← webhooker.eu

Legal

Privacy Policy

Last updated: 6 July 2026 · Applies to webhooker.eu and app.webhooker.eu

This policy explains what data Webhooker collects, why, where it lives, and how to get it deleted. The short version: your account data and every webhook payload are stored on servers in the European Union, we collect nothing we don't need to run the service, and we never sell your data.

Contents

  1. Introduction and Data Controller
  2. Personal Data We Collect
  3. Legal Basis for Processing
  4. How We Use Your Data
  5. Data Sharing and Sub-Processors
  6. International Data Transfers
  7. Data Retention
  8. Security Measures
  9. Cookies and Tracking Technologies
  10. Your Rights Under GDPR
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact and Supervisory Authority

1. Introduction and Data Controller

Webhooker ("we", "us", or "our") operates an inbound and outbound webhook gateway available at webhooker.eu. We are committed to protecting the personal data of our users and customers in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable EU and EEA privacy laws.

For the purposes of GDPR, Webhooker acts as the Data Controller for personal data collected through this website and the platform. Our infrastructure and the data we process on your behalf is hosted exclusively within the European Economic Area (EEA). Where we engage third-party service providers who process personal data, we do so under binding Data Processing Agreements (DPAs) that ensure an equivalent level of protection.

For any privacy-related inquiries, please contact us at privacy@webhooker.eu.

2. Personal Data We Collect

We collect personal data in the following categories:

3. Legal Basis for Processing

We process your personal data only where we have a valid legal basis under Article 6 GDPR:

Legal Basis Processing Purpose
Performance of a contract (Art. 6(1)(b)) Creating and managing your account, receiving and delivering webhook events, processing payments, and providing customer support.
Legitimate interests (Art. 6(1)(f)) Ensuring platform security, detecting and preventing abuse and fraud, improving our services through aggregated analytics, and enforcing our Terms of Service.
Legal obligation (Art. 6(1)(c)) Compliance with EU tax and accounting requirements, responding to lawful requests from competent authorities.
Consent (Art. 6(1)(a)) Sending promotional communications and placing non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.

4. How We Use Your Data

We never sell your personal data to third parties, and we never use your webhook payload data for advertising or model training purposes.

5. Data Sharing and Sub-Processors

We engage a limited set of trusted sub-processors to help deliver our services. Each sub-processor is bound by a DPA that imposes data protection obligations consistent with GDPR. Categories of sub-processors include:

We do not disclose personal data to any other third party except when required to do so by applicable law, court order, or to protect the rights, property, or safety of Webhooker, our users, or the public. We will notify you of any such disclosure to the extent permitted by law.

6. International Data Transfers

Our primary infrastructure is located within the European Economic Area (EEA). Where a sub-processor operates outside the EEA, we ensure that any transfer of personal data is subject to appropriate safeguards as required by Chapter V of GDPR, including:

You may request a copy of the applicable transfer mechanisms by contacting privacy@webhooker.eu.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:

8. Security Measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure, including:

No method of transmission over the internet or electronic storage is 100% secure. We encourage you to use a strong, unique password, keep your signing secrets confidential, and enable two-factor authentication on your account.

9. Cookies and Tracking Technologies

We use the following categories of cookies:

You can manage or withdraw cookie consent at any time via your browser settings or our cookie preference centre. Withdrawing consent for analytics cookies does not affect the operation of the platform.

10. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights under GDPR:

To exercise any of these rights, contact us at privacy@webhooker.eu. We will respond within 30 days as required by Art. 12 GDPR. Identity verification may be required before we fulfil your request.

11. Children's Privacy

Our platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@webhooker.eu and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email (at the address associated with your account) and by updating the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the platform after the effective date of any changes constitutes your acceptance of the revised policy.

13. Contact and Supervisory Authority

For questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact privacy@webhooker.eu.

If you are not satisfied with our response, you have the right to lodge a complaint with the supervisory authority in your EU/EEA member state of residence or the competent lead supervisory authority.

See also our Terms of Service and Refund Policy.