Privacy Policy — maca.se
Version: 3.0
Last updated: 2026-09-12
Applies to: maca.se (https://maca.se/)
1. Introduction
We care about your privacy. This privacy policy describes which personal data we process, why, on what legal basis, how long the data is stored, who may access it, and what rights you have.
This policy describes how maca.se (“we”, “us”) processes personal data when you visit or use our website, in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
- The Swedish Data Protection Act (2018:218), which supplements the GDPR in Sweden
- Act (2003:389) on Electronic Communications (LEK) to the extent that it regulates cookies and similar technology (see also our cookie policy)
2. Data Controller
| | |
|—|—|
| Organization | maca.se |
| Website | https://maca.se/ |
| Email (privacy) | web@maca.se |
The data controller determines the purposes and means of processing. We may engage data processors (e.g. hosting, email, and analytics tools) that process data according to our instructions and written agreements.
3. Scope and target group
The policy applies to visitors, customers, and others who interact with the website. It does not cover processing that takes place entirely offline or in other systems unless otherwise stated.
4. What data do we process?
We only process personal data that is adequate, relevant, and necessary for the purposes set out below. Processing identified on the website based on installed plugins and integrated services is reported by activity.
Web server and operation logs
- Data: IP address, time, URL, browser, referer
- Purpose: Operation, troubleshooting, and security
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: Web hosting — normally 30–90 days in access logs
- Recipient: Web host/provider
- Transfer outside EU/EEA: May occur depending on where the server is located
Comments
- Data: Name, email, IP address, comment text
- Purpose: Publish and moderate comments
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: As long as the comment remains on the website
- Recipient: Web host
Fluent Support
- Source: maca Fluent Support Form
- Data: Name, email, ticket title, messages, attachments, status, possible customer ID, and technical metadata (IP, browser)
- Purpose: Handle customer support cases and store conversations in the support system
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: As long as the case is active and thereafter according to plugin settings (normally up to 24 months)
- Recipient: Website support staff
- Transfer outside EU/EEA: Stored in the WordPress database on your web hosting; may occur with email integrations
- Provider’s privacy policy: https://fluentsupport.com/privacy-policy/
maca DownList
- Source: maca DownList Pro
- Data: Email and possibly name in email gate, download log (file, time, IP address may be logged)
- Purpose: Provide file downloads and track downloads according to the site owner’s settings
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: Download log according to plugin settings; email gate session temporarily
- Recipient: Website staff
- Transfer outside EU/EEA: Normally processed within the EU/EEA via your web hosting
Google Site Kit
- Source: Site Kit by Google
- Data: Website statistics and search data depending on activated Google services (Analytics, Search Console, etc.)
- Purpose: Statistics, keyword analysis, and website optimization
- Legal basis: Consent (GDPR Art. 6(1)(a))
- Retention period: According to the respective Google service — see Google’s documentation
- Recipient: Google LLC
- Transfer outside EU/EEA: May involve transfer to the USA depending on the service
- Provider’s privacy policy: https://policies.google.com/privacy
WPForms
- Source: WPForms Lite
- Data: Form content according to configured fields
- Purpose: Collect inquiries, bookings, or registrations
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
- Retention period: According to plugin settings and internal deletion routine
- Recipient: Website staff
- Transfer outside EU/EEA: May occur if WPForms cloud services are used
- Provider’s privacy policy: https://wpforms.com/privacy-policy/
Forms on the website
- Fluent Support — case portal — fields: name, email, subject, message, attachments, case history
- maca DownList email gate — fields: email, possibly name
- WPForms — fields: fields according to the configured form
Mandatory fields in forms are required so that we can handle your inquiry or order.
Support pages and case management
The website has support pages or a case portal where you can send inquiries. Data you provide there (e.g. name, email, messages, and attachments) is stored so that we can handle and follow up on your case.
Case data is normally stored in the website database (WordPress) or in a connected support tool until the case is closed and according to our internal deletion routine.
Identified support pages:
- maca Support
- Support — maca BackUp
- Support — maca Restu Pro
- Support — maca DownList Pro
- Customer cases — Fluent Support
Support tool:
- Fluent Support (maca Fluent Support Form)
You may request access to, correction of, or deletion of data in your support cases by contacting us.## 5. Where does the data come from?
We normally collect data directly from you (forms, orders, account, email) and automatically during visits (technical logs, cookies according to your consent). Data may also come from payment or delivery partners when you shop with us.
6. Legal basis for processing
Each processing activity must have a valid legal basis under GDPR Article 6. Below we describe the bases we use on the website:
Legal bases
- Legitimate interest (Art. 6(1)(f)) — for security, operation, troubleshooting, spam protection, and responding to general inquiries, following a balancing test where your interests do not override ours.
- Consent (Art. 6(1)(a)) — for optional cookies, newsletters, and marketing when consent is required. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
7. Retention period
We store personal data only as long as necessary for the purpose or as required by law. After that, the data is deleted or anonymized securely.
Specific retention periods are stated per processing activity in section 4. When data is no longer needed, it is deleted or anonymized unless statutory retention is required (e.g. the Accounting Act).
8. Recipients and data processors
Data may be shared with providers such as hosting, CDN, email, payment, analytics, and support tools. These may only process data under contract (processor agreement) and our instructions. A list of processing is shown in the activities above.
9. Cookies and similar technology
We use cookies, pixels, and similar technology. Necessary cookies may be stored without consent. Non-necessary cookies (e.g. statistics and marketing) are activated only after your consent via our cookie banner.
See our cookie policy for a full list, categories, and consent management.
10. Transfer to third countries
Some providers may process personal data outside the EU/EEA, especially in the USA. This only happens when there is a valid transfer mechanism.
We primarily use the European Commission’s Standard Contractual Clauses (SCC), supplemented by technical and organizational measures and providers’ binding corporate rules or adequacy decisions where applicable.
11. Security
We take appropriate technical and organizational measures under GDPR Art. 32 to protect personal data against unauthorized access, loss, destruction, and unlawful disclosure.
We continuously work with access control, updates, backups, and incident management to a reasonable extent based on the size and risk profile of the business.
12. Automated decision-making and profiling
We generally do not use automated decision-making or profiling that has legal effect or similarly significantly affects you. If this changes, the policy will be updated.
AI systems and transparency
The website uses AI-based tools (e.g. chatbot or content generation). Data you send to these functions may be processed by an external AI provider. We state the purpose, provider, and your rights in the table above. Under the EU AI Act, certain AI systems must be transparent — if a system is classified as high-risk, we comply with the requirements for information and human oversight.
13. Your rights
You have the following rights under the GDPR when we process your personal data:
Your rights
- Right of access (Art. 15) — receive confirmation and a copy of your data
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure (Art. 17) — request deletion when there is a legal basis
- Restriction (Art. 18) — request restricted processing in certain situations
- Objection (Art. 21) — object to processing based on legitimate interest or direct marketing
- Data portability (Art. 20) — receive data in a structured, machine-readable format when processing is based on contract or consent
- Withdraw consent (Art. 7(3)) — when processing is based on consent
- Complaint (Art. 77) — to a supervisory authority
To exercise your rights, contact us at web@maca.se.
We respond to requests regarding your rights without undue delay and no later than within one month (which may be extended by an additional two months in complex cases pursuant to Art. 12(3)).
Supervisory authority
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, telephone 08-657 61 00, website imy.se — if you believe the processing violates the GDPR.
14. Children
The website is not directed to children under 16 years of age. We do not knowingly collect personal data from children without the consent of a parent or guardian.
15. Changes to the policy
We may update this policy when the website, our tools, or legal requirements change. Always check the date of the latest update.
In the event of material changes affecting your consent, we may ask you to confirm your choices again via the cookie banner.
Manual review
The following plugins are active but lack detailed policy text in maca Polly — review manually:
- AI (ai)
- AI Provider for Google (ai-provider-for-google)
- AI Provider for OpenAI (ai-provider-for-openai)
- Easy Updates Manager (stops-core-theme-and-plugin-updates)
- Fluent Forms (fluentform)
- Fluent Support (fluent-support)
- FluentSMTP (fluent-smtp)
- maca AI Connector (maca-ai-connector)
- maca BackUp (maca-backup)
- Maca Co (maca-co)
- maca Hold (maca-hold)
- maca Hub Connector (maca-hub-connector)
- maca Licensserver (maca-licensserver)
- maca Nav (maca-nav)
- maca Njuvs (maca-njuvs)
- maca Projects (maca-projects)
- maca Sec (maca-sec)
- Maca Tjatt (maca-tjatt)
- maca Translate (maca-translate)
- Plugin Check (PCP) (plugin-check)
- SVG Support (svg-support)
- WP Fastest Cache (wp-fastest-cache)