Privacy Policy
This policy explains what data this website and my services collect, why, how long it is kept, and what you can ask me to do with it. It is written to be read rather than to be impenetrable.
Last updated: 1 August 2026
Who is responsible
Nadeem Khattak, based in Sector F-7, Islamabad, Islamabad Capital Territory, Pakistan, is the data controller for information collected through this website and in the course of providing services. You can reach me at hello@nadeemdev.com about anything on this page.
What this website collects
This site is deliberately light on data collection. There is no advertising network, no cross-site tracking, and no third-party embed that profiles you.
- Enquiry forms: the name, email, company, phone and message you choose to submit. Forms on this build open a pre-filled email draft in your own mail client, so nothing is stored on this site.
- Analytics: aggregate page-view data if analytics is enabled. It is configured without cross-site identifiers and is not used to profile individuals.
- Server logs: your IP address, user agent and requested URL, retained briefly for security and abuse prevention.
- Cookies: only what is functionally necessary. No advertising or profiling cookies are set.
What I collect as a client
When you engage me for work, I collect what is needed to do the job and to invoice you: your contact details, company details, project requirements, and any credentials you choose to share for access to your systems.
Where a project gives me access to your customers' data — a WordPress database, an order history, a customer table — I am acting as a processor on your behalf. I access the minimum needed, do not copy it out of your environment except where a staging copy is necessary, and delete any local copies at the end of the engagement.
Credentials and access
Credentials you share are used only for the agreed work. I ask for the least access that will do the job, prefer staging over production, and use your own credential-sharing process where you have one.
At the end of an engagement I confirm that access can be revoked, and I encourage you to rotate anything shared. I do not retain card details or payment credentials at any point.
How long data is kept
Enquiries that do not become projects are kept for up to 12 months, in case you come back. Project correspondence and files are kept for the duration of the engagement plus a reasonable period afterwards for support and reference — typically 24 months.
Invoices and financial records are kept as long as tax law requires. Server logs are kept for a short period, generally under 30 days.
Who else sees your data
I do not sell or rent data to anyone, ever. A small number of service providers process data on my behalf as part of ordinary operations — email hosting, calendar booking, payment processing, and cloud storage.
Where a project requires a third-party service (a payment gateway, an AI provider, an SMS service), I tell you which one and what is sent to it before it is wired in.
AI and machine learning
Where a project uses an AI provider, I use API tiers that do not train on submitted data, and I configure retention settings deliberately. The documentation for your project states exactly what is sent where.
I do not feed your data, code or customer information into consumer AI tools.
Your rights
Depending on where you live you may have rights over your data — including access, correction, deletion, restriction, portability and objection. I will honour any of these regardless of whether the law technically requires it in your jurisdiction.
- Ask what data I hold about you and get a copy
- Ask me to correct anything inaccurate
- Ask me to delete data I no longer need to keep
- Object to any processing you are not comfortable with
- Complain to your data protection authority if you are unhappy with my response
Security
This site is served over HTTPS. Credentials and client data are stored in an encrypted password manager rather than in notes or spreadsheets. Devices are encrypted at rest and access is protected with two-factor authentication.
No system is perfectly secure. If a breach affects your data I will tell you promptly and specifically — what happened, what was affected, and what I am doing about it.
Changes to this policy
If this policy changes materially, the date at the top changes and, for anything significant affecting existing clients, I will tell you directly rather than relying on you noticing.
Not legal advice. These documents are written to be clear and fair, and they are not a substitute for a solicitor. Have them reviewed before relying on them commercially — particularly the liability and jurisdiction clauses.