Privacy policy
We collect what it takes to answer you, do the work, and keep this site running. We sell none of it, and we delete what we no longer need. The rest of this page is the detail, including every outside service the site uses and what each one sees.
01Who we are
This site is run by The DaaS Labs (Pvt.) Ltd., a software development company registered in Islamabad, Pakistan. In this policy, we and us mean The DaaS Labs, and you means anyone who visits the site, gets in touch, applies for a role, or becomes a client.
For data protection purposes we are the controller of the information described below, and a processor of any personal data inside systems we build or maintain for a client. Client agreements govern the second case.
02What we collect
When you visit. The pages you view, the site that sent you, your browser and device, and an approximate location worked out from your IP address. We also see recordings of how pages are used — where people click, scroll and move the pointer. Anything typed into a form is masked in those recordings: they show that a field was filled in, not what was written.
When you send a message. Your name, email address, company if you give one, what you write, and how far along you are, from the options on the form.
When you book a call. Your name, email address, the time you pick, and anything you write about what is blocking you.
When you subscribe. Your email address, and nothing else.
When you apply for a role. Your name, email address, the links you give to your work and CV, your two written answers, and your availability.
On any of those forms. Google reCAPTCHA checks that a person, not a script, is sending it. It loads when you start filling in a form, and judges from how the page is being used and from details of your browser, device and IP address.
When you work with us. The access credentials, repositories and systems you grant us, and the contact details of the people we work with day to day.
03Why we use it
To reply to you, to prepare for and run the call you booked, to consider your application, to send the newsletter you asked for, to deliver the work you engage us for, to invoice, and to meet our own legal and accounting obligations.
The analytics, recordings and error reports tell us which pages get read, where people get stuck and what breaks, so we can fix it. We use them to improve the site, not to identify you. reCAPTCHA keeps the forms free of spam.
We do not use your data to train models, we do not add to it with data bought from brokers, we do not sell it, and we do not send marketing to anyone who has not asked for it.
04Legal basis
Where the GDPR or UK GDPR applies, we rely on contract for work you have engaged us for; on legitimate interest for replying to messages and bookings, considering applications, keeping the site secure and free of spam, and understanding how it is used; on your consent for the newsletter, which you can withdraw at any time; and on legal obligation for tax and accounting records.
07Where it is stored
We are based in Pakistan, and most of the services above run from the United States. Where the GDPR or UK GDPR applies, transfers rely on the safeguards those services provide, such as the standard contractual clauses approved by the European Commission.
08How long we keep it
Messages and booked calls that do not turn into work are deleted within twelve months. Newsletter addresses are kept until you unsubscribe, and every issue carries a link to do that.
Applications are held in HireBench rather than on this site, and we delete yours on request. Analytics, recordings and error reports are kept for the periods each service sets, and hosting logs only briefly.
Client records are kept for the length of the engagement plus the seven years our accounting obligations require. Access credentials are revoked and deleted at the end of an engagement, and we ask you to rotate anything shared with us.
09Your rights
You can ask for a copy of what we hold about you, ask us to correct or delete it, object to a particular use, or ask us to stop contacting you. Write to hello@thedaaslabs.com and we will act within thirty days.
If you are in the EU or UK and you think we have handled something badly, you may complain to your local supervisory authority. We would rather you told us first.
10Security and changes
Access to client systems is limited to the sprint team, granted through your own identity provider wherever possible, and revoked when the engagement ends. Company devices are encrypted and require multi-factor authentication.
If this policy changes materially we will say so on this page and update the date above. Continued use of the site after that means the updated policy applies.