Privacy Policy
Last updated: 2026-08-19
This Privacy Policy explains how WP FOSS LLC (“WPfoss”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit wpfoss.com, use our free domain security checker, contact us, or engage us for security work.
WPFOSS is a registered Data Controller and Data Processor certified by the Office of the Data Protection Commissioner (ODPC) – Kenya, under the Data Protection Act, 2019. This policy is written to meet our obligations under that Act.
1. Who we are, and when we are a Controller or Processor
WPfoss is operated by WP FOSS LLC, a company registered in Delaware, United States, and registered with the Office of the Data Protection Commissioner (ODPC) in Kenya. We serve clients in Kenya and internationally, and this policy is governed primarily by the Kenya Data Protection Act, 2019. You can reach our privacy team any time at hello@wpfoss.com.
- We are the Data Controller for the personal data relating to your enquiry, billing, support requests, marketing preferences, and your use of our website.
- We are the Data Processor for any personal data we encounter inside your own systems while carrying out an engagement, for example sending addresses in DMARC reports. For that data you are the Controller, and we process it only on your documented instructions.
2. The free domain security checker
This deserves its own section, because we would rather you knew exactly what the tool does than assumed. In short: we record the result, we do not record you.
What we keep
- The domain you checked, the grade it received, and which controls passed or failed.
- The country the request came from, your browser's user-agent string, and the page that referred you.
- We use this to see which problems are most common, to improve the tool, and to understand demand for our services.
What we do not keep
- No email address. None is requested or required, and there is no signup.
- No name, and no account. A logged check is not linked to a person.
- No IP address. A logged check does not store your IP, or any value derived from it. Until 11 August 2026 we kept a salted hash of it for an hour to limit abuse; that has been removed. Abuse limits are now counted by Cloudflare's rate-limiting service, which uses your IP as a short-lived counter and returns only a yes or no to us. Cloudflare's role is described in section 7. Our page-view analytics, described in section 2a, do derive a daily code from your IP — that is a separate record from the check log, and it never contains the domain you looked up.
How the checks run
- The lookups happen in your browser, sent directly from your device to public DNS resolvers over DNS-over-HTTPS. Those resolvers (currently Cloudflare, with Google as a fallback) receive the queries as they would any DNS lookup, under their own privacy policies.
- Everything the checker reads is public DNS, the same information any mail server on the internet already sees.
- Because you may check any domain, including ones you do not own, a logged domain does not imply any relationship between that domain's owner and WPfoss.
Our general website analytics also record page views, and because the domain can appear in the page address, third-party analytics and advertising tools on this site may receive it too. You can prevent that with any standard tracker-blocking extension, and the checker will still work normally.
2a. Our own page-view analytics
We run our own analytics on this website, rather than relying only on Google. It records which pages are opened, in what order, and which of a short list of buttons are clicked — WhatsApp, the phone number, an email address, the booking link, the checker, and links leaving the site. It is how we tell whether the site is doing its job.
How you are counted, and why it is not a way of following you
- We do not set a cookie for this, and we store nothing on your device.
- Instead, our server turns your IP address and browser into a short code, using a secret key and today's date. Your IP is used to work the code out and is then discarded — it is never written down.
- The code changes every day. Because the date is part of it, the same person is a different code tomorrow, and there is no way to join the two up. We can follow one visit through one day. We cannot recognise you next week, and we cannot recognise you on any other website.
- Without the secret key the code cannot be worked backwards into an IP address. The key never leaves our server, and if it is ever changed, every existing code becomes unmatchable.
What is recorded: the page address, the page title, whether you were on a mobile or a desktop, the country the request came from, roughly how long the page was open, and the website that referred you — the site name only, never the full link, because a full link from a search engine can contain what you typed.
What is never recorded: your IP address, your name or email address, anything you type into a form, anything after the ? in a page address, and any means of recognising you tomorrow.
This works the same way as Plausible, which is why it runs without a cookie banner — see section 12, where both are named. Any tracker-blocking extension stops it, and the site works normally without it. These records are kept for 90 days and then deleted automatically.
2b. Our email list
We send occasional guidance on DNS, email and password security. This is the only marketing email we send, and it stops the moment you use the unsubscribe link in any of them.
How your address gets on the list
- Sending us an enquiry through the contact form. Submitting it means accepting this policy, as the form states next to the send button.
- The subscribe box in the footer of this site.
Either way you are added straight away — we do not send a separate confirmation email asking you to click a link. We do it this way because you gave us the address while asking about, or asking for, exactly this subject. Submissions our spam filter judges to be automated are never added at all.
What we store: your email address, your name if you gave one, which form you used, the exact wording you agreed to, the date you confirmed, and the country the request came from. No IP address, consistent with the rest of this policy — the confirmation click is the record of your consent.
Leaving is one click. Every email we send carries an unsubscribe link that works immediately, with no login and no questions. When you use it we keep your address on a suppression list rather than deleting it — that is what stops a later form submission from quietly starting the emails again. Ask us and we will erase it entirely instead, though then nothing prevents a future sign-up.
We do not sell, rent or share this list. Unsubscribing has no effect on anything else: if you are a client or have an open enquiry, we will still reply to you, because that is not marketing.
3. Information we collect
Information you give us
- Contact details: name, email, phone number, company name, and role, when you submit an enquiry form, book a security review, or email us.
- Enquiry content: what you tell us about your setup and what you would like fixed.
- Where enquiries are stored: a contact form submission is written to our own database before we attempt to email ourselves about it. That is deliberate — it means an enquiry cannot be lost to a mail delivery failure and leave you waiting for a reply that was never going to come. It is held in Cloudflare D1, and reachable only by our team behind Cloudflare Access and a separate password.
- Billing details where you engage us for work.
- Communications with us: emails, calls, and support messages, including any attachments you choose to share.
Data we encounter during an engagement
- Configuration data from your domains, DNS zones, registrar and Cloudflare accounts, and mail platform.
- DMARC aggregate reports, which identify sending sources and may contain IP addresses.
- Administrative metadata such as user account names, roles, group memberships, sharing permissions, and login or session records, where a review requires it.
- We work on a least-privilege basis and read only what the agreed scope requires. We do not read the contents of your mailboxes, files or password vaults. Where we need temporary access to a specific credential in order to migrate it, that is agreed in advance and the credential is rotated afterwards.
Payment information
Payments are processed by Stripe and Zoho. We do not store full card numbers, PINs, or other sensitive payment credentials on our servers. We retain only limited details such as a payment reference, a masked identifier, and the billing details tied to your engagement.
Information we collect automatically
- Usage data (pages viewed, actions taken, errors encountered).
- Device and connection data (IP address, browser, operating system, referrer), and approximate, city-level location derived from your IP.
- Server logs and security events.
4. How we use information
- To respond to your enquiry and prepare a scope and quote.
- To carry out the security work you have engaged us for, and to produce the report and documentation that come with it.
- To process payments and meet our tax and accounting obligations.
- To provide support and respond to your requests.
- To keep this website secure and prevent abuse.
- To produce aggregated, de-identified analytics that help us improve the site.
- To send service messages and, with your consent, occasional marketing.
We do not sell personal data, and we do not share it with third parties for advertising.
5. Confidentiality of findings
What we find in your environment is your confidential information. We will not name you, use your logo, publish a case study, or quote you without your specific prior agreement in writing to the exact wording. We do not publish claims we cannot evidence, and that includes anything about our clients.
6. Lawful basis for processing
Under the Data Protection Act, 2019, we rely on one or more of the following bases:
- Performance of a contract — to deliver the engagement you asked for.
- Consent — for marketing messages, and for the analytics and advertising cookies described in section 12. You can withdraw either at any time.
- Legitimate interests — for security, fraud prevention, and improving our services, balanced against your rights.
- Legal obligation — for tax, accounting, and other regulatory requirements.
7. Sharing & sub-processors
We share personal data only with vetted providers who help us deliver the services, each bound by a data-protection agreement. We do not sell personal data.
| Provider | Purpose |
|---|---|
| Cloudflare | Website hosting, content delivery and firewall; public DNS resolution for the free checker (queries go direct from your browser); site performance analytics. Receives your IP address and request metadata |
| Google (Tag Manager, Analytics, Ads) | Website analytics and advertising measurement; fallback public DNS resolver for the checker; Workspace administration during engagements. Receives the page addresses you visit, which can include a domain you checked, plus device, browser and approximate location |
| Google reCAPTCHA | Spam protection on website forms. Receives your IP address and interaction signals on pages carrying a form |
| Meta (Facebook) | Advertising measurement. Receives the page addresses you visit and an advertising cookie identifier |
| Plerdy | On-page behaviour analytics: clicks, scrolling and heatmaps. Receives the page addresses you visit and your interactions with the page |
| HappierLeads | Business development. Identifies the organisation associated with a visitor's IP address; receives your IP address and the pages you visit |
| Growify | Marketing attribution. Receives the page addresses you visit, the referring page and an identifier |
| Encharge | Marketing automation. Receives the page addresses you visit and an identifier, linked to your email address if you have given us one |
| Plausible | Privacy-focused page-view analytics, self-hosted by us. Sets no cookie |
| heylogin | Password management licences and deployment, where engaged |
| Zoho | Email delivery for website forms, billing, and business operations |
| Stripe | Card payment processing |
| Google Calendar Appointment Scheduling | Booking security reviews. The booking form on /book-a-call/ is embedded from Google and receives the name, email address and any notes you enter into it, plus your IP address and the fact that you loaded that page |
We may also share data with professional advisors (legal, accounting, audit) under confidentiality, with authorities where legally required, and in connection with a merger or sale of assets subject to appropriate protections.
8. International transfers
Some of our providers process data outside Kenya. Where personal data is transferred across borders, we do so in line with the Data Protection Act, 2019, relying on appropriate safeguards such as data-protection contract terms with each provider, transfers to countries or recipients that offer adequate protection, or your consent where required.
9. Data retention
- Checker log: the domain, grade and control statuses are retained so we can track which problems are most common. It contains no identifier for you. Ask us and we will remove any specific domain from it.
- Rate-limiting hashes: no longer created. We stored a salted hash of your IP for one hour until 11 August 2026; the mechanism and the stored hashes have both been deleted.
- Submissions our spam filter rejects: kept for 30 days so we can spot and rescue a genuine message wrongly judged automated, then deleted automatically each night. These are never replied to and never added to any mailing list.
- Enquiry data (name, email, phone, company and your message): retained for 24 months from your last contact with us, so we can pick up a conversation where it left off, then deleted. Ask us sooner and we will delete it sooner, unless we are required to keep it for tax or legal reasons.
- Engagement records and reports: retained for the duration of the engagement and for a reasonable period after, so we can support you and evidence what was done. Deleted sooner on request where we have no legal need to keep them.
- Credentials and access: access to your systems is revoked at the end of an engagement, and any credential we held temporarily is rotated.
- Financial records: retained for up to seven years to meet tax and accounting obligations.
- Backups: retained for up to 90 days after deletion from active systems.
- Server logs & security events: typically up to 12 months.
- Email list (section 2b): retained until you unsubscribe. Unsubscribed addresses are kept as a suppression record so we do not email you again by accident; ask us and we will erase yours entirely.
- Our own page-view analytics (section 2a): retained for 90 days, then deleted automatically each night. The daily code they use stops being matchable to anything at midnight in any case.
- Aggregated, de-identified analytics: retained indefinitely, as it does not identify anyone.
10. Your rights
Under the Data Protection Act, 2019, you have the right to:
- Be informed of how your personal data is used.
- Access the personal data we hold about you.
- Ask us to correct data that is inaccurate, misleading, or out of date.
- Ask us to delete your personal data, subject to legal limits.
- Object to, or ask us to restrict, certain processing.
- Receive your data in a portable, commonly used format.
- Withdraw consent at any time, without affecting processing done before you withdrew it.
To exercise any of these, email hello@wpfoss.com and we will respond within 30 days. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), Kenya at odpc.go.ke.
11. Children
Our services are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18 without the consent of a parent or guardian. If you believe a child has provided us data, contact us and we will delete it.
12. Cookies & tracking
- Essential cookies for security and basic site function. These are always set.
- Functional cookies that remember your preferences, including the one record of the choice you make below.
- Analytics and advertising cookies used to measure how the site is used and how our advertising performs. These include Google Analytics (
_ga), Meta advertising (_fbp) and our marketing automation (encheventsnippet). Section 7 lists who receives the data.
Analytics and advertising cookies are set only if you accept them. Until you do, the tools in section 7 that rely on them are not loaded at all — not merely blocked from storing something, but never fetched. Rejecting is one click, in the same place and of the same size as accepting.
Two exceptions, and we would rather name them than let you find them. Plausible, our self-hosted page-view analytics, and our own analytics described in section 2a, both run whether or not you accept. Neither sets a cookie, neither stores anything on your device, and neither can follow you to another website. Our own one does count a visit as a visit — using a code rebuilt from scratch each day, which is why it cannot recognise you tomorrow — while Plausible counts only that a page was viewed. That is why they do not sit behind the choice above. If you would rather neither ran, any tracker-blocking extension will stop both.
You can change your mind at any time using Cookie settings, also linked in the footer of every page. If you accept and later reject, we clear those cookies and reload the page so nothing carries on running in it.
Your choice is recorded in your browser's local storage rather than in a cookie, so refusing cookies does not itself require setting one. Clearing your browsing data clears the record too, and you will be asked again. Declining does not limit the site: the free checker sets no cookie of its own and works normally either way, and so does the contact form.
13. Security
We use administrative, technical, and physical safeguards to protect personal data, including:
- Encryption in transit (TLS) and encryption at rest for sensitive credentials and tokens.
- Role-based access control on a least-privilege basis.
- Time-limited access to client systems, revoked at the end of an engagement.
- Audit logging of administrative actions and regular security reviews.
- A documented incident-response plan.
No system is perfectly secure. If we become aware of a personal-data breach likely to pose a risk to your rights, we will notify the ODPC within 72 hours where required, and affected users without undue delay.
14. Marketing communications
We send marketing only with your consent, and every marketing email includes an unsubscribe link. Service messages (billing and important notices about an engagement) are sent regardless of marketing preferences because they are needed to deliver the work.
15. Legal disclosures
We may disclose personal data where we believe in good faith it is required by law, court order, or a lawful regulatory request, or where necessary to protect the rights, safety, or property of WPfoss, our clients, or the public. Where lawful, we will let you know in advance.
16. Changes to this policy
We may update this policy from time to time. For material changes we will give notice on this page or by email before they take effect; for minor changes we will update the “Last updated” date above.
17. Contact
For any privacy question or to exercise your rights, contact us at hello@wpfoss.com. Please include enough detail for us to verify your identity and act on your request.
