Legal
International Data Transfers
We are a remote agency with a US server and people in Pakistan and the UAE. That means data crosses borders, so here is exactly where it goes and under what safeguard.
Where data actually is
| What | Where it sits | Who can reach it |
|---|---|---|
| Accounts, orders, messages, files | Server in the United States | Us, and the hosting provider |
| Email correspondence | Same server | Us |
| Analytics (only if accepted) | Google's infrastructure | Us, aggregated only |
| Our working access | From Pakistan and the UAE | Us |
The lawful basis for the transfer
For personal data of people in the EEA or UK, transfers outside those areas rely on:
- Standard Contractual Clauses with our providers, which is the mechanism the providers themselves operate under.
- Necessity for the contract under Article 49(1)(b) where you have engaged us directly — we cannot deliver a project without accessing the material for it.
- Your explicit consent where neither of the above applies, asked for plainly rather than buried.
What we do in practice to limit exposure
- We collect as little as possible. There is no CRM, no marketing platform, no chat widget and no session recorder, so there are fewer copies to move in the first place.
- Files are stored above the web root and served only to the account they belong to, never from a public URL.
- Access is by named account with rate-limited sign-in. There is no shared login.
- The free tools transfer nothing at all — they run in your browser and never upload your files.
If you are not happy with this
Tell us before we start. Some clients need data to stay in a specific region; we can sometimes arrange that with different hosting, and sometimes we cannot. Either way you get a straight answer up front rather than after you have signed.
Your rights over the data itself are in Your Data Rights, and the full provider list is in Sub-processors.
