Need a WordPress website built or improved? Start your project with us. Start Your Project

Content Privacy

Content Privacy

How We Handle Customer Content and Website Access.

This Content Privacy Policy explains how non-public website content, credentials, Project files, databases, technical information and other materials may be received, accessed, used, protected, retained and handled when Esposearch performs authorized WordPress Projects and related support.

Share only the access and information reasonably necessary for the agreed Project.

Have a Content Privacy question? Contact Esposearch →
Minimum Necessary Access Share or access only what the Project reasonably requires.
Purpose-Limited Use Customer Content should remain connected to authorized work.
Responsible Access Credentials and website access should be handled carefully.
Customer Control Restricted or temporary access is preferred where practical.
Applies To Esposearch.net
Policy Focus Customer Content & Technical Access
Company Esposearch Limited
Last Updated 29 September 2026

This Content Privacy Policy primarily addresses customer-controlled website and Project materials. Personal information is addressed separately in the Privacy Policy. Customer Content can itself contain personal information, in which case both policies may be relevant.

Content Privacy at a Glance

A practical standard for entrusted website and Project content.

Esposearch may need access to websites, Project materials, credentials, technical records or confidential business information to perform authorized work. Customer Content should remain connected to that authorized purpose and should not be accessed, retained or reused merely because it has been made available.

01

Customer Rights Remain

Making material available to Esposearch does not by itself transfer ownership of the underlying content.

02

Access Should Be Limited

Customer Content should be accessed only where reasonably relevant to the authorized work.

03

Confidential Material Has a Purpose

Non-public Project information should not be used for unrelated purposes without an appropriate basis.

04

Remove Unneeded Access

Temporary credentials and permissions should be revoked or reduced when continuing access is no longer required.

01

1. Scope

This Content Privacy Policy applies to Customer Content submitted to, shared with or made accessible to Esposearch in connection with custom WordPress Projects and related professional work.

Depending on the requirement, this may include WordPress Infrastructure, Design & Development, WordPress SEO, Website Performance, WordPress Security, WooCommerce, Content & Publishing, Analytics & Conversion, Maintenance & Troubleshooting, AI & Automation and related support.

The Policy may also apply to content received during pre-Project discussion, requirement review, quotation or scope preparation, diagnostics, troubleshooting or other service clarification before a formal Project begins.

02

2. Who We Are

Esposearch.net is a brand of Esposearch Limited (registered in Kenya). Esposearch operates as a Specialist WordPress Agency delivering agency-managed custom WordPress Projects.

AI & Automation is one professional capability within the wider WordPress service structure and does not replace Esposearch’s core WordPress specialization.

Website: https://esposearch.net/
Email: admin@esposearch.net

03

3. What Counts as Customer Content

“Customer Content” means materials that a customer owns, controls or is authorized to provide and that Esposearch receives or accesses for authorized work.

Depending on the Project, Customer Content may include website text, images, video, branding, documents, spreadsheets, WordPress files, databases, configuration files, screenshots, error logs, source code, custom code, CSS, JavaScript, product information, WooCommerce records, form submissions, CRM exports, hosting information, DNS information, credentials, API configuration, business documents, Project instructions, datasets, AI knowledge material, AI prompts, AI outputs and support communications.

Not every Project requires every category. Esposearch should request or access only the material reasonably relevant to the authorized work.

04

4. Ownership of Customer Content

Customer Content does not become Esposearch property merely because it is uploaded, emailed, shared, accessed, analyzed, modified, copied temporarily or otherwise processed during Project delivery.

Customer ownership is respected. Providing content to Esposearch does not by itself transfer ownership of the underlying material.

Underlying ownership remains with the customer, original rights holder or applicable third party, subject to the Project agreement and applicable law.

WordPress core, third-party plugins, themes, APIs, licensed assets, open-source software, stock materials and other external systems remain subject to their own ownership and licensing terms.

05

5. Limited Permission to Process Content

By making Customer Content available for authorized work, the customer gives Esposearch limited permission to access, copy where necessary, analyze, configure, modify, transmit, temporarily store, test, migrate, troubleshoot or otherwise process that content to the extent reasonably necessary for the Project.

Processing may also be reasonably necessary for related support, security, Project administration or applicable legal obligations.

This limited permission is not a transfer of ownership and does not authorize unrelated commercial use of Customer Content.

06

6. Confidential & Restricted Content

Customer Content may include unpublished business information, customer databases, revenue information, business plans, internal reports, proprietary processes, configuration information, unpublished website content, credentials, customer lists, development environments, analytics information and other non-public material.

Esposearch should use confidential Customer Content only for the authorized Project, related administration, supervision, support, security or applicable legal and compliance purposes.

Customers should identify unusually sensitive or restricted information where practical so that appropriate handling requirements can be considered before work begins.

07

7. Personal Information Inside Customer Content

Customer websites, files and databases may contain personal information relating to customers, employees, subscribers, buyers, website visitors or other individuals.

Where Esposearch processes that information only for customer-directed work, Esposearch may act as a processor, service provider or similar contractor depending on the circumstances and applicable law.

The customer remains responsible for having appropriate authority to provide or make such information accessible where the customer determines the purpose of the processing.

Personal-information handling is addressed further in the Privacy Policy.

08

8. Minimum Necessary Information & Safe Sharing

Customers should share only the content reasonably necessary for the authorized Project. An entire production database should not be provided where a screenshot, limited export, relevant table, test account, error log or other smaller dataset would reasonably support the required work.

Where practical, unnecessary exposure can be reduced by removing irrelevant records, masking sensitive values, using test data, limiting exports or using restricted access.

Minimum Necessary Access Share only the access and information reasonably necessary for the agreed Project.
09

9. Website Credentials & Technical Access

Some Projects may require WordPress administrator access, hosting access, domain or DNS controls, FTP/SFTP, database access, analytics, Search Console, APIs, email administration or integration settings.

Customers should use temporary or restricted accounts where practical, apply role-based permissions, avoid sharing master credentials unnecessarily, rotate passwords afterward where appropriate and revoke temporary access when it is no longer required.

Authorized Esposearch personnel should use credentials only for authorized work, avoid accessing systems beyond the approved scope and must not retain or reuse credentials for unrelated purposes.

Credential Security Temporary or restricted credentials are preferred whenever practical.
10

10. WordPress Administration

WordPress administration can expose users, posts, orders, forms, plugins, themes, settings, database information and administrator controls.

Access should be limited to what is reasonably necessary for the authorized Project. Where a lower-privilege WordPress role is sufficient, that role should be used where practical.

Administrator-level access may be requested where the approved scope reasonably requires that level of control.

11

11. Hosting, Domains & Infrastructure

Infrastructure work may involve hosting dashboards, file systems, databases, DNS records, SSL configuration, domain settings, backups and server or environment information.

These systems can contain non-public configuration or business information. Esposearch should avoid accessing or changing unrelated infrastructure settings and should use only the permissions reasonably required for the confirmed work.

Third-party hosting and infrastructure providers may independently process technical or account information under their own terms and privacy practices.

12

12. WooCommerce & Commerce Data

WooCommerce systems may contain customer names, contact information, orders, addresses, product information, transaction metadata, shipping information and account details.

Esposearch should avoid accessing commerce records unrelated to the authorized Project. Where practical, staging environments, test orders, sandbox payment modes and masked sample data should be used instead of unnecessary production customer information.

Do Not Send Payment Secrets Through Ordinary Support Channels Customers should not send full card numbers, CVV codes, banking passwords or payment-provider passwords through ordinary email or Live Chat.

Where payment testing is required, provider-issued sandbox credentials, customer-controlled authorization or suitably restricted API access is preferred where practical.

13

13. Website Databases & Exports

Database copies and website exports can contain substantially more information than is visible on the public website. They may include user accounts, orders, form submissions, internal settings, logs, tokens, metadata and other sensitive information.

Database exports should be treated as potentially sensitive, used only where reasonably necessary and duplicated as little as practical.

Temporary copies should be removed when no longer reasonably required, subject to legitimate backup, security, contractual or legal needs.

14

14. Files, Documents & Media

Customer Content may include PDFs, word-processing documents, spreadsheets, images, videos, compressed archives, reports, datasets and other Project files.

Customers are responsible for ensuring that they have authority to provide those materials.

Esposearch should not use non-public Project files for unrelated publication, promotion or commercial purposes without an appropriate contractual, legal or customer-authorized basis.

15

15. Screenshots, Logs & Diagnostics

Technical work may involve screenshots, server logs, error messages, plugin reports, browser-console output, performance reports or SEO reports.

These materials may inadvertently contain personal information, usernames, URLs, internal file paths, session information or access tokens.

Unnecessary sensitive information should be avoided, redacted, minimized or restricted where reasonably practical.

16

16. Communications & Support Content

Project and support communications may include email, Live Chat, customer instructions, account communications, technical explanations and Project notes.

These communications may be retained where reasonably necessary for Project delivery, support, administration, context, escalation, billing administration, dispute handling, security or legal records.

Communications should not be assumed to be visible only to one individual professional. Authorized Esposearch personnel may review relevant communications where reasonably necessary for the purposes described above.

17

17. Esposearch Expert Access

Clients engage Esposearch as the agency. Esposearch may coordinate appropriate professional capability internally according to the requirements of a Project.

Where an Esposearch Expert or other authorized professional needs access to Customer Content, that access should be limited to the information reasonably required for the assigned work and may be subject to applicable contractual, confidentiality, Project and data-protection requirements.

Customer Content must not be used for unrelated customer solicitation, personal marketing, independent contact databases, unrelated analysis, unauthorized publication or future unrelated use.

Clients are not expected to manage individual Experts directly merely because professional capability is coordinated internally.

18

18. Service Providers & Technical Vendors

Customer Content may sometimes pass through or be stored by systems reasonably used for Project delivery, such as hosting providers, cloud infrastructure, storage services, email systems, backup services, security tools, support or chat platforms, technical vendors or AI providers.

Where appropriate, Esposearch should consider provider risk proportionately, minimize unnecessary Customer Content and select configurations reasonably appropriate to the sensitivity and purpose of the work.

Specific providers should be identified publicly only where verified and useful for transparency or where contract or law requires such disclosure.

19

19. AI Tools & Customer Content

Esposearch may use AI-assisted tools where appropriate, and some customer Projects may include AI or automation functionality. Customer Content should not automatically be submitted to a third-party AI provider merely because AI tools are available.

Before using AI with Customer Content, relevant considerations may include whether AI processing is necessary, the sensitivity and confidentiality of the content, whether personal information is involved, provider terms, retention practices, model-improvement settings, international processing, customer instructions and the Project requirement.

AI & Confidential Content Confidential Customer Content should not automatically be submitted to third-party AI systems.
20

20. AI Inputs, Outputs & Model Providers

Customer-supplied prompts, documents, knowledge-base material, datasets and instructions remain Customer Content to the extent the customer or relevant rights holder owns those rights.

Esposearch does not intend to use confidential Customer Content for unrelated general model-training purposes. However, third-party AI providers may have their own retention, abuse-monitoring, model-improvement, training and privacy terms depending on the product, account and configuration used.

For highly confidential material, the suitability of AI processing should be considered before use. A private or enterprise configuration may be appropriate where available, or AI processing may be avoided where it is not suitable.

AI-generated output can also be subject to provider terms, factual limitations, copyright law and third-party rights. Esposearch does not promise exclusive ownership of every AI-generated output.

21

21. Content Use Restrictions

Esposearch should not use confidential Customer Content for unrelated advertising, public posting, independent commercial resale, data brokerage, Expert self-promotion, unrelated datasets, unrelated analysis, unrelated AI training or public portfolio publication without an appropriate contractual, legal or customer-authorized basis.

Customer Content should remain connected to the purposes of the authorized Project, support activity, legal obligation or other specifically authorized use.

22

22. Portfolio, Testimonials & Public Use

Esposearch does not automatically publish completed customer work, non-public screenshots, confidential Project descriptions or private customer materials in portfolios, case studies, social posts or marketing materials.

Where customer authorization is required, permission should be obtained before non-public Project content is used publicly.

Publicly accessible website information may have a different confidentiality status, but non-public Project information and the customer relationship should still be handled appropriately.

Permission to publish testimonial text does not automatically include permission to publish the customer’s logo, confidential Project details, job title or other identifying material unless the permission reasonably covers that use.

23

23. Intellectual Property & Deliverables

Customer Content, third-party materials, open-source software, licensed themes and plugins, Esposearch pre-existing materials and newly created Project deliverables can have different ownership and licensing rules.

Ownership or licensing of Project-specific deliverables follows the applicable Project terms, agreed scope, payment status where applicable, third-party licenses and applicable law.

Receipt of a finished deliverable does not automatically transfer rights in software, assets or materials that Esposearch does not own or cannot lawfully transfer.

24

24. Backups & Temporary Copies

Esposearch may create temporary backups, staging copies, database copies, development copies or local working files where reasonably necessary to perform, test, migrate, troubleshoot or protect authorized work.

Such copies should not be treated as permanent storage unless the approved Project specifically includes ongoing backup or storage.

Temporary copies should be removed when no longer reasonably required, subject to technical constraints, backup requirements, legitimate security needs, legal obligations or dispute records.

25

25. Content Storage

Project content may be stored temporarily or operationally in website systems, support or communication systems, Project records, backups, cloud infrastructure or service-provider systems actually used for the applicable work.

Storage location depends on the technologies and providers involved. Esposearch does not represent that all Customer Content is stored exclusively in Kenya.

Where a customer requires a specific storage location, infrastructure restriction or data-residency arrangement, that requirement should be raised before Project acceptance and may require additional Project-specific arrangements.

26

26. International Processing

Hosting, cloud, communication, technical and AI service providers may process Customer Content outside Kenya, outside the customer’s country or outside the country in which the content originated.

Where Customer Content includes personal information, international data-protection considerations are addressed further in the Privacy Policy.

Esposearch does not guarantee that every processing country provides identical legal protections. Where applicable law requires a particular transfer mechanism or safeguard, the relevant arrangement should be addressed as required.

27

27. Retention

Customer Content may be retained for periods reasonably necessary for active Project delivery, support, quality review, transaction records, accounting, dispute handling, security, legal claims or legal compliance.

Different content types can require different retention periods. Temporary credentials may require much shorter retention than invoices, contractual records or Project correspondence.

Esposearch does not use one universal fixed retention period for every category of Customer Content.

28

28. Deletion & Removal

Customers may request removal of eligible Project content where Esposearch no longer reasonably needs it and applicable law, contractual obligations or legitimate operational requirements do not require continued retention.

Deletion may be limited where retention is reasonably necessary for transaction records, legal obligations, disputes, security, fraud prevention, backups or legal claims.

Deletion from active systems does not necessarily mean instantaneous removal from every backup or replica. Backup copies may remain until overwritten, expired or otherwise handled through the applicable backup lifecycle.

After Project completion, customers should revoke or rotate temporary credentials where appropriate. Esposearch should no longer use access that is unnecessary for continuing maintenance, support or another authorized engagement.

29

29. Security

Esposearch seeks to use reasonable administrative, organizational, contractual and technical safeguards appropriate to the circumstances of the Customer Content and Project.

Depending on the context, these measures may include restricted access, authentication, minimum-necessary permissions, temporary credentials, software maintenance, confidentiality expectations, backups where appropriate and responsible use of service providers.

No Absolute Security No online system, website, storage service or transmission method can guarantee complete security.

Detailed internal security architecture is not published through this Policy.

30

30. Security Incidents

If Esposearch becomes aware of unauthorized access, disclosure, loss or another security incident materially affecting Customer Content, Esposearch may investigate, contain, remediate and document the incident.

Esposearch may notify the affected customer or other relevant parties where appropriate or legally required.

The response depends on the severity, the content involved, Esposearch’s role, applicable contractual requirements and applicable law. This Policy does not establish one fixed notification deadline for every incident or jurisdiction.

31

31. Customer Responsibilities

Customers are responsible for having authority to share Customer Content, providing lawful materials, identifying unusual sensitivity where practical, minimizing unnecessary information, protecting credentials and maintaining appropriate backups where required.

Customers should remove obsolete temporary access after completion, avoid sending unnecessary sensitive information and notify Esposearch of special handling requirements before the relevant work begins.

Customers remain responsible for their own applicable privacy and data-protection obligations to website users, customers and other individuals whose information they control.

The person instructing Esposearch should have lawful authority to authorize access to the relevant website, system and Customer Content, including where that person acts for another business or organization.

32

32. Prohibited Content

Customers must not knowingly use Esposearch to store, transmit or process content that is unlawful, contains malware, infringes intellectual-property rights, was obtained through unauthorized access, facilitates fraud, contains unlawfully obtained credentials, instructs unauthorized intrusion or otherwise violates applicable law or the Terms & Conditions.

Esposearch may refuse, suspend or discontinue work involving content or instructions that create material legal, security or integrity concerns.

34

34. Enterprise, NDA & Additional Requirements

Customers with heightened confidentiality, security or procurement requirements may request additional Project-specific arrangements such as a non-disclosure agreement, confidentiality terms, Data Processing Agreement, restricted Expert access, service-provider information, data-location requirements or enterprise AI restrictions.

Such requirements should preferably be raised before the relevant Project is accepted. Esposearch may review appropriate arrangements but does not automatically accept every requested contractual or technical condition.

Customers requiring tailored handling can Discuss Their Requirements before submitting or finalizing the Project.

35

35. Changes to This Policy

Esposearch may update this Content Privacy Policy to reflect changes in services, technical practices, AI-assisted tools, service providers, storage systems, security practices or legal requirements.

The current version should display a genuine Last Updated date. Where applicable law or an existing agreement requires additional notice for a material change, Esposearch should provide the appropriate form of notice.

37

37. Contact

For Content Privacy questions, contact:

Esposearch Limited
Esposearch.net is a brand of Esposearch Limited (registered in Kenya).
Website: https://esposearch.net/
Email: admin@esposearch.net
Contact: https://esposearch.net/contact/

Live Chat Is for General Guidance Do not submit passwords, API secrets, payment-card information, banking credentials, complete databases, government identifiers or highly sensitive files through ordinary Live Chat.
Content Privacy Questions?

Ask before sharing sensitive website or Project content.

If you are unsure what information a Project requires, ask before sending credentials, databases, customer information or confidential business material.

You can also review the Terms & Conditions. Live Chat may be used for general clarification, but sensitive credentials or confidential files should not be sent through ordinary chat.