Skip to content
My Site Got Hacked Get help now

Legal

Privacy policy

How we handle your information. Last updated 9 August 2026.

Who we are

My Site Got Hacked is an Australian WordPress malware removal and recovery service, operated from Australia and reachable at help@mysitegothacked.com.au. This policy explains how we handle personal information, consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

What we collect

We collect only what we need to answer you and do the work.

  • What you send us. When you use the contact form or email us: your name, email address, the website address in question, and whatever you tell us about the problem.
  • Access credentials, if you engage us. To clean a site we usually need hosting or WordPress access. We ask for these only after you decide to go ahead, and only for the site being worked on.
  • Technical information about your site. During an assessment or clean-up we necessarily see the contents of your website files, database and server logs. That can include personal information belonging to your users.
  • Usage data. Aggregate, non-identifying analytics about how this website is used — pages viewed, approximate region, referring site, device type.

We do not collect payment card details through this website, and we do not knowingly collect information from children.

How we use it

  • To reply to your enquiry, assess your site and quote the work.
  • To carry out the work you have engaged us to do.
  • To send you the written summary at the end of a job, and invoices.
  • To meet our tax and record-keeping obligations.
  • To understand which parts of this website are useful, in aggregate.

We do not sell your information. We do not use it for advertising, and we will not add you to a marketing list off the back of an enquiry.

Credentials, and how we treat them

Please do not send passwords or API keys in your first message — email is not a safe place for them. If you engage us, we will tell you a secure way to hand them over. We use credentials only for the agreed work, and we ask you to change them once the job is finished. Any credentials we still hold are destroyed when the engagement ends.

Your users' data

Cleaning a compromised site means handling a backup of it, which may contain personal information about your customers. We treat that data as yours. We do not access it beyond what the clean-up requires, we do not copy it anywhere it does not need to go, and we delete working copies once the job is complete and you have confirmed the site is working.

If a compromise looks like it involved a data breach affecting your customers, we will tell you. Assessing and notifying under the Notifiable Data Breaches scheme is your obligation as the entity that holds that data, but we will give you what we found so you can meet it.

Who else sees it

We use a small number of service providers to run this website and our business. They only ever receive what their function requires:

  • Website hosting and security — serves this site and protects it from attack.
  • Form and email delivery — carries your enquiry to our inbox.
  • Website analytics — aggregate usage statistics.
  • Accounting software — invoicing and records.

Some of these providers store data outside Australia, including in the United States and the European Union. Where that happens we take reasonable steps to ensure the provider handles the information consistently with the Australian Privacy Principles.

Beyond that, we disclose personal information only where the law requires it, or where you have asked us to (for example, lodging a review request with Google on your behalf).

Cookies and analytics

This website runs no advertising, and carries no advertising pixels or remarketing tags.

We use Google Analytics to count page views and understand which guides people find useful. It sets a first-party cookie in your browser so that repeat visits are not double-counted. We do not enable Google's advertising features or cross-device tracking, we do not build profiles of individual visitors, and we do not pass your enquiry details to Google.

You can block cookies and analytics in your browser settings, or use its Do Not Track setting, without losing access to anything on this site.

How long we keep it

  • Enquiries that do not become jobs — up to 12 months, then deleted.
  • Job records and correspondence — 7 years, as required for tax and business records.
  • Site backups taken during a clean-up — deleted once the job is complete and confirmed, unless you ask us to keep a copy.
  • Credentials — destroyed at the end of the engagement.

Security

We take reasonable steps to protect information from misuse, loss, and unauthorised access — encrypted transport, access limited to those who need it, and secure handling of credentials. No system is perfectly secure, which is a thing we are professionally well placed to appreciate. If something does go wrong in a way that affects you, we will tell you.

Accessing and correcting your information

You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email help@mysitegothacked.com.au and we will respond within a reasonable period, normally 30 days. There is no charge. We may need to verify your identity first, and in rare cases we may need to keep information the law requires us to retain.

Complaints

If you think we have mishandled your personal information, email help@mysitegothacked.com.au and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Changes to this policy

We update this policy when what we do changes. The date at the top always reflects the current version.