NOC & SOC live 24/7 Support portal
HomePrivacy policy
Legal

Privacy policy

We collect as little personal information as we can, we tell you what we do with it, and we do not sell it to anybody. This page explains the detail.

The short version. If you browse this website we collect nothing about you personally, because there are no analytics or advertising trackers on it. If you send us an enquiry, apply for a job, or become a client, we collect what we need to respond and to deliver the work, we keep it for as long as we have a reason to, and we do not share it with anyone outside the parties named below.

1. Who we are

OKTAGATE is an information technology solutions and services company registered in the Kurdistan Region of Iraq, with offices in Erbil, Baghdad and Basra. In this policy, "OKTAGATE", "we", "us" and "our" mean that company. "You" means anyone whose personal information we hold: a website visitor, an enquirer, a client contact, a supplier contact or a job applicant.

OKTAGATE is the controller of the personal information described in this policy. Where we handle personal information on behalf of a client as part of a managed service, we act as a processor and the client's own privacy notice governs that data. Section 9 explains the difference and what it means for you.

Registered address, company registration number and tax identification number are available on request and are stated on every contract and invoice we issue.

2. What this policy covers

This policy covers personal information we collect through:

  • this website, oktagate.com, including any forms on it;
  • email, telephone and messaging contact with us;
  • our commercial relationship with clients, prospective clients and suppliers;
  • recruitment, including speculative applications;
  • our service desk and ticketing system, when you raise a support request.

It does not cover third-party websites we link to. If you follow a link away from our site, that site's own privacy notice applies and we have no control over it.

3. What we collect

3.1 When you browse the website

Nothing that identifies you. This site carries no analytics platform, no advertising pixels, no social media trackers and no third-party cookies. The only thing stored in your browser is your light or dark theme preference, which stays on your device and is never transmitted to us. See our cookie policy for the full detail.

Our hosting provider keeps standard server logs, which typically include the requesting IP address, the page requested, the time of the request and the browser user-agent string. These are generated automatically by the web server, are used only to keep the site running and secure, and are not combined with anything else to build a profile of you.

3.2 When you contact us or send an enquiry

Whatever you choose to give us: usually your name, organisation, work email address, telephone number and the content of your message. If your enquiry relates to a project you may also send us technical detail about your environment. We treat that as confidential and we will sign a mutual non-disclosure agreement on request before you send anything sensitive.

3.3 When you become a client

Contact details for the people we work with at your organisation, contractual and billing information, records of the services we deliver, support tickets and correspondence, and technical documentation about the environment we support. Where a project requires it, we may also hold site access details and named engineer credentials, which are stored in an access-controlled password management system.

3.4 When you apply for a job

Your CV and covering note, contact details, work history, qualifications and certifications, right-to-work or residency status where relevant, interview notes and assessment results, and referee details if you provide them. We ask you not to send us information about your health, religion, political views or other special categories, and we will delete it if you do.

3.5 When you subscribe to our insights email

Your email address and nothing else. Every issue carries a one-click unsubscribe link.

4. Why we use it, and on what basis

What we doWhyBasis
Reply to an enquiry and prepare a proposalTo answer the question you asked usSteps taken at your request before entering a contract
Deliver projects and managed servicesTo perform the contract we signedPerformance of a contract
Run the service desk and SLA reportingTo meet our contracted obligationsPerformance of a contract
Issue invoices and keep accounting recordsTax and company lawLegal obligation
Keep our own systems and this website secureTo prevent fraud and misuseOur legitimate interest in operating safely
Assess a job applicationTo decide whether to make an offerSteps taken at your request before employment
Send the monthly insights emailBecause you asked us toYour consent, withdrawable at any time

We do not use personal information for automated decision-making that produces a legal or similarly significant effect, and we do not carry out profiling for marketing purposes.

5. What we do not do

  • We do not sell, rent or trade personal information. Ever, to anyone.
  • We do not share client lists or contact details with vendors as sales leads.
  • We do not use client data to train machine learning models.
  • We do not send marketing email to people who have not asked for it.
  • We do not track you across other websites.

6. Who we share it with

We share personal information only where there is a reason to, and only with:

  • Service providers who work for us, such as our email and productivity platform, our hosting provider, our accounting system and our ticketing system. Each is bound by a written agreement to process data only on our instructions.
  • Technology vendors and distributors, where a hardware or licence purchase has to be registered in your organisation's name, or where a support case must be escalated to the manufacturer. We share the minimum needed, which is normally an organisation name, a serial number and a technical contact.
  • Professional advisers such as our auditors and lawyers, where they need it and under a duty of confidence.
  • Public authorities, where we are legally required to disclose. We will tell you if that happens unless we are prohibited from doing so.

We do not use subcontractors on client engagements without telling the client first and putting equivalent confidentiality and data protection terms in place.

7. Where your information is held

Our corporate systems run on established cloud platforms whose data centres may sit outside Iraq, typically in the European Union or the Gulf region. Where information moves across borders we rely on the provider's contractual safeguards, including standard contractual clauses where the provider offers them.

Where a client contract or a regulator requires data to remain inside Iraq, we can deliver the service on infrastructure hosted in country. That is agreed in writing at the start of the engagement rather than assumed.

8. How long we keep it

CategoryRetention
Enquiries that do not become projects24 months from last contact
Client contracts, project records and as-built documentation7 years after the contract ends
Accounting and tax recordsAs required by Iraqi law, currently 7 years
Support tickets3 years from closure
Unsuccessful job applications12 months, then deleted unless you ask us to keep them longer
Insights email subscribersUntil you unsubscribe
Server logsTypically 30 days, set by our hosting provider

When a retention period ends we delete the information or irreversibly anonymise it.

9. When we handle data for a client

Much of our work involves administering systems that contain a client's own personal data: mailboxes, file servers, HR systems, CCTV recordings, access control logs. In those cases the client decides what is collected and why, so the client is the controller and OKTAGATE is the processor. We act only on the client's documented instructions, under a data processing agreement that sets out confidentiality, security measures, subprocessor rules, breach notification and what happens to the data when the contract ends.

If you are an employee or customer of one of our clients and you want to exercise rights over your data, please contact that organisation directly. We will support them in responding, but we cannot act on their data without their instruction.

10. How we protect it

We apply the same controls to ourselves that we recommend to clients:

  • multi-factor authentication on every account that supports it, with no shared logins;
  • role-based access, reviewed quarterly, on a need-to-know basis;
  • full-disk encryption on laptops and encryption in transit for all services;
  • endpoint detection and response on every company device;
  • separate privileged accounts for administrative work;
  • credentials for client environments held in an access-controlled password manager, never in email or spreadsheets;
  • backups that are tested by restore, not assumed;
  • security awareness training and phishing simulation for all staff;
  • a documented incident response plan, exercised annually.

No control set is perfect. If a breach occurs that is likely to affect you, we will tell you and the relevant authority without undue delay, describe what happened, what we are doing about it and what you should do.

11. Your rights

Subject to applicable law, you can ask us to:

  • confirm what personal information we hold about you and give you a copy;
  • correct anything that is inaccurate or incomplete;
  • delete information where we no longer have a reason to keep it;
  • restrict or object to a particular use;
  • provide your information in a portable, machine-readable format;
  • withdraw consent, where consent was the basis we relied on.

Write to privacy@oktagate.com. We will acknowledge within five working days and respond substantively within thirty days. We may need to verify your identity first, and we will explain if a legal obligation prevents us from acting on part of a request.

12. Children

Our services are sold to organisations, not to individuals, and this website is not directed at children. We do not knowingly collect information about anyone under 18. If you believe we have, contact us and we will delete it.

13. Changes to this policy

We update this policy when our practices change. The effective date at the top always reflects the current version. If a change materially affects how we use information we already hold, we will notify affected clients and subscribers directly rather than relying on you to re-read this page.

14. Contact us

Questions, requests or complaints about privacy:

If you are not satisfied with our response you may complain to the relevant supervisory authority in your jurisdiction.

Note for review. This policy has been drafted for OKTAGATE and reflects how the business actually operates. It is not legal advice. Before publication, have it reviewed by a qualified lawyer in Iraq and confirm the retention periods against your accounting and sector obligations. Insert the registered company details in section 1 and create the privacy@oktagate.com mailbox.

Cookie policy Terms of service