Privacy policy
Last updated 27 September 2026. Who we are, what stays on your WordPress, and what is sent to Bearmor or another provider.
Controller: Bearz OÜ, registry code 16076169, VAT EE102299201, Vana-Tartu mnt 79a, Rae vald, Estonia. Email security@bearmor.eu.
Scope
This policy covers bearmor.eu, messages sent through our forms, Bearmor Security registration and licensing, PRO services, and WordPress maintenance or one-off work performed by Bearz OÜ. A client website remains controlled by that website owner; Bearmor acts only within the access and instructions needed to provide the agreed service.
Data stored on your WordPress site
Malware findings, quarantine records, file checksums and changes, login attempts, blocked IPs, selected activity events, vulnerability findings and firewall logs are stored in your WordPress database or uploads area. The activity log is capped at 250 records. The free plugin does not create a Bearmor-hosted copy of your site content.
Registration and license verification
The plugin contacts Bearmor to register the installation and verify the current plan. This can include the site URL, generated site or license identifiers, plugin version, WordPress/PHP environment information required for compatibility, plan and expiry state, and request metadata such as time and source IP. We process this to provide the requested plugin and subscription under the contract, and to prevent abuse through our legitimate interests.
Uptime monitoring
PRO uptime monitoring uses EU relays to request the public site URL. Bearmor stores check results, response state and downtime events needed to show history and send alerts. Raw uptime data is retained for about 30 days before aggregation or deletion.
AI security analysis
PRO AI analysis sends a structured security summary through Bearmor to OpenAI. IP addresses are anonymised before that request, but the summary can contain plugin, theme and WordPress version context, vulnerability names, file paths, usernames, shortened request paths and counts derived from local security events. Do not enable AI analysis if those data categories are not appropriate for your site.
OpenAI processes the request in the United States. Bearmor relies on contractual safeguards, including standard contractual clauses, for this transfer. AI output is advice, not an automated decision about a person.
Other services contacted by the plugin
The plugin can contact WordPress.org for official core checksums, WPVulnerability for known vulnerability records, and ip-api.com for approximate location information associated with login IP addresses. Those providers receive the technical request needed to answer the lookup and operate under their own privacy terms.
Forms, support and service access
When you request a quote or support, we process the name, email, site URL, selected service and message you provide. If you hire us, we may process access credentials, technical logs, backups and site content only as needed to perform maintenance, development or cleanup. Share credentials through the method agreed with us and remove access when the work ends.
Messages and service records are retained while the request or contract is active and afterwards where reasonably needed for support, security, accounting or legal claims. You may request deletion when no overriding contractual or legal duty requires retention.
Billing
Stripe processes subscription and payment details. Bearmor receives billing identifiers, plan, payment status and contact details needed to run the subscription, but does not receive full card numbers. Accounting records are retained for the period required by Estonian law.
Cookies and analytics
Essential WordPress and security cookies may be used for administration, forms and logged-in sessions. If optional analytics or marketing cookies are enabled, the site must present the required consent controls and update this section with the current providers and retention periods.
Legal bases
We process data to perform a contract or answer steps requested before a contract, to meet legal obligations such as accounting, and for legitimate interests including service security, fraud prevention and support. Where the law requires consent, you can withdraw it without affecting processing already carried out.
Security and processors
Access is limited to people and providers needed to operate the service. We use reasonable technical and organisational safeguards, but no internet service can promise absolute security. Current processors include hosting and email providers used for bearmor.eu, Stripe for billing, and OpenAI when PRO AI analysis is enabled.
Your rights
Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability or objection. You may withdraw consent where consent is the basis. Write to security@bearmor.eu. You may also complain to the Estonian Data Protection Inspectorate.
Changes
We update this policy when the plugin, service providers or legal requirements change. The date at the top shows the current version.