1. Scope of this Policy
This Policy applies to:
- Visitors and customers of quizmage.vspapg.gr (the “Sales Site”), including checkout and license delivery;
- License holders who connect the QuizMage WordPress plugin to our self-hosted cloud infrastructure; and
- Information we provide to merchants regarding anonymous telemetry processed on their behalf.
Important — roles: When a merchant installs QuizMage on their WooCommerce store, that merchant is generally the data controller for personal data of their shoppers (e.g. email leads). We act as an independent controller for license/account data relating to you as a customer. For anonymous quiz telemetry synced to our cloud under the merchant’s license, we act as a processor on the merchant’s instructions; our obligations as processor are set out in the Data Processing Agreement (DPA), which forms an integral part of the QuizMage Terms of Service / license agreement (Article 28 GDPR). Merchants must provide their own privacy notice to shoppers.
This Policy does not govern third-party websites linked from the Sales Site (including Stripe Checkout). Please review the privacy policies of those providers separately.
2. Definitions
- Personal data
- Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- Telemetry / usage data
- Anonymous technical events generated by the plugin (quiz starts, progress, completions, answer selections, approximate country, browser locale). Telemetry is linked to a random session identifier, not to a named user account.
- License data
- Information necessary to authenticate, bill, and support a commercial QuizMage license (email, subscription tier, API credentials, site binding metadata).
- Processor
- A natural or legal person that processes personal data on behalf of the controller (Article 4(8) GDPR).
- Workspace
- A logical tenant in our cloud environment associated with a license holder and one or more bound WordPress site keys.
3. Data Controller
The controller responsible for processing described in this Policy is:
Vasilis Papagrigoriou (operating the QuizMage product)
Legal status: natural person — not a registered sole proprietorship or company; no VAT identification number (AFM) is issued for this activity.
Country of establishment: Greece
Email: vasilispapg@outlook.com
Pursuant to Articles 13–14 GDPR, a full postal address for written correspondence and verified data-subject requests is provided upon request to the email above. When you purchase a license, Stripe may additionally hold billing address details you provide at checkout.
For data protection enquiries, rights requests, or complaints, contact us at the email above. We respond within the time limits in Section 11.
4. Categories of Data We Process
4.1 Sales Site (quizmage.vspapg.gr)
| Category | Examples | Source |
|---|---|---|
| Contact & account | Email address; optional store URL for workspace labelling | Provided by you at checkout or contact |
| Payment metadata | Transaction status, subscription ID, billing email (held by Stripe) | Stripe Checkout / webhooks |
| Consent records | Acceptance of this Policy at checkout; acknowledgement of the informational cookie/privacy notice (stored locally in your browser only) | Your browser / checkout form |
| Technical logs | Standard server logs (IP, user agent, timestamps) where hosting applies | Automatic |
We do not store full payment card numbers. Card data is processed directly by Stripe.
4.2 Cloud services (licensed plugin)
| Category | Examples | Personal data? |
|---|---|---|
| License & auth | Email, subscription tier, hashed API key, workspace ID, site key / host | Yes |
| Funnel events | Session start, question progress, completion, recommended product ID, embed source | No* |
| Answer analytics | Predefined answer option selected per question (labels from merchant quiz content) | No* |
| Audience hints | ISO country code (CDN header and/or browser timezone); browser locale (e.g. el-GR) |
No* |
| Session identifier | Random UUID in sessionStorage, scoped to the browser tab |
No* |
*Provided telemetry remains anonymous and is not combined by us with shopper email, name, or payment credentials. Answer text reflects merchant-configured multiple-choice options, not free-form input by the visitor.
4.3 Merchant WordPress site (plugin behaviour)
On the merchant’s server, the plugin may store:
- Local analytics — events and answer rows in
wp_quizmage_eventsandwp_quizmage_session_answers, prior to optional cloud sync; - Email leads — where enabled, shopper email and related quiz metadata in
wp_quizmage_leads, subject to merchant consent UI.
Lead data is not transmitted to our cloud unless the merchant explicitly exports or integrates it through separate means. Merchants are responsible for their own GDPR compliance regarding leads.
4.4 Summary — anonymous telemetry, excluded data, and merchant-only data
The table below is a plain-language overview. It does not replace the detail above or the merchant’s own obligations.
| Synced to QuizMage cloud (anonymous) | Not collected in quiz telemetry | Stays on the merchant’s WordPress site |
|---|---|---|
| Quiz funnel events (start, progress, completion), recommended product ID, embed source | Shopper name, surname, email, phone, postal address | Email leads and consent records (wp_quizmage_leads) — if the merchant enabled lead capture |
| Predefined answer choices per question (labels from the merchant’s quiz) | Payment card or bank details; WooCommerce account passwords | Local copies of analytics events and answers until synced and/or pruned by the plugin |
Random session ID (sessionStorage); approximate ISO country; browser locale |
Precise GPS location; IP address stored inside analytics tables; cross-site advertising IDs | All other WooCommerce/store data (orders, customer accounts, etc.) — outside QuizMage |
| Quiz and site identifiers (quiz post ID, site key) — not linked to a named person | Free-text typed by the visitor (only multiple-choice options are logged) | Merchant’s full WordPress database backups and exports under their control |
License customers (you as buyer): Your email, subscription, and payment metadata are personal data processed by us and Stripe — not “anonymous telemetry”. See Sections 4.1 and 7.
5. Purposes and Legal Bases
| Purpose | Data involved | Legal basis (GDPR Art. 6) |
|---|---|---|
| License sale & delivery | Email, payment status, API key, workspace | Art. 6(1)(b) — performance of contract |
| Subscription & billing support | Account email, tier, Stripe customer ID | Art. 6(1)(b); Art. 6(1)(c) where fiscal records required |
| Service security & abuse prevention | API keys, site binding, server logs | Art. 6(1)(f) — legitimate interests |
| Product improvement & analytics | Anonymous telemetry synced from plugin | Art. 6(1)(f) — legitimate interests; balanced against minimal impact (no direct identification) |
| Merchant analytics dashboard (Pro/Agency) | Aggregated & session-level anonymous telemetry | Art. 6(1)(b) — contract (licensed feature) |
| Checkout & lead consent | Consent flags | Art. 6(1)(a) — consent, where applicable |
Where we rely on legitimate interests, you may object under Article 21 GDPR (see Section 11). We do not use telemetry for automated decision-making producing legal or similarly significant effects (Article 22 GDPR).
Product telemetry (Art. 6(1)(f)): Anonymous usage data is collected only when a valid license connects the plugin to our cloud, as described in the license agreement. Merchants retain local analytics on their server, may reset local event data from WordPress admin tools where provided, and stop new cloud uploads by deactivating the license or removing the API connection. Merchants remain responsible for informing their shoppers and for any personal data they collect locally (especially email leads).
7. Recipients and Processors
We share personal data only as necessary with the following categories of recipients:
| Recipient | Role | Processing activity |
|---|---|---|
| Stripe, Inc. | Independent controller / processor | Payment processing, subscription management, fraud prevention |
| OVH SAS (self-hosted, EU) | Processor | Self-hosted database and application servers (EU) for license verification and analytics ingest/query |
| Resend, Inc. | Processor (optional) | Transactional license delivery emails |
| Hosting provider | Processor | Sales Site infrastructure and logs |
We enter into data processing agreements (DPAs) or equivalent contractual safeguards with subprocessors where offered. A list of sub-processors may be available upon request.
Merchants as controllers: Where we process anonymous quiz telemetry on behalf of a merchant, our processor obligations (confidentiality, security, sub-processors, assistance with rights requests, deletion, etc.) are governed by the QuizMage Data Processing Agreement (DPA), incorporated into the Terms of Service / license agreement accepted when obtaining a Pro or Agency license.
We do not sell personal data. We do not share telemetry with advertising networks.
8. International Data Transfers
Some processors (including Stripe) may process data in the United States or other countries outside the European Economic Area (EEA). Our own database and application servers are self-hosted within the EU. Where transfers occur, we rely on appropriate safeguards under Chapter V GDPR, including:
- the EU–US Data Privacy Framework (DPF), where the recipient is certified; and/or
- Standard Contractual Clauses (SCCs) approved by the European Commission (2021/914), supplemented by technical and organisational measures where required; and/or
- other lawful transfer tools recognised under GDPR.
You may request further information on transfer mechanisms and copies of relevant safeguards by contacting us (Section 15).
9. Retention Periods
| Data type | Retention |
|---|---|
| License & account data | Duration of subscription plus up to 24 months thereafter for support, disputes, and legal claims, unless longer retention is required by law |
| Plaintext API key (checkout delivery) | Deleted after successful redeem or within approximately 2 hours, whichever is sooner |
| Anonymous telemetry (cloud) | Retained for product analytics and licensed merchant dashboards; may be aggregated or deleted periodically. Stored in quizmage_analytics_events and quizmage_session_answers |
| Local plugin copies | Controlled by merchant; may be pruned after successful cloud sync per plugin settings |
| Accounting / tax records | As required under applicable Greek and EU law (typically up to 5–10 years for fiscal documents) |
Upon verified request, we will delete or anonymise cloud data linked to your workspace where no overriding legal obligation prevents erasure.
10. Security Measures
We implement appropriate technical and organisational measures pursuant to Article 32 GDPR, including:
- Hashed storage of API keys; one-time plaintext delivery for initial activation;
- TLS encryption in transit for web and API communications;
- Row-level security and access restrictions on cloud analytics tables;
- Input validation on analytics ingest endpoints; site-key binding for licensed installations;
- Principle of least privilege for administrative access to infrastructure.
No method of transmission or storage is completely secure. In the event of a personal data breach affecting your rights, we will notify you and the supervisory authority where required by Articles 33–34 GDPR.
11. Your Rights
If you are located in the EEA or UK, you have the following rights under GDPR, subject to conditions and exceptions in law:
- Right of access (Art. 15) — obtain confirmation and a copy of your personal data;
- Right to rectification (Art. 16) — correct inaccurate data;
- Right to erasure (Art. 17) — request deletion where applicable;
- Right to restriction (Art. 18) — limit processing in certain circumstances;
- Right to data portability (Art. 20) — receive data you provided in a structured format, where processing is based on consent or contract and carried out by automated means;
- Right to object (Art. 21) — object to processing based on legitimate interests;
- Right to withdraw consent (Art. 7(3)) — where processing is consent-based, without affecting prior lawful processing;
- Right to lodge a complaint with a supervisory authority — in Greece: the Hellenic Data Protection Authority (HDPA), www.dpa.gr.
To exercise your rights, email vasilispapg@outlook.com with sufficient information to verify your identity. We respond within one (1) month, extendable by two further months where necessary, as permitted by Article 12(3) GDPR.
Shopper enquiries: If you completed a quiz on a third-party store and wish to access or delete an email you submitted, contact the store owner directly. We cannot identify you from anonymous telemetry alone.
12. Quiz Analytics — Merchants and End Users
12.1 License tiers
- Base (free tier): Anonymous telemetry may sync to our cloud for service operation and product improvement. The analytics dashboard in WordPress remains unavailable.
- Pro / Agency: Full analytics dashboard including funnel metrics, audience breakdown (country/locale), product recommendation share, local email leads, and a Responses module showing aggregated answer distribution and per-session anonymous detail.
12.2 What is not collected in telemetry
Telemetry excludes shopper name, email address, postal address, payment credentials, precise geolocation (GPS), and free-text personal input. Answer analytics reflect merchant-defined quiz options only.
12.3 Roles
For anonymous telemetry synced under a merchant’s license, the merchant is the controller for processing on their storefront; we provide cloud infrastructure and analytics tools as processor under the DPA. For license-holder account data (your purchase), we act as controller as described in this Policy.
12.4 Quick reference
See Section 4.4 for a side-by-side list of what is anonymous in the cloud, what is never collected, and what remains solely on the merchant’s server.
13. Children’s Data
Our services are directed at businesses and adults purchasing software licenses. We do not knowingly collect personal data from children under 16. If you believe a child has provided us personal data, contact us and we will take steps to delete such information.
14. Changes to this Policy
We may amend this Policy to reflect legal, technical, or business changes. Material updates will be indicated by revising the “Effective date” and, where appropriate, version number at the top of this page. Continued use of the Sales Site or licensed cloud features after the effective date constitutes acknowledgment of the updated Policy, to the extent permitted by law.
15. Contact & Governing Law
Questions regarding this Policy or our processing activities:
Vasilis Papagrigoriou (QuizMage)
Natural person, Greece
Email: vasilispapg@outlook.com
Postal address: provided upon verified request for GDPR correspondence.
This Policy is governed by the laws of Greece. Courts of competent jurisdiction in Greece shall have exclusive jurisdiction for disputes arising from this Policy, without prejudice to mandatory consumer protections in your country of residence.
This document is provided for transparency and does not constitute legal advice. Merchants should obtain independent counsel for their own compliance obligations.