Binding language version
This page is an English translation for reference and convenience only. If there is any difference between this text and the German Inclusio Privacy Policy (Datenschutzerklärung für Inclusio), the German version prevails. The English text has no independent legal standing.
Related documents
1. Scope and relationship to Wilken Privacy
This Inclusio Privacy Policy describes how Wilken UG (haftungsbeschränkt) (“Wilken”, “we”) processes personal data when you purchase or license Inclusio or use the related checkout, license server, customer area, or support features.
The general Wilken UG Privacy Policy also applies (including website visits, cookies, and contact forms). For Inclusio purchase and licensing, this Inclusio policy prevails in case of conflict; otherwise the Wilken Privacy Policy continues to apply.
Contractual terms for Inclusio are available in the supplementary Inclusio Terms.
2. Controller
Controller: Wilken UG (haftungsbeschränkt), managing director Tim Wilken, Braugasse 14C, 50859 Cologne, Germany, email: info@wilken.solutions. Further details are in the legal notice on wilken.solutions.
3. Data at purchase, account, and customer area
At checkout and for contract performance we process in particular: login email address, optional separate billing email, first and last name, company name (business customers), customer type (private/business), billing address (street, postal code, city, country), VAT/tax ID (business customers), domain labels (license identifiers), selected plan (monthly/yearly), number of licenses, license keys, checkout batch ID, license/subscription status, and the timestamp and version of the accepted Inclusio Terms and Inclusio Privacy Policy.
In the customer area you may maintain profile and billing data; changes are stored in our systems and synced to Stripe where required. You may optionally set a customer-area password (stored as a hash, not in plain text).
Purposes: concluding and performing the contract, licensing, support, billing, abuse prevention, and evidence of acceptance. Legal bases: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (legitimate interest in secure operation and auditability).
4. Customer area access
We offer magic-link email login and optional password login for the customer area. Magic links are time-limited and used for authentication. After successful sign-in we set a strictly necessary session cookie (wa_dashboard_session) to recognize you in the customer area; it does not contain plain-text passwords.
If the billing email differs from the login email, the billing email may receive limited dashboard access (invoices, payment methods, billing details) — magic link only, no password. The account owner (login email) manages licenses and technical settings.
If you change your login email, a confirmation link may be sent to the new address. To prevent abuse we temporarily store hashed identifiers (e.g. IP address, email) for rate limits on login requests.
Legal bases: Art. 6(1)(b) GDPR (contract/customer area use) and Art. 6(1)(f) GDPR (security).
5. Payments (Stripe)
Payments are processed via Stripe. Depending on configuration, Stripe processes payment data (e.g. card or payment-method details) as an independent controller and/or as a processor. Wilken does not store full card numbers on its own systems. We store Stripe customer and subscription IDs, invoice/receipt references, and payment status as needed for the contract and accounting.
Tax may be calculated automatically via Stripe Tax; Stripe then processes data required for tax calculation (e.g. country, VAT ID where applicable). In the customer area you can download invoices/receipts and manage payment methods via the Stripe customer portal.
See Stripe Privacy for more information. Legal bases: Art. 6(1)(b) GDPR; tax/retention duties may rely on Art. 6(1)(c) GDPR.
6. License server, CDN embed, and logs
To activate and periodically validate a license, your WordPress installation or a CDN-embedded widget version may contact Wilken’s Inclusio license server. Processed data may include: license key, domain/hostname of the active installation, timestamps, validation result, and technical connection data (e.g. IP address in server logs).
Static widget files may be delivered via a content delivery network (CDN); license validation still runs against our servers at wilken.solutions. The CDN typically does not process checkout customer data.
Purposes: contract performance, abuse prevention, support. Legal bases: Art. 6(1)(b) and (f) GDPR. Logs are retained only as long as needed for security and traceability, then deleted or anonymized unless longer statutory periods apply.
7. Forms, support, and bot protection
Inclusio pages (checkout, cancellation, customer area) may use forms for cancellation requests (email, domain, optional reason), support requests (subject, message, page URL), or sharing embed codes by email to third parties (recipient address).
Cloudflare Turnstile may be used to protect against automated abuse. Technical data is transmitted to Cloudflare (e.g. IP address, browser information). Details: Cloudflare Privacy. Legal bases: Art. 6(1)(b) GDPR (contract/support) and Art. 6(1)(f) GDPR (security).
8. Emails
We send transactional emails (e.g. purchase confirmation, license information, magic links, invoice/receipt delivery, cancellation confirmation, shared embed codes, support notifications) via Resend where configured, otherwise via WordPress/hosting mail.
Legal basis: Art. 6(1)(b) GDPR. Marketing emails only where consent or another lawful basis exists.
9. End users of your website
The Inclusio widget and related features (e.g. accessibility statement, “report a barrier” feedback form) run on your website. Typically the widget does not send personal end-user profiles to Wilken to identify individual visitors. Widget preferences may be stored locally in the end user’s browser (e.g. your site’s localStorage/cookies).
When visitors report a barrier via the Inclusio feedback form, you typically process that data on your own website (email to an address you configure). You are the controller for processing on your website and must inform your visitors about your own tools, cookies, and accessibility features. Wilken is not the controller of your website’s content or tracking.
10. Recipients and processors
Recipients may include hosting provider (wilken.solutions), Stripe (payments), Resend (email), Cloudflare (Turnstile), and Wilken staff who need access for support and operations. Where required, we conclude data processing agreements under Art. 28 GDPR.
See the current Inclusio Subprocessor List.
11. Retention
We store contract and billing data for the duration of the relationship and thereafter as required by statutory retention rules (e.g. commercial and tax law). License and validation data are kept while the license is active and thereafter as needed for evidence, defense of claims, or legal duties.
Session cookies and magic links expire automatically when their validity period ends. Password hashes remain stored until you change or remove the password or the account is no longer needed.
12. Your rights
You have rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, portability, objection) and may withdraw consent with effect for the future where processing is based on consent. Contact info@wilken.solutions. You may lodge a complaint with a supervisory authority; for Cologne/NRW typically the LDI NRW.
13. Changes
We may update this Inclusio Privacy Policy when the product, technology, or legal requirements change. The current version is available at this URL; the last-updated date appears above.
Last updated: 2026-07-29