Privacy

Collect less. Access only what the work needs.

Our preferred operating model reduces the amount of sensitive customer information WebAgencyOn needs to receive in the first place.

Website enquiries and briefs

When you submit a brief, we receive the information you deliberately provide, such as company/agency name, work email, project context and the selected form. Do not include passwords, recovery codes, payment-card information or private API keys in an ordinary project form.

Domain and hosting purchases through third parties

Where practical, WebAgencyOn recommends that the final client or agency contract the domain and hosting directly with the relevant provider. We may send the appropriate provider link and guide the setup, but the customer enters billing, identity and account information directly with that provider. This reduces unnecessary handling of sensitive purchasing and account data by WebAgencyOn.

The third-party provider processes that purchase under its own terms and privacy notice. If a referral or affiliate relationship applies to a link, it should be disclosed.

Remote assistance

For attended remote work, the client or agency may open the required hosting, registrar, DNS or administration panel on its own device and remain present during the session. You can type sensitive credentials yourself. Unrelated private folders, applications and documents should remain closed.

Remote sessions are not intended as permission to inspect, retain or use unrelated information. Unattended access is not required by default and should only be enabled when an ongoing arrangement specifically requires it.

Confidentiality and personal data processed for a client

Project and operational information accessed for delivery is treated as confidential within the scope of the engagement. If WebAgencyOn processes personal data on behalf of a client, the roles and obligations should be documented as required by applicable data-protection law, including instructions, purpose, confidentiality, security and return/deletion responsibilities where applicable.

For EU/EEA personal-data work, this may include an Article 28 GDPR data-processing agreement where WebAgencyOn acts as processor on the controller’s instructions.

Technical data and minimisation

Hosting, network and security providers may process ordinary request data needed to operate and protect the website. The WebAgencyOn application does not intentionally create an advertising profile from that information. Form protection is designed around data minimisation and short-lived anti-abuse controls.

Cookies and anti-abuse controls

Secure session cookies may be used for form security. They are not advertising cookies. A temporary derived client key may be used for rate limiting without intentionally storing the raw network address in the application’s rate-limit file.

Retention

Initial enquiry information is intended to be removed from active working records within 7 days when no relationship proceeds, unless retention is needed for an ongoing project, contract, accounting/legal obligation or claim. Project records are retained only as reasonably necessary for the engagement and applicable obligations.

Contact

Privacy enquiries: [email protected].

Start a brief