Tag: privacy

  • WpW: LiteSpeed Cache and the GDPR

    WpW: LiteSpeed Cache and the GDPR

    WordPress Wednesday: LiteSpeed Cache and the GDPR

    Welcome to another installment of WordPress Wednesday!
    Today’s topic is: LiteSpeed Cache for WordPress and the GDPR

    We discussed this in general terms a few days ago, but today we’re going to talk specifically about the WordPress plugin, and give you a few more details.

    As site owners, no doubt you are aware of the EU’s new GDPR. And if you are not, you should probably read this. And soon, because it becomes enforceable in 2 days.

    The GDPR applies to companies that collect data, and companies that process data. In the context of our cache plugins, YOU would be the data collector for your site, and LiteSpeed would be one of your data processors.

    LiteSpeed Technologies values your users’ privacy, and we want you to know that the use of our plugin should not have any effect on your ability to comply with the GDPR.

    Our software does not directly process any personally identifiable information from visitors to your site. However, LiteSpeed Cache for WordPress does brush up against personal data in a few ways, and we’re going to talk about those today.

    LiteSpeed Cache for WordPress and the GDPR: Private area sign on a fence

    Caching

    Each of our cache plugins potentially stores a duplicate copy of every web page on display on your site. The pages are stored locally on the system where LiteSpeed server software is installed and are not transferred to or accessed by LiteSpeed employees in any way, except as necessary in providing routine technical support if you request it. All cache files are temporary, and may easily be purged before their natural expiration, if necessary, via a Purge All command.

    In other words, LSCache software has access to whatever personally-identifiable data is already visible on your site, but it has no need to actually look at that data. LiteSpeed stores a copy on your server for fast access, and you may delete that copy whenever you like.

    Image Optimization and Reports

    In addition to caching, our WordPress plugin has an Image Optimization feature. When optimization is requested, images are transmitted to a remote LiteSpeed server, processed, and then transmitted back for use on your site. LiteSpeed keeps copies of optimized images for 7 days (in case of network stability issues) and then permanently deletes them.

    Similarly, LSCWP has a Reporting feature whereby a site owner can transmit an environment report to our server so that we may better provide technical support. We don’t currently have a deletion schedule for this data, but we probably will in the future. In the meantime, we’d be happy to remove your report data upon request.

    It’s important to realize that neither of these features actually collects any visitor data. Only information about your own site and server setup is included. I mention them here because we’ve had questions about them before. But really, image optimization and reporting shouldn’t have any impact on your ability to comply with the GDPR.

     

    LiteSpeed Cache for WordPress and the GDPR: Sign about owl sleeping habits on a fence

    Your Privacy Policy

    WordPress has a new Privacy menu in the Admin area that allows you to easily generate a Privacy Policy for your site. If you choose to use that tool, you will see that some plugins include their own paragraphs that you may insert into your policy. LiteSpeed provides the following small blurb that you may use, if you like:

    This site utilizes caching in order to facilitate a faster response time and better user experience. Caching potentially stores a duplicate copy of every web page that is on display on this site. All cache files are temporary, and are never accessed by any third party, except as necessary to obtain technical support from the cache plugin vendor. Cache files expire on a schedule set by the site administrator, but may easily be purged by the admin before their natural expiration, if necessary.
    
    

    NOTE: The LiteSpeed privacy blurb will be available in the Privacy Policy tool starting with LSCWP v2.2.6. The update should be available later this week. Until then, you can add the above text manually, if you wish.

    Keep up to Date!

    You can find our full GDPR Statement and Privacy Policy on our site. That document will always be the most up-to-date source for privacy information. Be sure to refer to it for the official word.

    If you have further privacy questions or concerns, please leave a comment, or contact us!

    Have some of your own ideas for future WordPress Wednesday topics? Leave us a comment!

    Don’t forget to meet us back here next week for the next installment. In the meantime, here are a few other things you can do:

  • LiteSpeed and the GDPR

    LiteSpeed and the GDPR

    LiteSpeed and the GDPR

    As you no doubt know by now, Friday marks the day that the EU’s GDPR becomes enforceable. This means that there are certain rules you will be required to follow if you collect or process data from European customers.

    LiteSpeed Technologies values your privacy as well as that of your users, and we have updated our Privacy Policy and our End User License Agreement to better reflect how we handle your (and your users’) data. We’re providing a summary here, but we encourage you to click on the links and read the actual documents.

    LiteSpeed as a Data Collector

    If you are a LiteSpeed customer, you can expect that we will collect only as much information from you as is necessary to provide you with our software, licenses and any technical support you may request. We don’t currently share your data with third parties, and we have no plans to do so in the future. However, if this changes, we will update our policy and keep you informed.

    If you have provided sensitive information (login credentials, etc.) while working with our support team, please know that we consider such data to be strictly confidential and we delete it from our system as soon as we close the ticket.

    We have the ability to comply with any of the rights that are granted to you under the GDPR, if you should wish to exercise them.

    LiteSpeed as a Data Processor

    Our software does not directly process any personally identifiable information from visitors to your site. Nevertheless, LiteSpeed may be considered a data processor, as your users’ information may be temporarily cached and/or logged.

    LiteSpeed server stores any cache or log files locally on the system where you have installed the software. Our employees never access the files in any way, except as necessary in providing routine technical support if you request it.

    The cache and log files are always under your control. You have the ability to decide how long (or if) to keep such files, and to delete them on demand.

    In Conclusion

    LiteSpeed Technologies is compliant with the GDPR in terms of how we handle your data. Additionally, our software will not prevent you from being GDPR compliant in turn. Please be sure to see our Privacy Policy and our End User License Agreement, and read them in full. These documents will always be the most up-to-date source of information.