, comments, metadata, structured data, or materials you upload, create, sync, or connect
- support materials you submit to us
- legal or CMS text you create or manage within the platform
Integration data
If you connect third-party services, we may process:
- access tokens or credentials through approved secret handling systems
- integration identifiers
- selected scopes and permissions
- sync metadata
- webhook and API event data
- content or files made available through connected services, as instructed by you
Communications data
- support messages
- survey responses
- request history
- onboarding or operational emails
- transactional message logs
Billing and transaction data
If and when billing is enabled, we or our payment providers may process:
- billing contact details
- subscription status
- payment-related metadata
- invoices and tax-related information
- limited payment transaction records
We do not store full payment card details. Payment processing is handled by our payment provider.
Website, device, and diagnostic data
- browser type
- device type
- operating system
- approximate location inferred from IP
- referral URLs
- page views and feature events
- error reports, stack traces, and error-triggered session replays
5. Sources of personal data
We collect personal data:
- directly from you
- from users or admins who invite you
- from your use of the Service
- from integrated third-party services you connect
- from payment providers and communications providers
- from security and error-monitoring tools
- from cookies and similar technologies, subject to applicable law
6. Purposes of processing
We process personal data for the following purposes:
- providing and operating the Service
- authenticating users and securing accounts
- enabling collaboration, invitations, comments, and staging access
- syncing with connected services
- processing deployments and deployment-related checks
- providing support and responding to inquiries
- maintaining logs, audit trails, and incident records
- detecting, preventing, and investigating fraud, abuse, and security incidents
- responding to reports of illegal content and meeting our obligations as a hosting provider
- monitoring performance, reliability, and service health
- improving the Service and user experience
- sending transactional and service-related communications
- managing subscriptions, billing, invoices, and payments when enabled
- complying with legal obligations
- enforcing our terms, policies, and rights
We do not sell personal data, use your content to train machine-learning models, or profile you for advertising.
7. Legal bases for processing
Where the GDPR or similar laws apply, we process personal data under one or more of the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, managing your account, billing | Performance of a contract (Art. 6(1)(b)) |
| Security, abuse prevention, audit logging, error monitoring | Legitimate interests (Art. 6(1)(f)) — keeping the Service and its users safe |
| Service improvement and reliability | Legitimate interests (Art. 6(1)(f)) |
| Transactional and security communications | Performance of a contract / legal obligation |
| Marketing communications, where sent | Consent (Art. 6(1)(a)), withdrawable at any time |
| Responding to illegal-content reports; tax, accounting, and record-keeping | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. You may object at any time — see section 15. A summary of the balancing assessment is available on request.
Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
8. Cookies and similar technologies
Weblooks uses only strictly necessary cookies. We do not use advertising, marketing, or third-party analytics cookies, and we do not run a third-party tag manager on our own website. Because no non-essential cookies are set, no consent banner is shown.
| Cookie | Purpose | Type |
|---|---|---|
| `wl_session` | Keeps you signed in | Strictly necessary |
| `gh_oauth_state` | Cross-site request forgery protection during a GitHub connection | Strictly necessary, short-lived |
| `gh_oauth_next` | Returns you to the right page after connecting GitHub | Strictly necessary, short-lived |
| Active-workspace cookie | Remembers which workspace you are working in | Necessary for functionality you requested |
We also use browser local storage for interface preferences on your own device. That is not transmitted to us.
If we later introduce analytics or other non-essential technologies, we will ask for your consent before setting them, and provide a means to change your choice.
This section is about our own website and platform. Websites you build and publish with Weblooks may set their own cookies. You control those, and you are responsible for the consent mechanism on your site. We provide a consent banner and consent log for that purpose — see section 19.
9. Communications
We may send:
- transactional emails
- sign-in links
- account and security notices
- billing notices
- support communications
- service announcements
Where permitted by law, we may also send product updates or marketing communications. You can opt out of marketing communications at any time. You cannot opt out of essential service or security communications.
10. Sharing of personal data
We may share personal data with:
- service providers and subprocessors that help us operate the Service — see Subprocessors
- integration providers, when you choose to connect them
- professional advisers such as lawyers, auditors, or insurers
- authorities, courts, regulators, or law enforcement where required by law or necessary to protect rights, safety, or the Service
- affiliates or acquirers in connection with a merger, sale, financing, acquisition, or reorganization
We do not sell personal data.
11. Subprocessors and service providers
The third parties we engage, their roles, the data they process, and where they process it are published at [Subprocessors](./subprocessors.md).
We give 30 days' notice before adding or replacing a subprocessor that processes personal data. To be notified, email [email protected].
12. International transfers
Your personal data may be processed in countries other than the country where you are located — see section 3 and the Subprocessors page.
Where personal data is transferred outside the EEA, we rely on:
- an adequacy decision of the European Commission; or
- the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), together with a transfer impact assessment and supplementary measures where appropriate.
For UK transfers we use the UK International Data Transfer Addendum. You may request a copy of the relevant safeguards at [email protected].
13. Data retention
We retain personal data for as long as reasonably necessary for the purposes described in this Policy. Specific periods:
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account |
| Deleted accounts | Hard-deleted 30 days after a deletion request. The request can be cancelled at any time during that window |
| Sessions | 30 days from creation; deleted immediately on sign-out, deactivation, or deletion |
| Sign-in (magic link) tokens | 15 minutes, then expired; single use |
| Audit logs and security event logs | 12 months, then pruned automatically |
| Consent records for published sites | 397 days by default, configurable per project up to a maximum of 730 days, then pruned automatically |
| Error reports and session replays | Per our error-monitoring provider's retention, currently 90 days |
| Support messages and wishlist submissions | For the life of the account |
| Billing, invoice, and tax records | As required by accounting and tax law, typically 7 years |
| Backups | Overwritten on their normal rotation |
Retention is enforced by scheduled jobs rather than manual action. When data is no longer required, we delete or anonymise it.
14. Security
We use administrative, technical, and organizational measures designed to protect personal data, including:
- passwordless authentication by default, with step-up re-authentication for sensitive actions
- role-based access control enforced server-side, on least-privilege principles
- encryption in transit, and AES-256-GCM encryption at rest for stored third-party credentials
- authentication tokens stored only as irreversible hashes
- segregated object storage with a private, never-publicly-readable bucket for uploaded project source
- secret management outside source control
- an enforced Content-Security-Policy and a full set of security response headers
- rate limiting, webhook signature verification, and automated secret and dependency scanning
- structured logging, audit logs, error monitoring, and documented incident playbooks
- separated production, development, and test environments
A fuller description is in Annex II of our Data Processing Agreement.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Personal data breaches
If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
Where we act as a processor for a customer, we notify that customer without undue delay and in any event within 48 hours of becoming aware, so they can meet their own obligations. Where we act as a controller, we notify the competent supervisory authority within 72 hours where the breach is notifiable under Article 33 GDPR.
16. Your rights
Depending on your location and applicable law, you have rights to:
- be informed about how we process your data
- access your data
- have inaccurate data rectified
- have your data erased
- restrict processing
- receive your data in a portable format
- object to processing based on legitimate interests
- withdraw consent, where we rely on it
- lodge a complaint with a supervisory authority
How to exercise them. Several rights are available as self-service in the Service:
- Access and portability — Settings → download a machine-readable export of your data
- Erasure — Settings → delete account, with a 30-day cancellable grace period
- Rectification — edit your profile and project data directly
For anything else, or if you cannot access your account, contact [email protected].
We respond within one month. Where a request is complex or you have made several, we may extend by up to two further months and will tell you why within the first month. We may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.
17. Children
The Service is not directed to children, and we do not knowingly collect personal data from children in violation of applicable law.
If you believe a child has provided personal data to us unlawfully, contact [email protected] so we can take appropriate steps.
18. Third-party services and integrations
If you connect third-party services or use integrations, you instruct us to interact with those services on your behalf, subject to your settings and permissions.
Your use of those services is subject to their own terms and privacy notices.
We are not responsible for the privacy or security practices of third parties that you choose to use.
19. Review links, collaboration, and content you publish
If you invite others to collaborate or review content, we process personal data needed to provide those sharing features, such as email addresses, invite status, access permissions, comments, review events, and audit logs.
You are responsible for selecting appropriate sharing settings and for ensuring you have a lawful basis to share personal data or content through the Service.
Consent records for sites you publish. Where you use the Weblooks consent banner, or send consent events to our ingest API from your own banner, we store a record so you can demonstrate consent under Article 7(1) GDPR. These records are deliberately minimal: we store the purposes granted or denied, the policy version, and a timestamp, identified by a keyed pseudonymous identifier that is salted per project, so records from two of your projects cannot be joined to follow an individual. We store no IP address, no user agent, and no URL. You are the controller for these records; we process them for you under the Data Processing Agreement.
20. Error monitoring
We use an error-monitoring service to detect and diagnose faults. It records error events, stack traces, and request metadata.
When an error occurs, it may also record a replay of that session. Replays are captured with all text masked and all media blocked — we see the shape of the interaction, not its content. We do not record replays of normal, error-free sessions. We rely on legitimate interests for this processing, and you may object under section 16.
21. Changes to this Policy
We may update this Policy from time to time.
If we make material changes, we will provide notice by appropriate means such as the Service, website, or email. The version stamp at the top of this page indicates when this version was published; previous versions are available on request.
22. EEA, UK, and other regional rights
If you are in the EEA, the UK, or another jurisdiction with similar rights, you may lodge a complaint with the supervisory authority in your country or region. We would appreciate the chance to address your concern first.
If laws in your jurisdiction require additional disclosures, rights, or notices, we may provide a region-specific supplement to this Policy.
23. Contact
| Topic | Address |
|---|---|
| Privacy, data protection, data subject rights | [email protected] |
| Security vulnerabilities | [email protected] |
| Illegal content and abuse reports | [email protected] |
| General support | [email protected] |
Koya Labs Legal entity details: [Company information](company-information.md)