Product Privacy Policy
This Policy explains the limited security, diagnostic, licensing, and support information processed when LEADER AD SECURITY protects a WordPress website.
Events are processed to detect attacks, abuse, unauthorized access, and file compromise.
The website operator selects modules, retention, notifications, and authorized access.
Security telemetry is not sold or used to build unrelated advertising profiles.
1. Scope and relationship to other policies
This Privacy Policy applies to the LEADER AD SECURITY WordPress plugin, its protection modules, licensing and update services, administrator dashboards, optional email notifications, and support or diagnostic functions associated with the plugin.
This Policy covers processing performed by or specifically through LEADER AD SECURITY. Website visits, Website accounts, checkout, product purchases, downloads, and communications made directly through LEADERAD.site remain subject to the LEADER AD Website Privacy Policy, unless this Policy expressly states otherwise.
2. Who is responsible and how to contact us
For processing under LEADER AD’s control and covered by this Policy, the responsible business is LEADER AD.
Privacy contact: [email protected]
Website: LEADERAD.site
Privacy Center: LEADERAD.site/privacy/
Where a customer uses the product to process information for its own website, business, personnel, learners, clients, visitors, or users, that customer may independently determine the purposes and means of that processing. In that context, the customer is responsible for its notices, instructions, permissions, and lawful basis, while LEADER AD acts only within the role required by the feature, agreement, and applicable law.
3. How SECURITY works
SECURITY operates primarily inside the customer’s WordPress environment. It analyzes requests, authentication attempts, configuration, files, and security events needed to provide enabled protections. Certain limited information may reach LEADER AD systems when the administrator activates a license, requests an update, enables a connected service, submits diagnostics, or contacts support. The customer remains responsible for the lawfulness of monitoring on the protected website and for informing its users where required.
4. Information processed
The information processed depends on the features used, configuration, product version, and the actions requested.
| Category | Examples | How it is handled |
|---|---|---|
| Security events | IP address, user agent, requested path, request method, timestamps, rule triggered, action taken, response status, authentication or rate-limit events. | Normally stored in the protected WordPress site; selected alerts or diagnostics may be sent when a connected feature is enabled. |
| Login and abuse indicators | Attempted username, login result, lockout counters, password-reset or enumeration indicators, honeypot or duplicate-submission signals. | Used to detect brute force, credential abuse, spam, and unauthorized access. Passwords are not intended to be logged. |
| File and malware scan data | File paths, names, sizes, timestamps, hashes, integrity changes, suspicious code indicators, scan findings and remediation status. | Processed locally where possible; content or excerpts should reach support only when intentionally submitted for investigation. |
| Site environment | Site URL, WordPress and PHP versions, active plugins and theme, hosting profile, Cloudflare/provider indicators, enabled modules and compatibility status. | Used for compatibility, diagnostics, security recommendations, and support. |
| License and update records | License identifier, activation state, site URL or installation identifier, plan, product version, entitlement, update status and timestamps. | May be processed by LEADER AD licensing and update systems. |
| Administrator communications | Configured notification address, critical-event digest, support messages, diagnostic packages intentionally submitted. | Used only to deliver notices, investigate issues, and provide support. |
5. How information is obtained
Information may be obtained through the following sources:
- automatically from requests and events occurring on the protected WordPress site;
- from WordPress, the server environment, installed extensions, and the security configuration;
- from the site administrator when configuring, licensing, updating, exporting diagnostics, or requesting support;
- from authorized LEADER AD update, licensing, or notification systems when those services are used.
We do not infer that optional information is present merely because the product can technically support a related feature.
6. Purposes and legal bases
Information may be processed only as reasonably related to the following purposes:
- detect, block, rate-limit, or investigate malicious, abusive, fraudulent, or unauthorized activity;
- protect logins, uploads, files, application routes, REST access, and administrative functions;
- scan for malware, unexpected file changes, vulnerable configuration, or integrity problems;
- maintain security and activity records, alerts, digests, and audit history;
- activate licenses, verify entitlements, deliver trusted updates, and prevent license abuse;
- diagnose compatibility and performance issues and provide requested support;
- comply with law and establish, exercise, or defend legal claims.
Where applicable law requires a legal basis, processing may rely on one or more of the following, depending on the activity:
- performance of a contract or steps requested before entering into a contract;
- LEADER AD’s legitimate interests in operating, securing, supporting, improving, and protecting the product, provided those interests are not overridden by applicable rights;
- compliance with legal, accounting, tax, security, or regulatory obligations;
- consent, where consent is required or selected by the user; and
- protection of users, systems, property, or legal rights where permitted by law.
The legal basis depends on the specific feature, context, jurisdiction, and information involved. Consent may be withdrawn for future processing without affecting processing already lawfully performed.
7. Information and access not intentionally required
The ordinary operation of this product is not intended to require unnecessary personal or sensitive information.
- SECURITY is not designed to record passwords, payment-card numbers, private cryptographic keys, or the full contents of ordinary website communications as routine telemetry;
- microphone, camera, contacts, precise device location, and advertising identifiers are not required for the WordPress plugin;
- file contents should not be transmitted to LEADER AD unless the administrator intentionally submits material needed for support, malware analysis, or another disclosed connected feature;
- security information is not used for unrelated behavioral advertising.
Do not submit passwords, secret keys, payment-card numbers, government identifiers, health data, or other sensitive information through ordinary support or description fields unless LEADER AD has specifically requested it through an appropriate secure process and it is genuinely necessary.
8. Website operator responsibilities
The operator of the protected website determines which SECURITY modules are enabled and is responsible for an appropriate legal basis and notice for server and security logging. The operator should limit administrator access, configure reasonable retention, exclude unnecessary sensitive fields, protect diagnostic exports, and ensure that monitoring is proportionate to the security risk.
SECURITY should not be used to conduct unlawful surveillance, capture credentials, interfere with systems without authorization, or retain visitor information longer than justified.
9. Updates, intelligence, and connected services
Update checks may transmit the product version, license status, site or installation identifier, WordPress/PHP compatibility information, and a request timestamp. Security intelligence or rule updates may be delivered without uploading the customer’s site content.
If the administrator enables email delivery, cloud intelligence, centralized management, or another optional connection, the interface or related notice should identify the information needed by that feature before activation.
Sharing, service providers, and disclosures
LEADER AD does not sell personal information processed under this Policy. Information may be disclosed only as reasonably necessary for the relevant purpose, subject to suitable safeguards and applicable law.
- hosting, email delivery, update, licensing, and security infrastructure providers acting for LEADER AD;
- the customer’s authorized administrators, hosting provider, incident responders, or support personnel;
- WordPress or other vendors only when their service is intentionally used by the customer;
- authorities or affected parties where disclosure is lawful and necessary to address a serious security incident or legal obligation.
Information may also be disclosed when reasonably necessary to comply with law or a valid legal process; protect users, systems, property, safety, or rights; investigate misuse or fraud; enforce applicable terms; or support a merger, financing, acquisition, reorganization, or sale of assets. Any business successor would remain subject to applicable privacy obligations for the information it receives.
International processing and transfers
Service providers, infrastructure, app stores, cloud platforms, or authorized recipients may operate in countries other than the user’s country. Where personal information is transferred internationally, LEADER AD will use the mechanism, authorization, contractual protection, or other safeguard required by the law applicable to that transfer.
A reference to an international provider does not by itself mean that every user’s information is transferred to every location in which that provider operates.
Retention
Information is retained only for as long as reasonably necessary for the purpose for which it was processed, including to provide the product, maintain security and transaction records, resolve disputes, enforce agreements, comply with legal or accounting requirements, and establish or defend legal claims.
- local security and activity logs follow the administrator’s configuration, database maintenance, and product limits;
- license and activation records are retained while the entitlement is active and for a reasonable period afterward for billing, fraud prevention, support, and dispute records;
- submitted diagnostics and support records are retained for the time needed to resolve the matter and protect against repeated incidents;
- aggregated or de-identified security statistics may be kept longer where they no longer identify a person.
Retention can vary because local information is controlled by the user or operating system, server logs rotate on different schedules, backup copies expire according to configured cycles, and legal duties may require certain records to be held longer. Information may be deleted, anonymized, aggregated, or isolated when it is no longer required.
Security
LEADER AD uses administrative, technical, and organizational measures selected according to the nature of the product and information involved. Measures may include access controls, separation of duties, authentication, encryption in transit where supported, secure coding and update practices, logging, monitoring, rate limits, integrity checks, and restricted administrative access.
No product, transmission, device, storage system, or security measure can be guaranteed to be completely secure. Users and customer administrators must protect accounts, devices, recovery material, API keys, hosting access, and other credentials under their control; apply updates; limit privileges; review activity; and report suspected compromise promptly.
User and administrator controls
Authorized administrators can configure protection modules and, where available, view, export, rotate, or delete local logs and disable connected features.
- adjust logging and retention settings;
- review blocked events, file findings, and audit records;
- disable notifications or connected modules that are not required;
- revoke a license activation or remove the plugin;
- delete plugin data using supported controls, subject to WordPress, server, backup, and legal retention behavior;
- contact LEADER AD to request access to or deletion of centrally held license or support records where applicable.
Removing a local app, disconnecting an integration, or deleting an account does not necessarily erase records that another controller, app store, payment provider, backup destination, or legal obligation independently requires that party to keep.
Privacy rights and requests
Depending on where you live and the law that applies, you may have rights to request access to personal information, obtain a copy, correct inaccurate or incomplete information, object to or restrict certain processing, request deletion where the legal conditions are met, withdraw consent for future processing, and receive certain information in a portable format.
These rights are not absolute. A request may be limited where information must be retained to complete a transaction, protect security, establish or defend legal claims, comply with law, preserve the rights of others, or where another lawful exception applies. We may ask for information reasonably necessary to verify the requester and prevent unauthorized disclosure.
Requests may be sent to [email protected] or through the LEADER AD contact page. We will respond through the appropriate channel and within the period required by applicable law.
Children
SECURITY is a business and website-administration tool and is not directed to children. It may nevertheless process technical events relating to any visitor of a protected site; the site operator is responsible for the audience and legal requirements of that site.
If LEADER AD learns that information was collected from a child in circumstances requiring parental authorization and that authorization was not validly obtained, we may delete or restrict the information as required by law. A parent or guardian may contact [email protected].
Automated decisions
SECURITY uses automated rules to identify and respond to potentially malicious behavior. A block or alert is a protective technical response, not a decision intended to determine a person’s eligibility for employment, credit, housing, education, insurance, or another legally significant service.
Security, fraud, spam, licensing, integrity, or quality systems may automatically flag, limit, queue, or block an event. Where required by law, a person may contact LEADER AD to request appropriate review of a decision producing legal or similarly significant effects.
Changes to this Policy and product evolution
LEADER AD may update this Policy to reflect product changes, new optional features, security improvements, provider changes, or legal requirements. The “Last Updated” date will identify the current published version. Where required, material changes will be communicated through an appropriate product, account, website, store-listing, or direct notice before they take effect.
A future feature is not treated as active processing solely because this Policy explains how it would be handled if offered. If a new feature materially changes data practices, LEADER AD will update the applicable notice and obtain consent where the law requires it.
Contact and interpretation
LEADER AD Privacy
Email: [email protected]
Contact form: https://leaderad.site/contact-us/
Privacy Center: https://leaderad.site/privacy/
This Policy is intended to describe actual product data practices in clear language. It does not waive rights that cannot lawfully be waived, create processing that does not otherwise occur, or require publication of private personal details that are not necessary for a valid public notice.
