Privacy & data collection
This page explains exactly which data the ReleaseMonitoring agent and WordPress plugin collect from a monitored website or server, why we collect it, and how we handle it. ReleaseMonitoring only monitors and reports: it is read-only, never changes anything on your site, and cannot perform updates.
Who is responsible
ReleaseMonitoring is a service of Provalue B.V. (the "controller"). For questions about this statement or your data you can reach us at info@releasemonitoring.com.
Provalue B.V., [company address], [Chamber of Commerce number].
What we collect from a WordPress site
When you connect a WordPress site, the plugin reads the following once a day and sends it securely to ReleaseMonitoring:
- Website address (URL) and domain name, server hostname, the time of the measurement and the agent/plugin version.
- PHP version and loaded PHP extensions, the database server and version, and the WordPress core version.
- All plugins and themes (active and inactive) with their installed and available versions, and abandoned/withdrawn plugins via public wp.org metadata.
- Security/hardening settings (e.g. debug options, HTTPS, auto-updates, XML-RPC on/off).
- Exposure signals as counts only: number of administrators and users, whether an "admin" user exists, whether user enumeration is possible. No names or e-mail addresses.
- Integrity signals against possible intrusion: PHP files in the uploads folder, suspicious code in core/theme/mu-plugin files (path, signal and line number only), a core-checksum comparison, exposed sensitive files and WP-Cron health.
- A one-way hash of the WordPress admin e-mail address, so the site owner can later sign in to ReleaseMonitoring. Never the address itself.
What we collect from a server
On a Debian or Ubuntu server a lightweight agent reads only version and update information:
- Server hostname, the distribution and version (Debian/Ubuntu), the kernel version and the time of the measurement.
- All installed packages with their version, available updates (security updates flagged separately) and held (on-hold) packages.
- Configured package sources (apt repositories) and whether a reboot is required.
What we deliberately do NOT collect
- No file contents (only signals and line numbers).
- No usernames, passwords or e-mail addresses (only a hash of the admin address).
- No database contents or visitor data.
- No custom login/wp-admin path.
Why we collect it and on what legal basis
We process this data to provide the monitoring service you signed up for: giving you insight into versions, updates and vulnerabilities across your sites and servers. The legal basis is the performance of our agreement with you and our legitimate interest in keeping the monitored environments secure. We do not use the data for advertising and we do not sell it.
How the data is stored and secured
Transmission always happens over an encrypted connection (HTTPS). The data is stored on servers within the European Union, protected by access controls. We keep the data for as long as your account is active and for [retention period] afterwards, after which it is deleted. Where we use sub-processors (for example hosting), they are bound by a processing agreement.
Your rights
Under the GDPR you have the right to access, rectify, delete or export your data, and to object to processing. Send your request to info@releasemonitoring.com; we respond within the statutory period. You may also lodge a complaint with your national data protection authority.
Cookies
The public website uses only functional cookies that are necessary for language choice and login status. The monitoring portal uses a session cookie to keep you signed in. We do not use tracking or advertising cookies.
Changes to this statement
We may update this statement when the service changes. The date above shows the latest version.