Professional WordPress Web Design in Wigan

Data Security Policy

Data Security Policy

Last Updated: 18 September 2026

This Data Security Policy explains the measures used to help protect personal data, client information, website credentials and other digital assets handled while providing WordPress web design and related services through https://www.webdesigninwigan.co.uk/.

Protecting client information is an important part of website design, development, migration, maintenance and ongoing support.

Throughout this document, “we”, “us” and “our” refer to the operator of webdesigninwigan.co.uk. “Client” refers to any individual, business or organisation engaging our services.

  1. Purpose of This Policy

The purpose of this policy is to explain the technical and organisational measures used to reduce security risks when handling information in connection with website projects.

This may include information relating to:

  • WordPress websites and administration accounts
  • Website hosting accounts
  • Domain and DNS settings
  • Website databases
  • Website backups
  • Contact-form enquiries
  • Customer or ecommerce information
  • Booking-system data
  • CRM or email marketing integrations
  • Analytics and tracking platforms
  • Internal client information and project communications

Security controls are intended to reduce the likelihood of unauthorised access, accidental loss, misuse, alteration or disclosure of information.

  1. Secure Website Connections

HTTPS should be used on live websites where appropriate so that information transmitted between a visitor’s browser and the website is encrypted.

Security measures may include:

  • SSL/TLS certificates
  • HTTPS website connections
  • Secure access to WordPress administration areas
  • Secure hosting control-panel connections
  • Encrypted connections to third-party platforms

Encryption helps protect information while it is being transmitted across networks, although it does not remove the need for other security measures.

  1. WordPress Security

WordPress websites require ongoing attention because security can be affected by WordPress core, themes, plugins, hosting configuration and user access.

Where included within the agreed service, security measures may include:

  • Keeping WordPress core updated
  • Updating themes and plugins
  • Removing unused plugins or themes where appropriate
  • Restricting administrator access
  • Using appropriate security plugins or hosting-level protection
  • Monitoring for suspicious activity
  • Maintaining suitable website backups

The exact security measures used will depend on the website, hosting environment and level of maintenance or support agreed with the client.

  1. Hosting and Server Security

Where hosting forms part of the website service, suitable hosting infrastructure should be used for the requirements of the website.

Hosting security may include features such as:

  • Firewall protection
  • Server monitoring
  • Malware detection
  • Security patching
  • Backup systems
  • Restricted server access
  • Protection against common automated attacks

Hosting providers maintain their own infrastructure and security systems.

Where a client uses a hosting provider independently, responsibility for the hosting environment remains subject to the client’s agreement with that provider.

  1. Access Control

Access to client websites, hosting accounts and connected systems should be limited to people who genuinely need access.

Security controls may include:

  • Password-protected accounts
  • Strong and unique passwords
  • Two-factor authentication where available
  • Role-based WordPress permissions
  • Separate user accounts rather than shared credentials where practical
  • Restricted administrator access
  • Removing unnecessary access when work has finished

Administrative privileges should only be granted where they are required.

  1. Password and Credential Security

Website projects often require temporary or ongoing access to WordPress, hosting, domain, analytics and third-party services.

Credentials should be handled carefully and should not be made publicly available or stored unnecessarily in insecure locations.

Where possible:

  • Passwords should be strong and unique
  • Two-factor authentication should be enabled on important accounts
  • Credentials should not be reused across unrelated services
  • Access should be revoked when it is no longer required
  • Client accounts should remain under the client’s ownership wherever practical

Clients are also responsible for protecting credentials supplied to their own employees, contractors or other third parties.

  1. Website Backups

Backups can help recover a website following accidental deletion, failed updates, technical faults or certain security incidents.

Where backups form part of the agreed service, arrangements may include:

  • Automated website backups
  • Database backups
  • Off-site backup storage
  • Defined backup retention periods
  • Restoration testing where appropriate

Backup arrangements vary between hosting providers and website-support services.

Clients should understand what backup service is included and whether additional backups are required for business-critical websites.

  1. Development and Staging Websites

Website development, redesign and migration work may involve creating temporary staging or development copies of an existing website.

These copies can contain the same information as the live website, including personal data.

Where appropriate, steps may be taken to:

  • Restrict public access to development sites
  • Discourage search-engine indexing
  • Protect staging environments with passwords or access controls
  • Limit administrative access
  • Remove development copies after they are no longer required

Clients should notify us before migration or development work begins if the website contains particularly sensitive information.

  1. Website Migration Security

Website migrations can involve transferring files, databases, user accounts and other information between servers or platforms.

Reasonable precautions may include:

  • Using secure transfer methods
  • Restricting access to exported databases
  • Keeping migration copies only for as long as required
  • Checking website functionality after migration
  • Removing unnecessary temporary copies

Website migrations should also consider DNS, SSL certificates, forms, email delivery and other connected systems so that the new environment remains properly configured.

  1. Contact Forms and Website Enquiries

Website contact forms can collect personal information such as names, telephone numbers, email addresses and enquiry details.

Appropriate security measures may include:

  • HTTPS encryption
  • Spam protection
  • Limiting unnecessary form fields
  • Controlling where form submissions are stored
  • Restricting access to stored enquiries
  • Removing old information where it is no longer required

Clients remain responsible for deciding what information they need to collect from their customers and how long it should be retained.

  1. Ecommerce and Payment Security

WordPress websites using WooCommerce or other ecommerce functionality may process customer names, addresses, contact information and order details.

Where online payments are accepted, card information should normally be processed through an appropriate third-party payment provider rather than being unnecessarily stored directly within the website.

Payment gateways and merchant providers maintain their own security and compliance requirements.

Clients should ensure that ecommerce accounts, payment-provider accounts and WordPress administrator accounts are appropriately protected.

  1. Third-Party Platforms and Integrations

WordPress websites may connect to external services including:

  • Google Analytics
  • Google Search Console
  • Email marketing systems
  • CRM platforms
  • Booking systems
  • Payment gateways
  • Cloud storage services
  • Security and backup services
  • Website hosting providers

Third-party services operate their own security systems, privacy policies and terms.

Security settings within these platforms should be configured appropriately, and access should be restricted to authorised users.

  1. Plugins, Themes and Software

Third-party WordPress themes and plugins can add useful functionality but can also introduce additional security risks if they are poorly maintained or left outdated.

Where appropriate, good practice may include:

  • Using established themes and plugins from reputable sources
  • Keeping software updated
  • Removing unused plugins
  • Avoiding unnecessary functionality
  • Reviewing compatibility before major updates
  • Using backups before significant changes

No WordPress plugin or security product can guarantee that a website will never experience a security incident.

  1. Website Updates and Maintenance

Keeping website software up to date can reduce exposure to known vulnerabilities.

Where website maintenance is included within the agreed service, work may involve:

  • WordPress core updates
  • Plugin updates
  • Theme updates
  • Security monitoring
  • Backup monitoring
  • General website health checks

Where ongoing maintenance is not included, responsibility for updates and monitoring will normally pass to the client or their chosen provider after handover.

  1. Monitoring and Risk Management

Security practices may be reviewed periodically to identify emerging risks or changes to website technology.

This can include:

  • Reviewing administrative access
  • Monitoring unusual login activity
  • Checking outdated website software
  • Reviewing security warnings
  • Assessing newly identified vulnerabilities
  • Updating working practices where appropriate

The objective is to maintain a proportionate level of security based on the nature of the website and the information it processes.

  1. Data Retention

Client data should not be retained indefinitely without a valid reason.

Retention periods can depend on:

  • The type of website service being provided
  • Hosting and backup settings
  • Client requirements
  • Legal obligations
  • Ongoing maintenance agreements
  • The nature of temporary development or migration files

Where practical, access to client systems and unnecessary project copies should be removed when they are no longer required.

  1. Security Incidents and Data Breaches

If a security incident is identified, appropriate steps will be taken based on the nature and severity of the issue.

Actions may include:

  • Investigating the cause of the incident
  • Restricting compromised access
  • Changing affected credentials
  • Removing malicious software or files
  • Restoring a clean backup where appropriate
  • Applying security updates
  • Reviewing affected systems

Where an incident affects personal data processed on behalf of a client, the client will be informed without undue delay where required.

The client remains responsible for determining whether notification to regulators or affected individuals is required where they act as the Data Controller.

  1. Client Responsibilities

Website security is a shared responsibility.

Clients are expected to take reasonable steps to protect their own accounts and systems, including:

  • Keeping login details confidential
  • Using strong passwords
  • Enabling two-factor authentication where available
  • Removing accounts belonging to former staff or contractors
  • Not sharing administrator credentials unnecessarily
  • Informing us promptly about suspected security problems
  • Maintaining suitable security arrangements after website handover

Security can be weakened if credentials are shared widely or website software is left unmaintained.

  1. Website Handover

When a website project is completed, appropriate access and ownership information should be transferred or confirmed with the client.

Depending on the project, this may include:

  • WordPress administrator access
  • Hosting details
  • Domain information
  • Analytics accounts
  • Third-party service accounts

Clients should update or secure credentials after handover where appropriate.

Responsibility for ongoing maintenance, backups and security should also be clearly understood once the project has been completed.

  1. No Absolute Security Guarantee

Reasonable security precautions can reduce risk, but no website, server, plugin, hosting service or online system can be guaranteed to be completely secure.

Security risks can arise from:

  • New software vulnerabilities
  • Compromised passwords
  • Third-party services
  • Hosting infrastructure
  • Malicious attacks
  • User error
  • Outdated software

Security measures should therefore be viewed as an ongoing process rather than a one-time website feature.

  1. Updates to This Policy

This Data Security Policy may be updated to reflect changes in:

  • WordPress technology
  • Website security practices
  • Hosting arrangements
  • Third-party services
  • Legal or regulatory requirements
  • Operational procedures

The current version will be published on this page together with the latest revision date.

  1. Contact

If you have any questions about this Data Security Policy or security relating to a WordPress website project, please contact me through:

https://www.webdesigninwigan.co.uk/contact/

expand_less