# GDPR & Personal Data Information

## Overview

SDP EU Withdrawal for WooCommerce stores personal data strictly related to the withdrawal request workflow and the administrative review process.

The plugin does not send data to external services and stores all information locally within the WordPress/WooCommerce database.

This document explains:

* what personal data may be stored.
* when the data is stored.
* how the data is used.
* how administrators can export or remove stored personal data.

The plugin provides technical tools to help merchants manage withdrawal requests, but each merchant remains responsible for configuring and operating their store in accordance with applicable privacy and consumer protection regulations.

---

# Data Stored by the Plugin

## Customer Information

When a withdrawal request is submitted, the plugin may store:

* Customer name.
* Customer email address.
* Customer company name (if provided).
* Customer comments submitted through the withdrawal request form.

This information is used exclusively for withdrawal request management and communication purposes.

---

## Technical & Forensic Information

The plugin may store technical information associated with the withdrawal request, including:

* IP address used when submitting the request.
* Browser user agent string.
* Submission timestamps.
* Request activity logs.
* Notification delivery logs.

This information is intended to support administrative traceability and dispute management.

---

## WooCommerce Order Information

The plugin stores references to the related WooCommerce order, including:

* WooCommerce order ID.
* WooCommerce order number.
* Requested products and quantities.
* Withdrawal request status.
* Administrative review actions.

This information is required to associate withdrawal requests with WooCommerce purchases.

---

## Digital Product Eligibility Information

If the store sells downloadable products and digital withdrawal rules are enabled, the plugin may store or retrieve additional information related to withdrawal eligibility.

This may include:

* Whether the customer accepted a digital withdrawal waiver.
* The waiver text shown to the customer at checkout.
* Download activity associated with downloadable products.

The plugin retrieves download information from WooCommerce download logs at the moment the withdrawal request is created.

### Pro Version

SDP EU Withdrawal Pro additionally stores download-related information inside the request log after a withdrawal request has been created, allowing administrators to review download activity directly from the request review screen.

---

# Personal Data Export & Erasure

The plugin integrates with the native WordPress privacy tools available under:

* Tools → Export Personal Data.
* Tools → Erase Personal Data.

Store administrators can use these tools to:

* export withdrawal-related personal data associated with a customer email address.
* erase personal data stored by the plugin.

When personal data is erased, the plugin replaces personal information with anonymized placeholders where necessary to preserve request integrity and administrative traceability.

---

# Automatic Log Cleanup (Pro Version)

SDP EU Withdrawal Pro includes an optional automatic cleanup feature for request logs and stored personal data.

Administrators can configure:

* whether automatic cleanup is enabled.
* how long logs and personal data should be retained.

Cleanup tasks are executed using the native WordPress scheduled task system (WP-Cron).

Because WP-Cron depends on site traffic and WordPress execution, scheduled cleanup operations may not run exactly at the configured time on low-traffic websites or misconfigured hosting environments.

Administrators are responsible for periodically reviewing their privacy and retention settings.

---

# Data Storage Location

All plugin data is stored locally within the WordPress database.

The plugin does not transmit withdrawal request data to external APIs, third-party analytics platforms or remote servers.

---

# Responsibility Notice

This plugin provides technical tools intended to support withdrawal request workflows and personal data management.

However, legal compliance requirements may vary depending on jurisdiction, business model and the specific products or services sold.

Store owners are responsible for:

* determining which data should be retained.
* configuring retention periods appropriately.
* maintaining a compliant privacy policy.
* obtaining legal advice where necessary.

---

# Recommended Privacy Policy Disclosure

Store owners should disclose in their privacy policy that withdrawal request data may be stored for administrative, legal and customer service purposes, including technical metadata such as IP addresses and download activity where applicable.