maca Sec – Privacy

Privacy Policy for maca Sec

Document version: 2026-07-06
Last updated: 2026-07-06
Data controller: maca Development
Website: https://maca.se/
Plugin: maca Sec (WordPress plugin)



1. Overview

This privacy policy describes how maca Sec handles information. There are two main roles:

Role Who What
Website owner You who install the Plugin Data controller for visitors’ and users’ data stored on your server
maca Development Publisher of the Plugin Data controller for certain telemetry to api.maca.se (see section 4)

As the website owner, you are responsible for informing your visitors about how you process personal data, including data that maca Sec collects locally on your website.


2. Data stored locally on your website

When maca Sec is active, the following data may be stored in your WordPress database and file system:

2.1 Security log

  • Visitor IP address and login attempts
  • Event type, severity and message
  • WordPress user ID (if logged in)
  • Timestamp
  • Context data (e.g. country code, block reason)

2.2 IP blocking and whitelist

  • IP addresses or CIDR ranges
  • Label/description
  • Blocking time or permanent status

2.3 Login protection

  • Number of failed login attempts per IP
  • Temporary locks (transients)

2.4 Two-factor authentication (2FA)

  • TOTP secret (encrypted storage in user meta)
  • Recovery codes
  • Activation status per user

2.5 Scanning and file monitoring

  • Security scan results
  • File hashes for monitored files
  • Approved scan findings

2.6 Settings

  • Plugin configuration
  • Any API keys you enter (e.g. WPScan, reCAPTCHA, Turnstile)
  • Email address for security alerts (if you configure it)

Retention period

Logs and blocks are cleared according to the Plugin’s settings and scheduled tasks. Upon uninstalling the Plugin, plugin data is deleted according to uninstall.php, including log tables, IP lists and 2FA metadata.


3. Legal basis for the website owner (GDPR)

As the website owner, you must determine the legal basis for processing visitors’ IP addresses and logs yourself. Common bases are:

  • Legitimate interest — to protect the website against attacks and misuse
  • Legal obligation — if you are required to log certain activity
  • Consent — in some cases, e.g. if you use captcha services that require it

You should document this in your own website privacy policy.


4. Telemetry to maca Development (api.maca.se)

maca Sec sends limited telemetry to https://api.maca.se/v1/sec/events.php on certain events:

Event When
activated The Plugin is activated
deactivated The Plugin is deactivated
uninstalled The Plugin is uninstalled
protection_enabled Security protection is turned on
protection_disabled Security protection is turned off

Data that may be sent

  • Plugin slug and version
  • Website URL (normalized public address)
  • WordPress version
  • PHP version
  • Language/locale
  • On deactivation: optional deactivation reason (if you provide one in the dialog)
  • Source of protection toggle (admin, hub or api)

No passwords, security log contents, visitor IP addresses or personal user data are sent in this telemetry.

Legal basis

maca Development processes the telemetry on the basis of legitimate interest (Art. 6(1)(f) GDPR) to understand usage, improve the product and maintain operations. You may object to this processing by contacting us (see section 9).

Retention period

Telemetry data is stored as long as necessary for statistics and product improvement, normally up to 24 months, unless shorter storage is required or requested.


5. Third-party services

If you enable certain features, the Plugin may send data to external services:

5.1 ip-api.com

  • Purpose: Country-code lookup for IP addresses (country-code blocking)
  • Data: Visitor IP address
  • Note: ip-api.com has restrictions for commercial use; results are cached locally for up to 7 days

5.2 Google reCAPTCHA

  • Purpose: Bot protection at login
  • Data: Interaction data according to Google’s terms
  • Policy: Google Privacy Policy

5.3 Cloudflare Turnstile

  • Purpose: Bot protection at login
  • Data: Interaction data according to Cloudflare’s terms
  • Policy: Cloudflare Privacy Policy

5.4 WPScan API

  • Purpose: CVE scanning of installed plugins and themes
  • Data: Plugin/theme slug and version (via your API token)
  • Policy: WPScan

5.5 maca Hub (optional)

If you use maca Hub, security status, log events and website information may be shared with the maca Hub app according to your configuration. This is governed by maca Hub’s own terms.

5.6 Collective threat intelligence (optional)

If enabled, the Plugin may use locally cached information about IP addresses seen in attacks against multiple maca Sec installations. No automatic transfer of your full log takes place through this feature in the current version.


6. Cookies and browser tracking

maca Sec’s admin interface uses WordPress standard cookies for logged-in administrators.

On the login page (wp-login.php), third-party services (reCAPTCHA, Turnstile) may set their own cookies if you have enabled captcha. Inform visitors about this in your website cookie/privacy policy.


7. Security measures

maca Sec implements technical measures intended to protect stored data, for example:

  • Input sanitization in logs
  • Hash-based file monitoring
  • Ability to delete all data upon uninstall

However, no method is 100% secure. You are responsible for server security, HTTPS, backups and limited administrator access.


8. Your rights (against maca Development)

If maca Development processes personal data about you in the telemetry (e.g. as a representative of a website), under GDPR you have the right to:

  • request access to your data
  • request rectification of incorrect data
  • request erasure (”the right to be forgotten”)
  • request restriction of processing
  • object to processing based on legitimate interest
  • request data portability (where applicable)
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY)

Contact us using the details in section 9. We respond within 30 days unless otherwise stated.


9. Contact

maca Development
Website: https://maca.se/
Email: contact via the website

For data stored locally on your website (visitor logs, IP blocking, etc.), you as the website owner should be the contact point for your visitors.


10. Changes

We may update this policy. The latest version is published on maca.se with the stated date.


Related documents