Privacy Policy

DATED 2023-07-28 · VERSION 20230802_rev01 · COMPARED WITH 20230601_rev01 · ARCHIVE SNAPSHOT

Full text changes — 20230601_rev01 to 20230802_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1(Updated: January 3, 2023)
1(Updated: July 28, 2023)
22
33WPEngine, Inc. ("WP Engine," "we," "us," "our") maintains this Privacy Policy to inform you of our practices with regard to personal data we collect from or about you in connection with our web site (the "Site") or through the provision of our services (the "Services"). We may update this Privacy Policy from time to time. We will notify you of any significant change by providing a notice on our web site or, if you are a customer, by whatever other means upon which we have mutually agreed. The current version of this Privacy Policy may be found at [https://wpengine.com/legal/privacy/](https://wpengine.com/legal/privacy/). By using the Site or the Services you acknowledge your consent to the practices described herein.
44
55If you are a customer who is subject to the privacy laws of California or the European Union, the Data Privacy Addendum located at [https://wpengine.com/legal/dpa/](https://wpengine.com/legal/dpa/) as it may be updated from time to time governs the obligations between us with regard to personal data as defined by such laws.
66
77**Personal Data We Collect**
3030We remain responsible for compliance with this Privacy Policy by third parties to whom we disclose your personal data.
3131
3232- **Procedures to Protect Personal Data.** We have put in place reasonable measures and appropriate procedures for implementing these policies and for safeguarding the personal data we collect. However, we cannot guarantee that personal data we collect will never be disclosed in a manner inconsistent with this Privacy Policy. We follow generally accepted standards to protect the personal data submitted to us, both during transmission and once it is received.
3333
3434- **Your Rights over Personal Data that We Control.** Upon request, we will provide you with details regarding your personal data that has been collected by us or which is under our control. If you would like to change information that we maintain about you, you may log into your account and change it or submit a support request for any information to which you don't have access or the ability to change yourself. Information covered by this Privacy Policy may be deleted upon your request, provided that such deletion may impact our ability to provide you with the Services. You may also request that we update or correct your personal data by writing us at: WPEngine, Inc., Attn: Legal Department, 504 Lavaca St., Ste. 1000, Austin, Texas 78701, or by sending an email to [\[email protected\]](https://wpengine.com/cdn-cgi/l/email-protection) We will respond to your request within a reasonable timeframe. You may opt-out of receiving most e-mails from us by following the "unsubscribe" instructions provided in the e-mails. Alternatively, you may contact us as described herein. If you are our customer, you may not be able to opt out of all emails, including certain administrative or billing communications which are important to the ongoing maintenance of your account. We may keep your personal data for as long as reasonably required to meet the purposes described herein. Additionally, we will retain this information as required by law, as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
3535
36- **EU-US and Swiss-US Privacy Shield. On July 16, 2020, the Court of Justice of the European Union issued a judgment declaring the European Commission's Decision (EU) 2016/1250 of July 12, 2016 as invalid on the adequacy of the protection provided by the EU-U.S. Privacy Shield. As a result of that decision, the EU-U.S. Privacy Shield Framework is no longer a valid mechanism to comply with European Union data protection requirements when transferring personal data from the European Union to the United States. Nonetheless, the U.S. Department of Commerce continues to administer the Privacy Shield program and we participate in and continue to comply and maintain certification with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework.** We are committed to subjecting all personal data received from European Union member countries, United Kingdom, and Switzerland, respectively, in reliance on each Privacy Shield Framework, to the Framework's applicable Principles. To learn more about the Privacy Shield Frameworks, visit the U.S. Department of Commerce's Privacy Shield List at [https://www.privacyshield.gov/list](https://www.privacyshield.gov/list). Under the Privacy Shield Frameworks, we are responsible for the processing of personal data that we collect from you and subsequently transfer to a third party acting as an agent on our behalf. We comply with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland including the onward transfer liability provisions. With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, we are subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including requests made to meet national security or law enforcement requirements. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at [https://feedback-form.truste.com/watchdog/request](https://feedback-form.truste.com/watchdog/request). Under certain conditions more fully described on the Privacy Shield website located at [https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint](https://www.privacyshield.gov/article), you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
36- **EU-U.S. and Swiss-U.S. Data Privacy Frameworks.** We comply with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF") and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") (collectively, the "DPFs") as set forth by the U.S. Department of Commerce. We have certified to the U.S. Department of Commerce that we adhere to the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF, and that we adhere to the Swiss-U.S. DPF Principles with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF (collectively, the "DPF Principles"). To learn more about the Data Privacy Framework program, and to view our certification, please visit [https://www.dataprivacyframework.gov](https://www.dataprivacyframework.gov/). Under the DPFs, we are responsible for the processing of personal data that we collect from you and subsequently transfer to a third party acting as an agent on our behalf. We comply with the DPF Principles for all onward transfers of personal data from the EU and Switzerland including the onward transfer liability provisions. The U.S. Federal Trade Commission has jurisdiction over our compliance with the DPFs. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including requests made to meet national security or law enforcement requirements. If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the DPF Principles shall govern. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at [https://feedback-form.truste.com/watchdog/request](https://feedback-form.truste.com/watchdog/request). Under certain conditions more fully described on the Data Privacy Framework website located at [https://www.dataprivacyframework.gov/s/article/How-to-Submit-a-Complaint-Relating-to-a-Participating-Organization-s-Compliance-with-the-DPF-Principles-dpf](https://www.dataprivacyframework.gov/s/article/How-to-Submit-a-Complaint-Relating-to-a-Participating-Organization-s-Compliance-with-the-DPF-Principles-dpf), you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
3737
3838- **California Residents.** If you are a resident of the State of California, this Section addresses your rights and our obligations under the California Consumer Privacy Act of 2018 and California Privacy Rights Act of 2023 (collectively the "California Privacy Laws"). Terms used in this Section have the same meaning as provided in the California Privacy Laws.
3939
4040**Information We Collect** Our Site collects information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device ("personal information"). In particular, our Site has collected the following categories of personal information from visitors within the last 12 months:
4141
4242Category: Identifiers.