Privacy Policy

Last updated: 16/07/2025

Welcome to wpaiworkflowautomation.com (“Website”), operated by Massive Shift (“we”, “us”, or “our”). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Website or purchase WP AI Workflow Automation (“Plugin”).

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Website.

1. Data Controller

Massive Shift is the data controller responsible for your personal data. If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: legal@wpaiworkflowautomation.com
Address: Fred. Roeskestraat 115, 1076 EE Amsterdam

2. Personal Data We Collect

2.1 Information You Provide to Us

Contact Forms: When you contact us via our contact forms powered by Gravity Forms, we collect your name, email address, and any other information you choose to provide. The forms are hosted on our WordPress instance on Amazon Web Services (AWS) servers located in Europe. Note: Information submitted through contact forms is used solely for responding to your inquiry and is not used for marketing purposes.

Newsletter Subscription: If you subscribe to our newsletter through subscription forms on our Website, we collect your email address and any preferences you specify.

2.2 Information Collected During Purchase

Purchases via Paddle: When you purchase our Plugin, the transaction is processed by Paddle.com Market Limited (“Paddle”), our Merchant of Record and payment processor. Paddle acts as the vendor for all purchases and handles:

  • Payment processing (credit card, PayPal, and other payment methods)
  • Sales tax/VAT calculation and remittance
  • Billing information collection
  • Transaction security and fraud prevention
  • Order fulfillment and license key delivery

We receive the following information from Paddle after a successful purchase:

  • Your email address
  • Your name (if provided)
  • Country/region of purchase
  • Transaction ID
  • Product purchased and license information
  • Purchase date

Important: Paddle collects and processes additional information including payment details, billing address, and IP address. We do not have access to your full payment information (such as credit card numbers). Please refer to Paddle’s Privacy Policy and Paddle’s Buyer Terms to understand how they handle your personal data.

2.3 Information We Collect Automatically

Usage Data: We collect information about your interactions with our Website, such as pages visited, links clicked, and time spent on the site.

Cookies and Similar Technologies: We use cookies and similar tracking technologies necessary for the functionality of certain features of our Plugin and Website.

  • Essential Cookies: Required for the operation of our Website and Plugin functionalities.
  • Analytics Cookies: With your consent, we may use analytics tools to understand how users interact with our Website.

3. How We Use Your Personal Data

We use your personal data for the following purposes:

To Communicate with You:

  • Responding to inquiries sent through our contact forms
  • Providing customer support for Plugin-related issues
  • Sending transactional emails related to your purchase

To Process Transactions:

  • Facilitating the purchase of our Plugin via Paddle
  • Managing license activations and validations
  • Providing purchase receipts and license information

For Marketing and Promotional Purposes:

  • With your explicit consent, sending newsletters about Plugin updates, features, and promotions via Brevo
  • Informing you about new products or services (only with your consent)
  • Sending educational content related to WordPress and workflow automation (only with your consent)

To Improve Our Services:

  • Analyzing usage data to enhance user experience
  • Optimizing our Website and Plugin functionality
  • Conducting research to improve our products

Legal Obligations:

  • Complying with legal requirements
  • Enforcing our Terms and Conditions
  • Protecting our rights and the rights of our users

4. Email Marketing and Communications

4.1 Email Service Provider

We use Brevo (formerly Sendinblue) as our email service provider for sending marketing communications and transactional emails. When you subscribe to our newsletter or purchase our Plugin, your email address and name are securely transmitted to Brevo’s servers for email delivery purposes.

4.2 Sources of Email Addresses for Marketing

We collect email addresses for marketing purposes from:

  • Newsletter subscription forms on our Website
  • During the purchase process (with your separate consent for marketing)
  • Webinar or event registrations
  • Free resource downloads (with your consent)

Important: We do not use email addresses collected through support contact forms for marketing purposes unless you explicitly opt-in separately.

4.3 Marketing Consent and Preferences

  • Marketing emails are only sent to users who have explicitly opted in
  • You can unsubscribe from marketing communications at any time using the unsubscribe link in every marketing email
  • Unsubscribing from marketing emails does not affect transactional emails (such as purchase confirmations or critical Plugin updates)
  • You can update your email preferences by contacting us at legal@wpaiworkflowautomation.com

5. Legal Basis for Processing

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

Consent: For sending marketing communications and using non-essential cookies, where you have given explicit consent.

Performance of a Contract: Processing necessary to:

  • Complete your Plugin purchase
  • Provide customer support
  • Deliver Plugin updates and license management

Legitimate Interests: For:

  • Improving our services and Plugin functionality
  • Ensuring the security of our Website
  • Preventing fraud and abuse
  • Basic analytics to understand Website performance

Legal Obligations: Complying with applicable laws and regulations, including tax and accounting requirements.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.

Contact Form Information: Retained for up to 2 years, unless a longer retention period is required for legal reasons or ongoing support issues.

Marketing Communications: Until you unsubscribe or withdraw your consent, or if no engagement for 3 years.

Transaction Records: Retained for 7 years as required by tax and accounting laws.

Plugin License Information: Retained for the duration of your license validity plus 2 years for support purposes.

7. Disclosure of Your Personal Data

We may share your personal data with:

Service Providers:

  • Paddle: Payment processing and order fulfillment
  • Brevo: Email delivery and marketing automation
  • AWS: Website and data hosting
  • Support tools: Customer support ticket management

Legal Obligations: Authorities if required by law, court order, or to protect our rights.

Business Transfers: In the event of a merger, acquisition, or sale of assets, with appropriate notices.

We ensure that all third parties respect the security of your personal data and treat it in accordance with the law. We have data processing agreements in place with all service providers who process personal data on our behalf.

8. International Data Transfers

While our servers are located in Europe, some of our service providers may process your data outside the European Economic Area (EEA):

Paddle: May process data internationally. They use appropriate safeguards including Standard Contractual Clauses. See Paddle’s Privacy Policy for details.

Brevo: Primarily processes data within the EU but may transfer data internationally with appropriate safeguards. See Brevo’s Privacy Policy for details.

We ensure that appropriate safeguards are in place for any international transfers, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions
  • Binding Corporate Rules

9. Your Rights

Under the GDPR, you have the following rights:

Right of Access: Request a copy of your personal data we hold.

Right to Rectification: Correct inaccurate or incomplete data.

Right to Erasure: Request deletion of your personal data (subject to legal obligations).

Right to Restrict Processing: Request limitation of processing under certain circumstances.

Right to Data Portability: Receive your data in a structured, commonly used format.

Right to Object: Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise your rights, please contact us at legal@wpaiworkflowautomation.com. We will respond to your request within one month. You also have the right to lodge a complaint with your local data protection authority.

10. Cookies and Tracking Technologies

10.1 Types of Cookies We Use

Essential Cookies: Necessary for the Website and Plugin to function properly. These cannot be disabled.

Functional Cookies: Enhance the performance and functionality of our Website and Plugin but are non-essential.

Analytics Cookies: With your consent, used to understand how users interact with our Website.

10.2 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to:

  • View what cookies are stored
  • Delete cookies individually or entirely
  • Block third-party cookies
  • Block all cookies
  • Receive a warning before a cookie is stored

However, disabling certain cookies may affect the functionality of the Website and Plugin.

11. Security Measures

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

Technical Measures:

  • SSL/TLS encryption for all data transmission
  • Encrypted storage of sensitive data
  • Regular security updates and patches
  • Firewall protection
  • Access logging and monitoring

Organizational Measures:

  • Restricted access to personal data (need-to-know basis)
  • Confidentiality agreements with all personnel
  • Regular security training
  • Incident response procedures
  • Regular security assessments

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.

12. Third-Party Links

Our Website may contain links to third-party websites or services. We are not responsible for the privacy practices of such sites. We encourage you to read the privacy policies of every site you visit. This includes but is not limited to:

  • Paddle (payment processing)
  • WordPress.org
  • Documentation and tutorial links
  • Social media platforms

13. Children’s Privacy

Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at legal@wpaiworkflowautomation.com to have it removed.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. Any changes will be posted on this page with an updated “Last updated” date.

Notification of Changes:

  • Material changes will be notified via email to users who have provided their email address
  • We encourage you to review this Privacy Policy periodically
  • Your continued use of our Website and Plugin after changes constitutes acceptance of the updated Privacy Policy

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: legal@wpaiworkflowautomation.com
Website: wpaiworkflowautomation.com

For data protection specific inquiries, you may also contact our Data Protection Officer at the same email address.


This Privacy Policy is effective as of the date stated at the top of this page.