// legal

Privacy PolicyHow we handle your data.

This policy explains what this website collects, what we do with client data during a security engagement, who processes it on our behalf, and how to ask us to delete it.

Last updated: 29 August 2026

What We Collect and Why

Who we are

VAPT.PK is a penetration testing and vulnerability assessment practice based in Karachi, Sindh, Pakistan, operated by Hassan Jawaid. For any privacy question, or to exercise any right described below, email pentest@vapt.pk. We are the controller for the data described here.

Data you give us through this website

The only form on this site is the contact form. When you submit it we receive the name, email address, company name, service you selected, and the message you wrote. We use that solely to reply to you and to scope the work you asked about. The form is delivered by Formspree, which processes the submission on our behalf and passes it to our inbox.

If you email us directly, or start a chat through the WhatsApp button, we hold whatever you choose to send us in that conversation. WhatsApp conversations happen on Meta's platform and are covered by Meta's own privacy terms, not ours.

Data collected automatically

  • Google Tag Manager loads our measurement tags. It does not collect data by itself, but it is the mechanism through which the tags below run.
  • Google Analytics 4 records page views, approximate location derived from IP address, device and browser type, and how you moved through the site. It sets cookies in your browser to recognise a returning session.
  • Our host serves the site and keeps standard server logs, which include IP addresses, for security and abuse prevention.
  • Typefaces are loaded from Google Fonts. Requesting a font sends your IP address to Google's servers.

We do not run advertising pixels, we do not build marketing profiles, and we never sell or rent personal data.

Cookies and how to refuse them

This site sets analytics cookies only. It does not set advertising cookies. You can block or delete cookies in your browser settings at any time, and Google publishes a browser add-on that opts you out of Google Analytics entirely. Blocking these cookies does not break anything on this site.

Client engagement data

Security testing is different from ordinary website use, so it deserves its own section. When you engage us for a penetration test:

  • We work under a signed agreement and a written authorization letter, and we sign an NDA before any testing begins.
  • We test only the systems and scope you have signed off in writing.
  • During testing we may encounter your data, including personal data belonging to your users. We treat everything we see as confidential, we minimise what we capture, and we redact personal data in evidence wherever the finding can still be proven without it.
  • Findings, evidence and working files are held on encrypted storage and shared with you over an agreed channel.
  • When the engagement closes we delete the testing data we collected. We retain the final report and the engagement record, because you and your auditors may need us to attest to the work later.

Who else processes your data

We keep third parties to the minimum a small practice needs to run:

  • Formspree, for contact form delivery.
  • Google, for Tag Manager, Analytics and serving fonts.
  • Our hosting and DNS provider, for serving this site.
  • Meta, if and only if you choose to contact us through WhatsApp.

These providers operate outside Pakistan, so using this site involves transferring some data internationally. We do not pass your data to anyone else, and we do not sell it.

How long we keep things

  • Contact enquiries: kept while we are in conversation, and for a reasonable period afterwards in case you come back to us. Ask and we will delete yours sooner.
  • Analytics: retained on Google's default retention schedule for the property.
  • Engagement records and reports: retained for the period agreed in your contract, because they are the evidence of work performed.

Your rights

You can ask us to show you what personal data we hold about you, correct it if it is wrong, delete it, or stop using it for a particular purpose. Email pentest@vapt.pk and we will respond within 30 days. If you are in the UK or the European Economic Area, the UK GDPR and the GDPR give you these rights directly, along with the right to complain to your local supervisory authority. We extend the same handling to everyone who writes to us, wherever you are.

Security

This site is static, serves over HTTPS only, and sends a strict Content Security Policy along with HSTS and other hardening headers. Client data is held on encrypted storage with access limited to the tester working your engagement. Testing this site's own security is welcome in principle, but please write to us first so we can agree scope in writing.

Children

This is a business to business service. It is not directed at children, and we do not knowingly collect data from anyone under 18.

Changes to this policy

If we change how we handle data, we will update this page and move the date at the top. Material changes to an active engagement are communicated to that client directly.

Contact

Questions about this policy, or a request to access or delete your data, go to pentest@vapt.pk. You can also use the contact form, though for a deletion request email is easier for both of us to track.

Want to see it or have it deleted?

Email us and we will confirm what we hold about you and remove it. No form to chase, no conditions attached.