Security & Privacy Policy
Last updated: [Month Day, Year]
1. Introduction
Advisory Specialist Engg. Ahmad (“we”, “us”, “our”) provides advisory services to boards and executives. This Security & Privacy Policy explains how we collect, use, store, protect, and disclose information when you engage with us or visit our website www.enggahmad.co (the “Site”). Compliance with applicable privacy and data protection laws is a priority for us.
2. Scope
This Policy applies to:
- Personal data collected via our Site, email, phone, or in-person interactions.
- Personal data you provide to us in connection with advisory services, including meetings, proposals, and engagement letters.
- Non-personal data collected automatically through our Site (e.g., analytics, cookies) to improve user experience.
3. Data We Collect
3.1 Information You Provide
- Contact details (name, title, organization, email, phone).
- Professional information necessary to provide advisory services (industry, responsibilities, engagement goals).
- Communications content (emails, meeting notes, proposals).
- Payment and invoicing information as required to bill for services (handled securely and only as needed).
3.2 Information Collected Automatically
- Device and usage information collected via cookies and similar technologies (e.g., browser type, pages visited, referral source, date/time).
- Aggregated analytics to understand Site performance and improve services.
3.3 Sensitive Data
We do not knowingly collect sensitive personal data (e.g., health, race, religion) unless necessary for the engagement and with explicit consent or as required by law. If sensitive data is provided, we will take additional protections and obtain consent where applicable.
4. How We Use Your Information
- To provide, manage, and improve advisory services to boards and executives.
- To communicate with you about engagements, proposals, invoices, and updates.
- To personalize your experience on the Site and tailor our services.
- To comply with legal obligations and resolve disputes.
- To protect the security and integrity of our systems and services.
5. Legal Bases for Processing (where applicable)
- Processing is necessary for the performance of a contract or to take steps at your request prior to entering into a contract.
- We may process data to comply with legal obligations or to protect legitimate interests (e.g., security, fraud prevention), provided those interests do not override your rights and freedoms.
6. Data Sharing and Disclosure
6.1 Service Providers
We may share information with trusted third-party service providers (e.g., IT services, data hosting, payment processors) who act on our behalf and are contractually obliged to protect your data.
6.2 Legal Compliance and Safety
We may disclose information if required by law or to protect our rights, property, or safety, or the rights, property, or safety of others.
6.3 International Transfers
If you are located outside our primary service region, we may transfer your information to countries with different data protection laws. We will ensure appropriate safeguards are in place.
7. Data Retention
We retain personal data only as long as necessary to fulfill the purposes described in this Policy and to comply with legal obligations. When no longer required, we securely delete or anonymize data.
8. Data Security
- Access controls: Only authorized personnel with a legitimate business need can access personal data.
- Encryption: Data in transit is protected with TLS/HTTPS; sensitive data at rest is encrypted where feasible.
- Secure development and operations: We follow secure coding and incident response practices.
- Regular monitoring: We monitor for security threats and conduct periodic security assessments.
- Vendors and subcontractors: We require security measures in our contracts with third parties.
8.1 Incident Response
In the event of a data breach or security incident, we will investigate promptly, notify affected parties when required by law, and take corrective actions.
9. Your Rights
- Access: You may request access to the personal data we hold about you.
- Correction: You may request correcting inaccurate or incomplete data.
- Deletion: You may request deletion of your personal data, subject to legal and contractual constraints.
- Objection/Restriction: You may object to certain processing or request restriction under applicable laws.
- Data Portability: You may request a portable copy of your data in a commonly used machine-readable format, where applicable.
To exercise these rights, contact us at the information in Section 12.
10. Cookies and Tracking Technologies
- We use cookies to improve user experience, analyze Site usage, and tailor content.
- You can manage cookies in your browser and opt out of certain tracking where legally permissible.
- We do not use cookies to serve targeted advertising unless explicitly stated.
11. Third-Party Links and Services
Our Site may contain links to third-party sites or services. We are not responsible for their privacy practices. Review their policies before sharing information.
12. How to Contact Us