This Privacy Policy explains how WordPress97 (the web agency operating at wordpress97.com) collects, uses, stores, and protects the personal information you share with us when you visit our website, contact us, or engage our services.
WordPress97 is a full-service web agency operating under the business name ‘WordPress97’, founded and operated by Muhammad Irfan. We provide web design, WordPress development, SEO, digital marketing, content writing, website security, and site migration services primarily to businesses in the United States, United Kingdom, and globally.
We collect personal data in two ways: information you provide to us directly, and information collected automatically through your use of our website.
When you visit wordpress97.com, we and our third-party service providers collect certain information automatically through cookies and similar technologies:
This data is collected via Google Analytics 4 (GA4) and Google Search Console. It is used in aggregate form to understand how visitors use our website and to improve our content and user experience. We do not use this data to identify individual visitors.
We use the personal data we collect for the following purposes:
To respond to your enquiries
When you contact us via our contact form, email, or WhatsApp, we use your contact details and project description to respond to you and provide the information or service you requested.
To prepare and deliver proposals
We use the project details you provide to scope your project, prepare a written proposal, and if you proceed, to deliver the services outlined in that proposal.
To manage your project
During an active project, we use your contact information and project details to communicate progress updates, request approvals, deliver work, and provide post-launch support.
To send service-related communications
We send monthly performance reports, maintenance reports, and project updates to clients on ongoing retainer services. These are not marketing emails — they are operational communications directly related to the services you have engaged.
To process payments
We use your name and email address to issue invoices and confirm payment receipt. We do not handle card payments directly — payments are processed through Wise, PayPal, Payoneer, or bank transfer, each with their own privacy policies.
To improve our website
Aggregated, anonymised analytics data from GA4 helps us understand which content is useful, which pages have high bounce rates, and where to focus our content and UX improvements.
To comply with legal obligations
We retain certain business records (invoices, contracts, correspondence) as required by applicable laws and to protect ourselves in the event of a legal dispute.
We do not use your personal data for: automated decision-making, profiling, unsolicited marketing to non-clients, or sale to third parties.
For visitors and clients located in the European Union, United Kingdom, or other jurisdictions where the General Data Protection Regulation (GDPR) or equivalent legislation applies, we process your personal data under the following legal bases:
For US-based visitors, we comply with applicable US privacy laws including the California Consumer Privacy Act (CCPA) where applicable. Under the CCPA, California residents have specific rights regarding their personal information — see Section 8 for details.
We do not sell, rent, or trade your personal data. We share data only with the following categories of third-party service providers, solely to the extent necessary to operate our business:
We may also disclose your personal data if required to do so by law, court order, or governmental authority, or where we reasonably believe disclosure is necessary to protect our legal rights or the safety of others.
Our website uses cookies — small text files stored on your device — to improve functionality and understand how visitors use our site. We use the following types of cookies:
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our website. For more information about managing cookies, visit www.aboutcookies.org. We also maintain a separate Cookie Policy at wordpress97.com/cookie-policy/ with full details of all cookies set.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
12 months from date of last contact, then deleted unless you become a client
5 years after project completion, for legal and warranty purposes
7 years from the date of the transaction, as required by financial regulations
Retained for 26 months in GA4, then automatically deleted
5 years from the date of the correspondence
1 year from date of consent, then re-requested
Depending on your location and applicable law, you may have some or all of the following rights regarding your personal data. We will respond to any valid request within 30 days (or within the timeframe required by applicable law).
You have the right to request a copy of the personal data we hold about you. We will provide this in a structured, commonly used format within 30 days.
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it.
You have the right to request deletion of your personal data where there is no compelling reason for us to continue processing it. Note: we may be required to retain certain records by law.
You have the right to request that we restrict how we process your data in certain circumstances — for example, while we verify the accuracy of data you have disputed.
Where processing is based on your consent or contract performance, you have the right to receive your data in a machine-readable format and to have it transmitted to another controller.
You have the right to object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Where processing is based on your consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.
California residents have the right to know what personal information is collected about them, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.
How to exercise your rights:
Email us at irf297@gmail.com with the subject line ‘Privacy Rights Request’ and specify what you would like us to do. We will respond within 30 days. We may ask for proof of identity before processing your request.
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction:
• SSL/TLS encryption on all website connections (HTTPS enforced)
• Password-protected access to all systems holding personal data
• Two-factor authentication (2FA) on all administrative accounts
• Regular security audits of our own website and systems
• reCAPTCHA v3 on all public-facing forms to prevent automated attacks
• Cloudflare DDoS protection on our website
• Personal data accessed only by team members who need it to perform their role
• All team members informed of their data protection responsibilities
• Client credentials and sensitive project data stored securely with restricted access
• Third-party service providers evaluated for their own security and privacy standards before use
• Incident response procedure in place for data breaches
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and any relevant supervisory authority as required by applicable law.
WordPress97 is based in Pakistan and serves clients primarily in the United States and United Kingdom. When you interact with our website or contact us, your personal data may be transferred to and processed in Pakistan.
Pakistan is not currently considered an ‘adequate’ jurisdiction for data protection purposes under UK GDPR or EU GDPR. Where transfers of personal data from the UK or EU to Pakistan occur, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) where applicable, and ensure that recipients of your data are bound by appropriate data protection obligations.
Personal data provided by US visitors is subject to applicable US federal and state privacy laws. We do not sell personal information as defined under the CCPA or any other US state privacy legislation.
Our third-party service providers (Google, Meta/WhatsApp, Wise, PayPal) maintain their own international transfer mechanisms and privacy policies, which we encourage you to review.
Our website and services are directed exclusively at business owners, marketing professionals, and other adults acting in a professional capacity. We do not knowingly collect personal data from individuals under the age of 18.
If you believe we have inadvertently collected personal data from a minor, please contact us immediately at irf297@gmail.com and we will delete the data without delay.
Our website may contain links to third-party websites, including client websites we have built or manage. This Privacy Policy applies solely to wordpress97.com. We are not responsible for the privacy practices of any third-party websites, and we encourage you to review their privacy policies before providing any personal data.
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make material changes, we will update the ‘Last Updated’ date at the top of this page and, where appropriate, notify active clients by email.
We encourage you to review this Privacy Policy periodically. Continued use of our website after any changes constitute your acknowledgement of the updated policy.
If you have concerns about how we handle your personal data, please contact us in the first instance — we take every privacy concern seriously and aim to resolve all complaints within 30 days:
If you are located in the United Kingdom and are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
If you are located in the European Union, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
If you are a California resident and have concerns about our CCPA compliance, you may contact the California Attorney General’s office at oag.ca.gov/privacy.