Last updated: June 11, 2026
This Privacy Policy explains how BlueBotts collects, uses, stores, shares, and protects information about you when you visit our website at bluebotts.com, submit an enquiry or audit request, subscribe to a maintenance plan, or engage us for WordPress support services. It also explains the rights available to you and how to exercise them. Please read it alongside our Cookie Policy and Terms of Service.
Who We Are
BlueBotts is a WordPress maintenance agency that provides ongoing website care, security, backup, performance, uptime monitoring, emergency support, and related services to businesses in the United States, United Kingdom, European Union, United Arab Emirates, and other regions worldwide.
When this policy refers to “BlueBotts”, “we”, “us”, or “our”, it means the business operating under the BlueBotts brand. Where applicable data protection law requires us to identify a data controller, that is BlueBotts. You can reach us at hello@bluebotts.com with any privacy question or request.
Information We Collect
Information you provide directly: When you fill in a contact form, request a free audit, subscribe to a maintenance plan, raise a support ticket, or communicate with us by email or chat, you may give us your name, email address, phone number, company name, website URL, job title, billing details, and any other information included in your messages or attachments.
Information collected through our audit and lead tools: If you complete our site-audit questionnaire or the homepage quiz, we collect your responses, scores, and the contact details you submit at the end of the flow. This information is used to generate your audit report, calculate a care score, and send you the results.
Information collected automatically: When you visit bluebotts.com, our servers and analytics tools may collect your IP address, browser type and version, operating system, referring URL, pages visited, time on page, scroll depth, clicks, and device type. This data is collected via server logs, cookies, and analytics scripts as described in our Cookie Policy.
Information from client websites: To perform maintenance services, we may need temporary or ongoing administrative access to your WordPress site. In the course of carrying out updates, security scans, backups, performance work, or emergency recovery, we may encounter technical data, security logs, database records, or operational information stored on or generated by your site. We access this data only to the extent necessary to deliver the agreed service.
Billing and payment information: When you purchase a plan or pay an invoice, payment is processed through our payment provider. We do not store full card numbers. We retain billing records including plan type, amount, transaction reference, and billing contact details for accounting, tax, and dispute-resolution purposes.
Communications: If you email us, reply to a support ticket, leave a review, or contact us through any other channel, we retain a record of that communication including the content and metadata such as timestamps and sender details.
How We Collect Information
We collect information through the following channels: contact and enquiry forms on our website; the free site-audit tool and homepage lead-magnet quiz; email correspondence and support desk tickets; client onboarding processes where you share access credentials, hosting details, and account information; billing and invoicing workflows; cookies and analytics scripts during website visits; server access logs; and, in limited cases, publicly available sources such as LinkedIn or a business website when researching a prospective client relationship.
Why We Use Your Information
Responding to enquiries and delivering services: The primary purpose for collecting your contact and project information is to respond to your request, provide a quote or audit result, onboard you as a client, and carry out the maintenance, security, backup, performance, or support work covered by your plan or agreement.
Billing, invoicing, and payments: We use billing details to issue invoices, process payments, manage subscriptions, handle refund or dispute requests, and maintain financial records required by law.
Security, monitoring, and fraud prevention: We use technical data, IP addresses, login records, and activity logs to detect and prevent unauthorised access, abuse, malicious behaviour, and security incidents on our website and in our service infrastructure.
Service quality and improvement: Analytics and usage data help us understand how visitors interact with our website, identify content that performs well or poorly, improve our service pages, test changes, and develop better tools and processes.
Legal and compliance obligations: We may process and retain information to comply with tax, financial reporting, anti-money laundering, and other legal requirements, and to respond to lawful requests from courts, regulators, or law enforcement.
Marketing and service communications: If you have given consent or there is a legitimate interest, we may send you information about relevant services, plan updates, security bulletins, or content we think may be useful. Every marketing email includes a clear opt-out link. We do not sell your information to third parties for their marketing.
Audit reporting and PDF generation: When you complete a full site audit, we use your responses and contact information to generate a personalised PDF report, score your site’s health, and send the report to the email address you provided.
Legal Bases for Processing
Where EU, UK, EEA, or similar laws require a legal basis for processing personal data, we rely on the following: Contract performance – processing necessary to provide the services you requested, manage your plan, deliver your audit, or handle your support request. Legitimate interests – processing necessary for our reasonable business interests, such as improving our website, detecting fraud, maintaining service records, sending relevant service communications to existing clients, and protecting the security of our systems, provided those interests are not overridden by your rights. Legal obligation – processing required to comply with a legal requirement such as tax records, regulatory obligations, or a valid court order. Consent – processing based on a clear, freely given consent, such as setting non-essential cookies or sending marketing emails to prospects.
You may withdraw consent at any time without affecting processing already carried out on that basis.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies for essential site operation, analytics, performance measurement, security, and in some cases marketing attribution. Essential cookies are required for forms, session handling, consent preferences, and basic navigation to work. Analytics cookies help us understand how pages are used.
Marketing or attribution cookies, if active, may help us measure which channels lead to enquiries. Where consent is required before setting non-essential cookies, we request it before activating those scripts.
You can review, change, or withdraw your cookie preferences at any time using the controls available on our site or through your browser settings. For full details of the specific cookies we use, their purpose, duration, and provider, please see our Cookie Policy.
Who We Share Information With
We do not sell personal information. We may share information with trusted service providers and partners in the following categories, strictly for the purposes described in this policy:
Hosting and infrastructure: Our website and service systems are hosted on servers provided by hosting companies. They may process technical data such as IP addresses and server logs in the course of providing that infrastructure.
Analytics and performance: We use third-party analytics tools to measure website traffic and user behaviour. These tools may set cookies and collect browsing data in accordance with their own privacy policies.
Email and communication: We use email service providers to send transactional messages such as audit reports, invoices, support updates, and service notifications. Marketing communications, where applicable, are also sent through a managed email platform.
Payments: Payments are processed by a third-party payment provider. Your payment card details are handled directly by that provider under their security standards. We receive a transaction reference and billing summary only.
Security and malware tools: We use professional security scanning, monitoring, firewall, and malware-removal tools. These tools may process website files, database records, IP addresses, and traffic logs to detect threats.
Backup and storage: Backup copies of client websites are stored in secure cloud storage. These backups may contain website content, database records, and configuration files.
PDF and document generation: Audit reports are generated using a server-side PDF library. This processing happens within our own infrastructure and does not involve third-party cloud services for the document content.
Support and project management: We use internal tools for managing support tickets, project tasks, and client communications. These tools store relevant project and contact information as part of service delivery.
Professional and legal advisors: In limited circumstances, we may share information with accountants, lawyers, or insurers where necessary for legal compliance, dispute resolution, or professional advice.
Law enforcement and regulators: We may disclose information if required by law, court order, or a binding request from a competent authority, or to protect the rights, safety, or property of BlueBotts, our clients, or the public.
We require all third-party providers to handle information securely and to use it only for the specific purpose for which it was shared.
International Data Transfers
BlueBotts serves clients globally and works with service providers whose infrastructure may be located in multiple countries, including the United States, European Union member states, the United Kingdom, and other jurisdictions.
If your personal data is transferred from the EU, EEA, or UK to a country without an equivalent level of data protection, we take steps to ensure appropriate safeguards are in place.
These may include Standard Contractual Clauses approved by the European Commission or the UK ICO, adequacy decisions, binding corporate rules where applicable, or documented risk assessments and supplementary measures. For transfers involving UAE personal data, we apply equivalent diligence in line with the UAE Federal Decree-Law on Personal Data Protection.
If you would like more information about the specific safeguards applied to your data, please contact us at hello@bluebotts.com.
How Long We Keep Your Information
Enquiries and audit submissions: We retain records of website enquiries, contact form submissions, lead-magnet quiz responses, and audit submissions for as long as we have a legitimate interest in the relationship, typically up to three years from the last meaningful interaction, unless you ask us to delete them sooner.
Client account and service records: Information related to an active maintenance plan, support ticket history, access logs, billing records, and project correspondence is retained for the duration of the engagement and for a reasonable period afterwards – generally five to seven years – for accounting, legal, tax, and dispute-resolution purposes.
Security and access logs: Server logs, security scan records, and access logs are retained for a limited operational period, typically 30 to 180 days, unless a specific incident requires us to retain them longer for investigation or legal purposes.
Marketing contacts: If you subscribed to marketing communications, we retain your details until you unsubscribe, withdraw consent, or we determine the contact is no longer active.
When information is no longer required for any of the purposes described in this policy, we delete it, anonymise it, or archive it securely in a way that means it can no longer be attributed to an identifiable individual.
How We Keep Your Information Secure
We implement administrative, technical, and operational safeguards proportionate to the sensitivity of the information we hold.
These include access controls and role-based permissions limiting who can view client data; encryption in transit using TLS for all data transmitted between your browser and our website; secure credential storage practices; two-factor authentication on key administrative accounts; regular security monitoring and malware scanning of our own infrastructure; controlled access to backup storage and client credentials; and an incident response process for identifying, containing, and reporting security events.
Our service model is built around active security – it is both what we sell and what we practise internally. However, no website or online system is completely immune from attack.
If a security incident occurs that affects your personal data, we will notify you and any relevant regulators as required by applicable law.
Your Privacy Rights
EU, EEA, and UK individuals (GDPR and UK GDPR): You have the right to access a copy of your personal data, correct inaccurate information, request erasure where no overriding legitimate purpose applies, restrict processing in certain circumstances, receive your data in a portable format, object to processing based on legitimate interests, and withdraw consent where processing relies on it.
You also have the right to lodge a complaint with a supervisory authority. In the EU or EEA this is the data protection authority in your country of residence. In the UK this is the Information Commissioner’s Office (ICO).
California residents (CCPA and CPRA): If you are a California resident, you have the right to know what personal information we collect about you, the purposes for which we use it, and the categories of third parties we share it with.
You have the right to request deletion of your personal information, subject to legal exceptions. You have the right to correct inaccurate personal information.
You have the right to opt out of the sale or sharing of your personal information – BlueBotts does not sell personal information and does not share it for cross-context behavioural advertising. You have the right not to receive discriminatory treatment for exercising these rights.
To make a CCPA request, contact us at hello@bluebotts.com.
UAE residents (Federal Decree-Law No. 45 of 2021): If you are located in the UAE, you have rights to access, correct, and request deletion of your personal data, to object to or restrict certain processing, and to withdraw consent where processing is consent-based. These rights apply to the extent BlueBotts processes your personal data in connection with services provided to you or in connection with your interactions with our website.
All other users: Regardless of where you are located, you may contact us at any time to ask what information we hold about you, to correct it, or to ask us to delete it. We will respond in a reasonable time and in accordance with any obligations under applicable local law.
How to Exercise Your Rights
To make a privacy rights request, email us at hello@bluebotts.com with a clear description of your request and enough information for us to identify your records.
We will acknowledge your request within five business days and aim to respond fully within 30 days, or within the timescale required by applicable law.
In some cases we may ask you to verify your identity before processing a request, particularly for access or deletion requests, to protect against unauthorised disclosure. Where we cannot fulfil a request, we will explain why and advise you of any recourse available.
Marketing Communications
We may send you service-related emails in connection with your plan, audit results, support ticket updates, or account activity. These are transactional and cannot be opted out of while you are an active client, as they are necessary to deliver the service.
Where we send marketing emails – such as service announcements, tips, or new offer notifications – we include a clear unsubscribe link in every message. You can also opt out by emailing hello@bluebotts.com at any time. Unsubscribing from marketing will not affect transactional messages.
Third-Party Websites and Integrations
Our website may contain links to third-party websites, case studies referencing external tools, or embedded content from providers such as video platforms or review widgets. Clicking a link or interacting with embedded content may involve those third parties collecting data about you under their own privacy policies.
BlueBotts has no control over and accepts no responsibility for the privacy practices of third-party websites. We also do not control the privacy practices of plugins, tools, or integrations installed on client websites we maintain.
Our maintenance work focuses on keeping your site secure and functional – responsibility for the data handling of your site’s third-party integrations rests with you as the site owner.
Children
Our website and services are directed at businesses and adult decision-makers. We do not knowingly collect, process, or store personal information from anyone under the age of 18. If we become aware that personal information from a child has been submitted through our website, we will delete it promptly. If you believe we have inadvertently received information from a child, please contact us at hello@bluebotts.com.
Changes to This Policy
We may update this Privacy Policy when our services, processes, or applicable legal requirements change. When we make material changes, we will update the “Last updated” date at the top of this page.
We may also notify active clients by email for significant changes that affect how we process their personal data. We encourage you to review this page periodically. Continued use of our website or services after a change is posted constitutes acceptance of the updated policy.
Contact
If you have a question about this Privacy Policy, want to know what information we hold about you, or wish to submit a rights request, please email us at hello@bluebotts.com. We aim to acknowledge privacy enquiries within five business days and to resolve them as promptly as possible.