sudo cat ./blog/seus-dados-seu-servidor-por-que-parly-e-sudo-forms-crm-nunca-enviam-nada-para-fora-do-seu-wordpress.md

Your data, your server: why Parly and Sudo Forms & CRM never send anything outside your WordPress

There is a question almost nobody asks before installing a plugin or subscribing to a SaaS tool: where does my data go? The answer, in most cases, is uncomfortable. Your site’s content passes through third-party servers, your form leads live in a foreign company’s cloud, and your entire CRM depends on a subscription that takes the data with it if you ever cancel.

Sudo’s plugins were built on the opposite principle. Both Parly, our translation plugin, and Sudo Forms & CRM (formerly Presto), our forms and CRM plugin, keep absolutely everything inside your own WordPress. Nothing is sent to external systems. No data passes through our servers, because there is no “our servers”: the software runs entirely in your environment.

In this article, we explain why this architectural decision matters far more than it seems, from two angles: privacy and digital sovereignty.

Architecture decides everything

When a tool is an external service, your data has to travel. A typical SaaS form builder sends every submission to the vendor’s cloud. A proxy-based translation service processes and stores your site’s content on its servers. That is not bad faith on anyone’s part, it is simply how the model works: the product is their server.

With Sudo’s plugins, the product is code running on your infrastructure. In Parly, every translation is a normal WordPress page, saved in your database, editable with the editor you already use. In Sudo Forms & CRM, every captured lead, every contact and every step of the pipeline lives in tables inside your own database. Deactivate the plugins tomorrow and the data is still there, intact and accessible, because it was never anywhere else.

The privacy angle: fewer intermediaries, less risk

Form data is, almost by definition, personal data: names, emails, phone numbers, sometimes IDs and sensitive business information. The moment that data enters a SaaS, your company starts depending on an external processor to stay compliant with the GDPR, the LGPD or whichever privacy law applies to you. And that processor is often in another country, which adds the whole layer of international data transfers, with everything that entails.

When data never leaves your server, that entire chain disappears. Some practical effects:

  • Fewer processors to map and audit: your privacy policy becomes simpler and more honest, because fewer third parties have access to your users’ data.
  • No international transfers: if your hosting is in your country, your leads’ personal data stays in your country, without relying on standard contractual clauses or adequacy decisions.
  • Easier data subject requests: when someone asks to access, correct or delete their data, everything is in one place, under your direct control, with no vendor tickets involved.
  • Smaller attack surface: every external service that receives your data is one more place it can leak from. SaaS platform breaches expose their customers in bulk; data that never travels cannot leak in transit.

The same reasoning applies to Parly on the content side: your site’s text, including unpublished pages, drafts and internal material, is never processed by an external translation service you do not control.

The digital sovereignty angle: actual control

Digital sovereignty is an organization’s (or a country’s) ability to decide where its data lives, who can access it and under which laws it sits. The topic has left the academic realm: companies and governments worldwide are rethinking their dependency on foreign clouds and SaaS, subject to other countries’ legislation and to commercial decisions they have no vote in.

Plugins that keep data inside the client’s environment contribute directly to that autonomy:

  • Jurisdiction chosen by you: the data sits where your hosting sits, under the legislation you chose, not under the laws of a vendor’s home country.
  • Vendor independence: if Sudo disappeared tomorrow, your forms, leads and translations would keep working and remain accessible in your database. Compare that with a discontinued SaaS, where a shutdown announcement means racing to export whatever you can before the lights go out.
  • No perpetual rent on your own data: in the SaaS model, part of what you pay monthly is continued access to what is yours. In the plugin model, the data is yours in the most literal sense: it is on your server.
  • Auditability: code that runs in your environment can be inspected. You do not have to trust a privacy policy’s promise, you can verify what the software does.

For public sector bodies, regulated companies and any organization with data residency requirements, this difference is not a detail: it is the criterion that decides whether a tool can be used at all.

The honest trade-off

Keeping data at home means the home is your responsibility. Backups, updates and the security of your hosting become part of your duty of care, not the vendor’s. For most companies this is already reality (the WordPress site already exists and is already maintained), so the additional cost is close to zero. But it is fair to say it plainly: sovereignty comes with stewardship. We prefer it that way, and we think you should too.

The short version

Every piece of data that leaves your environment becomes a dependency: on a contract, on a jurisdiction, on a company that needs to keep existing and keep being well-intentioned. Parly and Sudo Forms & CRM remove that dependency by architecture: translations, forms, leads and CRM live in your WordPress, on your server, under your rules.

Privacy and digital sovereignty do not have to be expensive compliance projects. Sometimes, they are just a choice of tooling.

Parly and Sudo Forms & CRM are products by Sudo, a digital product studio from Brazil.

Got a similar project in mind?