Derisory Ventures B.V. (trading as "WP Clinic")
Version: 2026-02 / v1.0 — Effective date: 15 February 2026
Introduction
This Privacy Policy explains how Derisory Ventures B.V., trading as WP Clinic, collects and uses personal data when you visit our website, contact us, or use our services including domain registrations, WordPress hosting, theme development, and email management.
This policy is written to meet the requirements of the EU/EEA GDPR. Contact: info@wp-clinic.com.
1. Roles under GDPR (Controller vs Processor)
Depending on the context, WP Clinic may act as Controller (we decide why and how personal data is processed, e.g. for our website, invoicing, and sales) or Processor (we process personal data on your behalf, e.g. when we host your WordPress site or manage DNS).
If we act as your processor, we can provide a Data Processing Agreement (DPA) on request.
2. Personal data we collect
When you visit our website we may process technical data such as IP address, device/browser type, operating system, referral pages, pages visited, and timestamps.
When you contact us or request a quote we may process your name, company name, email address, phone number, message contents, and internal notes.
When you purchase or use our services we may process account and billing details, domain registration details, support communications, and service configuration data.
If you use our Hosting or Email services, you may upload personal data in website content, form submissions, and customer databases. This data is typically controlled by you.
3. Purposes and legal bases
- To provide and manage services — performance of a contract (Art. 6(1)(b)).
- To register/renew/transfer domains and manage DNS — performance of a contract and legal obligation where registries require certain data.
- Customer support and incident handling — performance of a contract and/or legitimate interest.
- Billing, accounting, and collections — legal obligation and performance of a contract.
- Security and abuse prevention — legitimate interest and/or performance of a contract.
- Marketing and relationship management — legitimate interest or consent where required.
4. Cookies and similar technologies
We may use strictly necessary cookies for core website functionality and security, preference cookies to remember settings, and analytics cookies to measure website performance when enabled and permitted under your cookie choices.
Your choices can typically be changed at any time through the cookie banner or via your browser settings.
5. Sharing personal data (recipients)
We do not sell personal data. We may share personal data with service providers such as hosting infrastructure providers, domain registrars, DNS providers, email platform providers, monitoring tools, backup providers, payment providers, and customer support tools.
We may disclose personal data if required by law, court order, or to protect rights, safety, and security.
6. International data transfers
Some suppliers may process data outside the EEA. When personal data is transferred outside the EEA, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses (SCCs), or other lawful transfer mechanisms under GDPR.
7. Data retention
We keep personal data only as long as necessary for the purposes described above. Billing and tax records are retained according to legal requirements. Support communications, domain records, and security logs are retained for periods appropriate to their purpose.
8. Security
We take reasonable technical and organizational measures to protect personal data, which may include access controls, encryption in transit, monitoring, patching, and backups. No method of transmission or storage is 100% secure.
9. Your rights (EEA/UK GDPR)
To exercise rights, email info@wp-clinic.com. We may ask you to verify your identity. You can also lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
- Access your personal data
- Rectify inaccurate data
- Erase data in certain cases
- Restrict processing in certain cases
- Data portability in certain cases
- Object to processing based on legitimate interests
- Withdraw consent where processing is based on consent
10. Domain registrations and WHOIS
Domain registries/registrars often require registrant and contact details. Depending on the TLD and registry rules, certain registrant/contact data may be published in WHOIS or made available to parties with legitimate access.
11. Email services (including Google)
If we set up or manage email via Gmail/Google services, Google may process personal data as an independent controller or processor depending on the specific service. Your use is subject to Google's applicable terms and privacy documentation.
12. Third-party websites
Our website or services may link to third-party sites. We are not responsible for their privacy practices. Please review their policies separately.
13. Changes to this Privacy Policy
We may update this Privacy Policy. The newest version will be published with an updated effective date. If changes are material, we will take reasonable steps to notify affected customers.
14. Contact
For privacy questions, requests, or complaints: info@wp-clinic.com.