Dunicot A cybersecurity consultancy and advisory firm.

Legal · Privacy policy

Privacy policy

What data this site and this practice collect, why, for how long, and how to exercise your rights.

Who we are

Dunicot (“we”) operates as Dunicot Private Limited in Karachi, Pakistan and as Dunicot LLC in Sheridan, Wyoming in the United States. Depending on which entity you contract with, the data controller for personal data processed through this website and through our commercial relationships is Dunicot Private Limited (Pakistan) or its United States affiliate.

For engagement data, meaning the data we encounter while testing a client’s systems, we normally act as a processor on the client’s instructions. That relationship is governed by the Data Processing Addendum rather than by this policy.

Contact for any privacy matter: support@dunicot.com.

What we collect

This site runs no advertising, no third-party trackers, no social media pixels and no cross-site profiling. Fonts, styles, scripts and images are all served from this domain. No request leaves it as a side effect of viewing a page.

Personal data processed, by source
SourceDataPurposeLawful basis
Contact formName, work email, company, message, and any scope details you choose to includeResponding to your enquiry and preparing a proposalLegitimate interest and steps prior to entering a contract
Email to usWhatever the message contains, plus routing metadataResponding and maintaining a record of the exchangeLegitimate interest
Engagement contractsNames, business contact details and role of client personnelDelivering and administering the engagementContract performance
Web server logsIP address, user agent, requested URL, timestampSecurity, abuse prevention and availabilityLegitimate interest
Admin authenticationA session cookie for the site’s own administratorSecuring content administrationLegitimate interest

How long we keep it

  • Enquiries that do not become engagements, 12 months from last contact, then deleted.
  • Engagement records and reports: retained for the period agreed in the engagement contract, by default 24 months, then securely destroyed.
  • Raw testing evidence (requests, responses, screenshots, extracted samples), destroyed on engagement closure unless the client asks in writing that it be retained for retest purposes.
  • Contracts, invoices and tax records, for the period required by applicable law.
  • Server logs, retained by our hosting provider on a rolling short-term basis for security and diagnostics.

Who we share it with

We do not sell personal data, and we do not share it for advertising. Data is disclosed only to the following categories of recipient:

  • Infrastructure providers: this website and its content administration run on Cloudflare. Email is delivered through our email provider.
  • Professional advisers: legal or accounting advisers, where necessary and under confidentiality.
  • Authorities: where we are legally required to disclose, and only to the extent required.

We do not engage subcontractors to deliver testing work without the client’s prior written consent.

International transfers

We operate from Pakistan and the United States and serve clients across North America, the United Kingdom, the European Union, the Gulf and South Asia, so personal data may be processed outside your jurisdiction.

Where personal data originating in the EEA or United Kingdom is transferred, we rely on Standard Contractual Clauses together with the technical and organisational measures described in our Data Processing Addendum. Clients with data residency requirements should raise them during scoping: we can work entirely against synthetic data, or confine evidence to a region you nominate.

How we protect it

Dunicot Private Limited operates a certified ISO/IEC 27001 information security management system. The certificate and its scope statement are available to clients and prospects on request under NDA.

In practice that means: access to client data limited to the individuals delivering the engagement, encryption in transit and at rest, multi-factor authentication on systems holding client data, documented incident response, and destruction of engagement data at closure. This is not a marketing claim. We ask the same questions of our own suppliers.

Your rights

Depending on where you are, you may have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing relies on it.

To exercise any of these, email support@dunicot.com. We respond within 30 days and will not charge you for a reasonable request. If you are in the EEA or United Kingdom and are unsatisfied with our response, you may complain to your national supervisory authority.

Changes to this policy

Material changes are reflected in the review date shown on this page. This policy applies to this website and to Dunicot’s commercial relationships; it does not override the terms of a signed engagement contract.