evoLeadGate: data it handles and compliance
This page describes what the extension does with data. It is not a legal assessment.
Where the data is stored
In three tables of your own Joomla site's database (with your table prefix). evoLeadGate does not send leads to any external service. Dates are stored in UTC.
What is stored for each lead
Leads table (#__evoleadgate_leads), one row per form submission:
| Data | Detail |
|---|---|
| Stored in lower case. | |
| Extra fields | What the visitor typed into the fields you defined in the element, as JSON. |
| Form and delivery | The form ID and the delivery mode. |
| Lead identifier | A UUID, used as the event_id in the analytics events. |
| Source page and referrer | The URL of the page where the form was submitted and the referring page, if the browser provides it. |
| IP | Full or anonymised, depending on a setting (see below). |
| Browser | The user-agent header, cut to 255 characters. |
| Privacy consent | Always accepted (the checkbox is mandatory) and the exact text that was shown. |
| Marketing consent | Ticked or not, and the exact text that was shown. The checkbox is presented unticked and only exists if the form has a marketing text. |
| Consent date | The moment of submission. |
| Delivered file | Relative path inside the private folder, copied at the time of sign-up. |
| Download link | A random 64-character token and its expiry date. |
| Verification | The date the visitor opened the link, in double opt-in mode. |
| Email status | Outcome of the notice and of the delivery email: sent, failed or skipped. |
| Attribution | utm_source, utm_medium, utm_campaign, utm_term, utm_content, gclid and fbclid if they were in the URL; and _fbp and _fbc if those cookies existed in the browser. |
| Creation date | The moment of submission. |
Downloads table (#__evoleadgate_downloads), one row per download: the lead, the date, the user agent and the IP (with the same rule as the lead's IP).
Attempts table (#__evoleadgate_attempts), one row per submission received: the IP and the date. It is used only for the per-IP submission limit. This IP is stored in full, whatever the IP setting says. Attempts older than one day are purged on every new submission, and also by the scheduled retention task.
IP: full or anonymised
The "Store the full IP address" setting is Yes by default. With "No", the lead and the downloads store the anonymised IP:
- IPv4: the last octet becomes 0 (for example
192.0.2.0). - IPv6: the 48-bit prefix is kept and the rest becomes 0.
If you have told Joomla the server is behind a proxy, the stored IP is the one Joomla identifies as the visitor's.
How long data is kept
| Data | Default period | How to change it |
|---|---|---|
| IP of the lead and of the downloads | 12 months. After that, the retention task clears it. | Option "IP retention (months)". 0 means no limit. |
| Leads and their downloads | No limit (0). | Option "Lead retention (months)". After that, the task deletes them. |
| Anti-spam attempts | Less than one day. | Not configurable. |
The first two periods only apply if you have created and enabled the scheduled task "evoLeadGate: data retention". The package does not create it. Until it exists, IP addresses and leads are kept indefinitely. You can also delete leads by hand from the panel, with the delete permission.
Cookies and data leaving the site
- The form script sets no cookies of its own. The CSRF token relies on the Joomla session. It reads the
_fbpand_fbccookies if they exist, to store them with the lead. It does not check consent: that depends on how you load those cookies and pixels. - The form loads no third-party scripts. In the browser it pushes an event to the
dataLayerand callsgtagandfbqonly if your site has loaded them. What those scripts send to third parties depends on your setup. - Emails (notice and delivery) leave through the mail server configured in Joomla. With the default texts, the visitor's email carries the download link, and the notice carries their email, the field values and the link to the lead in the panel.
- If you have pasted a Download ID, the licence client queries the evoaddons.com licence server at most once a day (or every six hours after a failure). It sends the Download ID, the product, the domain, a site identifier (
site_id), the extension version, the PHP version, the Joomla version and the environment. It sends no lead data. With no Download ID there is no query. Joomla's updater, when it looks for updates, queries the same server with the Download ID.
Privacy plugin
The package includes a plugin of Joomla's privacy group, used from Users → Privacy. It identifies the person by email (the Joomla user's or the request's).
| Request | What it does |
|---|---|
| Export | Includes the leads for that email with all their columns except the download token, and the downloads of those leads. |
| Check whether it can be removed | Always answers yes. |
| Remove | Deletes the leads for that email and their downloads. |
Anti-spam attempts are not touched: they are not tied to an email and are purged within a day.
Who can see the data
- Joomla panel: anyone with the permission to access evoLeadGate's administration (
core.manage) sees the leads, including the IP. Exporting to CSV needs its own permission, and deleting another. The CSV includes the IP and the source data, but not the user agent or the text of the consents (only whether they were accepted). - REST API: read-only, with
core.manage. It does not return the IP or the user agent. - evoMCP (optional): the tools flag leads as personal data. Reading a lead does not include the IP or the user agent. Deleting always needs human approval.
- Joomla events: plugins subscribed to
onEvoleadgateLeadCreatedreceive the whole lead, including the IP and the download token.
Uninstalling
When uninstalling, the tables are only dropped if you switched on "Delete data on uninstall" beforehand. By default they are kept. More in Uninstalling.
What is missing
[PENDIENTE: a specific data-processing record for evoLeadGate (purposes, legal basis, recommended periods and suggested wording for the privacy policy). It does not exist yet.]
This is not legal advice; consult your own adviser.