Legal · Four documents
The paperwork, in plain English.
A firm that sells ISO 27001 and GDPR expertise should be able to hand you its own policies without a delay and an apology. These are written to be read by the person reviewing them, not to be skipped.
Documents
Privacy policy
Privacy policy
What data this site and this practice collect, why, for how long, and how to exercise your rights.
Terms of serviceTerms of service
Terms for this website, and the basis on which engagements are delivered.
Cookie policyCookie policy
No tracking cookies, no advertising, no third-party requests. Here is what is stored.
Data processingData processing addendum
The processor-side commitments that apply when we handle your data during an engagement.
Procurement quick answers
- Entity
- Dunicot Private Limited (Karachi, Pakistan) and Dunicot LLC (Sheridan, Wyoming, USA)
- Governing law
- Pakistan or Wyoming, depending on the contracting entity
- Security certification
- ISO/IEC 27001 certified ISMS; certificate under NDA
- DPA
- Available signed, send yours or ask for ours
- Breach notification
- Within 24 hours of becoming aware
- Sub-processors
- No testing subcontracted without written consent
- Data deletion
- Evidence destroyed at closure; written confirmation on request
- Tracking
- No advertising or analytics cookies on this site
- NDA
- Mutual NDA signed before scoping