Working securely with Web Wonderland
Proportionate access, controlled changes and clear handover.
Technical website and automation work can require access to systems, code and business data. We agree what is genuinely needed, arrange sensitive access separately from public enquiry forms and keep the delivery route proportionate to the work.
This page explains the working approach used during qualification and delivery. It is not a security certification, contractual guarantee or substitute for project-specific terms.
Do not send credentials through public forms
Public enquiry forms are for the visible problem, business requirement and non-sensitive project information. Passwords, API keys, recovery codes and private access links should not be included. Where access is required, Web Wonderland will arrange an appropriate secure transfer route after the enquiry has been reviewed.
Least-required access
We request only the access reasonably required for the agreed scope. The exact access can vary by project and may include a WordPress account, staging environment, repository, hosting tools, logs or relevant third-party platform access.
Staging, backups and source control
Changes are prepared through staging, backups and source control where the website and available setup allow it. Inherited websites do not always arrive with an ideal development workflow, so any limitations and the safest practical route are explained before work begins.
Confidentiality and agency relationships
Client ownership, communication routes, portfolio permissions and NDA requirements are agreed before confidential project material is shared. White-label work remains behind the agency unless a different client-facing role is expressly agreed.
Data minimisation
Project information is limited to what is needed for qualification and delivery. Personal information submitted through the website is handled in accordance with the Web Wonderland privacy policy. Project-specific retention, access and deletion requirements should be agreed where they go beyond the standard service.
Testing, change notes and deployment
The agreed work includes checks appropriate to the change and a clear completion or handover summary. Production deployment responsibility and approval are confirmed as part of the scope rather than assumed.
Limits and specialist incidents
No provider can promise absolute security. Malware incidents, forensic investigations, compromised hosting accounts and some third-party platform failures may require a specialist incident-response or hosting route outside a standard Fix Desk, automation or white-label package.
Confidentiality paperwork
NDA available on request. We agree the appropriate document and signing route before confidential project material is shared.
