Website Access & Security Policy
Effective Date: 01/01/2026
1. Purpose
This policy establishes the standards governing access to websites, hosting environments, and digital infrastructure managed by 1UpDigital. Its purpose is to protect the security, stability, integrity, and confidentiality of client websites while ensuring professional and transparent management practices.
2. Scope
This policy applies to:
* All websites developed or managed by 1UpDigital.
* All employees, contractors, consultants, and third-party service providers.
* All clients whose websites are hosted or maintained by 1UpDigital.
3. Guiding Principles
1UpDigital is committed to:
* Protecting client data and digital assets.
* Following the principle of least privilege, whereby users receive only the access required to perform their duties.
* Maintaining website security and operational stability.
* Providing transparent communication with clients regarding access and management.
4. Website Ownership
1. The client retains ownership of their website content, branding, and any intellectual property created specifically for them, unless otherwise agreed in writing.
2. 1UpDigital may retain ownership of proprietary systems, frameworks, development tools, software licences, and internal infrastructure used to build or manage the website.
3. Ownership of a website does not automatically grant unrestricted administrative access to managed infrastructure or security systems.
5. Access Management
5.1 User Access
Access will be granted according to business requirements and the principle of least privilege.
User roles may include:
* Content Editor
* Website Administrator
* Developer
* Hosting Administrator
* Super Administrator (Restricted)
5.2 Super Administrator Access
Super administrator access is reserved exclusively for authorised personnel of 1UpDigital.
Super administrator access will not ordinarily be granted to:
* Third-party agencies
* External developers
* Marketing companies
* Contractors not engaged directly by 1UpDigital
Exceptions may be considered only where approved by management and documented in writing.
6. Third-Party Agencies
Where a client appoints another agency to assist with their website:
* 1UpDigital will cooperate professionally.
* Appropriate role-based access may be provided where operationally necessary.
* Access will be limited to the minimum permissions required.
* Shared administrator accounts are prohibited.
* All access remains subject to 1UpDigital’s security standards.
7. Website Changes
Clients may request website updates by:
* Submitting requests directly to 1UpDigital.
* Authorising an approved third party to perform specific work using the access level provided.
8. Security
To protect client websites:
* Multi-factor authentication should be enabled where available.
* Individual user accounts must be used.
* Password sharing is prohibited.
* Access permissions may be reviewed, modified, suspended, or revoked where necessary to protect website security.
9. Liability
1UpDigital cannot accept responsibility for:
* Changes made by third parties outside the permissions granted.
* Security incidents resulting from unauthorised access.
* Downtime, data loss, or functionality issues caused by modifications made without 1UpDigital’s involvement.
10. Website Transfers
Should a client choose another service provider:
* 1UpDigital will cooperate fully in facilitating a professional handover.
* Any outstanding contractual obligations must be settled before the transfer is completed.
* The handover will include all client-owned assets in accordance with the applicable agreement.
11. Policy Amendments
1UpDigital reserves the right to amend this policy from time to time to reflect changes in security requirements, technology, legislation, or business operations.
⸻
1UpDigital
Committed to secure, professional, and transparent website management.