Legal

Privacy Policy

Last updated: Back to Home

Your privacy matters. This policy explains how Jawad Iftikhar Studio collects, uses, processes, and safeguards your personal information when you visit this website. I am committed to complete transparency, data minimization, and full compliance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

I operate the website jawadiftikhar.com (the “Site”). By accessing or using the Site, you acknowledge the terms of this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of the Site.

1. Information I Collect

Personal Information you voluntarily provide: When you contact me or initiate a project via my contact forms or direct communications, I may collect:

  • Full Name: Used to address you professionally.
  • Email Address: Used to respond to inquiries and deliver project estimates.
  • Company / Organization Name (optional): Used for business context and invoicing.
  • Project Scope & Requirements: Technical specifications and creative assets shared for evaluation.

Automatically Collected Technical Data (Usage Data): When you browse the Site, certain diagnostic data is automatically recorded, including:

  • Anonymized IP addresses (truncated to prevent geographic identification where possible)
  • Browser user-agent, version, and operating system
  • Referral URLs and navigation paths across pages
  • Time spent per page, interaction timestamps, and Core Web Vitals telemetry
  • Device parameters (e.g., screen resolution, viewport orientation)

Cookies & Local Storage: I utilize essential and privacy-first analytics cookies. See Section 6 for granular controls.

2. How I Use Your Information

Your personal data is processed strictly for legitimate, declared purposes:

  • To evaluate client project requests, formulate quotes, and deliver design/development services.
  • To maintain, optimize, and secure the Site’s performance, speed, and cross-device accessibility.
  • To provide ongoing support, bug fixes, and security patches for contracted client deliverables.
  • To detect, prevent, and mitigate fraudulent activity, unauthorized access, or DDoS attacks.
  • To comply with statutory accounting, taxation, and legal dispute obligations.

I will never use your data for automated profiling, AI model training without consent, or unrelated secondary purposes.

3. Legal Bases for Processing (GDPR Article 6)

If you are located within the European Economic Area (EEA) or UK, data processing relies on the following lawful bases:

  • Contractual Necessity: To fulfill pre-contractual proposals or execute client service agreements.
  • Legitimate Interests: To operate a secure, functional web design studio and analyze traffic quality.
  • Consent: Where you have granted explicit consent for direct communication or non-essential cookies.
  • Legal Compliance: Where required by applicable international or Pakistani statutory laws.

4. Sharing and Disclosure of Information

I do not sell, rent, monetize, or trade your personal information. Data is disclosed solely under the following conditions:

  • Vetted Service Providers: Trusted third-party infrastructure providers (e.g., email routing, high-performance hosting CDN) bound by strict confidentiality and Data Processing Agreements (DPAs).
  • Legal & Regulatory Mandates: Where disclosure is strictly compelled by enforceable subpoenas, court orders, or applicable law enforcement requirements.
  • Business Transfers: In the event of an asset acquisition or merger, with prompt advance notification.

5. Data Retention & International Transfers

I retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements. Contact inquiries without an active contract are deleted after 24 months.

Because this Studio operates globally, data may be stored on servers located outside your jurisdiction. All international transfers are safeguarded via Standard Contractual Clauses (SCCs) and end-to-end encryption protocols.

6. Data Security Safeguards

I employ strict technical and organizational safeguards to ensure data integrity:

  • Full site enforcement of HTTPS (TLS 1.3 encryption) in transit.
  • Hardened server configurations, Content Security Policies (CSP), and automated vulnerability scans.
  • Principle of Least Privilege (PoLP) access controls applied to all client data repositories.

While no transmission method over the internet is completely infallible, I actively implement industry best practices to mitigate risks.

7. Your Privacy Rights (GDPR, CCPA/CPRA & UK DPA)

Depending on your residency, you possess comprehensive legal rights regarding your personal data:

  • Right of Access & Portability: Obtain a copy of your personal data in a structured, commonly used format.
  • Right to Rectification: Request correction of incomplete or outdated data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal records.
  • Right to Object & Restrict: Limit how your information is processed or object to legitimate interest justifications.
  • Non-Discrimination (CCPA): Exercising your rights will never result in degraded service quality or altered pricing.

To exercise any statutory right, please submit a request via Section 10. All requests are resolved free of charge within 30 days.

8. Cookies and Tracking Technologies

Cookies are compact text files stored on your device to maintain UI preferences and performance metrics:

  • Essential Cookies: Critical for session management, security checks, and theme state persistence (light/dark mode).
  • Preference Cookies: Store language selection and UI accessibility configurations.
  • Telemetry & Analytics Cookies: Provide aggregate, privacy-centric traffic insights without individual profiling.

You can disable or purge cookies at any time through your browser settings. Note that disabling essential cookies may impact specific dynamic layout features.

9. Third-Party Integrations

The Site contains integrations with select third-party services that govern their data under separate privacy policies:

  • Google Services: Google Fonts and Google Translate for localized browsing.
  • Professional Portfolios & Code Repositories: GitHub, Figma, LinkedIn, and WhatsApp.

I recommend reviewing the respective privacy disclosures of these third-party platforms when interacting with external links.

10. Contact & Data Protection Inquiries

If you have any questions, formal privacy requests, or complaints regarding this policy, please reach out directly:

Jawad Iftikhar Studio
Data Controller: Jawad Iftikhar
Email: [email protected]
WhatsApp / Phone: +92 307 6987496 (Opens WhatsApp)
Location: Islamabad, Pakistan

I am dedicated to resolving all legitimate data protection inquiries promptly and transparently.

Effective Date: Return to Homepage