Updated: 29th September, 2026
Security and Data Handling
A short summary of how I look after your website and the personal data it handles, written for your IT, procurement or data protection team. It summarises the Statamic Maintenance Terms and Conditions and the Data Processing Annex. Where anything here differs, those documents apply.
Who I am
D3 Network Ltd, trading as D3 Creative. Company number 07662407, registered in England and Wales.
Registered office: The Old Bakery, 90 Camden Road, Tunbridge Wells, TN1 2QP. Trading address: Broadstone Mill, Broadstone Road, Stockport, SK5 7DL.
D3 Creative is a one-person business. I am the only person who accesses your systems. If that ever changes, anyone else is bound by the same confidentiality and security measures.
Roles
You are the controller of the personal data your website handles. I am your processor when I handle it to provide the Services.
Services you contract with directly, such as your hosting provider, CRM or email platform, are your own processors, not mine.
Your infrastructure stays yours
Your hosting account and your Ploi server management account are set up in your name. You pay the providers directly and keep full control.
I work only with access you give me, and you can remove it at any time.
I do not host your website or keep backups of it. Backups are set up with your hosting provider, and I can help you configure them.
Security measures
Credentials you provide are kept secure and used only to provide the Services.
Two-factor authentication on accounts used to access your website and server, where the service offers it.
Encrypted connections only: SSH for server access, HTTPS for the CMS and web-based services.
The laptop and phone I work on are encrypted, locked with a password and biometrics (fingerprint or Face ID), and kept up to date.
Local copies of your website, used for testing, are kept to what the work needs and deleted afterwards.
Every update is tested locally, then on staging, before it reaches your live site.
Server security updates are applied automatically every day. Critical security patches for Statamic and your site's Composer and npm packages are typically applied within one business day.
What data I may see
Server logs and monitoring data: IP addresses, the pages requested, browser and time of each request, and errors and performance data.
When needed to fix an issue or test an update: data held in your website, such as form submissions and CMS user accounts, or in a connected service such as your CRM.
The Services do not require access to special category data, such as health information.
Monitoring and sub-processors
Laravel Nightwatch (Laravel Holdings Inc.) provides application monitoring. Data is held in EU data centres by default, or the US if you ask for it, and is kept for 90 days.
I will tell you before adding or replacing a sub-processor that handles your personal data.
Retention
Server logs and monitoring data are deleted automatically after 90 days, so problems and security incidents found some time after they happen can still be traced.
Individual log entries are not searched or edited in response to a data rights request. They expire after 90 days instead.
Breaches and data rights
If I become aware of a personal data breach, I will tell you without undue delay, and in any event within 48 hours.
I will help you respond to people exercising their data rights by finding or removing their data in your website or a connected service.
When the agreement ends
Your website and its data stay on your own systems throughout.
I delete any copies of your personal data I hold, such as local copies of your website.
You remove my access to your website, server and third-party services.
Questionnaires and audits
I am happy to complete your security questionnaire or provide anything else you need to check how your data is handled.
Audits are covered in section 8 of the Data Processing Annex.