Part I – Privacy Policy
1. Controller(s)
Different roles apply to the processing of personal data in connection with the use of Bitkurier Activity Guard®, depending on the purpose of processing:
- Website operator (customer): Controller within the meaning of Art. 4 No. 7 GDPR for the processing of personal data of visitors to their WordPress website, including security events recorded via Activity Guard.
- BITkurier GmbH: Processor on behalf of the customer (Art. 28 GDPR) for providing the security functions on the respective installation.
- BITkurier GmbH as (joint) controller: For the cross-customer aggregation and evaluation of security events within the threat intelligence network (see Part II, Section 6), BITkurier GmbH additionally processes data for its own purposes and is, to that extent, independently or jointly responsible with the customer within the meaning of Art. 26 GDPR.
Contact:
BITkurier GmbH, Akazienweg 33, 51147 Cologne, Germany
2. Purpose of Processing
Bitkurier Activity Guard® processes personal and technical data to provide the agreed security functions, for attack detection, error diagnosis, license management, support, product improvement, and — within the threat intelligence network — for the cross-customer detection of new attack patterns.
3. Data Processed
Depending on the scope of functions used, the following data may be processed and transmitted to BITkurier GmbH’s infrastructure: public IP addresses (including those of website visitors who are not customers of BITkurier), IP addresses of suspected attackers, timestamps, HTTP headers, user agent, URLs, referrers, login and brute-force events, XML-RPC and REST API access, WAF events, malware indicators, file hashes, technical system information, license data, and diagnostic logs.
Note on misclassification: IP addresses flagged as “suspected attackers” may, in individual cases, also relate to regular visitors (e.g., due to automatically triggered WAF rules, shared IP addresses, or VPN endpoints). Such data is subject to the same deletion and correction rules as other personal data.
4. Purposes of Transmission
Transmission to BITkurier GmbH takes place for the detection, analysis, and defense against cyberattacks, for developing new protective rules, for providing threat intelligence, for contract fulfillment, and for improving security mechanisms.
5. Legal Bases
- Art. 6(1)(b) GDPR (performance of the contract with the customer)
- Art. 6(1)(f) GDPR (legitimate interest of the customer and of BITkurier GmbH in defending against cyberattacks and maintaining IT security)
Where processing is based on Art. 6(1)(f) GDPR, a right to object exists under Art. 21 GDPR (see Section 8).
6. Recipients
The recipient of the data is BITkurier GmbH and the processors it engages (e.g., hosting infrastructure). A current list of subprocessors can be requested from BITkurier GmbH via Contact.
7. International Data Transfers
No data is transferred to third countries outside the EU/EEA.
8. Retention Periods
- Security events for an individual installation: in accordance with the retention period configured by the customer (in days), but no more than 12 months, unless a statutory retention obligation requires otherwise.
- Data aggregated/pseudonymized within the threat intelligence network: anonymized or deleted after no more than 12 months, unless a specific ongoing security interest exists (e.g., an active attack campaign).
- License and contract data: for the duration of the contractual relationship plus statutory retention obligations (generally 6–10 years under the German Commercial Code (HGB)/Fiscal Code (AO)).
9. Data Subject Rights
Data subjects — including website visitors who are not in a direct contractual relationship with BITkurier GmbH — have the statutory rights under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21).
Requests can be directed to:
- the respective website operator (as the primary point of contact for visitors to the affected website), or
- directly to BITkurier GmbH via Contact.
There is additionally a right to lodge a complaint with the competent data protection supervisory authority.
10. Security
Transmission is encrypted (transport encryption). Appropriate technical and organizational measures are used to protect the data (see Part II, Section 12).
Part II – Threat Intelligence & Security Data Processing Policy
1. Purpose and Scope
This policy supplements Part I and describes the processing of security-relevant data within Bitkurier Activity Guard® for all installations, cloud services, and support services.
2. Security Architecture
The product is based on a multi-tier security concept. Security events are first detected locally on the customer’s installation and — where necessary for the security function — transmitted to BITkurier GmbH’s infrastructure.
3. Categories of Data Processed
Public IP addresses, source IP of suspected attackers, timestamps, user agent, HTTP headers, referrer, requested URLs, HTTP methods, error codes, login attempts, XML-RPC and REST API events, firewall/WAF logs, malware indicators, file hashes, file integrity information, WordPress, PHP, plugin, and theme versions, server configurations, license information, technical diagnostic data, and support logs.
4. Data Not Processed
The content of posts, pages, media, customer databases, or emails is generally not analyzed or transmitted, unless required in an individual case for malware analysis, error diagnosis, or due to legal obligations. In such a case, the customer will be informed in advance, provided this does not conflict with overriding security interests.
5. Purposes of Processing
Protection against cyberattacks, detection of new exploits, zero-day analysis, threat intelligence, signature development, abuse detection, license management, support, product improvement, and quality assurance.
6. Threat Intelligence Network (Cross-Customer Processing)
Security events from various installations may be aggregated and evaluated in order to detect new attack patterns, botnets, IOC data (Indicators of Compromise), reputation data, and malware campaigns at an early stage.
The following applies to this cross-customer evaluation:
- BITkurier GmbH processes the data for its own purposes to this extent and is (jointly) responsible for it within the meaning of Art. 26 GDPR.
- Pseudonymization or aggregation is applied wherever possible, so that tracing data back to individual visitors of a specific customer installation is only possible with additional effort.
- Re-identification of pseudonymized data occurs only where strictly necessary to defend against a concrete, active threat.
- The legal basis is Art. 6(1)(f) GDPR based on a balancing of interests; data subjects may object under Art. 21 GDPR.
7. Legal Bases
Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in IT security, including operation of the threat intelligence network).
8. Data Transmission
Transmissions occur exclusively via encrypted, suitable transport encryption (e.g., TLS 1.2 or higher). Only the information necessary for the respective security purpose is transmitted (data minimization).
9. Recipients and Processing on Behalf
The recipient is BITkurier GmbH. Hosting or infrastructure partners are engaged exclusively as processors under Art. 28 GDPR. On request, BITkurier GmbH enters into a separate data processing agreement (DPA) with the customer governing the obligations under Art. 28 GDPR. For the purposes of the threat intelligence network (Section 6), a joint controller agreement under Art. 26 GDPR additionally applies; its essential content is made available to customers on request and is summarized here in substance: BITkurier GmbH is responsible for the technical security, pseudonymization, and deletion of the aggregated data; the customer remains responsible for informing its website visitors.
10. International Data Transfers
No data is transferred to third countries outside the EU/EEA.
11. Retention Periods
See Part I, Section 8. Security data is deleted or anonymized once the respective period has expired.
12. Technical and Organizational Measures
Transport encryption, access restrictions based on the need-to-know principle, logging of administrative access, role- and permission-based access concepts, backup and recovery procedures, regular security reviews in accordance with ISO 27001.
13. Incident Response
Security incidents are documented, assessed, and handled according to internal processes. In the event of incidents posing a risk to data subjects, BITkurier GmbH informs affected customers without delay so that they, in turn, can meet their reporting obligations under Art. 33/34 GDPR.
14. Secure Development Lifecycle
Security aspects are taken into account during the development, testing, and release of new versions.
15. Vulnerability Disclosure
Reports of security vulnerabilities are accepted, assessed, and processed via Contact.
16. Data Subject Rights
See Part I, Section 9.
17. Right to Object (Art. 21 GDPR)
Data subjects may object to the processing of their data based on Art. 6(1)(f) GDPR for reasons arising from their particular situation. This applies in particular to the inclusion of their data in the cross-customer threat intelligence network (Section 6). An objection can be directed to Contact or via the respective website operator.
18. Transparency and Changes
Changes to this policy are documented and published with a version number and date. The current version is made available to customers. Last updated: July 1, 2026.
Appendix A – Typical Security Data
- Public IP addresses
- Source IP of suspected attackers
- Timestamps
- HTTP headers
- User agent
- HTTP methods
- URLs and referrers
- Login and brute-force events
- XML-RPC and REST API access
- Firewall/WAF events
- Malware indicators
- File hashes and file integrity information
- WordPress, PHP, plugin, and theme versions
- Server and license information
- Diagnostic and error logs
Appendix B – Sample Privacy Policy Clause for the Customer (Website Operator)
To protect this website, we use the “Bitkurier Activity Guard®” plugin from BITkurier GmbH. As part of the security functions, technical data from visitors to this website — in particular IP addresses, timestamps, HTTP headers, requested URLs, and data on detected login and attack attempts — is transmitted to and processed on BITkurier GmbH’s infrastructure.
The purpose of this processing is the detection, defense against, and analysis of cyberattacks on this website. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in the security of our IT systems.
Your data may also be processed in pseudonymized or aggregated form within BITkurier GmbH’s cross-customer threat intelligence network in order to detect new attack patterns industry-wide. BITkurier GmbH is, to that extent, a joint controller together with us (Art. 26 GDPR). Further information can be found in BITkurier GmbH’s privacy policy: https://wordpress-hackschutz.de/en/privacy-policy/.
You have the right to object to this processing for reasons arising from your particular situation (Art. 21 GDPR). Please contact the website operator or BITkurier GmbH via Contact.
Appendix C – Transparency Overview
| Data Category | Purpose | Legal Basis | BITkurier’s Role | Retention |
|---|---|---|---|---|
| IP addresses (visitors/suspected attackers) | Attack detection | Art. 6(1)(b)/(f) | Processor | Configurable, max. [X days] |
| Diagnostic data | Support | Art. 6(1)(b) | Processor | Contract duration + [X] |
| License data | License management | Art. 6(1)(b) | Controller (own contractual relationship) | Contract duration + statutory periods |
| WAF/malware data (individual installation) | Security function | Art. 6(1)(f) | Processor | Configurable, max. [X days] |
| Aggregated/pseudonymized threat intelligence data | Cross-customer threat detection | Art. 6(1)(f), Art. 26 (joint controllership) | (Joint) Controller | Max. [X months], then anonymization/deletion |