A WordPress site serving organisations in Geneva sits next to Palais des Nations, WTO and WHO headquarters, ICRC and hundreds of NGO offices in Canton de Genève. That proximity does not turn a marketing site into a UN enterprise system or a bank transaction platform. It does mean updates, backups, logs and form integrations are discussed before the first production change, not as an appendix after an incident that triggers a question from legal about revFADP and the Federal Data Protection and Information Commissioner (FDPIC, EDÖB in German).
WPPoland delivers ongoing WordPress maintenance from a senior Polish team for businesses, foundations, international organisations and financial-sector clients with a headquarters, branch or donor base in Geneva. Scope is WordPress maintenance: tested updates, daily backups, security and performance monitoring, incident response under a written SLA, and up to four hours of small development changes per month. Custom theme builds and plugin development are separate topics, described on the WordPress developer in Geneva page.
#WordPress maintenance in Geneva and Canton de Genève
Geneva is not Zurich with banking towers and the stock exchange, nor Bern with the Bundeshaus. It is the densest node of international organisations on the planet: Palais des Nations, WTO, WHO, ICRC, dozens of UN specialised agencies and hundreds of NGOs with offices near Place des Nations. Alongside that sits Geneva Financial Centre: private banking, wealth management, family offices and regulatory advisory within a few tram stops of Rive. Geneva Digital Hub at Rue du Stand 5 adds startups and scale-ups that ship digital products but still need a site that survives a compliance audit.
For WordPress maintenance those facts translate into three recurring requirements. First, update discipline: Core, plugins and themes ship through staging, with regression checks in FR-CH and EN before production promotion. Second, decision trail: who approved the update, what changed, what was rolled back, and what remains in the monthly report. Third, residency and retention: backup location, log retention and processor documentation are recorded in the runbook, not assumed because hosting sits in Switzerland.
The typical brief that reaches maintenance in Geneva does not read “keep it updated somehow”. It reads: last Core update was eight months ago, backup plugin shows green but nobody has restored since 2022, WPML or Polylang serving English text on the French version after a patch, and a new conference landing broke layout because someone updated Elementor without staging the day before a Council session. That is an operations and process problem, not a marketplace-theme problem.
WPPoland is not a contractor for the UN or a Geneva private bank. Proximity to international organisations and Geneva Financial Centre sets the bar for documentation, roles and multilingual delivery. It does not set a list of institutional references.
#What the monthly maintenance package includes
Maintenance in Geneva is a written SLA, not a vague “we look after the site”. The monthly package covers:
- Tested updates: WordPress core, plugins and themes updated on staging first. Regression checks cover front templates, forms, FR-CH/EN language pairs, consent banners and critical user journeys. Production promotion follows a documented step with rollback path.
- Daily backups with 30-day retention: automated backups stored in geographically separate locations. Restore is tested on staging at onboarding and at least quarterly thereafter. A backup that has never been restored is decoration, not recovery.
- Security monitoring: malware scanning, file integrity checks, login attempt monitoring, WAF rules tuned for WordPress attack vectors, and quarterly security review of plugin inventory and admin accounts.
- Uptime and performance monitoring: synthetic checks at one-minute intervals, PageSpeed and Core Web Vitals tracking on templates that actually exist (not only the homepage), alerts via Slack and email.
- Small development hours: typically two to four hours per month for content-model tweaks, block fixes, form adjustments, accessibility patches and editorial workflow improvements without opening a separate project.
- Priority support: sub-four-hour weekday response for priority tickets. Confirmed security incidents and production outages trigger the SLA workflow outside hours where the contract covers it.
- Monthly status report: metrics (uptime, backup success, update log, performance trend), decisions taken, remaining risks, and incident summary if applicable.
Pricing is individual and delivered in writing after scope is agreed. There is no rate card on this page.
#Onboarding audit and inherited installs
Every engagement in Geneva starts with an onboarding audit, usually about one hour on the live install plus follow-up on staging setup. The audit documents:
| Area | What is checked |
|---|
| Plugin inventory | active plugins, last update dates, known CVEs, overlap with consent and cache layers |
| Hosting | PHP version, memory limits, object cache, TLS, CDN, CH residency if contract requires it |
| Backups | schedule, retention, last successful restore test, off-site copy |
| Security | admin accounts, 2FA, file permissions, XML-RPC, file editor, secrets in Git |
| FR-CH/EN setup | Polylang or WPML configuration, hreflang, broken language pairs, string sync |
| Performance | Lighthouse baseline on homepage, CPT archive and a representative landing in both languages |
| Compliance hooks | consent plugin behaviour, form data flows, log retention, privacy policy links |
Inherited installs are common in Geneva. The first month often involves more remediation than routine maintenance: patching vulnerable plugins, fixing broken backups, removing malware, stabilising an FR-CH/EN pair that drifted apart, or moving secrets out of wp-config.php in Git history. Remediation is listed with priorities before steady cadence begins. Steady maintenance does not start on a site where restore has never been verified.
#Tested updates and staging discipline
The most expensive maintenance failure in Geneva is not a missed minor plugin update. It is a Core or major plugin update pushed to production on a Thursday because “it looked fine on localhost”, breaking the French version of a conference landing the day before a Council session at Palais des Nations.
Staging is a production copy with anonymised data. WP-CLI search-replace on URL, separate keys, crons that send mail to real donors or journalists disabled. Editorial and IT click through staging with real Gutenberg patterns in both languages, not on the developer’s laptop. Multilingual regression, form submission and keyboard navigation happen here.
Production promotion is a documented step: tag or merge, asset build, cache warmup, rollback path to the previous tag. The team does not “quick upload” one PHP file over SFTP, because nobody can reconstruct what was on production on Friday before an annual report publication goes live.
Update cadence follows risk, not calendar superstition. Security patches for actively exploited CVEs move faster than cosmetic plugin updates. Major version jumps (PHP, Core, WooCommerce if present) get their own written plan and acceptance criteria. WooCommerce stores are a separate scope; if the brief includes checkout, see WooCommerce developer in Geneva.
Release freeze around major UN conferences or annual report publication is an operator decision, not only a calendar note. During Council session, climate summit or report launch week, production does not get a new theme.json, new CPT, URL map change or header rebuild. A security patch that cannot wait goes through staging as hotfix, with rollback written before anyone presses deploy.
#Backups, restore and hosting in Switzerland
Hosting “in Switzerland” is a jurisdiction argument in procurement, not a magic shield. A donor form collecting personal data without legal basis is not fixed by a server in Geneva alone. Maintenance still records where backups live, whether off-site copies cross borders, and what the client’s processor agreement requires.
Practical backup rules written into the runbook:
- Daily automated backup of files and database, 30-day retention minimum unless contract says otherwise.
- Off-site copy in a separate region or provider from production.
- Restore test on staging at onboarding, then quarterly. The test produces a timestamped note in the monthly report.
- Backup encryption at rest where the hosting stack supports it.
- Documented recovery time objective agreed in the SLA, not invented after an outage.
Infomaniak, headquartered in Geneva, is a common choice for clients who want Swiss data centres and green energy credentials. Hostpoint, Cyon and Metanet cover other profiles. Edge through Cloudflare or Fastly with origin in CH is the typical compromise between performance and residency. If the client requires backups to remain in CH, that is a contract topic checked at onboarding against the actual provider configuration, not an assumption from the TLD.
#Security, revFADP, FDPIC and GDPR in cross-border briefs
Proximity to international organisations and Geneva Financial Centre does not turn a marketing WordPress site into a FINMA-supervised system. WPPoland does not claim “ISO 27001 compliant” or “WCAG certified” unless the client ran that audit. Maintenance delivers inventory, access trail and update discipline the client can paste into procurement or processor-agreement documentation, not an agency compliance stamp.
Posture maintainable in code and process:
- No secrets in Git. Keys, database passwords and CRM or donor-system tokens go through environment variables or outside the repo.
- Admin accounts use 2FA. Polish editors do not get install_plugins on production. Roles are cut to what Gutenberg requires.
- XML-RPC stays disabled unless a justified client needs it. File editor in the admin too.
- Headers: HTTPS, HSTS where certificate and CDN allow, CSP matched to real scripts (consent, tag manager, fonts).
- Dependencies: pinned plugin versions, CVE awareness, updates on staging before production. Unpatched Core is worse than skipping a new “security” plugin.
- Logs: who logged into wp-admin, which plugin change shipped when. Retention agreed with revFADP and client policy, not “keep everything forever”.
The revised Federal Act on Data Protection (revFADP / nDSG) took effect on 1 September 2023. It is GDPR-aligned but not identical: stricter on consent for profiling, lighter on documentation thresholds for SMEs, explicit on data export outside the EEA. Supervision sits with the Federal Data Protection and Information Commissioner (FDPIC / EDÖB) in Bern. Art. 19 requires identity of the controller, purpose, recipients and, on cross-border transfer, country and safeguards. A personal data breach is reported by the controller when there is likely high risk to personality or fundamental rights; the processor reports to the controller, not the portal.
GDPR still applies to processing aimed at people in the EU. A Geneva company site with EU traffic therefore has two layers, not one. A cookie plugin copied from a German shop is not automatically “nDSG-compliant”, and no banner is not automatically legal when tracking, profiling or transfer to an inadequate country is in play. Maintenance supports the data controller with evidence: what personal data the site processes through forms and analytics, which subprocessors touch it, where backups and logs sit, and what happened during an incident. After a personal-data breach the client may need to notify FDPIC; logs and the incident timeline must fit a notification workflow. WPPoland documents interventions with timeline, root cause and remediation steps. It does not file on behalf of the data controller.
For Geneva financial-sector clients FINMA cyber-security guidance adds incident reporting, third-party risk and operational resilience. An advisory information site usually does not meet that directly, but a client portal or application form already does. That is flagged at onboarding, not at launch.
#FR-CH/EN multilingual maintenance
The most common post-update regression in Poland-Geneva collaboration is not PHP fatal errors. It is the French version showing English strings because a plugin update reset language mappings or because someone edited the EN page and the FR-CH copy was never synced.
Maintenance for multilingual sites in Geneva includes:
- Regression checks in both language versions after every staging update cycle.
- Monitoring for hreflang errors and broken language switcher links.
- String-level awareness: consent banners, form errors and aria-labels must stay aligned across FR-CH and EN. French interface strings use formal vous, not tu.
- Editorial freeze windows recorded in the runbook (Council session, report launch, donor campaign) when production changes require explicit approval.
- Monthly report note when a language pair was touched, what was verified, and what remains for client-side FR or EN approval.
FR-CH is not FR-FR. Swiss French uses different administrative terms, spelling on some words and a different official register. A pipeline that outputs Parisian French sounds wrong near Place des Nations even with correct grammar. Polylang and WPML solve hreflang and language copies. They do not solve process: who approves French text, who approves English, before production. The maintenance runbook records whether approval sits with the client in Geneva, with the foundation editorial desk, or with the Polish content lead.
#Monitoring, SLA and incident response
Monitoring combines synthetic uptime checks, application-level alerts and security scanning. Alerts route to Slack and email with enough context to triage without logging into five dashboards.
Incident management follows ITIL-lite: detection, triage, resolution, post-mortem. Every confirmed incident gets a root cause summary within 48 hours. SLA compliance is tracked against the contracted uptime tier, with monthly reports surfacing target and actual rather than a marketing number.
Priority tickets: sub-four-hour response on weekdays. Confirmed security incidents and production outages: response outside hours where the SLA covers it. The intervention is logged with timeline, containment steps, remediation and follow-up risks. That log is what legal and IT in Geneva need when asking “what happened between 14:00 and 16:30 on Tuesday”.
Communication runs through a written ticketing channel. Calls unblock decisions; they do not replace the audit trail.
#Performance maintenance
Speed in Geneva is not vanity. NGOs, foundations and financial-sector firms compete on credibility; a site that loads in four seconds on mobile loses form completions and signals neglect to reviewers accustomed to international project standards.
Performance maintenance includes:
- Core Web Vitals tracking on real templates: homepage, publication CPT archive, single report, hero pattern page in FR-CH and EN.
- Image pipeline review: AVIF/WebP delivery, responsive srcsets, lazy loading without breaking LCP.
- Cache layer health: object cache hit rate, CDN cache rules, transient bloat from abandoned plugins.
- Database hygiene: autoloaded options audit, revision limits, orphaned post meta from retired plugins.
- Quarterly performance trend in the monthly report with before/after when a change was shipped.
Performance budgets are set at onboarding and checked against lab and, where available, CrUX field data. Regressions after updates are caught on staging, not discovered by the client on Monday morning before a briefing at Place des Nations.
#Relationship to development and handover
Maintenance is the steady state after launch, or the rescue lane for a site that outgrew DIY updates. If the site needs a new block theme, custom plugin or large refactor, scope moves to WordPress developer in Geneva. If the site needs checkout, TWINT or product catalogues, scope moves to WooCommerce developer in Geneva.
Development engagements end with a runbook: how to add a pattern, how to ship a branch, how to rebuild staging, whom to call when the editor will not save, which conference dates block release. Maintenance picks up that runbook and keeps it current as Core, plugins and hosting evolve. A handover without a runbook is a support ticket waiting to happen.
#Geneva Digital Hub and the local tech scene
Geneva Digital Hub at Rue du Stand 5 is a reference point for Geneva’s digital ecosystem: meetups, networking, projects linking international organisations, startups and IT suppliers. It is not a WPPoland sales argument. It is a barometer: editorial and IT teams in Geneva ask about restore tests and staging because they heard those questions at local meetups and in foundation compliance reviews.
Commuters from Lausanne, Nyon and the French border work in one office in French and English, so an FR-CH/EN front with Polish editorial back office is more common here than a purely Polish front with a French panel. For Geneva, multilingual delivery, NGO and financial-sector adjacency, and revFADP documentation matter more than pretending to be Zurich banking or Bern federal administration.
#How to start maintenance in Geneva
A short brief is enough to begin: which theme and plugins exist today, who edits (PL/FR/EN), when backups last restored successfully, whether the front is multilingual, where hosting sits and whether backups must stay in CH, and whether Geneva IT requires Git and staging from day zero. WPPoland reviews the install, lists risks (unpatched Core, secrets in repo, broken FR-CH/EN pair, consent plugin sending data outside CH) and proposes a plan with acceptance criteria and SLA terms.
Contact: WPPoland contact form. The service pillar without city in the slug remains at WordPress maintenance. Custom development in Geneva is at WordPress developer in Geneva.