Spayne Studio – Website Care Scope & Disclaimer
Plain-language terms covering website care, security, and maintenance work.
What I do
- Manage WordPress core, plugin, and theme updates as part of agreed work.
- Apply basic hardening steps: password resets, admin user review, and removing unnecessary access.
- Act on findings from security scanning tools (such as MalCare, Sucuri, or Wordfence), and escalate to a specialist when a serious compromise is identified.
- Coordinate with hosting providers and security vendors when issues arise, within the hours agreed for the project.
- Take reasonable care and follow current best practice for WordPress site management.
What I don’t do
- I am not a 24/7 security operations centre, and I don’t monitor your site around the clock unless that’s specifically agreed as part of an ongoing arrangement.
- I don’t guarantee that your site will never be hacked, compromised, or affected by malware. No one can promise that.
- I don’t provide legal advice, data-breach notification advice, or formal forensic investigation. If a compromise requires that level of specialist work, I’ll recommend a suitable provider.
- I don’t take responsibility for issues caused by third-party plugins, themes, hosting infrastructure, or actions taken by other people with access to your site.
Your responsibilities as the client
- Maintain your own legal policies (privacy policy, terms and conditions, disclaimers) — I’m happy to point you toward tools that can help with this.
- Let me know promptly if you notice anything unusual or suspicious on your site.
- Approve any significant changes before I make them: installing new plugins, removing staging environments, deleting user accounts, and similar.
- Keep your own account credentials (hosting login, domain registrar, etc.) secure on your end.
Limitation of liability
I’ll take reasonable care and follow current best practice in everything I do, but I can’t guarantee your site will never be compromised, and I can’t be held responsible for losses beyond the amount you’ve paid me for the specific service in question.
A note on incident response
If your site is compromised, there’s a difference between:
- Routine care — updates, monitoring, basic hardening — which is covered under an ongoing arrangement where one exists.
- Active incident investigation and coordination — deep log review, liaising with removal specialists, and managing a security incident from end to end — which is treated as separate, billable work unless otherwise agreed in writing.
I’ll always tell you clearly which category a piece of work falls into before I start it.
This document sets out my working terms in plain language. It isn’t a substitute for formal legal advice, and either of us can raise questions about it at any time.
Spayne Studio spaynestudio.com