Last updated: August 2026
We collect information you provide directly to us: your name, email address, company name, and billing information when you register for an account or contact us. We also collect usage data, log files, and cookies to improve our service.
We use the information we collect to: provide and improve our services, send service-related communications, process transactions, and comply with legal obligations. We never sell your personal data to third parties.
Your data is stored on secure servers. We implement industry-standard security measures: data in transit is encrypted via TLS, and sensitive data (passwords, SMTP credentials, OAuth and API tokens) is encrypted at rest using AES-256; access to production systems is limited to authorized staff, and two-factor authentication is available for account access, with regular security review of our own infrastructure.
In the event of a personal data breach affecting your data, we will assess the incident, notify the competent supervisory authority within 72 hours where required by law, inform affected users where their data is at meaningful risk, and take corrective action.
Our marketing website (wpwarden.io) uses a small number of essential cookies/local storage entries required for the site to function (e.g. remembering your language and theme preference), plus, only if you consent, analytics cookies that help us understand how visitors find and use the site. On your first visit, a cookie banner lets you accept analytics cookies or continue with essential cookies only. You can change your choice at any time using the “Cookie Preferences” link in the site footer. No analytics or marketing cookies are set before you give consent.
The WP Warden application itself (app.wpwarden.io, used by registered accounts) does not use advertising or marketing cookies; it relies on a session token to keep you signed in. It does, however, let account holders send emails (client reports) that include an open-tracking pixel β this records only an open timestamp and count, never an IP address or device data, and is always paired with a visible notice in the email itself. See our Terms of Service, Section 3, for the full description of this feature and who is responsible for its use.
We use a limited set of third-party vendors (“sub-processors”) to operate WP Warden. Each is bound by its own data protection terms and only processes data as needed to provide its service to us:
Separately, WP Warden lets you (the account holder) connect certain third-party services under your own account and credentials β for example your own SMTP provider for outbound alert emails, your own Slack workspace webhook, your own Google Drive/OneDrive for backup storage, your own Google Analytics 4 property for site analytics, or your own AI provider (e.g. Claude, OpenAI, or Gemini) for optional AI-assisted security review. For these tenant-configured integrations, you control the connection and decide what it’s used for, and the receiving service’s own privacy terms apply to the data it receives. In practice our backend handles the mechanics of that connection on your behalf β decrypting your stored credentials to authenticate the request, transmitting the relevant content (e.g. a flagged file’s contents to your chosen AI provider, or your backup archive to your connected Drive/ OneDrive), and where applicable storing the connection’s access tokens β rather than merely redirecting your browser to the destination. You remain responsible for that destination’s compliance with your own obligations toward your end-clients, and for the choice of provider itself.
WP Warden currently operates a single processing region: the European Union. Your account data, database records, and backups you store with us are held on infrastructure located in the EU. Backup storage in our dashboard is presented as a region choice, but only the EU region is currently active β a US region is planned for a future release once we have genuine infrastructure in that region to support it, and is disabled/unselectable until then. We will update this section with details of any additional processing region before it becomes available to customers.
Depending on your jurisdiction β including under the GDPR if you’re in the EU/EEA β you may have the right to access, correct, update, port, or request deletion of your personal information. WP Warden is built with these rights in mind and gives you working, self-service tools for two of them directly from your dashboard, rather than requiring a support request:
For any other request, or if you have questions about the scope of the above, contact us at contact@wpwarden.io.
WP Warden is a software platform that gives you β the account holder (“Client”) β the tools and visibility to manage, monitor, and secure your own WordPress sites and your relationships with your own end-clients. You control what data you input, which features you enable, which third-party integrations you connect, and how you use the platform’s output (including AI-assisted findings, which are advisory only and not a guarantee of detection, accuracy, or completeness).
You are solely responsible for your own use of WP Warden, for your relationship and agreements with your end-clients, and for your own compliance obligations under GDPR or any other law applicable to how you process your end-clients’ data using our platform. PaxAgent LLC, and its owners, employees, contractors, and staff, do not participate in and are not a party to your relationship with your end-clients, and act solely as a processor of the data you choose to store with us under your instructions. Neither this Privacy Policy nor your use of WP Warden creates any legal obligation, duty of care, or liability on the part of PaxAgent LLC, its owners, or its staff toward your end-clients or any other third party. See our Terms of Service for the full limitation of liability and indemnification terms that govern your use of the platform.
If you have any questions about this Privacy Policy, please contact us at contact@wpwarden.io or visit our Contact page.