Who We Are

Incsub, LLC provides WordPress and web hosting/development services via WPMU DEV, CampusPress, and Edublogs. This privacy policy applies to all visitors and customers using or accessing any of the websites that we produced and maintain for the services that we provide, including wpmudev.com, campuspress.com, edublogs.org, incsub.com, and theedublogger.com. It also applies to the WordPress services that we provide as part of WPMU DEV memberships that use APIs to interact with our servers or the WPMU DEV site and to human resources data of our employees and contractors.

This policy DOES NOT cover websites that we host for our customers as part of WPMU DEV or CampusPress. For these sites, the site owner/customer is responsible for publishing its own privacy policy.

Incsub, LLC is a registered corporation in Alabama, USA. Our mailing address is:

Incsub, LLC
120 19th St N Ste 201 PMB 88100
Birmingham, AL, 35203-3219
USA

For any privacy-related questions, you can reach us at dpo@incsub.com.

In short: 

We use third-party services (data processors) across our sites. The extent to which your data is shared with these providers depends on your use of our services, and we list the specific third-parties in use (with links to their privacy policies) in the sections below.

Each third-party provider has been vetted by our security team to ensure that privacy policies and practices meet or exceed the same levels of compliance and standards that we follow. Where appropriate and available, we hold additional signed Data Privacy Agreements with these companies as an additional layer of accountability in order to help ensure your data is safe and secure.

We disclose potentially personally-identifying and personally-identifying information only to our employees, contractors and affiliated organizations that (i) need to know that information in order to process it on our behalf or to provide services, and (ii) that have agreed, in writing, not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using our websites and services, you consent to the transfer of such information to them. We will not rent or sell potentially personally-identifying and personally-identifying information to anyone.

We may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

If we ever were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we would provide you with an opt-out choice to limit the use and disclosure of your personal data.

Our services are  intended for use by a general audience and does not offer services to children. Should a child whom we know to be under 18 send personal information to us, we will use that information only to respond to that child to inform him or her that they cannot use our services. We do not sell any personal information.

Data Privacy Framework (DPF) Program

Incsub, LLC complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.  Incsub, LLC has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Incsub, LLC has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.  If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.  To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data privacy framework website https://www.dataprivacyframework.gov/.

The Federal Trade Commission has jurisdiction over Incsub, LLC’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).

Personal Data We Collect (Why & How Long)

Incsub, LLC commits to subject to the Principles all personal data received from the EU in reliance on the EU-U.S. DPF.

a. Registered Users

  • Your Profile Picture (Gravatar), Display Name, Website (URL) (if any) and Biographical Info (if any) may be visible to visitors to the website (e.g. if you leave a comment, forum post, or contribute an article/post).
  • If you author an article/post, your Username, User ID, Profile Picture (Gravatar), Display Name, Website (URL) (if any) and Biographical Info (if any) are provided to any visitor using the website’s REST API interface.
  • If you upload media (e.g. images) to the website (in forums, posts, or comments), you should avoid uploading images with EXIF GPS location data included. Visitors to the website can download and extract any location data included in images on the website.
  • Visitors using the website’s REST API interface can correlate uploaded media to a particular user.
  • This may allow such visitors to map a user to a particular time and location if EXIF GPS location data was included in the uploaded media.
  • If you edit or publish an article/post, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
  • When visitors leave comments on our site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
  • If you leave a comment on a site you may opt-in to saving your name, email address and website in cookies so we can recognize you as a commenter. These cookies will persist for one year.
  • Additional spam detection is provided by Automattic/Akismet. The Automattic privacy policy is available here.
  • Published content and comments are stored indefinitely unless deletion/removal is requested by the original author.

  b. Publishing Content (comments, forums)

  • We use Google/G Suite to process all internal email and communication with our customers. Google’s privacy policy is available here.
  • Customers that email us, or use any of the contact forms on our website, will have their email address, IP address, and any data provided in the contact form or body of the email stored in G Suite archives and in our help desk third-party service provider, HelpScout. The HelpScout privacy policy is found here.
  • We use LiveChatInc to provide live chat and live support services. Any data provided during a live chat session with one of our team members will be recorded and logged in an email that is sent to our HelpScout help desk. This includes your name, email address, and IP address. The LiveChatInc privacy policy is found here.
  • LiveChatInc uses cookies to tailor chat sessions to the individual. No personal information is stored in these cookies (only visit history). Cookies expire in 3 years.
  • We keep all email and chat communication indefinitely to help us provide support and improve our services. Individuals can request copies of any previous correspondence with us at any time.

  c. Agency Directory (WPMU DEV)

  • Agencies interested in having a profile on our Agency Directory should provide the following information:
    • Company name
    • Company description
    • Website link
    • Logo
    • Location
    • Social media links (FB, LinkedIn, Instagram, and Twitter)
    • The services that the agency offers
    • Contact us page link
    • Screenshots and links to websites completed by the agency
    • The number of employees
    • The project sizes the agency accepts
    • The minimum project budget the agency accepts
  • We won’t share the agency information with third parties, although the directory is a publicly accessible page.
  • Your agency profile may be promoted through WPMU DEV social media channels, including Facebook, LinkedIn, Twitter, and Instagram.
  • Agencies may request updating or removing their agency profile via our contact us page here.
  • We may, in our discretion and without liability to you, with or without prior notice and at any time, modify or discontinue, temporarily or permanently, our agency directory.

CAMPUSPRESS

  a. Data We Collect

  • We don’t ask you for personal information unless we truly need it.
  • We encourage organizations we work with to integrate with existing authentication services so that passwords are not ever shared with us.
  • A valid email address is required for adult users that create registered accounts. This email address is for systems emails only and is not ever added to any marketing list or sold to any 3rd parties.
  • We maintain financial transaction records and contact information of school, district, and education organizations that purchase our services.
  • Beyond the above, no other personal information is collected. We do NOT collect education records, directory information, biometric data, health data, behavioral data, or other sensitive data.

  b. Data We Share

  • We do not rent or sell personally-identifying information to anyone.
  • We only use the information and data we collect for the purpose for which it was collected. We do share data with a limited number of 3rd parties explicitly to assist with the operation of our platform, including web hosts, email sending, payment processing, and support services.
  • We have vetted the policies of the 3rd parties we work with and a full and updated list is found in the subprocessors section below.
  • The CampusPress platform is 100% advertising free. We do not display ads, and we do not participate in any services that track visitors to display targeted ads on other websites.
  • We are a web publishing platform that allows registered users to upload and publish content. We have filtering tools in place to monitor user content for inappropriate misuse of our platform, such as spam.

  c. End-Of-Life of Data

  • As the host, our customers are responsible for determining end-of-life procedures for any and all data. This includes deleting or archiving data for individual sites or users. Otherwise, all data and content will remain in the database for as long as the site(s) remain hosted by us.
  • Should a customer leave us, or should a local archive of user data be required, we can provide a complete MySQL export and database dump of a network. We will completely purge all customer data within three months of canceling service from all backups and instances.

EDUBLOGS

  a. Data We Collect

  • We don’t ask you for personal information unless we truly need it.
  • We only require a username to create accounts for students.
  • A valid email address is required for adult users that create registered accounts.
  • Those who engage in financial transactions with Edublogs – by upgrading to a Pro account, for example – are asked to provide additional information, including as necessary the personal and financial information required to process those transactions.
  • Beyond the above, no other personal information is collected. We do NOT collect education records, directory information, biometric data, health data, behavioral data, or other sensitive data.

  b. Data We Share

  • We do not rent or sell personally-identifying information to anyone.
  • We only use the information and data we collect for the purpose for which it was collected. We do share data with a limited number of 3rd parties explicitly to assist with the operation of our platform, including web hosts, email sending, payment processing, and support services. We have vetted the policies of the 3rd parties we work with and a full and updated list is found in the subprocessors section below.
  • The Edublogs platform is 100% advertising free. We do not display ads, and we do not participate in any services that track visitors to display targeted ads on other websites.
  • We are a web publishing platform that allows registered users to upload and publish content. We have filtering tools in place to monitor user content for inappropriate misuse of our platform, such as spam.
  • All users have the right to a copy of their content and data that we store, and we will fully delete or anonymize any user’s data on request. We will verify the identity of the requestor via email, and parents have these rights for their minor children.

User Rights

WPMU DEV

  • If you are a registered user or have left comments on our site you can request to see or download the data we have about you.
  • Typically for visitors that have left comments, the data will be their email address, any IP addresses assigned to them at the time of leaving the comments and the user agent strings of the browsers they used. The rest of the data is public as published by the visitors.
  • For registered users or paying customers, this will also include profile information and download, payment, and support ticket histories.
  • You can also request “to be forgotten” and we will erase any personally identifiable data we have about you. Of course, this excludes data we need for administrative or security purposes or if we are required by law to retain some of the data.
  • An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his/her query to contact@wpmudev.com. We will respond within a reasonable timeframe, not to exceed one week.

CAMPUSPRESS

  • All users have the right to a copy of their content and data that we store, and we will fully delete or anonymize any user’s data on request. We will verify the identity of the requestor via email, and parents have these rights for their minor children.
  • The data request and erasure tools are built right into the WordPress dashboard and are automated. For those that can’t access the WordPress dashboard, they should contact the school/organization that owns the account first, and then contact@campuspress.com if needed.

EDUBLOGS

  • If you are a registered user or have left comments on our site you can request to see or download the data we have about you.
  • You can also request “to be forgotten” and we will erase any personally identifiable data we have about you.
  • Parents can also request a copy of the data we have or for data to be erased for their minor children.
  • We will verify the identity of those requesting copies of data or to be forgotten via email. Please email us at support@edublogs.org to get the process started.

Depending upon where you reside, you may have the following rights with regard to your personal information:

RightApplies To
The right to opt out of use of your personal information for the purposes of targeted advertising.Residents of Virginia, Colorado, Utah, Connecticut, Oregon, and Texas only
The right to access the personal information that we have collected about you.Residents of California, Canada, Australia, the European Union and/or the European Economic Area, the United Kingdom, Virginia, Colorado, Utah, Connecticut, Quebec, Oregon, and Texas only
The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which the personal information was collected, the business or commercial purpose for collecting, selling or sharing personal information, the categories of third parties to whom we disclose the personal information.Residents of California only
The right to know whether your personal information is sold or disclosed and to whom.Residents of California only
The right to say no to the sale of your personal information.Residents of California, Nevada, Virginia, Colorado, Utah, Connecticut, Oregon, and Texas only
The right to opt out of the sharing of your personal information.Residents of California only
The right to opt out of the use of your personal information for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.Residents of Virginia, Colorado, Connecticut, Oregon, and Texas only
The right to request that we delete all or some of the personal information that we have collected on you.Residents of California, the European Union and/or the European Economic Area, the United Kingdom, Virginia, Colorado, Utah, Connecticut, Oregon, and Texas only
The right not to be discriminated against based upon your exercise of your privacy rights.Residents of California, Virginia, Colorado, Utah, Connecticut, Oregon, and Texas only
The right to equal service and price, even if you exercise your privacy rights.Residents of California, Virginia, Colorado, Utah, and Connecticut only
The right to ask us to transmit your personal information that we have collected on you to another provider (where technically feasible).Residents of California, the European Union and/or the European Economic Area, and the United Kingdom only
The right to request that we amend any of the information that we have collected about you.Residents of California, Canada, Australia, the European Union and/or the European Economic Area, the United Kingdom, Virginia, Colorado, Connecticut, Quebec, Oregon, and Texas only
The right to withdraw your consent to the processing of your data.Residents of Canada, the European Union and/or the European Economic Area, the United Kingdom, and Quebec only
The right to request that we restrict the processing of your data.Residents of the European Union and/or the European Economic Area and the United Kingdom only
The right to lodge a complaint regarding our collection, sharing and processing of data with competent authorities in the proper jurisdiction.Residents of Canada, Australia, the European Union and/or the European Economic Area, the United Kingdom, and Quebec only
The right to not have to identify yourself, or of using a pseudonym in certain circumstances.Residents of Australia only
The right to stop receiving unwanted direct marketing.Residents of Australia and the European Union and/or the European Economic Area only
The right to receive the personal information that we hold about you in a portable and, to the extent feasible, a readily usable format that allows you to transmit this information to another entity.Residents of California, the European Union and/or the European Economic Area, the United Kingdom, Virginia, Colorado, Utah, Connecticut, Oregon, and Texas only
The right to limit the use and disclosure of your sensitive personal information.Residents of California and Connecticut only
The right to confirm whether we are processing your personal information.Residents of Oregon and Texas only
The right to obtain a list of the specific third parties to whom we have disclosed your personal information.Residents of Oregon only
The right to confirm the categories of your personal information that we have processed or are currently processing.Residents of Oregon only

Third Parties (Subprocessors)

a. Embedded Content From Other Websites

b. Analytics

  • We use Google Analytics for tracking visitors and aggregating information about the traffic to our website. The Google Analytics privacy policy can be found here. You can learn more about how to opt-out of tracking in Google Analytics here.
  • We use Mixpanel to track the logged-in activity of users of WPMU DEV. This includes profile information provided during signup. Mixpanel’s privacy policy is found here. Mixpanel uses cookies to track activity on the WPMU DEV site. Cookies include a unique identifier tied to your WPMU DEV account but does not include personally identifying information. Cookies expire within 1 year. Mixpanel, like Google Analytics, respects ‘Do Not Track’ settings that are available in modern web browsers.
  • We use Hotjar to help us analyze and improve user experiences. You may opt-out from having Hotjar collect your information when visiting a Hotjar Enabled Site at any time by enabling Do Not Track (DNT) in your browser. Hotjar’s privacy policy is found here.
  • We use Sentry for application monitoring. Sentry’s privacy policy can be found here.

c. Marketing Campaigns

  • We use email marketing to communicate with customers and potential customers from time to time.
  • We may also send you “system” emails, such as password reset requests or payment notifications/receipts even if you have not opted-in to email marketing lists.
  • All marketing emails sent by us will include an unsubscribe link in the footer of the email. Emails sent to you may also include standard tracking, including open and click activities.
  • We use a number of different services for email marketing. You can read the privacy policy of each service here: Mailjet, Airship, G2.
  • We may utilize social media and web advertising campaigns. These service providers use cookies on our sites and/or pixel tracking to serve ads across the different platforms.

d. Payment Processors

  • For business analytics and payment subscription records for WPMU DEV, we use Chartmogul. Chartmogul’s privacy policy can be found here.
  • For business analytics, CRM, and subscription records of Enterprise customers, we use Hubspot. Hubspot’s privacy policy can be found here.
  • For payment transactions for WPMU DEV, we support a number of different providers. You can read the privacy policy of each here: PayPal, Stripe, Google Pay, Apple Pay, Microsoft Pay.
  • To comply with accounting and legal requirements, we keep data on financial transactions in the systems above for up to 10 years.

e. Hosting, Domains, and API Services

  • All web servers and hosting are managed by our team on the Amazon Web Services, Digital Ocean, Vultr, and Linode platforms located in different regions around the world. This includes website hosting, backups, web database, file storage, APIs, and log files. Hosting and Enterprise customers may choose which region/country their website is hosted in, and in that case, all WordPress and database files for that site will be stored in that region only. Amazon’s privacy policy can be found here. Digital Ocean’s privacy policy can be found here. Linode’s privacy policy can be found here. Vultr’s privacy policy can be found here.
  • Our domain name registration services are provided by OpenSRS. In order to comply with the domain name registration rules outlined in our Terms of Service, domain registration information is collected and may be shared with OpenSRS. Domain owner information is required by OpenSRS and maintained in a Whois directory. OpenSRS’ privacy policy can be found here.
  • Our ‘Hummingbird’ and ‘Smush’ products and our hosting services use the Bunny Content Delivery Network (CDN). Bunny may collect anonymous web log information of site visitors, including browser name, pages visited, and points of interest on the website. Bunny may also share information with key third parties, including IP, browser user agent, browser language, and email address. Bunny’s privacy policy can be found here.
  • Our AI chatbot uses DocsBot AI (privacy policy) and Open AI (privacy policy).
  • For safely storing passwords and sensitive data, we use 1Password (privacy policy).

Data Security

The security and reliability of our service is our number one priority. We invest heavily in the training of our staff and our infrastructure to ensure that best practices are followed in everything that we do. We acquired a SOC type 2 certificate, you can request for a copy and find most controls in place in the following page: https://security.incsub.com/. See https://wordpress.org/about/security/ for details on the security of the WordPress core itself.

  • Prevention is best when it comes to security, and as a first step, we follow all WordPress Code Standards in the plugins that we build and use.
  • In addition, we have an extensive internal review and Quality Assurance process in place specifically to prevent potential security vulnerabilities in our plugins and services.
  • Every Incsub, LLC employee and contractor goes through background checks and an onboarding process that includes a trial period where access to customer data is provided only when working directly under the supervision of another staff member.
  • All staff only have access to systems that are directly required to complete the functions of their job. We use dual factor authentication for all critical systems and communications services, and automatically log all staff activity using an internal logging tool, Google ‘G’ Suite features, and Amazon Cloud Trail.
  • All staff (including any contractors) undergo initial training to ensure proper understanding of all security-related processes. Staff regularly attend industry conferences and otherwise stay informed of best practices and relevant trends. Staff review and agree, in writing, to all policies and procedures annually.
  • We only use third-party services, such as Amazon Web Services, that are fully vetted and adhere to the highest levels of privacy and security practices.

CAMPUSPRESS

How safe is CampusPress?

  • All user accounts can only be created under a school, district, university, or education organization sponsored account.
  • Account registration is required in order to access the web publishing platform and before any data is shared with us.
  • We aim to make it as simple as possible for customers to control the content that is visible to the public, seen by search engines, kept private, and permanently deleted.
  • We fully encrypt all user data both at rest and in transit, including all system backups and user-uploaded files and content.
  • All employees receive regular training on privacy practices, and we utilize detailed audit logging of employee and staff activity to track when customer data is accessed or changed.
  • We have a security breach notification plan in place, which can be found here.
  • We follow best security practices and can provide 3rd party reports about our security and privacy practices on request.

EDUBLGOS

How safe is Edublogs?

  • For children under 13, student accounts can only be created under a teacher or school-sponsored account (using an invite code), otherwise, express written permission from a parent or guardian is required.
  • Account registration is required in order to access the web publishing platform and before any data is shared with us.
  • By default, blogs and student-created content are private and can only be made public with the approval of a teacher (when attached to a class account) or by express written request by a parent.
  • We aim to make it as simple as possible for you to control the content that is visible to the public, seen by search engines, kept private, and permanently deleted.
  • We fully encrypt all user data both at rest and in transit, including all system backups and user-uploaded files and content.
  • All employees receive regular training on privacy practices, and we utilize detailed audit logging of employee and staff activity to track when customer data is accessed or changed.
  • We have a security breach notification plan in place, which can be found below.
  • We follow best security practices and can provide 3rd party reports about our security and privacy practices on request.

Data Breach Procedures

Should any event occur where customer data has been lost, stolen, or potentially compromised, our policy is to alert our customers via email no later than 48 hours of our team becoming aware of the event. We will also report such incident to any required data protection authority. We will work closely with any customers affected to determine next steps such as any end-user notifications, needed patches, and how to avoid any similar event in the future.

Independent Dispute Resolution Body

In compliance with the EU-U.S. DPF, and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, Incsub, LLC commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF, and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF to JAMS, an alternative dispute resolution provider based in the United States.  If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint.  The services of JAMS are provided at no cost to you.

Regulatory Compliance & Privacy Protection

In the course of operating our web business in the United States, we want to transparently communicate our commitment to regulatory compliance and the protection of your privacy. As part of this commitment, it’s essential to highlight that we are subject to the investigatory and enforcement powers of various U.S. authorities, including the Federal Trade Commission (FTC) and other authorized statutory bodies. We take these obligations seriously, ensuring that our practices align with the standards set forth by these entities.

Moreover, in certain circumstances, individuals have the option to invoke binding arbitration. This means that, under specific conditions, you have the ability to resolve disputes in a fair and impartial manner. We believe in providing you with avenues for recourse that are accessible and reasonable (Annex I for additional information https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction).

Additionally, we want to make it clear that we adhere to legal requirements regarding the disclosure of personal information. This includes responding to lawful requests from public authorities, especially when it comes to meeting national security or law enforcement requirements. Our commitment to transparency extends to these scenarios, where we prioritize compliance with applicable laws and regulations.

Furthermore, we acknowledge our responsibility in cases of onward transfers of personal information to third parties. We understand the importance of ensuring that your information remains protected even when shared with external entities, and we take measures to maintain the privacy and security of your data.

In summary, our dedication to regulatory compliance and privacy protection is fundamental to our business operations. By outlining these principles, we aim to build trust and confidence in our users, assuring you that we prioritize your privacy rights and adhere to the highest standards of data protection in the United States.For those wanting something more formal in place (and enhanced GDPR compliance), please contact us to request a signed copy of a Data Protection Agreement (DPA).

Cookie Declaration

Changelog

  • v1 – complying with the Data Privacy Framework program