This Privacy Policy explains how WEFT Security (“WEFT,” “we,” “us,” or “our”) handles personal data when you visit our website, contact us, take part in an application-security engagement, or otherwise communicate with us.
1. Who is responsible
WEFT Security is responsible for personal data it processes to operate the website, manage business relationships, and deliver services. A customer may remain responsible for personal data in systems or materials it authorizes us to review. Contact jawad@weftsecurity.com with questions or requests.
2. Data we may collect
- Contact and business data: name, work email, role, organization, and correspondence.
- Engagement data: project contacts, authorized scope, access records, repository or asset metadata, findings, evidence, remediation status, and deliverables.
- Technical data: IP address, browser information, timestamps, security logs, and diagnostics generated when using the website or agreed delivery systems.
- Administrative data: proposals, orders, invoices, payment status, and related business records. We do not intentionally collect complete payment-card numbers.
3. How we use data
We use data to respond to inquiries; assess and agree scope; deliver and secure authorized services; communicate findings and remediation; maintain records; troubleshoot delivery; prevent abuse; improve our processes; invoice and administer the relationship; and comply with legal, tax, accounting, and security obligations.
4. Legal bases
Depending on location and context, we process personal data to perform a contract, take requested pre-contract steps, pursue legitimate interests in operating and securing a professional service, comply with legal obligations, protect rights and safety, or act with consent.
5. Sharing and service providers
We may use infrastructure, communications, file-transfer, monitoring, accounting, security, and professional-service providers that process limited data on our behalf. We may share data with customer-directed systems, advisers, or authorities when required by law or necessary to protect rights and safety. We do not sell personal data.
6. Security engagement data
Access methods, where work runs, what evidence is retained, and how reports are transferred are agreed for the engagement. We aim to minimize source, credentials, personal data, and raw traffic in shared evidence. Customers should not provide unrelated regulated or sensitive data.
7. International processing
WEFT and its providers may process data outside your country. Where required, we use contractual and organizational safeguards intended to protect personal data during international transfers.
8. Retention
We retain data only as reasonably necessary to deliver the engagement, maintain security and business records, resolve disputes, enforce agreements, and meet legal obligations. The applicable proposal may define a project-specific retention or deletion period. When data is no longer required, we delete or de-identify it where reasonably practicable.
9. Security
We use administrative, technical, and organizational safeguards designed to protect data, including scoped access, encryption in transit where supported, least-privilege delivery methods, and security logging. No method is completely secure, so absolute security cannot be guaranteed.
10. Cookies and website storage
We may use essential cookies or similar storage for security, preferences, and site operation. We do not currently use the public website for third-party behavioral advertising.
11. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability, or object to certain processing. You may also have the right to complain to a data-protection authority. We may verify identity and coordinate engagement-data requests with the responsible customer.
12. Children
Our services are intended for businesses and professionals and are not directed to children under 18. We do not knowingly collect their personal data.
13. Changes and contact
We may update this policy as our services, providers, or legal requirements change and will post the revised date. Send privacy questions or requests to jawad@weftsecurity.com.