Legal
Privacy policy
What we collect, why, and what you can ask us to do about it. This covers our own website and our handling of customer data.
Two different roles
This policy covers two things people often confuse.
Our own website and customers. When you visit websiteguardians.com or buy from us, we decide what to collect and why. We are the controller of that data.
Websites we host. When we host your website, your visitors' data belongs to you. We hold it on your behalf, act on your instructions, and do not use it for our own purposes. In data protection language, you are the controller and we are the processor.
What we collect about you
| What | Why | Kept |
|---|---|---|
| Name, business name, email, phone | To provide the service and contact you about it | Life of the account + 7 years |
| Billing address and tax details | Invoicing and tax obligations | 7 years |
| Payment card details | Handled entirely by our payment processor. We never see or store your full card number. | Not held by us |
| Support correspondence | To answer you and to keep a record of what was done | 3 years |
| Server and access logs | Security, diagnosing faults, abuse investigation | 90 days |
This website
We do not run advertising trackers, social media pixels or cross-site profiling on this website. We do not sell or share personal information with anyone for advertising.
The site loads a web font from Google Fonts, which means Google receives the request including your IP address. Everything else is served from our own infrastructure.
We keep basic server logs as described above. We do not use cookies to track you across other websites.
Data about your website's visitors
Hosting a website means holding whatever it holds: form submissions, account records, enquiries, order history. We hold that for you.
- We access it only to operate, back up, secure and support the service, or where you ask us to
- We do not use it for our own purposes, and we never sell it
- We return or delete it when the service ends, at your choice
- If you need a written data processing agreement, ask and we will provide one
Who else touches your data
We use a small number of suppliers to deliver the service. Each has access only to what its function requires.
- Infrastructure providers — the data centres where the servers run
- Payment processing — to take payment and issue receipts
- Email delivery — to send service and billing messages
- Content delivery and DNS — to serve and protect the site
We will name the current suppliers on request. We do not sell personal information to anyone, for any purpose.
Security
Data is encrypted in transit. Access to production systems is restricted to the people who operate the service, over authenticated connections. Backups are held separately from the primary environment.
If a breach affects your data, we will tell you without undue delay and in any event within 72 hours of becoming aware of it, with what we know, what we are doing and what you may need to do.
Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or give you a copy in a portable format. Email [email protected] and we will respond within 30 days.
We will never charge you for exercising these rights, and we will never treat you worse for having done so.
Your California privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights. We honour them for every customer regardless of where they live, but they are set out here explicitly.
What we collect, in CCPA categories
- Identifiers — name, email, phone, billing address, IP address
- Commercial information — the plan you bought and your payment history
- Internet activity — server logs relating to your use of our service
We collect these to provide and bill for the service, to support you and to keep the service secure. We do not collect sensitive personal information as the CCPA defines it, and we do not use personal information for automated decision-making or profiling.
Do not sell or share
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. There is therefore nothing for you to opt out of, and no "Do Not Sell or Share My Personal Information" mechanism is required. If that ever changes, this section changes first and we will tell affected customers before it takes effect.
Your rights
- Know what we collect, why, and who we disclose it to
- Access a copy of the specific pieces of information we hold
- Correct anything inaccurate
- Delete what we hold, subject to our legal obligation to keep billing records
- Limit use of sensitive personal information — we hold none, so this right has nothing to operate on
- Non-discrimination — we will not deny service, charge a different price or provide a lesser service because you exercised a right
How to exercise them
Email [email protected] with what you would like. We will confirm within 10 business days and respond substantively within 45 days. An authorised agent may act for you with written permission from you.
Residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comparable laws have substantially the same rights, and the same address reaches us.
Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16.
Changes and contact
We will post any change here with a new effective date, and will email customers directly about anything that materially affects them.
Privacy questions, requests and complaints: [email protected], or write to Kyoken Labs Inc., New York, United States.