This policy explains how SMMKit ("SMMKit", "we") processes personal data collected through smmkit.app, the associated service, and the Panelora — SMM Reseller for WooCommerce plugin. Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 of 5 December (LOPDGDD).
1. Data controller
- Controller: ORIOL NADAL SERRA
- Spanish Tax ID (NIF): 39403253K
- Address: Quarter Ponent 11, 08460 Santa Maria de Palautordera, Barcelona, Spain
- Privacy contact: [email protected]
2. What data we process and why
2.1 Browsing the website
- Data: IP address, browser identifiers, pages visited, date and time.
- Purpose: security, abuse prevention, aggregated usage metrics.
- Legal basis: legitimate interest (Art. 6.1.f GDPR) in keeping the site operational and secure.
- Retention: up to 12 months in server logs; thereafter deleted or anonymised.
2.2 Account registration and dashboard access
- Data: name, email, hashed password, WordPress installation identifier (site URL, non-reversible fingerprint).
- Purpose: account creation and management, authentication, support and operational communication.
- Legal basis: performance of a contract (Art. 6.1.b GDPR).
- Retention: while the account is active, plus the legal limitation periods after closure (up to 6 years for tax obligations).
2.3 Profile validation service (smmkit.app API)
When a Panelora-equipped site invokes the validation service, we receive:
- The user's licence token.
- The public profile/post URL to validate (Instagram, TikTok, YouTube, Facebook, X, Threads).
- Or the public username that the merchant's end customer enters in the form.
We do not receive personal data about the merchant's end customer (no name, email, address, customer IP or payment data is sent). Only the public URL/username that the end customer has voluntarily entered for validation is processed.
- Purpose: deliver the contracted validation service and meter usage for billing.
- Legal basis: performance of a contract (Art. 6.1.b GDPR) with the licence holder.
- Retention: validation logs kept for 90 days for support and abuse detection. Billing records kept for up to 6 years (tax obligation).
2.4 Payments
- Data: card data does not reach our servers. The payment gateway processes it directly and returns a transaction ID and the last 4 digits for invoice display.
- Purpose: processing payments.
- Legal basis: performance of a contract (Art. 6.1.b GDPR) and legal obligation (Art. 6.1.c GDPR).
- Retention: up to 6 years to comply with tax law.
2.5 Support communications
- Data: what the user provides via email (name, message content, attachments).
- Purpose: answer the enquiry.
- Legal basis: consent (Art. 6.1.a GDPR) or contract performance (Art. 6.1.b) when the enquiry stems from a contracted service.
- Retention: 3 years from the last communication.
3. Recipients and processors
We share data only with the providers strictly necessary to operate the service. All of them sign Data Processing Agreements (DPA) and, when located outside the European Economic Area, ensure GDPR compliance through Standard Contractual Clauses (SCC) approved by the European Commission or equivalent.
| Provider | Function | Location |
|---|---|---|
| Stripe / MONEI | Payment processing | EU / USA (with SCC) |
| Vercel / hosting provider | Web and API hosting | EU / USA (with SCC) |
| Transactional email provider | Operational email delivery | EU / USA (with SCC) |
| Upstream social scraping provider | Public profile/post metadata resolution | EU / USA (with SCC) |
We do not sell or transfer personal data to third parties for their own commercial use.
4. International transfers
Some providers (notably payments and scraping) may be located in the USA. Such transfers rely on a mechanism set out in Chapter V GDPR: adequacy decision (Data Privacy Framework when applicable), EU Standard Contractual Clauses, or explicit user consent.
5. Cookies
The site uses strictly necessary cookies for session and security. No advertising or profiling cookies are used. If consent-required cookies are added in the future, a banner compliant with the AEPD cookie guide will be displayed and this policy updated.
6. Your rights
Under Articles 15-22 GDPR, you may at any time exercise the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection, the right not to be subject to automated decisions with legal effects (we do not perform such profiling), and withdrawal of consent without retroactive effect.
To exercise these rights, email us at [email protected] with a copy of an ID document. We will respond within one month (extendable to two in complex cases, with prior notice).
7. Lodging a complaint
If you believe the processing of your data does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan, 6, 28001 Madrid, Spain.
8. Security
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss or alteration: encryption in transit (TLS 1.2+), passwords stored with bcrypt or equivalent hashing, role-based access control, and audit logs for sensitive operations.
9. Minors
SMMKit is not directed to children under 14. We do not knowingly collect data from children below that age. If accidental processing is detected, the data will be deleted.
10. Changes
This policy may be updated to reflect legal or technical changes. The latest update date appears at the top. If the changes are material we will notify registered users by email with reasonable advance notice.