Last updated September 2026
Privacy policy
Short version: this site collects nothing unless you submit a form, and what you submit is used only to reply to you.
Before publishing: replace the bracketed placeholders below with your registered entity name, address and jurisdiction, and have the final text reviewed by a lawyer — particularly if you take on clients in the EU or UK, where GDPR obligations apply. This is a working draft, not legal advice.
Who we are
This website is operated by Afoxlabs ([registered entity name]), [registered address], India. For any question about this policy or your data, write to [email protected].
What we collect
There are exactly two ways information reaches us from this site.
- Forms you choose to submit. The contact form and the QA Health Check review request collect your name and email address, and optionally your company, role, team size, release cadence and message. If you completed the health-check assessment, your score and answers are attached to that submission so we can respond usefully.
- Standard server logs. Our host records requests, including IP address, user agent and requested page, for security and reliability. We do not combine these logs with form submissions to build a profile of you.
What we do not do
- No advertising or cross-site tracking cookies.
- No selling, renting or sharing of your information with third parties for marketing.
- No newsletter or automated drip sequence. We reply to you; we do not campaign at you.
- No session recording, heatmaps or behavioural analytics.
The theme preference stored in your browser is kept in localStorage on your own
device. It never reaches us and is not a cookie.
Health Check answers
The assessment runs entirely in your browser. Your answers and score are not transmitted anywhere unless you explicitly submit the review request form — and if you simply read your result and close the tab, we never see it.
Why we hold it, and for how long
The lawful basis is your consent, given by submitting the form, and our legitimate interest in responding to a business enquiry. We keep enquiry correspondence for up to 24 months so that we have context if you come back to us, then delete it. Client records under a signed contract are retained as long as that contract and applicable tax and accounting law require.
Who else processes it
We keep the list deliberately short. Website hosting and delivery is provided by Cloudflare. Form submissions are delivered by email through our transactional email provider and land in a standard email inbox. Each of these processes data only to provide its service to us.
Your rights
You can ask us what we hold about you, ask for it to be corrected, ask for it to be deleted, or withdraw your consent — by emailing [email protected]. We will respond within 30 days. If you are in the EU, UK or another region with statutory data protection rights, those rights apply in addition to this and are not limited by this policy.
Client data during engagements
This policy covers the website only. Data accessed while performing testing work for a client is governed by the NDA and master services agreement for that engagement, which take precedence. Our standing practice is least-privilege access, synthetic or masked test data by default, secrets held in a secrets manager, and no customer data copied to local machines.
Security
The site is served over HTTPS only. Form submissions are transmitted over TLS. We do not store submissions in a database on this site — they are delivered to an email inbox protected by multi-factor authentication.
Changes
If this policy changes materially we will update the date at the top of this page. Continued use of the site after a change means you accept the revised policy.