Privacy Policy
Privacy Policy
We have reviewed and updated our privacy practices in line with the 2026 reforms to the
Privacy Act 1988 (Cth), including the narrowing of the small business exemption.
Web Security Pro — a division of Internet Marketing Direct Pty Ltd ABN 84 374 653 342
Last Reviewed: 14th July 2026
Web Security Pro ("we", "us", "our") is a division of Internet Marketing Direct Pty Ltd, providing WordPress website security, maintenance, and emergency remediation services to Australian businesses via https://websecuritypro.com.au.
We are committed to protecting your personal information and handling it in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and where applicable, the General Data Protection Regulation (GDPR).
1. What Information We Collect
When you interact with our website, purchase a service, or contact us, we may collect the following personal information:
- Identity & Contact Information: Full name, business name, email address, phone number, and postal address.
- Account & Credential Information: Website URL, hosting login credentials, WordPress admin credentials, and other access details submitted through our client onboarding intake form (required to deliver services).
- Billing & Payment Information: Billing address, payment method details, and transaction history. All payment processing is handled by Stripe. We do not store your full card details on our systems.
- Technical & Usage Information: IP address, browser type, operating system, pages visited, and time spent on our website.
- Communications: Records of correspondence, support requests, and emails between you and our team.
- Free Security Scan Submissions: Your name, business website URL, and email address submitted via our free scan tool.
2. How We Use Your Information
We use the personal information we collect for the following purposes:
- To deliver and manage your purchased services (Essential, Peace of Mind, Done For You, or Emergency Malware Remediation).
- To process payments and manage billing through Stripe.
- To communicate with you about your account, service updates, security alerts, and support requests.
- To onboard your website and securely configure our security and maintenance infrastructure.
- To send your monthly security reports and performance updates.
- To respond to free security scan requests and deliver your plain-English scan report.
- To improve our services, website, and client experience.
- To comply with our legal obligations and protect our legal rights.
We will not use your personal information for unrelated purposes without your consent.
3. How We Store and Protect Your Information
- We take reasonable technical and organisational steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.
- Security measures include encrypted data transmission (SSL/TLS), access controls, secure credential storage, and limited internal access on a need-to-know basis.
- Website credentials and sensitive access details submitted through our onboarding intake form are stored securely and accessed only by the engineers responsible for delivering your service.
- Payment information is processed and stored by Stripe in accordance with PCI-DSS standards. We do not store full card numbers on our systems.
4. Who We Share Your Information With
We do not sell your personal information. We may share it with:
- Our Team: Employees and contractors involved in delivering your services, on a need-to-know basis.
- Service Providers: Third-party platforms and tools we use to operate our business, including Stripe (payment processing), n8n (workflow automation), and our hosting infrastructure providers. These parties are contractually required to handle your information in accordance with applicable privacy laws.
- Legal & Regulatory Authorities: Where required by law, court order, or to protect our legal rights.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the relevant successor entity, with notice provided to you where required.
5. Client Credential Data — Special Note
For clients on any monthly plan or the Emergency Malware Remediation service, you will be asked to submit hosting and WordPress credentials through our secure onboarding intake form. This data is:
- Used solely for the purpose of delivering your contracted services.
- Accessible only by our technical team members assigned to your account.
- Not shared with any third party except as strictly required to resolve a technical issue (e.g., your hosting provider's support team).
- Retained only for as long as your service is active. Upon cancellation, you should change your credentials as a matter of good security hygiene, and we will delete any stored access details within 30 days of your service ending.
6. Data Retention
We retain your personal information for as long as necessary to:
- Provide your active services.
- Comply with our legal and tax obligations (typically 7 years for financial records under Australian law).
- Resolve disputes or enforce our agreements.
When your personal information is no longer required, we will take reasonable steps to securely destroy or de-identify it.
7. Your Rights
Australian residents have rights under the Privacy Act 1988 (Cth) and the Australian Privacy
Principles, including the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Make a complaint if you believe we have mishandled your personal information.
Individuals in the European Economic Area (EEA) may have additional rights under the GDPR,
including the right to erasure, data portability, restriction of processing, and the right to object.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website, including for analytics,
advertising, and remarketing/retargeting purposes.
When you first visit our website, you will be asked to actively provide your consent before any non-essential cookies (including advertising and analytics cookies) are set.
You can accept all cookies, reject non-essential cookies, or manage your preferences in detail at any time using the cookie preference tool available on our website.
Essential cookies required for the website to function correctly do not require consent and cannot be disabled.
You may also manage or clear cookies through your browser settings, however this is in
addition to, not instead of, the consent controls provided on our website.
9. Automated Decision-Making
Our website includes tools, such as our Free WP Security Assessment quiz, that use automated processes to generate a risk score or assessment based on the information you provide. These results are provided for informational purposes and do not result in any automated decision that produces a legal or similarly significant effect on you without the opportunity for human review. Any recommendations or offers arising from your results are reviewed and followed up by a member of our team.
10. Data Breach Response
We maintain a data breach response plan in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will assess the breach and, where required, notify both the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with our legal obligations.
11. Complaints
If you believe we have breached the Australian Privacy Principles or your privacy rights, please contact us in the first instance at [email protected]. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be posted on this page with an updated effective date. We encourage you to review this page periodically.
13. Overseas Disclosure
Some of the third-party service providers we use, including Stripe, may store or process
personal information outside Australia. Where this occurs, we take reasonable steps to ensure
these providers handle your information in a manner consistent with the Australian Privacy
Principles.
14. Contact Us
For all privacy-related enquiries or requests:
Web Security Pro A division of Internet Marketing Direct Pty Ltd ABN: 84 374 653 342 Phone: (07) 5609 9457 Email: [email protected] Website: https://websecuritypro.com.au
