1. Who We Are
Oaklogix ("we", "us", or "our") is an independent Salesforce integration and automation consultancy operated by Waleed Rafique, providing specialized consulting services to UK and European businesses. Our primary website is located at https://oaklogix.com.
For inquiries regarding data protection and this Privacy Policy, you may contact us at [email protected].
2. Information We Collect
We collect information only when necessary to communicate with prospective clients, scope technical engagements, and deliver our services:
- Inquiry & Form Data: When you submit a contact or service request form on our website, we collect your name, work email address, company name, systems to be integrated, and project requirements.
- Technical Information: Standard server logs containing your IP address, browser user-agent, operating system, and timestamp. Your IP address may be processed transiently to determine currency display (€ EUR / $ USD) and for DDoS prevention.
- Communication History: Correspondence via email, video conference notes, and mutually executed scoping agreements.
3. Legal Basis for Processing (UK & EU GDPR)
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and EU GDPR under the following legal bases:
- Legitimate Interests: To respond to your direct technical inquiries, assess project feasibility, and protect the security of our website.
- Contract Preparation & Performance: To take preliminary steps at your request prior to entering into a consulting sprint or retainer contract, and to execute agreed engineering scopes.
- Legal Compliance: To comply with relevant tax, accounting, and legal requirements.
4. Third-Party Service Providers
We do not sell, rent, or trade your personal information. We work only with reputable infrastructure and software providers who adhere to strict data security standards:
- Web3Forms: Used to securely dispatch web form submissions via encrypted HTTPS directly to our business email inbox.
- Hosting & DNS Infrastructure: High-security cloud hosting providers with end-to-end TLS encryption and European data routing options.
- Communication Tools: Google Workspace / Proton for professional email and calendar management.
5. Codebase & Client Data Security
We strictly distinguish between website visitors and consulting clients. During consulting audits and integration sprints:
- We mandate mutual Non-Disclosure Agreements (NDAs) prior to accessing any client code repository or sandbox environment.
- We never access production customer data without explicit written consent. Work is performed in isolated sandbox environments with dummy or masked test data.
- We never store client API credentials, tokens, or repository copies on unencrypted local drives.
6. Data Retention
We retain contact form inquiries and business correspondence only for as long as necessary to manage our business relationship or comply with legal and accounting record-keeping standards (typically 6 years for executed commercial agreements). Unsuccessful inquiries are pruned periodically.
7. Your Data Protection Rights
Under UK and EU data protection legislation, you have the following rights regarding your personal information:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Request deletion of your personal information where there is no compelling reason for its continued processing.
- Right to Restriction & Objection: Object to or restrict certain processing activities.
To exercise any of these rights, please email us directly at [email protected]. We respond to all verified requests within 30 days without charge.
8. Updates to this Policy
We may update this policy periodically to reflect operational, legal, or regulatory updates. Any changes will be posted on this page with an updated "Last Updated" timestamp.