Legal and compliance
Privacy Notice
Last updated: September 11, 2026
This notice explains how SecurityOla, a BarndAI product, handles information when you use our website, WordPress software, API, support channels and commercial services.
1. Roles and scope
For SecurityOla-controlled account, website, purchase, support and entitlement information, the service operator acts as the controller subject to the verified business identity below. When SecurityOla or AppCare scans or monitors a customer site on the customer’s documented instructions, customer-site personal data may be processed on that customer’s behalf; the customer remains responsible for its own controller obligations, notices and lawful instructions. SecurityOla does not claim that this notice alone establishes a processor agreement.
2. Controller contact
Trader information
Business identity disclosure
- Trading name
- SecurityOla
- Product relationship
- SecurityOla is a BarndAI product.
- Support email
- support@securityola.com
- Legal business/entity name
- Not published: verified owner record required.
- Geographic business address
- Not published: verified owner record required.
- Company register, VAT and telephone
- Not provided in the verified records available to this deployment.
These fields are intentionally not guessed from product branding. Replace this status with verified owner/business records before requesting Paddle domain review.
3. Purposes and legal bases
- Contract or steps before contract: provide licenses, site registration, checkout handoff, activation, updates, reports and support.
- Legitimate interests: maintain security, fraud and abuse controls, site limits, reliability, diagnostics and incident response, balanced against individual rights.
- Legal obligation: maintain records needed for accounting, tax, disputes and lawful requests.
- Consent: used only if a future non-essential tracking or marketing feature is enabled; the current first-party site has no observed non-essential tracking.
4. Information and data categories
- Identity and contact information, support correspondence and diagnostic IDs.
- Customer, license, entitlement and Paddle customer/transaction references.
- WordPress site and domain identifiers, versions, scan status, updater health, report freshness and integrity status.
- During an authorized scan, WordPress files, database conditions, options, pages, uploads and suspicious-code evidence may be inspected to produce findings. Raw contents are not needed for normal support diagnostics, but scanning is not equivalent to never processing site data.
- Payment-card details are handled by Paddle’s checkout rather than directly collected by this site.
5. Recipients and providers
Data may be disclosed only as needed to Paddle for payment and billing, the SecurityOla hosting/runtime provider, Amazon SES SMTP for server-side email, and the separately scoped Backblaze B2 AppCare backup adapter described in /subprocessors. Local API logs and entitlement/site/release state are stored on the SecurityOla server. No separate external error-reporting provider or AI/model provider was observed in the current SecurityOla API/site paths.
6. International transfers
Provider locations and transfer mechanisms are not fully recorded in the verified deployment materials. Do not treat this notice as confirming a specific adequacy decision, standard contractual clause or other transfer mechanism; the provider contracts and locations require owner/operator review before a final public compliance claim.
7. Retention
No single public retention period is stated because the verified production records do not contain a complete schedule for logs, scan results, backups, site data, support records, security evidence and account data. Records are retained only for the shortest operationally reasonable period needed for service delivery, security, accounting, disputes or legal obligations, then deleted or de-identified where practical. A documented store-by-store schedule remains an open compliance item.
8. Security safeguards
Observed safeguards include access controls, bounded logging, secret separation, signed webhook verification, package-hash verification and isolated provider scopes. No internet service can guarantee absolute security.
9. Your rights
Depending on your location and the applicable legal basis, you may request access, correction, deletion, restriction, objection or portability where applicable. If processing relies on consent, you may withdraw consent at any time; withdrawal does not affect earlier lawful processing. You may complain to the supervisory authority in your place of residence or work. Contact support@securityola.com with enough information to locate a request, but do not send passwords, card numbers or raw database exports.
10. Automated decisions and profiling
No automated decision-making or profiling intended to produce legal or similarly significant effects was observed in the current public site, SecurityOla API or Paddle entitlement flow. Security findings are signals for review, not automated decisions about individuals.
11. Children
SecurityOla is business and website-administration software and is not intended for children.