Privacy Policy

Privacy Policy — maca.se

Version: 3.0

Last updated: 2026-08-01

Applies to: maca.se (https://maca.se/)

1. Introduction

We value your privacy. This privacy policy describes which personal data we process, why, on what legal basis, how long the data is stored, who may access it, and what rights you have.

This policy describes how maca.se («we», «us») processes personal data when you visit or use our website, in accordance with:

  • The European Parliament and Council Regulation (EU) 2016/679 (GDPR)
  • The Swedish Data Protection Act (2018:218) supplementing the GDPR in Sweden
  • Act (2003:389) on Electronic Communication (LEK) to the extent that it regulates cookies and similar technology (see also our cookie policy)

2. Data Controller

| | |

|—|—|

| Organization | maca.se |

| Website | https://maca.se/ |

| Email (privacy) | web@maca.se |

The data controller determines the purposes and means of the processing. We may engage data processors (e.g. hosting, email and analytics tools) that process data according to our instructions and written agreements.

3. Scope and target audience

The policy applies to visitors, customers and others who interact with the website. It does not cover processing that takes place entirely offline or in other systems unless otherwise stated.

4. What data do we process?

We process only personal data that is adequate, relevant and necessary for the purposes stated below. Processing identified on the website based on installed plugins and integrated services is reported by activity.

Web server and operational logs

  • Data: IP address, time, URL, browser, referrer
  • Purpose: Operations, troubleshooting and security
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Retention period: Web hosting — normally 30–90 days in access logs
  • Recipients: Web host/provider
  • Transfer outside the EU/EEA: May occur depending on where the server is located

Comments

  • Data: Name, email, IP address, comment text
  • Purpose: Publish and moderate comments
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Retention period: As long as the comment remains on the website
  • Recipients: Web host

Fluent Support

  • Source: Fluent Support
  • Data: Name, email, case title, messages, attachments, status, any customer ID and technical metadata (IP, browser)
  • Purpose: Handle customer support cases and store conversations in the support system
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Retention period: As long as the case is active and thereafter according to plugin settings (normally up to 24 months)
  • Recipients: The website’s support staff
  • Transfer outside the EU/EEA: Stored in the WordPress database on your web host; may occur in connection with email integrations
  • Vendor privacy policy: https://fluentsupport.com/privacy-policy/

maca DownList

  • Source: maca DownList
  • Data: Email and any name in the email gate, download log (file, time, IP address may be logged)
  • Purpose: Provide file downloads and track downloads according to the site owner’s settings
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Retention period: Download log according to plugin settings; email gate session temporarily
  • Recipients: Website staff
  • Transfer outside the EU/EEA: Normally processed within the EU/EEA via your web host

Google Site Kit

  • Source: Site Kit by Google
  • Data: Web statistics and search data depending on activated Google services (Analytics, Search Console, etc.)
  • Purpose: Statistics, keyword analysis and website optimization
  • Legal basis: Consent (GDPR Art. 6(1)(a))
  • Retention period: According to the respective Google service — see Google’s documentation
  • Recipients: Google LLC
  • Transfer outside the EU/EEA: May involve transfer to the USA depending on the service
  • Vendor privacy policy: https://policies.google.com/privacy

WPForms

  • Source: WPForms Lite
  • Data: Form content according to configured fields
  • Purpose: Collect inquiries, bookings or registrations
  • Legal basis: Legitimate interest (GDPR Art. 6(1)(f))
  • Retention period: According to plugin settings and internal deletion routine
  • Recipients: Website staff
  • Transfer outside the EU/EEA: May occur if WPForms cloud services are used
  • Vendor privacy policy: https://wpforms.com/privacy-policy/

Forms on the website

  • Fluent Support — case portal — fields: name, email, subject, message, attachments, case history
  • maca DownList email gate — fields: email, any name
  • WPForms — fields: fields according to the configured form

Mandatory fields in forms are required so that we can handle your inquiry or order.

Support pages and case management

The website has support pages or a case portal where you can submit inquiries. Information you provide there (e.g. name, email, messages and attachments) is stored so that we can handle and follow up your case.

Case data is normally stored in the website’s database (WordPress) or in a connected support tool until the case is closed and in accordance with our internal deletion routine.

Identified support pages:

Support tool:

  • Fluent Support (Fluent Support)

You may request access to, rectification of, or deletion of data in your support cases by contacting us.## 5. Where do the data come from?

We normally collect data directly from you (forms, orders, account, email) and automatically when you visit (technical logs, cookies according to your consent). Data may also come from payment or delivery partners when you shop with us.

6. Legal basis for processing

Each processing activity must have a valid legal basis under GDPR Article 6. Below we describe the bases we use on the website:

Legal bases

  • Legitimate interest (Art. 6(1)(f)) — for security, operations, troubleshooting, spam protection and answering general inquiries, following a balancing test where your interests do not outweigh ours.
  • Consent (Art. 6(1)(a)) — for optional cookies, newsletters and marketing when consent is required. You can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

7. Retention period

We store personal data only as long as necessary for the purpose or as required by law. After that, the data are deleted or anonymized securely.

Specific retention periods are stated for each processing activity in section 4. When data are no longer needed, they are deleted or anonymized, unless statutory archiving is required (e.g. the Swedish Accounting Act).

8. Recipients and data processors

Data may be shared with providers such as hosting, CDN, email, payment, analytics and support tools. These may only process data under contract (data processing agreement) and our instructions. A list of processing is shown in the activities above.

9. Cookies and similar technology

We use cookies, pixels and similar technology. Necessary cookies may be stored without consent. Non-essential cookies (e.g. statistics and marketing) are enabled only after your consent via our cookie banner.

See our cookie policy for the full list, categories and consent management.

10. Transfer to third countries

Some providers may process personal data outside the EU/EEA, especially in the USA. This only takes place when there is a valid transfer mechanism.

We primarily use the European Commission’s Standard Contractual Clauses (SCCs), supplementary technical and organizational measures, as well as providers’ binding corporate rules or adequacy decisions where applicable.

11. Security

We take appropriate technical and organizational measures under GDPR Art. 32 to protect personal data against unauthorized access, loss, destruction and unlawful disclosure.

We continuously work with access control, updates, backups and incident handling to a reasonable extent for the size and risk profile of the business.

12. Automated decision-making and profiling

We generally do not use automated decision-making or profiling that has legal effects or similarly significantly affects you. If this changes, the policy will be updated.

AI systems and transparency

The website uses AI-based tools (e.g. chatbot or content generation). Data you send to these functions may be processed by an external AI provider. We provide information about the purpose, provider and your rights in the table above. Under the EU AI Act, certain AI systems must be transparent — if a system is classified as high-risk, we follow the requirements for information and human oversight.

13. Your rights

You have the following rights under GDPR when we process your personal data:

Your rights

  • Right of access (Art. 15) — obtain confirmation and a copy of your data
  • Rectification (Art. 16) — correct inaccurate or incomplete data
  • Erasure (Art. 17) — request deletion where there is a legal basis
  • Restriction (Art. 18) — request restricted processing in certain situations
  • Objection (Art. 21) — object to processing based on legitimate interest or direct marketing
  • Data portability (Art. 20) — receive data in a structured, machine-readable format when processing is based on contract or consent
  • Withdraw consent (Art. 7(3)) — when processing is based on consent
  • Complaint (Art. 77) — to a supervisory authority

To exercise your rights, contact us at web@maca.se.

We respond to requests regarding your rights without undue delay and at the latest within one month (may be extended by another two months in complex cases under Art. 12(3)).

Supervisory authority

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, telephone 08-657 61 00, website imy.se — if you believe the processing violates the GDPR.

14. Children

The website is not intended for children under 16 years of age. We do not knowingly collect personal data from children without the consent of a parent or guardian.

15. Changes to the policy

We may update this policy when the website, our tools or legal requirements change. Always check the date of the latest update.

In the event of significant changes affecting your consent, we may ask you to confirm your choices again via the cookie banner.

Manual review

The following plugins are active but lack detailed policy text in maca Polly — review manually:

  • AI (ai)
  • AI Provider for Google (ai-provider-for-google)
  • AI Provider for OpenAI (ai-provider-for-openai)
  • Easy Updates Manager (stops-core-theme-and-plugin-updates)
  • Fluent Forms (fluentform)
  • maca AI Connector (maca-ai-connector)
  • maca BackUp (maca-backup-pro)
  • Maca Co (maca-co)
  • maca FAQList (maca-faqlist)
  • maca Hold (maca-hold)
  • maca Hub Connector (maca-hub-connector)
  • maca Licensserver (maca-licensserver)
  • maca Nav (maca-nav)
  • maca Njuvs (maca-njuvs)
  • maca Sec (maca-sec)
  • Maca Tjatt (maca-tjatt)
  • maca Translate (maca-translate)
  • Plugin Check (PCP) (plugin-check)
  • Post SMTP (post-smtp)
  • SVG Support (svg-support)
  • WP Fastest Cache (wp-fastest-cache)

Related documents