Privacy

Last updated: 10th July 2026 for CC Security Essentials Pro version 1.0

Introduction

Website security and visitor privacy should work together.

Some security features require a website to process limited information in order to protect administrator accounts, investigate suspicious activity or help maintain the website.

CC Security Essentials Pro has been designed to support these activities while keeping the collection and retention of information to the minimum necessary.

Any information processed by the website remains under the control of the website administrator.


Privacy First

CC Security Essentials Pro follows several important privacy principles.

The website:

  • processes only information needed for security purposes;
  • keeps security information on the website;
  • does not send security events to Caterham Computing;
  • does not rely on external monitoring services;
  • does not use security telemetry;
  • does not create marketing profiles from security information.

The aim is to improve website security without unnecessarily sharing information with third parties.


What Information May Be Processed?

Depending on which security features are enabled, the website may process limited security-related information.

This may include:

  • IP addresses;
  • user identifiers;
  • dates and times of security events;
  • failed login attempts;
  • temporary login restrictions;
  • blocked REST API requests;
  • requested REST API routes;
  • password age information;
  • password change events.

The exact information depends upon the features that have been enabled.


What Is Not Processed?

CC Security Essentials Pro does not require the website to:

  • send security information to Caterham Computing;
  • transmit security logs to external services;
  • upload administrator activity for analysis;
  • store user passwords;
  • record password contents;
  • collect unnecessary personal information for security features.

The website administrator remains responsible for deciding how long locally stored security information should be retained.


Why Is This Information Processed?

Security-related information is processed only where it helps protect the website or assists authorised administrators.

Typical purposes include:

  • identifying repeated failed login attempts;
  • applying temporary login restrictions;
  • reviewing blocked REST API requests;
  • helping investigate unexpected behaviour;
  • monitoring password age;
  • supporting organisational password policies.

Processing is intended to improve website security rather than monitor normal visitor activity.


Who Can Access Security Information?

Security information should normally be available only to authorised administrators.

The website administrator is responsible for ensuring that appropriate WordPress user roles and permissions are used to protect access to security information.

Where security information is no longer required, it should be removed in accordance with the website’s own retention policies.


Retention

Different organisations have different requirements for retaining security information.

When deciding how long to retain records, consider:

  • why the information is being collected;
  • how often it is reviewed;
  • whether it is still useful;
  • any applicable legal or organisational requirements.

Keeping security information for longer than necessary rarely improves security and may increase the amount of personal information retained by the website.


Sharing Information

CC Security Essentials Pro does not automatically share security information with external organisations.

If a website administrator chooses to export or share security information—for example when investigating a security incident—they remain responsible for ensuring that the information is handled appropriately.

Before sharing exported information, consider whether:

  • all recorded information is necessary;
  • personal information can be reduced or removed;
  • the recipient genuinely requires the information;
  • appropriate safeguards are in place.

Passwords

User passwords are never stored or displayed by the security features documented in this guide.

Password-related features work with information such as:

  • password strength;
  • password age;
  • password change dates.

The password itself is not retained as part of these security features.


Security Events

Where Security Events are enabled, the website may record selected security-related activity to help authorised administrators investigate problems and review unusual behaviour.

These records are intended to support website administration.

They are not intended to provide detailed surveillance of routine user activity.

Administrators should review recorded events periodically and remove older records when they are no longer required.


Exporting Security Information

Some security information may be exported to assist with troubleshooting or security investigations.

Before exporting information, consider:

  • whether the export is necessary;
  • whether the recipient requires all of the recorded information;
  • how the exported file will be stored;
  • when it should be securely deleted.

Once information has been exported from WordPress, it is no longer protected by the website’s normal access controls.


Updating Your Website’s Privacy Information

If your website processes security-related information, you should review your website’s privacy information to ensure it accurately reflects how the website operates.

The information should describe:

  • what information the website processes;
  • why it is processed;
  • who can access it;
  • how long it is retained;
  • whether it may be shared.

The wording should reflect the behaviour of the website rather than the technical implementation used to provide that functionality.


Best Practice

We recommend:

  • enabling only the security features your website requires;
  • reviewing stored security information periodically;
  • retaining information only for as long as necessary;
  • restricting access to authorised administrators;
  • reviewing your website’s privacy information whenever security features are introduced or significantly changed.

These steps help balance effective website security with good privacy practices.


Common Questions

Does the website send security information to Caterham Computing?

No.

Security information remains on the website unless the website administrator chooses to export or share it.


Are passwords stored?

No.

The website does not store user passwords as part of these security features.


Can security information contain personal data?

Depending on the enabled features, information such as IP addresses or user identifiers may be processed because they are necessary for protecting the website.

Website administrators should review their own legal obligations regarding the processing and retention of this information.


Does every website need to update its privacy information?

Not necessarily.

Whether changes are appropriate depends on the security features being used and the information processed by the website.

Website administrators should review their own circumstances and update their privacy information where appropriate.


Related Articles

Continue with: