Effective date: 4 September 2026
Forms part of: The WP Geeks Care Plan Terms of Service and the WP Geeks Development Rates and Terms of Service.
Why this document exists
When we maintain your website, we can see the personal data your website holds — your customers’ names, email addresses, orders, form submissions, member accounts. We back that data up. We can read it. We could change it.
That data is yours, not ours. This document sets out what we’re allowed to do with it, what we must do to protect it, and what happens when something goes wrong. It’s the contract that data protection law requires between a business and the suppliers who handle its data.
You can sign it, or you can rely on it as published — either works, and clause 12 explains how.
1. Who is who
You are the controller. You decide what personal data your website collects, why, and for how long.
We are the processor. UpThink Limited, trading as WP Geeks, a limited company incorporated in Hong Kong (company number 2226128), registered office Flat/Rm A-C, 25/F, Seabright Plaza, 9-23 Shell Street, North Point, Hong Kong. We handle that data only to deliver the services you’ve bought.
Where the terms controller, processor, sub-processor, personal data, processing, data subject and personal data breach appear here, they carry the meaning given by whichever data protection law applies to you — the EU GDPR, the UK GDPR, the California Consumer Privacy Act as amended, any other US state privacy law, the Hong Kong Personal Data (Privacy) Ordinance, or an equivalent.
Under US state privacy law, we are a service provider (California) or a processor (Virginia, Colorado, Connecticut, Texas, and the rest). We do not sell or share your personal data, we do not use it for cross-context behavioural advertising, and we do not combine it with data from anywhere else. We use it only to perform the services, and for no other purpose. We’re happy to certify that in writing on request.
2. What we’re allowed to do
We process personal data only on your documented instructions.
Your instructions are: this document, the care plan or development terms, your plan’s published inclusions, and anything you ask us to do in writing through our normal support channels.
We will not use your data for our own purposes, sell it, share it, or use it to train anything.
If we ever believe an instruction of yours breaks the law, we’ll tell you and we may pause that instruction until it’s resolved.
If a law compels us to process your data some other way, we’ll tell you first, unless that law forbids us from telling you.
3. What we handle
Categories of data subject: your website’s customers, members, subscribers, commenters, form submitters, and your own staff who have accounts on the site.
Categories of personal data: whatever your website stores. Typically names, email addresses, postal addresses, phone numbers, usernames, hashed passwords, IP addresses, order and payment history (not full card numbers), support messages, membership and course records, and analytics identifiers.
Special category data: we don’t ask for it and we don’t want it. If your website collects health, biometric, religious, political, racial, sexual-orientation, trade union, criminal or children’s data, tell us before we start, so we can agree extra safeguards or decline the work.
Nature and purpose of processing: hosting-adjacent maintenance. Taking and storing backups; applying updates; scanning for and removing malware; monitoring; diagnosing and fixing faults; making content edits you request; and development work you commission.
Duration: for as long as your plan runs, plus the retention periods in clause 9.
4. Our people
Everyone we let near your data is bound by a written confidentiality obligation that survives the end of their engagement, is given access only to what their job needs, and is trained on how to handle it.
5. Security
We maintain appropriate technical and organisational measures to protect personal data. As of the effective date, those include:
- Named individual accounts. Every person who touches a client site has their own account. We do not use shared logins.
- Two-factor authentication on every account that supports it — WordPress, hosting, backup provider, password manager, email.
- A password manager with a separate vault per client. Credentials are never sent by email or chat.
- Least privilege. Access is granted per client, per task, and reviewed at least quarterly.
- Encryption in transit (TLS/HTTPS/SFTP) for all connections to client systems, and encryption at rest for backups held by our backup provider.
- Backups held with a reputable third-party provider, on the retention schedule in our Sub-processor List.
- Endpoint protection — full-disk encryption, automatic screen lock and current operating systems on every device used for client work.
- Offboarding. Access is revoked within 24 hours of a person leaving or an engagement ending.
- An access register recording who has access to which client systems.
- A written incident response plan, reviewed at least annually.
We may change these measures as technology moves on, but we won’t materially reduce the level of protection.
Full details are in our Access and Credential Security Policy, available on request.
6. Sub-processors
You give us general authorisation to use sub-processors. The current list, with what each one does and where it is, is published at wpgeeks.co/sub-processors/ and reproduced in our Sub-processor List.
Before we add or replace a sub-processor we’ll give you at least 21 days’ notice by email, or by an update to that page if you’ve subscribed to change notices there.
You can object within those 21 days, on reasonable data protection grounds. If you do, we’ll try to find an alternative. If we can’t, either of us may terminate the affected part of the service, and we’ll refund the unused portion of any fees you’ve paid in advance. That’s your only remedy for an objection.
Every sub-processor is bound by written obligations no less protective than this document, and we remain fully liable to you for what they do.
7. Helping you meet your obligations
Data subject requests. If one of your customers contacts us to access, correct, delete or export their data, we won’t respond ourselves. We’ll forward it to you within 3 working days and help you deal with it. Reasonable assistance is included; anything substantial we’ll quote for.
Assessments. We’ll give you the information you reasonably need for a data protection impact assessment, a vendor security review, or a regulator’s enquiry.
Audits. Once a year, on 30 days’ written notice, you can ask us for evidence that we’re doing what this document says — our security policy, our access register, our sub-processor list, and answers to a reasonable security questionnaire. If your regulator requires an on-site audit, we’ll cooperate, and you’ll cover our reasonable costs.
8. When something goes wrong
We will notify you of a personal data breach affecting your data without undue delay, and in any event within 24 hours of becoming aware of it.
Our notice will tell you, as far as we know at the time: what happened and when, what categories of data and roughly how many people are affected, what the likely consequences are, and what we’re doing about it. If we don’t have all of it at first, we’ll send what we have and follow up.
We’ll help you meet your own notification deadlines — including the 72-hour deadline under the EU and UK GDPR, and the deadlines in US state breach notification laws, which in most states require whoever holds another business’s data to notify that business promptly.
We won’t notify your customers or a regulator on your behalf unless you ask us to in writing. That’s your decision to make.
We’ll keep a record of every breach, and we won’t publicly identify you in connection with one without your consent, unless the law requires it.
9. Returning and deleting data
When your plan ends, or on your written request at any time:
- We remove our access to your systems.
- We keep our backups of your site for 30 days, so you can ask for a copy, and then delete them.
- We delete personal data from our own tools — helpdesk, project management, notes — within 90 days, except for what we need to keep for billing, tax and legal records.
- We’ll confirm in writing that we’ve done it, if you ask.
Where a sub-processor’s retention schedule is longer, we’ll tell you what it is.
10. Where your data goes
We are established in Hong Kong and our people work from Thailand. Our sub-processors are listed with their locations in our Sub-processor List. So personal data will be accessed from, and stored in, countries outside your own.
For US clients: this is a disclosure, not a restriction. US law doesn’t limit these transfers, but you should know they happen so your own privacy notice is accurate.
For clients in the EU, EEA, UK or Switzerland: Hong Kong does not have an adequacy decision. Where you need one, we will enter into the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Four where you are the processor and Module Two where you are the controller, together with the UK Information Commissioner’s International Data Transfer Addendum for UK data, and we’ll provide a transfer impact assessment. Ask us and we’ll annex them to this document.
For clients in Hong Kong: we’ll adopt the Privacy Commissioner’s Recommended Model Contractual Clauses on request.
11. Liability
Each party’s liability under this document is subject to the limitation of liability in the Care Plan Terms of Service or the Development Rates and Terms of Service, whichever applies — except where the applicable data protection law says liability can’t be limited that way.
12. How this document is agreed
This addendum takes effect automatically as part of your agreement with us, from the date you first subscribe or from the effective date above, whichever is later.
If your organisation needs a countersigned copy, email support@wpgeeks.co with your entity’s full legal name and address and we’ll return a signed version within 5 working days.
If we update this document, we’ll email you 30 days before the change takes effect. Changes won’t reduce the protections you have for data we’re already handling.
13. Order of precedence
If this addendum conflicts with the Care Plan Terms of Service, the Development Rates and Terms of Service, or the Privacy Policy, this addendum wins on anything to do with personal data we handle on your behalf.
If it conflicts with the Standard Contractual Clauses once those are in place, the Clauses win.
WP Geeks is a service of UpThink Limited, a limited company incorporated in Hong Kong. Company number 2226128 · Business Registration number 64643460. Registered office: Flat/Rm A-C, 25/F, Seabright Plaza, 9-23 Shell Street, North Point, Hong Kong. Data protection contact: privacy@upthinkisgood.com.