Legal

Privacy Policy

Last updated: July 12, 2026

Who We Are

QilaSec is a boutique offensive cybersecurity consulting brand operated by an independent freelancer based in Bosnia and Herzegovina. For the purposes of this Privacy Policy, the operator of the QilaSec brand acts as the data controller for personal data collected through this website.

If you have any questions regarding this Privacy Policy or the processing of your personal data, you may contact us at [email protected].

Information We Collect

When you submit our contact form, we collect the information you voluntarily provide, including:

  • Your name
  • Company name
  • Email address
  • Phone number (if provided)
  • Service of interest
  • The content of your message

We also temporarily process your IP address solely for the purpose of rate limiting and preventing automated abuse of the contact form. This information is stored only in server memory for up to 10 minutes and is never written to a database or log files.

Legal Basis for Processing

We process information submitted through our contact form on the basis of our legitimate interests pursuant to Article 6(1)(f) of the General Data Protection Regulation (GDPR), namely to respond to business inquiries initiated by you.

If a business relationship or contractual engagement is established, further processing of your personal data is based on the performance of a contract pursuant to Article 6(1)(b) GDPR.

How We Use Your Information

We use your personal information solely to:

  • Respond to your inquiry
  • Communicate regarding a potential engagement
  • Deliver agreed cybersecurity consulting services

We do not add you to mailing lists, use your information for marketing purposes, or disclose your personal data to third parties for marketing.

Data Processors

To operate our services, we rely on the following third-party service providers:

  • Resend (email delivery)
  • Vercel (website hosting)
  • Cloudflare (DNS, CDN, and security services)

These providers may process personal data in the United States and other jurisdictions. Where required, international data transfers are safeguarded through appropriate transfer mechanisms, including the European Commission's Standard Contractual Clauses (SCCs).

Cookies and Analytics

This website does not use analytics platforms, advertising pixels, or tracking cookies. We do not use Google Analytics, Meta Pixel, or similar tracking technologies.

Cloudflare may use strictly necessary technical cookies as part of its network and security services. These cookies are essential for the operation and security of the website and do not require consent under applicable electronic communications laws.

Data Retention

If no business engagement results from your inquiry, we delete your personal data no later than 90 days after our last communication.

Where a business relationship is established, relevant communications may be retained for the duration of the engagement and for up to five years thereafter to comply with applicable legal, accounting, and contractual obligations.

Your Rights

Where the GDPR applies to the processing of your personal data, you have the right to:

  • Access your personal data
  • Request correction of inaccurate or incomplete data
  • Request erasure of your personal data where legally applicable
  • Object to processing based on legitimate interests
  • Request restriction of processing
  • Request data portability where applicable

To exercise any of these rights, please contact us at [email protected]. Where applicable, we will respond to your request within 30 days.

Supervisory Authority

If the GDPR applies to the processing of your personal data and you believe your rights have been infringed, you have the right to lodge a complaint with the competent data protection authority in your EU Member State.

If you are located in Bosnia and Herzegovina, you may also contact the Personal Data Protection Agency of Bosnia and Herzegovina.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal obligations, or the technologies we use. Any material changes will be published on this page together with an updated “Last updated” date.