Legal

Privacy policy

LAST UPDATED 12 SEPTEMBER 2026

We collect what it takes to answer you, do the work, and keep this site running. We sell none of it, and we delete what we no longer need. The rest of this page is the detail, including every outside service the site uses and what each one sees.

01Who we are

This site is run by The DaaS Labs (Pvt.) Ltd., a software development company registered in Islamabad, Pakistan. In this policy, we and us mean The DaaS Labs, and you means anyone who visits the site, gets in touch, applies for a role, or becomes a client.

For data protection purposes we are the controller of the information described below, and a processor of any personal data inside systems we build or maintain for a client. Client agreements govern the second case.

02What we collect

When you visit. The pages you view, the site that sent you, your browser and device, and an approximate location worked out from your IP address. We also see recordings of how pages are used — where people click, scroll and move the pointer. Anything typed into a form is masked in those recordings: they show that a field was filled in, not what was written.

When you send a message. Your name, email address, company if you give one, what you write, and how far along you are, from the options on the form.

When you book a call. Your name, email address, the time you pick, and anything you write about what is blocking you.

When you subscribe. Your email address, and nothing else.

When you apply for a role. Your name, email address, the links you give to your work and CV, your two written answers, and your availability.

On any of those forms. Google reCAPTCHA checks that a person, not a script, is sending it. It loads when you start filling in a form, and judges from how the page is being used and from details of your browser, device and IP address.

When you work with us. The access credentials, repositories and systems you grant us, and the contact details of the people we work with day to day.

03Why we use it

To reply to you, to prepare for and run the call you booked, to consider your application, to send the newsletter you asked for, to deliver the work you engage us for, to invoice, and to meet our own legal and accounting obligations.

The analytics, recordings and error reports tell us which pages get read, where people get stuck and what breaks, so we can fix it. We use them to improve the site, not to identify you. reCAPTCHA keeps the forms free of spam.

We do not use your data to train models, we do not add to it with data bought from brokers, we do not sell it, and we do not send marketing to anyone who has not asked for it.

05Services that see your data

The site runs on a short list of outside services. Each handles data under its own terms and privacy policy.

Vercel hosts the site. Like any web host it logs each request, including your IP address, and keeps those logs briefly to run and secure the service.

Google provides four things: Analytics, which counts visits and where they come from; reCAPTCHA, which protects the forms; Calendar and Meet, which hold a booked call and send you its invite; and an icon font on one older page, which your browser fetches from Google when you open it. What Google does with that data is covered by its privacy policy.

Microsoft Clarity shows us how pages are used, through heatmaps and recordings of visits, with form fields masked. It is covered by the Microsoft Privacy Statement.

Sentry reports errors so we can fix them. A report can include your IP address and details of the request that failed. It also keeps a replay of one visit in ten, and of any visit where an error occurs, with all text and input masked.

Resend holds the messages sent through the contact form and the list of newsletter subscribers, and sends the newsletter.

HireBench, our screening partner, receives job applications and runs the assessments that go with them. It emails you a link to set up an account. Once you do, that account and your results — including what other companies hiring through HireBench can see — are covered by the HireBench privacy policy.

For client work we also use an accounting system, a payment processor, and our email and calendar provider. We never sell personal data, and we do not share client code, credentials or business information with anyone outside the sprint team assigned to that client.

06Cookies and recordings

Our own code sets no cookies and stores nothing in your browser. The services above do. Google Analytics sets cookies named _ga to recognise a returning browser. Microsoft Clarity sets _clck and _clsk to tie a visit together, along with Microsoft's own cookies. reCAPTCHA sets a cookie on google.com when a form loads it. They last from a few minutes to two years. Sentry keeps an identifier for the visit in your browser while the tab is open.

You can block or delete cookies in your browser settings, and the site works the same without them. The exception is blocking reCAPTCHA itself: a form that cannot confirm a person is sending it will ask you to email us instead.

07Where it is stored

We are based in Pakistan, and most of the services above run from the United States. Where the GDPR or UK GDPR applies, transfers rely on the safeguards those services provide, such as the standard contractual clauses approved by the European Commission.

08How long we keep it

Messages and booked calls that do not turn into work are deleted within twelve months. Newsletter addresses are kept until you unsubscribe, and every issue carries a link to do that.

Applications are held in HireBench rather than on this site, and we delete yours on request. Analytics, recordings and error reports are kept for the periods each service sets, and hosting logs only briefly.

Client records are kept for the length of the engagement plus the seven years our accounting obligations require. Access credentials are revoked and deleted at the end of an engagement, and we ask you to rotate anything shared with us.

09Your rights

You can ask for a copy of what we hold about you, ask us to correct or delete it, object to a particular use, or ask us to stop contacting you. Write to hello@thedaaslabs.com and we will act within thirty days.

If you are in the EU or UK and you think we have handled something badly, you may complain to your local supervisory authority. We would rather you told us first.

10Security and changes

Access to client systems is limited to the sprint team, granted through your own identity provider wherever possible, and revoked when the engagement ends. Company devices are encrypted and require multi-factor authentication.

If this policy changes materially we will say so on this page and update the date above. Continued use of the site after that means the updated policy applies.