Skip to content

GDPR Commitment

Sitebefy is built to serve customers in the EU, and the GDPR is treated as the baseline for everyone, not a regional add-on. This page summarizes how; the Privacy Policy is the full, binding version.

Your rights are product features, not a mailbox. Exporting your data is a button in Settings, Privacy, and produces a machine-readable archive. Consent for analytics and marketing is a switch you flip yourself. Deletion is a request away through the contact page, with a 14-day grace period in case you change your mind.

Data minimization is in the defaults. Without consent, our visitor analytics sets no cookie and rotates its identifier daily, so visits cannot be linked across days. Third-party embeds do not load until clicked. We do not buy, sell or rent personal data.

Retention is enforced by machines, not by policy documents. The retention periods in the Privacy Policy (90 days for IP addresses in security records, 7 days for export archives, 14 days for backups and server logs) are executed by scheduled jobs, not by someone remembering.

Security is layered. Encrypted transport everywhere, hashed passwords, per-site isolation, re-authentication for sensitive actions, optional two-factor authentication, and an audit trail of security-relevant events. The Security Policy has the detail.

For your own site's visitors, we are your processor. You decide what data your website collects; we process it on your instructions under our Data Processing Agreement, which is part of the service.

Who to talk to: chidang@flexa.vn, or the contact page.

Last updated: 5 Sep 2026