1. Introduction & Scope
Welcome to Scope IT Solutions ("we", "our", "us", or "the Agency"). We operate the website https://scopeitsol.com and provide enterprise-grade digital services including Web Design & Development, Search Engine Optimization (SEO), Pay-Per-Click Advertising (SEM / Google Ads), Local SEO, E-Commerce SEO, and Social Media Marketing.
This Privacy Policy applies to all individuals who visit our website, submit information through our interactive audit request forms, communicate with us via phone, email, or WhatsApp, and prospective or active commercial clients engaging our digital marketing retainers.
We treat your data with the highest degree of confidentiality. We do not sell your personal data to advertisers, data brokers, or third parties. We collect only what is strictly necessary to evaluate your web performance, execute agreed marketing deliverables, and provide transparent reporting.
2. Information We Collect
Depending on how you interact with our website and services, we collect information across three primary categories:
A. Information You Voluntarily Provide
When you submit a contact inquiry, request a website audit, or enter into a service contract, you may provide:
- Contact Information: Your full name, job title, corporate email address, and direct telephone/WhatsApp number.
- Business & Domain Details: Company name, website URL (e.g.
yourstore.com), e-commerce platform (Shopify, WooCommerce, Magento), and target geographic markets. - Marketing & Growth Objectives: Monthly advertising budgets, current traffic metrics, target keywords, and commercial goals.
- Billing & Financial Information: Company billing address, tax identification numbers, and payment details required for invoice settlement.
B. Information Collected Automatically
When you navigate https://scopeitsol.com, our servers and analytics tools automatically log standard technical telemetry:
- Device & Browser Data: Internet Protocol (IP) address, browser type and version, operating system, screen resolution, and preferred language.
- Usage & Interaction Telemetry: Pages visited, time spent on each section, referral source URLs, click paths, and scroll progression.
- Approximate Geolocation: City and country-level location derived from IP address for regional routing.
C. Client-Delegated Account Access (Active Engagements)
To execute contracted technical SEO, Google Ads management, or web development services, clients may grant us delegated access to third-party tools:
- Google Search Console & Google Analytics 4 (GA4) properties.
- Google Ads, Meta Business Manager, LinkedIn Campaign Manager, or TikTok Ads accounts.
- Content Management Systems (WordPress, Shopify, Webflow) and DNS / web hosting servers.
3. Legal Grounds for Processing Data
Under international data protection frameworks (including the EU/UK General Data Protection Regulation and comparable standards), we process personal data under the following lawful bases:
| Lawful Basis | Processing Purpose | Examples |
|---|---|---|
| Contract Performance | Executing agreed deliverables and services | Delivering SEO audits, managing Google Ads campaigns, developing websites |
| Legitimate Interests | Improving site functionality, security & analytics | Preventing DDoS attacks, analyzing traffic performance, safeguarding infrastructure |
| Explicit Consent | Responding to voluntary requests | Submitting lead audit forms, subscribing to newsletters, requesting WhatsApp consultations |
| Legal Obligation | Regulatory and accounting compliance | Retaining billing invoices for commercial tax compliance and legal records |
4. How We Use Collected Information
We process personal and corporate data strictly for legitimate operational purposes:
- Audit Delivery & Proposals: Performing manual technical audits, keyword competitiveness evaluations, and customized growth proposals.
- Campaign Execution: Managing paid ad campaigns, deploying on-page SEO meta elements, publishing social media calendars, and writing optimized copy.
- Performance Dashboards: Generating real-time GA4 and Search Console reporting dashboards to evaluate traffic, rankings, and conversion ROI.
- Client Communications: Providing weekly milestone updates, responding to technical support tickets, and scheduling strategy meetings.
- Security & Fraud Prevention: Detecting spam form submissions, protecting our digital infrastructure against brute-force attacks, and verifying client identities.
5. Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies (such as web beacons and script tags) to enhance your browsing experience and analyze site traffic.
Types of Cookies We Use
- Strictly Necessary Cookies: Essential for site navigation, security token verification, and fast content delivery via our CDN.
- Performance & Analytics Cookies: Google Analytics 4 cookies (
_ga,_ga_*) that collect aggregated, anonymized data regarding visitor volume and popular pages. - Functional Cookies: Remembering user UI preferences (such as collapsed menus or form draft states).
How to Control & Disable Cookies
You can instruct your browser to refuse all cookies or indicate when a cookie is being sent. If you disable cookies, all informational content on our website remains fully accessible. You can manage cookies in your browser settings:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Apple Safari: Preferences → Privacy → Manage Website Data
- Mozilla Firefox: Settings → Privacy & Security → Enhanced Tracking Protection
- Microsoft Edge: Settings → Cookies and site permissions → Manage and delete cookies
6. Client Account Credentials & Non-Disclosure (NDA)
Scope IT Solutions enforces strict security protocols regarding client accounts, credentials, and proprietary business metrics:
- Principle of Least Privilege: We request only the minimum permission levels required to execute our tasks (e.g., standard "Analyst" or "Standard User" rather than full account ownership).
- Delegated OAuth Access: Whenever possible, we request access through official partner portals (Google Ads Manager Accounts / MCC, Meta Business Partner access) so clients never need to disclose raw passwords.
- Two-Factor Authentication (2FA): All agency workstations and team member accounts access client portals exclusively through enforced 2FA and enterprise password management vaults.
- Proprietary Confidentiality: Client advertising budgets, revenue figures, margin data, customer lists, and proprietary keyword roadmaps are strictly confidential and protected by standard mutual Non-Disclosure Agreements (NDAs).
- Immediate Revocation: Upon retainer completion or cancellation, all delegated access is severed immediately and stored tokens are wiped from agency records.
7. Third-Party Service Providers & Sub-Processors
We partner with trusted third-party infrastructure and software providers to host our website, process inquiries, and deliver campaign analytics:
| Provider Category | Representative Services | Privacy Safeguard |
|---|---|---|
| Hosting & CDN | Cloudflare, Vercel, Node / Astro Static Edge | TLS 1.3 Encryption, DDoS Protection, ISO 27001 Certified |
| Analytics & Search | Google Analytics 4, Google Search Console | IP Anonymization, Aggregated Reporting, GDPR Aligned |
| Advertising Platforms | Google Ads, Meta Ads Manager, LinkedIn Ads | OAuth Delegated Partner Access, API Rate Limiting |
| Communication Tools | Google Workspace, WhatsApp Business API | End-to-End Encryption, Business Associate Agreements |
8. Zero-Sale Policy: We Never Sell Personal Data
Scope IT Solutions has never sold, rented, leased, or traded personal data, email addresses, or client lists to any third party or data broker since our founding in 2025, and we will never do so in the future.
We disclose data to third parties only when strictly necessary to deliver contracted services (such as submitting an ad creative to Google Ads upon your instruction) or when required by enforceable legal process.
9. International Data Transfers
Scope IT Solutions serves enterprise clients across Pakistan, the United States, the United Kingdom, Canada, Australia, and the Middle East & UAE.
If you access our website or engage our services from outside Pakistan, please be aware that your information may be transferred to and processed on secure cloud infrastructure located in various international data centers. Whenever cross-border data transfers occur, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) and strict end-to-end transport encryption.
10. Data Retention & Deletion Schedule
We retain personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Website Audit Inquiries: Lead form submissions and website diagnostic reports are retained for 12 months to allow follow-up consultations, after which they are automatically purged.
- Active Client Records: Marketing campaign roadmaps, technical audit files, and analytical data are retained throughout the duration of the client relationship.
- Invoices & Accounting Records: Commercial invoices, payment receipts, and contract agreements are retained for 7 years in compliance with standard corporate tax and financial statutory requirements.
11. Technical & Organizational Security Safeguards
We implement comprehensive technical and organizational measures to safeguard your personal data against accidental loss, unauthorized access, alteration, and disclosure:
- Transport Layer Security (TLS/SSL): All web traffic to
https://scopeitsol.comis encrypted using 256-bit modern SSL certificates. - Firewalls & Intrusion Prevention: Enterprise-grade web application firewalls (WAF) inspect incoming requests to block malicious traffic, bots, and SQL injection attempts.
- Role-Based Access Control (RBAC): Access to client marketing data is restricted strictly to assigned strategists, developers, and account managers on a need-to-know basis.
- Data Sanitization: Any temporary diagnostic data used during technical SEO audits is securely wiped following project milestone approvals.
12. Your Data Subject Rights
Depending on your jurisdiction, you may have the following legal rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete contact records.
- Right to Erasure ("Right to be Forgotten"): Request the complete deletion of your personal information from our CRM and audit archives.
- Right to Restrict or Object to Processing: Object to specific processing activities (e.g., opting out of marketing communications).
- Right to Data Portability: Request that your data be provided in a structured, machine-readable format.
- Right to Withdraw Consent: Revoke consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise any of these rights, email our compliance team at contact@scopeitsol.com. We respond to all verified requests within 30 days free of charge.
13. Children's Privacy
Our website and business services are strictly intended for business professionals and individuals aged 18 and older. We do not knowingly collect or solicit personal data from children under the age of 16. If we discover that we have inadvertently collected information from a minor, we take immediate steps to delete that data from our servers.
14. Policy Updates & Revision Notifications
We may update this Privacy Policy periodically to reflect enhancements in our services, technological advancements, or changes in legal regulations. When material modifications occur, we will update the "Last Revised" date at the top of this page and post a prominent notice on our website homepage.
15. Data Protection Officer & Direct Contact
If you have questions, feedback, or concerns regarding this Privacy Policy or our data management practices, please contact our compliance department through any of the following verified channels:
Deans Trade Center, Peshawar, Pakistan