Updated: 26 August 2026
This policy explains what personal data Bugzio (“we”) processes when you use our website and service, and what rights you have.
1. Controller
Service provider and data controller: SIA "WD Team", reg. No. 40203097825. For any question about data processing write to [email protected].
2. When we are a controller and when a processor
For your account (sign-up, billing, support) we act as the controller.
For the data Bugzio collects on your website — bug reports, screenshots, console and network captures, video and session replays — you (our customer) are the controller and we act as a processor on your instructions only.
3. What we process
3.1. Account data
- name, email address, password hash (we never store the password itself);
- workspace name, role, selected plan and subscription history;
- support correspondence.
3.2. Bug report content
- the description and email the reporter enters (if provided);
- screenshot, video and voice note (when the reporter records them);
- browser console logs, network requests (HAR), page URL, browser and screen parameters;
- the step timeline and session replay leading up to the bug.
This data may incidentally contain personal data that was visible on screen. The widget includes a blur tool and we recommend masking sensitive fields before sending.
3.3. Monitoring data
- the domains and URLs you add to monitoring;
- check results (uptime, speed, security headers, SSL, SEO, WCAG, cookies, DNS, email authentication and others).
3.4. Technical logs and cookies
- IP address, timestamp, request data (for security and abuse prevention);
- cookies — see the Cookie policy.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating an account and providing the service | Performance of a contract (GDPR 6(1)(b)) |
| Invoicing and accounting | Legal obligation (6(1)(c)) |
| Security, fraud and abuse prevention | Legitimate interests (6(1)(f)) |
| Product improvement and support | Legitimate interests (6(1)(f)) |
| Website analytics | Consent (6(1)(a)) |
| Bug reports collected on a customer site | Customer instructions — we are a processor (Art. 28) |
5. Sub-processors
We use the following providers to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting | EU (Germany) |
| Cloudflare, Inc. | CDN, DNS and attack protection | EU/US |
| Anthropic PBC | AI triage and reports for bug reports (only when the feature is enabled) | US |
| Google LLC | PageSpeed Insights and Web Risk APIs for site checks; Google Analytics (with consent only) | EU/US |
| Sales.lv Ltd. | SMS alerts (when enabled) | EU (Latvia) |
Transfers to the US rely on the European Commission’s standard contractual clauses or the provider’s participation in the EU–US Data Privacy Framework.
6. Retention
6.1. Content while the account is active
- Bug reports (description, screenshots, video, voice notes, logs, session replays) — per your plan’s retention window: Solo 90 days, Starter 12 months, Studio, Agency and Enterprise keep them for as long as the subscription runs. You can also delete them yourself at any time.
- Monitoring check results — Solo and Starter 30 days, Studio 12 months, Agency and Enterprise with no time limit. Aggregate figures (a monthly uptime percentage, say) may outlive the individual check records they were computed from.
The current window for each plan is shown in the comparison table on the pricing page.
6.2. After the account is closed
Two separate periods apply, and neither overrides the other:
- Your content — bug reports, attachments, video, monitoring results and project settings — is deleted within 30 days of the account being closed, as clause 5 of the Terms of service states. You can export it before closing.
- The account and billing record — name, email address, workspace, plan and subscription history — is kept for a further 12 months in case of a dispute about the service or a payment, and is then deleted. It is the minimum needed to show what was provided and when; your content is not part of it.
6.3. Everything else
- Accounting records — 5 years (statutory).
- Security logs — up to 12 months.
7. Your rights
You may access, rectify or erase your data, restrict or object to processing based on legitimate interests, and receive your data in a portable format. Consent (e.g. for analytics) can be withdrawn at any time.
Send requests to [email protected]. We respond within 30 days.
If you believe we process data unlawfully you may complain to the Latvian Data State Inspectorate (dvi.gov.lv) or your local supervisory authority.
8. Security
All traffic runs over HTTPS, passwords are stored only as hashes, production access is restricted and logged, and backups run regularly. Report vulnerabilities to [email protected] or see security.txt.
9. Changes
We may update this policy. Material changes are announced by email or in the panel at least 14 days in advance.