What we process, why, for how long — and what rights you have.
The German version of this page is legally binding. This translation is provided for information purposes only.
In short: Our plugins store the data of your website visitors on your server — not with us. This statement concerns the website kakapowp.com itself: the purchase, your customer account and the license check. How the product Kakapo Analytics measures is covered separately under point 12.
The controller for data processing on this website is:
Marcze Media UG (haftungsbeschränkt)
Marienstraße 15
12459 Berlin
Germany
Represented by Marcel Czeranski.
Phone: 030 / 233 278 40
Email: hallo@kakapowp.com
We have not appointed a data protection officer; the statutory requirements for this do not apply to us. For any data protection matters you can reach us at the address given above.
We only process personal data where there is a legal basis for it. In this statement we name the purpose, the legal basis and the storage period for each processing operation. The relevant legal bases are:
For storing information on your device and reading it out — that is, for cookies and comparable technologies — the following additionally applies: § 25 TDDDG. Anything that is not strictly necessary on technical grounds is only used after you have given consent.
This website is hosted by ALL-INKL.COM – Neue Medien Münnich GmbH, Hauptstraße 68, 02742 Friedersdorf. The servers are located in Germany. A data processing agreement under Art. 28 GDPR is in place with the provider.
With every request the server automatically writes log files. They contain:
Purpose: trouble-free operation, security of the systems, investigation of misuse.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, functioning service.
Storage period: as a rule 7 days, then automatic deletion. Longer only if a specific security incident makes an analysis necessary.
This data is not merged with other data sources.
On your first visit we show a consent dialog. Only when you agree there do we load services that are not technically necessary — in particular Google Analytics and the Google Tag Manager. If you decline, none of this happens.
We store your decision in a cookie on your device, so that you are not asked again on every visit, and in a proof log on our server. The log contains the time, the categories selected, the version of the banner and a shortened identifier that cannot be traced back — it serves as proof under Art. 7(1) GDPR.
Legal basis: § 25(2) no. 2 TDDDG for the necessary cookie, Art. 6(1)(c) GDPR for the duty to provide proof.
Storage period: Cookie up to 12 months, proof log up to 3 years.
You can change or withdraw your decision at any time — via the “Cookie settings” link in the footer of every page. The withdrawal takes effect for the future; the lawfulness of the processing carried out up to that point remains unaffected.
On this website we use Google Analytics 4, a web analytics service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics uses cookies and similar techniques to analyse your behaviour on this website: which pages you open, how long you stay, which route brought you here, which device and which approximate region (based on the IP address) you use. The IP address is shortened by Google before it is stored.
Purpose: We want to understand which content gets read and where visitors drop off, in order to improve the website.
Legal basis: solely your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. Without approval in the consent dialog, Google Analytics is not loaded.
Storage period: We delete the event data in Google Analytics after 14 months. The cookies used expire after 24 months at the latest.
Google also processes data on servers of Google LLC in the United States. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is therefore covered by an adequacy decision of the European Commission under Art. 45 GDPR. In addition, Google has concluded standard contractual clauses under Art. 46(2)(c) GDPR.
We point out that US authorities may access such data under certain conditions and that the legal protection against this does not meet the European level. If you want to avoid that, refuse consent — the website works fully without it.
More information: policies.google.com/privacy
We use the Google Tag Manager provided by Google Ireland Limited. The Tag Manager is not itself an analysis tool and does not set any cookies on its own; it is an administration tool through which we load and unload other services — in our case Google Analytics.
When the container is loaded, however, your IP address is transmitted to Google, because that is technically necessary for every connection. That is why we only load the Tag Manager after your consent.
Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Recipients: Google Ireland Limited; transfer to the USA as described under point 5.
This website loads fonts from Google's servers (fonts.googleapis.com and fonts.gstatic.com). In doing so, your IP address is transmitted to Google. We use the fonts so that the page is displayed consistently in all browsers.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in a consistent presentation. If the fonts are only retrieved after you have agreed in the consent dialog, the processing is additionally based on Art. 6(1)(a) GDPR.
Full disclosure: Our plugin Kakapo Consent includes a function that serves Google Fonts locally. We are switching this website over to it; until then, this section describes the actual state.
For a purchase we create a customer account. In doing so we process:
| Data | Purpose | Legal basis | Duration |
|---|---|---|---|
| Name, email, password (as a hash only) | Account access, login | Art. 6(1)(b) GDPR | until the account is deleted |
| Billing address, plus company and VAT ID where applicable | Invoicing, tax law | Art. 6(1)(b) and (c) GDPR | 10 years (§ 147 AO, § 257 HGB) |
| Orders, license keys, purchased products | Contract performance, support | Art. 6(1)(b) GDPR | Contract term + 3 years |
| URLs of the websites where a license is active | Enforcing the license scope | Art. 6(1)(b) GDPR | until the website is deregistered |
| Voucher and referral codes | Discounts, affiliate accounting | Art. 6(1)(b) GDPR | Contract term + 3 years |
Providing this data is necessary for concluding the contract. Without it we cannot issue a license or generate an invoice.
We process card payments via Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. For this, a script from Stripe is loaded during the payment process (js.stripe.com).
You enter your payment details — card number, security code, expiry — directly with Stripe. We never see or store this data. From Stripe we only receive the information whether the payment was successful, the amount, the payment method and a transaction ID.
The data transmitted to Stripe are name, email, billing address, amount and order number. Stripe also processes this data for fraud prevention and acts as an independent controller in doing so.
Legal basis: Art. 6(1)(b) GDPR for processing the order, Art. 6(1)(f) GDPR for fraud prevention.
Stripe's privacy policy:stripe.com/de/privacy
If you pay by bank transfer, we receive your name, your IBAN and the payment reference from our bank. This is necessary in order to allocate the payment (Art. 6(1)(b) GDPR) and is subject to the commercial and tax law retention period of 10 years.
For the login to your account we process your username and password. We store the password exclusively as a cryptographic hash value — we do not hold it in plain text.
On request, instead of a password we send a one-time Login link to the email address you have on file. The link is valid for a limited time only and expires after the first use.
Have you Two-factor confirmation is enabled, we additionally check a six-digit one-time code. For this we store a secret from which your device generates the codes.
To fend off login attempts by third parties, we log failed logins with the time and a shortened IP address.
Legal basis: Art. 6(1)(b) GDPR for access, Art. 6(1)(f) GDPR for protection against unauthorised access.
Storage period: Logs of failed logins 30 days.
The installed plugins check with us at regular intervals whether the stored license is valid. In doing so they transmit to our server:
Purpose: Determining whether the license is valid and how many websites already use it.
Legal basis: Art. 6(1)(b) GDPR — without this check the agreed licence scope cannot be enforced.
Storage period: Time of the last check per website, until the website is deregistered or the licence ends.
No content from your website is transmitted in the process — neither posts nor user data, neither statistics nor backups.
This section does not describe this website but the product — it answers the question we are asked most often.
Kakapo Analytics measures without cookies and without cross-device recognition. The evaluation is created on your own server and stays there. No visitor data flows to us. As the operator of your website you are responsible for this processing; we are not involved in it and receive no access.
The same applies to Kakapo Consent (consent logs), Kakapo Backup (backups), Kakapo Performance, Kakapo SEO and Kakapo Security: All data stays in your WordPress installation or in the storage destination you choose.
The only thing transmitted to us is what is described under point 11 — license key, website address, product and version.
For the free trial we process your email address, your name and the address of the test website. After the trial ends we delete the access data if no contract is concluded, at the latest after 90 days.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual measure).
You can subscribe to our newsletter. For that we need your email address; providing a name is voluntary.
We only send after you have confirmed your sign-up via a confirmation link (double opt-in). We store the time of sign-up, the time of confirmation and the IP address used as proof.
We measure whether a message was opened and whether a link in it was clicked, in order to improve the content.
Legal basis: Art. 6(1)(a) GDPR.
Storage period: until you unsubscribe; we keep the proof data for a further 3 years.
You can unsubscribe at any time — via the link at the end of every message or informally by e-mail to us. The withdrawal takes effect for the future.
If you take part in our affiliate program, we additionally process your referral identifier, the orders placed through it and the details needed for payout.
Visitors who arrive via an affiliate link are recognised by a cookie so that the referral can be assigned to the right order.
Legal basis: Art. 6(1)(b) GDPR vis-à-vis partners; for the attribution cookie Art. 6(1)(a) GDPR and § 25(1) TDDDG — it is only set after your consent.
Storage period: Cookie up to 30 days, billing data 10 years.
If you write to us, we process the details you provide in order to handle your enquiry. For technical enquiries we sometimes ask for details about your installation (WordPress and PHP version, active plugins, error messages). What you send us is up to you.
Legal basis: Art. 6(1)(b) GDPR where a contract is involved, otherwise Art. 6(1)(f) GDPR.
Storage period: until the enquiry has been conclusively resolved, at most 3 years; statutory retention periods remain unaffected.
We only share data when it is necessary for the purposes stated. Recipients are:
Data is not sold. Data is not passed on to third parties for advertising purposes.
You have the following rights in relation to us:
Right to object under Art. 21 GDPR: Where we process data on the basis of a legitimate interest, you can object to that processing on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds. If your objection concerns direct marketing, we will stop processing the data for that purpose in any case.
For all of this, an informal message to hallo@kakapowp.com. We reply within one month.
Regardless of this, you can lodge a complaint with a data protection supervisory authority — at your place of residence, your place of work or the place of the alleged infringement. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin
This website transmits all data encrypted via HTTPS. You can tell by the padlock symbol in your browser's address bar and by the address that starts with https:// begins.
Automated decision-making or profiling with legal effect for you under Art. 22 GDPR does not take place.
We adjust this statement when our processing or the legal situation changes. The version published here at the time is authoritative.
As of: August 2026