Who We Are
We are The DaaS Labs, registered in Pakistan. We provide Development as a Service to founders and ambitious teams. This policy applies to all visitors to our website, clients using our sprint boards, and anyone who contacts us.
Our Data Controller is directly accountable for this policy. You can reach them at privacy@thedaaslabs.com.
What We Collect
Information you give us directly:
| Data | When | Why |
|---|---|---|
| Name, email | Contact form, onboarding | To communicate with you |
| Company name, role | Intake form | To understand your project |
| Project details, files | Sprint board | To deliver your sprint |
| Payment info | Via Stripe/Wise | To process your subscription |
Information we collect automatically:
| Data | Source | Why |
|---|---|---|
| IP address, browser type | GA4, server logs | Security and analytics |
| Pages visited, scroll depth | GA4, Microsoft Clarity | To improve the site |
| Session recordings | Microsoft Clarity | To identify UX issues |
| Error logs | Sentry | To fix bugs |
How We Use It
We use your project brief, access credentials, and communication history to complete the work you've hired us for.
Lawful basis: Contract performanceSprint updates, Loom links, invoices, and account notices. You cannot opt out of these while an active client.
Lawful basis: Contract performanceNew labs, case studies, relevant content. You can opt out at any time.
Lawful basis: Legitimate interestAggregate analytics data informs layout, content, and performance decisions.
Lawful basis: Legitimate interestWho We Share It With
We use specific third-party sub-processors to process data on our behalf. Here is exactly who they are:
| Processor | Data Processed | Hosting Location | Privacy Policy |
|---|---|---|---|
| Stripe | Payment data | USA | Link ↗ |
| Wise | Payment data | UK | Link ↗ |
| GitHub | Code and project files | USA | Link ↗ |
| Linear | Sprint tasks and briefs | USA | Link ↗ |
| Slack | Communication data | USA | Link ↗ |
| Google Analytics | Anonymous usage data | USA | Link ↗ |
| Microsoft Clarity | Session recordings | USA | Link ↗ |
| Sentry | Error logs | USA | Link ↗ |
| HubSpot | Contact and CRM data | USA | Link ↗ |
| Notion | Documentation and SOPs | USA | Link ↗ |
Cookies & Tracking
A cookie is a small text file stored on your device that helps us remember your preferences and understand how you use our site. Here is what we use:
Data Retention
| Data type | Retention period | Reason |
|---|---|---|
| Client project data | Duration of engagement + 2 years | Legal and audit purposes |
| Payment records | 7 years | Tax law requirement |
| Email communications | 3 years | Dispute resolution |
| Analytics data | 26 months | GA4 default, then deleted |
| Session recordings | 90 days | UX review window |
| Inquiry form submissions | 12 months if no engagement | Lead follow-up |
After each period, data is automatically deleted or permanently anonymized so it can no longer uniquely identify you.
Your Rights (GDPR / CCPA)
GDPR Rights (EU/UK users):
- Right to access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion within 30 days
- Right to restrict processing — pause processing while in dispute
- Right to portability — receive your data in a portable format
- Right to object — object to processing based on legitimate interest
- Right to withdraw consent — for any consent-based processing
- Right to lodge a complaint — with your national supervisory authority
CCPA Rights (California users):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt out of the sale of personal information
- Right to equal service and price (non-discrimination)
International Data Transfers
We are based in Pakistan. Our clients are typically in the US, UK, and EU. This means data flows across borders. We ensure safeguards are in place for these transfers by relying on Standard Contractual Clauses (SCCs) with our sub-processors or localized adequacy decisions where applicable. Specifically, your data may be transferred to and hosted in the United States and the United Kingdom by our aforementioned sub-processors.
Children's Privacy
We do not knowingly collect data from anyone under 16. If we discover we have, we delete it immediately. Contact us if you have a concern.
Changes to This Policy
We will notify active clients by email before material changes to this policy take effect. We maintain a log of significant changes below.
| Date | Version | Change |
|---|---|---|
| February 24, 2026 | v1.0 | Initial policy published. |
Contact Us
Data Controller: The DaaS Labs
Email: privacy@thedaaslabs.com
Response time: Within 48 hours
Postal address: [Pakistan registered address]