Privacy Policy
This policy explains what personal data zencryptix.com collects, why we collect it, and what you can do about it. It is written in plain English because that is how we prefer to work.
Who we are and how to contact us
Zencryptix is a cybersecurity consultancy headquartered in Pakistan and serving clients worldwide. We are the data controller for personal data collected through this website.
For anything related to privacy, email Business@zencryptix.com. We aim to respond within 24 hours.
What we collect
This is a brochure site. There are no accounts, no logins, no payments and no newsletter. We collect only what is listed here:
- Contact form: your name, email address and message, plus an optional phone number with country code. The form sends these details to our company inbox by email. The server also includes your IP address and browser user-agent string in that email so we can spot spam and abuse.
- Rate-limit logs: to stop the form being flooded, the server keeps short-lived logs and temporary block records keyed by a hashed (SHA-256) version of your IP address. They hold timestamps only, not your message, and are purged automatically once they are more than 7 days old.
- Server access logs: our web hosting provider records the IP address, requested URL, time and browser user agent of each request, as almost every web server does, and keeps those logs for a limited period for security and troubleshooting.
- Analytics: Google Analytics 4, with IP anonymisation switched on, gives us aggregate statistics such as page views, approximate location, device type and referral source. We also measure clicks on our WhatsApp, phone and email links, and whether the contact form was submitted. We do not send names, email addresses or message content to Google.
- Third-party resources: pages load Google Fonts, Font Awesome icons from cdnjs (Cloudflare), flag images from flagcdn.com and the Google Analytics script. Your browser requests these directly, so each provider receives your IP address and standard request headers.
- Direct contact: if you email, call or message us on WhatsApp, we hold whatever you choose to share with us.
How we use it
We use the data described above for three purposes:
- To respond to your enquiry, scope the work you describe and, if you engage us, manage that relationship.
- To run and protect the site: block spam, rate-limit abusive traffic and investigate attacks against the form.
- To measure traffic, so we understand which pages and services people care about and where the site can improve.
We do not use your data for automated decision-making or profiling, and we do not build marketing lists from form submissions.
Legal bases
Where data protection law such as the GDPR or UK GDPR applies, we rely on the following bases:
- Steps before a contract: when you submit the contact form or message us, we use what you send to reply and to scope the work you describe. You can ask us to delete it at any time.
- Legitimate interests: answering enquiries, keeping the site secure and free of abuse, and understanding aggregate traffic through anonymised analytics. We have balanced these interests against your privacy and kept the data involved to a minimum.
- Contract: if you become a client, processing needed to deliver the engagement.
- Legal obligation: where the law requires us to keep or disclose records.
Sharing and processors
We do not sell personal data. We do not share it with advertisers or data brokers. The only parties that handle it are the providers we need to run the site:
- Our web hosting provider, which serves the site and keeps standard server access logs (IP address, requested URL, time and user agent) for a limited period for security and troubleshooting.
- Our email hosting provider, which delivers and stores contact form emails.
- Google, for Google Analytics 4 and Google Fonts.
- Cloudflare, which serves Font Awesome through cdnjs.
- flagcdn.com, which serves the flag images in the country-code selector.
- Meta (WhatsApp), if you choose to open a chat with us. That conversation is governed by WhatsApp's own terms and privacy policy.
Each provider processes data under its own terms. We may also disclose data where the law requires it, or to protect our rights or the safety of others.
International transfers
We are based in Pakistan. The providers above operate globally, so data may be processed in the United States, the European Economic Area or other countries. Where EEA or UK data protection law applies, we rely on the safeguards those providers offer, such as standard contractual clauses, and on the fact that we collect very little in the first place.
Retention
We keep personal data only for as long as it serves the purpose it was collected for:
- Enquiry emails: kept for as long as needed to handle the enquiry and any resulting business relationship, then deleted. You can ask us to delete them sooner.
- Rate-limit and abuse logs: purged automatically once they are more than 7 days old. Housekeeping runs periodically, so removal is not instantaneous.
- Server access logs: kept by our hosting provider for a limited period, then rotated.
- Analytics: kept for the retention period set in our Google Analytics account, which is never longer than 14 months for user-level data. Aggregate reports may persist longer.
- WhatsApp, phone and email conversations: kept for as long as the business relationship requires.
Cookies and analytics
This site sets no cookies of its own. The only cookies come from Google Analytics 4, which uses them to distinguish visitors and sessions. IP anonymisation is enabled, so Google truncates your IP address before storing it.
You can opt out in several ways:
- Block or delete cookies in your browser settings. The site works fine without them.
- Install the Google Analytics opt-out browser add-on, available from Google.
- Use a content blocker that stops the googletagmanager.com script from loading.
Google's own privacy policy explains how Google handles the data it receives.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct anything that is inaccurate.
- Have it deleted.
- Object to, or restrict, our processing.
- Receive a copy in a portable format.
- Withdraw any consent you have given.
Visitors in the EEA and UK have these rights under the GDPR and UK GDPR, and may complain to their local supervisory authority. To exercise any right, email Business@zencryptix.com. We may need to verify your identity first. We respond within one month, extendable where the law allows for complex requests, and do not charge for reasonable requests.
Security
We are a security company and we treat our own site accordingly:
- All traffic is encrypted with TLS.
- The form handler is hardened: same-origin checks, signed anti-CSRF tokens, a honeypot field, per-IP and global rate limits, strict input validation and header-injection-safe mail composition.
- We collect the least data needed. Rate-limit logs store hashed IPs rather than raw addresses, and the site holds no database of visitor records beyond routine server logs. If an enquiry email fails to send, the server error log may briefly record the IP address so we can diagnose the failure.
- Access to the inbox that receives enquiries is restricted to the team members who need it.
No system is perfectly secure, and we will not pretend otherwise. If you notice a security issue with this site in the course of normal use, we would genuinely like to hear from you at security@zencryptix.com. Our Terms of Service explain how we handle such reports.
Children
This site is aimed at organisations and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has sent us personal data, email us and we will delete it.
Client engagement data
During a security assessment we may handle sensitive data belonging to a client: credentials, source code, system configurations, vulnerability findings and sometimes personal data of the client's own users. That data is not covered by this policy. It is governed by the NDA and contract for the engagement, together with our Rules of Engagement.
In short: we sign an NDA before scoping, we encrypt evidence in transit and at rest, and we handle client data only as the contract allows.
Changes to this policy
We will update this policy when the site or our practices change. The effective date at the top tells you when it was last revised. Material changes will be flagged on this page. Continued use of the site after a change means the new version applies.
Governing law
This policy is governed by the laws of Pakistan. Nothing in it removes rights you have under mandatory data protection law where you live, including the GDPR and UK GDPR.