Privacy Policy for maca Sec
Document version: 2026-07-06
Last updated: 2026-07-06
Data controller: maca Development
Website: https://maca.se/
Plugin: maca Sec (WordPress plugin)
1. Overview
This privacy policy describes how maca Sec handles information. There are two main roles:
| Role | Who | What |
|---|---|---|
| Website owner | You who install the Plugin | Data controller for visitors’ and users’ data stored on your server |
| maca Development | Publisher of the Plugin | Data controller for certain telemetry to api.maca.se (see section 4) |
As the website owner, you are responsible for informing your visitors about how you process personal data, including data that maca Sec collects locally on your website.
2. Data stored locally on your website
When maca Sec is active, the following data may be stored in your WordPress database and file system:
2.1 Security log
- Visitor IP address and login attempts
- Event type, severity and message
- WordPress user ID (if logged in)
- Timestamp
- Context data (e.g. country code, block reason)
2.2 IP blocking and whitelist
- IP addresses or CIDR ranges
- Label/description
- Blocking time or permanent status
2.3 Login protection
- Number of failed login attempts per IP
- Temporary locks (transients)
2.4 Two-factor authentication (2FA)
- TOTP secret (encrypted storage in user meta)
- Recovery codes
- Activation status per user
2.5 Scanning and file monitoring
- Security scan results
- File hashes for monitored files
- Approved scan findings
2.6 Settings
- Plugin configuration
- Any API keys you enter (e.g. WPScan, reCAPTCHA, Turnstile)
- Email address for security alerts (if you configure it)
Retention period
Logs and blocks are cleared according to the Plugin’s settings and scheduled tasks. Upon uninstalling the Plugin, plugin data is deleted according to uninstall.php, including log tables, IP lists and 2FA metadata.
3. Legal basis for the website owner (GDPR)
As the website owner, you must determine the legal basis for processing visitors’ IP addresses and logs yourself. Common bases are:
- Legitimate interest — to protect the website against attacks and misuse
- Legal obligation — if you are required to log certain activity
- Consent — in some cases, e.g. if you use captcha services that require it
You should document this in your own website privacy policy.
4. Telemetry to maca Development (api.maca.se)
maca Sec sends limited telemetry to https://api.maca.se/v1/sec/events.php on certain events:
| Event | When |
|---|---|
activated |
The Plugin is activated |
deactivated |
The Plugin is deactivated |
uninstalled |
The Plugin is uninstalled |
protection_enabled |
Security protection is turned on |
protection_disabled |
Security protection is turned off |
Data that may be sent
- Plugin slug and version
- Website URL (normalized public address)
- WordPress version
- PHP version
- Language/locale
- On deactivation: optional deactivation reason (if you provide one in the dialog)
- Source of protection toggle (
admin,huborapi)
No passwords, security log contents, visitor IP addresses or personal user data are sent in this telemetry.
Legal basis
maca Development processes the telemetry on the basis of legitimate interest (Art. 6(1)(f) GDPR) to understand usage, improve the product and maintain operations. You may object to this processing by contacting us (see section 9).
Retention period
Telemetry data is stored as long as necessary for statistics and product improvement, normally up to 24 months, unless shorter storage is required or requested.
5. Third-party services
If you enable certain features, the Plugin may send data to external services:
5.1 ip-api.com
- Purpose: Country-code lookup for IP addresses (country-code blocking)
- Data: Visitor IP address
- Note: ip-api.com has restrictions for commercial use; results are cached locally for up to 7 days
5.2 Google reCAPTCHA
- Purpose: Bot protection at login
- Data: Interaction data according to Google’s terms
- Policy: Google Privacy Policy
5.3 Cloudflare Turnstile
- Purpose: Bot protection at login
- Data: Interaction data according to Cloudflare’s terms
- Policy: Cloudflare Privacy Policy
5.4 WPScan API
- Purpose: CVE scanning of installed plugins and themes
- Data: Plugin/theme slug and version (via your API token)
- Policy: WPScan
5.5 maca Hub (optional)
If you use maca Hub, security status, log events and website information may be shared with the maca Hub app according to your configuration. This is governed by maca Hub’s own terms.
5.6 Collective threat intelligence (optional)
If enabled, the Plugin may use locally cached information about IP addresses seen in attacks against multiple maca Sec installations. No automatic transfer of your full log takes place through this feature in the current version.
6. Cookies and browser tracking
maca Sec’s admin interface uses WordPress standard cookies for logged-in administrators.
On the login page (wp-login.php), third-party services (reCAPTCHA, Turnstile) may set their own cookies if you have enabled captcha. Inform visitors about this in your website cookie/privacy policy.
7. Security measures
maca Sec implements technical measures intended to protect stored data, for example:
- Input sanitization in logs
- Hash-based file monitoring
- Ability to delete all data upon uninstall
However, no method is 100% secure. You are responsible for server security, HTTPS, backups and limited administrator access.
8. Your rights (against maca Development)
If maca Development processes personal data about you in the telemetry (e.g. as a representative of a website), under GDPR you have the right to:
- request access to your data
- request rectification of incorrect data
- request erasure (”the right to be forgotten”)
- request restriction of processing
- object to processing based on legitimate interest
- request data portability (where applicable)
- lodge a complaint with the Swedish Authority for Privacy Protection (IMY)
Contact us using the details in section 9. We respond within 30 days unless otherwise stated.
9. Contact
maca Development
Website: https://maca.se/
Email: contact via the website
For data stored locally on your website (visitor logs, IP blocking, etc.), you as the website owner should be the contact point for your visitors.
10. Changes
We may update this policy. The latest version is published on maca.se with the stated date.
Related documents