HYPERCONTROL Back

[ Privacy policy ]

Privacy Policy

Last updated: 30 April 2026

This policy explains what data HyperControl collects, why, where it is stored, and what rights you have over it. We try to collect the minimum we can ship a product with.

Who is the data controller

HyperControl is a product of Hyperlink. For the purposes of GDPR, Hyperlink is the data controller for personal data submitted by HyperControl account holders. Reach us at [email protected] for any privacy enquiry.

What we collect

From you, the account holder

From the WordPress sites you connect

We do not collect content from the connected WordPress sites: no posts, no comments, no user data, no traffic logs. The agent only reports its own state and version metadata.

Agent secrets

Each agent secret is generated server-side, shown to you exactly once, and stored encrypted at rest with AES-256-GCM. The encryption key (HC_SECRETS_KEY) is held in our hosting provider's secret manager and never written to logs or backups.

Why we collect it

We do not use any of this for marketing, profiling, advertising, or sale to third parties.

Where it lives

These are our subprocessors. Each has its own infrastructure security and is GDPR-compliant.

How long we keep it

Your rights

Under GDPR you can request:

Email [email protected] and we will respond within 30 days.

Cookies

HyperControl sets a small number of strictly-necessary cookies to keep you signed in (set by Supabase Auth) and to verify webhook requests from Stripe. We do not use marketing or analytics cookies.

Data breaches

If we discover a personal-data breach that puts you at risk, we will notify you within 72 hours of becoming aware of it, with the details we have at that point.

Changes

If this policy changes materially we will email all account holders.

Contact

Privacy enquiries: [email protected].