Privatumo politika

Kokius duomenis Bugzio tvarko, kodėl ir kiek laiko juos saugo.

Atnaujinta: 2026 m. rugpjūčio 26 d.

Šis dokumentas kol kas prieinamas tik anglų kalba. Atverti versiją anglų kalba

This policy explains what personal data Bugzio (“we”) processes when you use our website and service, and what rights you have.

1. Controller

Service provider and data controller: SIA "WD Team", reg. No. 40203097825. For any question about data processing write to [email protected].

2. When we are a controller and when a processor

For your account (sign-up, billing, support) we act as the controller.

For the data Bugzio collects on your website — bug reports, screenshots, console and network captures, video and session replays — you (our customer) are the controller and we act as a processor on your instructions only.

3. What we process

3.1. Account data

  • name, email address, password hash (we never store the password itself);
  • workspace name, role, selected plan and subscription history;
  • support correspondence.

3.2. Bug report content

  • the description and email the reporter enters (if provided);
  • screenshot, video and voice note (when the reporter records them);
  • browser console logs, network requests (HAR), page URL, browser and screen parameters;
  • the step timeline and session replay leading up to the bug.

This data may incidentally contain personal data that was visible on screen. The widget includes a blur tool and we recommend masking sensitive fields before sending.

3.3. Monitoring data

  • the domains and URLs you add to monitoring;
  • check results (uptime, speed, security headers, SSL, SEO, WCAG, cookies, DNS, email authentication and others).

3.4. Technical logs and cookies

  • IP address, timestamp, request data (for security and abuse prevention);
  • cookies — see the Cookie policy.

4. Purposes and legal bases

PurposeLegal basis
Creating an account and providing the servicePerformance of a contract (GDPR 6(1)(b))
Invoicing and accountingLegal obligation (6(1)(c))
Security, fraud and abuse preventionLegitimate interests (6(1)(f))
Product improvement and supportLegitimate interests (6(1)(f))
Website analyticsConsent (6(1)(a))
Bug reports collected on a customer siteCustomer instructions — we are a processor (Art. 28)

5. Sub-processors

We use the following providers to deliver the service:

ProviderPurposeLocation
Hetzner Online GmbHServer hostingEU (Germany)
Cloudflare, Inc.CDN, DNS and attack protectionEU/US
Anthropic PBCAI triage and reports for bug reports (only when the feature is enabled)US
Google LLCPageSpeed Insights and Web Risk APIs for site checks; Google Analytics (with consent only)EU/US
Sales.lv Ltd.SMS alerts (when enabled)EU (Latvia)

Transfers to the US rely on the European Commission’s standard contractual clauses or the provider’s participation in the EU–US Data Privacy Framework.

6. Retention

6.1. Content while the account is active

  • Bug reports (description, screenshots, video, voice notes, logs, session replays) — per your plan’s retention window: Solo 90 days, Starter 12 months, Studio, Agency and Enterprise keep them for as long as the subscription runs. You can also delete them yourself at any time.
  • Monitoring check results — Solo and Starter 30 days, Studio 12 months, Agency and Enterprise with no time limit. Aggregate figures (a monthly uptime percentage, say) may outlive the individual check records they were computed from.

The current window for each plan is shown in the comparison table on the pricing page.

6.2. After the account is closed

Two separate periods apply, and neither overrides the other:

  • Your content — bug reports, attachments, video, monitoring results and project settings — is deleted within 30 days of the account being closed, as clause 5 of the Terms of service states. You can export it before closing.
  • The account and billing record — name, email address, workspace, plan and subscription history — is kept for a further 12 months in case of a dispute about the service or a payment, and is then deleted. It is the minimum needed to show what was provided and when; your content is not part of it.

6.3. Everything else

  • Accounting records — 5 years (statutory).
  • Security logs — up to 12 months.

7. Your rights

You may access, rectify or erase your data, restrict or object to processing based on legitimate interests, and receive your data in a portable format. Consent (e.g. for analytics) can be withdrawn at any time.

Send requests to [email protected]. We respond within 30 days.

If you believe we process data unlawfully you may complain to the Latvian Data State Inspectorate (dvi.gov.lv) or your local supervisory authority.

8. Security

All traffic runs over HTTPS, passwords are stored only as hashes, production access is restricted and logged, and backups run regularly. Report vulnerabilities to [email protected] or see security.txt.

9. Changes

We may update this policy. Material changes are announced by email or in the panel at least 14 days in advance.