1. Scope and who we are
This Privacy Policy describes how Your Writing Hub (“Your Writing Hub”, “we”, “us”, or “our”) handles personal information when you visit our website, submit a project brief, request a quotation, communicate with us, or use our research-coaching, editing, proofreading, citation-checking, business-content, website-content, or related services.
Your Writing Hub is based in Karachi, Pakistan. For personal information used to administer the website, enquiries, quotations, client relationships, and our own business operations, Your Writing Hub determines why and how the information is processed. In data-protection terminology, we generally act as the data controller or equivalent responsible organisation.
Where a business or institutional client supplies personal information contained in its materials and instructs us how to handle it, the client may remain responsible for that information and we may act only as its service provider or processor. Any separate written data-processing terms agreed with that client will take priority for that processing.
|
POLICY SCOPE This policy covers the Your Writing Hub website and direct service communications. It does not govern a third-party website, payment service, email provider, file-transfer platform, or other service that publishes its own privacy policy. |
2. The information we collect
The information we collect depends on how you interact with us. We aim to collect only information that is relevant and proportionate to the purpose.
|
CATEGORY |
EXAMPLES |
TYPICAL SOURCE |
|
Identity and contact |
Name, email address, telephone number, organisation, role, country or location, and preferred contact method. |
Provided by you, your organisation, or an authorised contact. |
|
Enquiry and project |
Requested service, subject, purpose, deadline, word count, project stage, instructions, messages, feedback, revision requests, and support records. |
Project-brief form, email, telephone, chat links, meetings, or other agreed channels. |
|
Files and content |
Drafts, notes, references, datasets, questionnaires, transcripts, images, presentations, reports, and other materials supplied for assessment or service delivery. |
Provided by you or an authorised third party. |
|
Commercial and transaction |
Quotation, invoice, amount, currency, payment date, transaction reference, payment status, billing contact, and relevant tax or accounting information. |
You, our records, banks, or payment providers. We do not need full card details in the project form. |
|
Technical and usage |
IP address, browser and device type, operating system, referring page, timestamps, requested pages, error and security logs, and similar hosting data. |
Generated by browsers, servers, hosting providers, and external resources. |
|
Communications and preferences |
Correspondence, consent records, complaint history, service preferences, and whether you wish to receive non-essential updates. |
Your interactions and our administrative records. |
Information we do not intentionally request
The website project-brief form asks for your name, email address, required service, ideal deadline, project details, and consent to be contacted. It is not designed to collect passwords, full payment-card details, government identification numbers, medical information, precise financial information, or other highly sensitive data.
Project content can nevertheless reveal sensitive or confidential information. Please remove unnecessary identifiers and tell us before sending material that contains sensitive personal data, confidential business information, unpublished research involving human participants, or information subject to professional secrecy or legal restrictions.
3. How we collect information
We collect personal information through the following routes:
- directly from you when you complete the project-brief form, send an email, call us, attend a meeting, request a quotation, make a payment, provide feedback, or submit project materials;
- from an organisation, colleague, supervisor, representative, or other person authorised to communicate with us on your behalf;
- automatically through standard web-server, security, browser, and hosting technologies when the website is accessed;
- from service providers involved in communications, file transfer, hosting, payment processing, accounting, fraud prevention, or project administration; and
- from publicly available sources where reasonably necessary to verify a citation, professional profile, business identity, publication, factual claim, or other information relevant to an agreed project.
If you provide personal information about another person, you must have a lawful basis and appropriate authority to do so and should give that person any notice required by applicable law.
4. How and why we use information
We process personal information only for identified business purposes and on an appropriate legal basis where applicable. The exact basis depends on the information, the relationship, and the law that applies to the individual.
|
PURPOSE |
INFORMATION COMMONLY USED |
POSSIBLE BASIS |
|
Respond to enquiries, understand requirements, check service fit, and prepare quotations. |
Contact, enquiry, project, and communication information. |
Steps requested before a contract; legitimate interests; consent where required. |
|
Create, administer, perform, review, revise, and deliver an accepted project. |
Contact, project, files, communications, and transaction information. |
Contract performance; legitimate interests; legal obligations. |
|
Select and coordinate appropriate editors, researchers, writers, or other specialists. |
Project requirements and the minimum contact or file information needed for delivery. |
Contract performance; legitimate interests; client instructions. |
|
Issue invoices, confirm payments, maintain accounts, prevent fraud, and resolve payment disputes. |
Identity, contact, transaction, and communication information. |
Contract; legal obligations; legitimate interests. |
|
Protect systems, investigate misuse, maintain backups, and ensure website and service security. |
Technical, usage, identity, project, and communication information. |
Legitimate interests; legal obligations. |
|
Handle complaints, claims, audit trails, quality reviews, and legal or regulatory requests. |
Relevant project, transaction, communication, and technical records. |
Legal obligations; legal claims; legitimate interests. |
|
Improve internal procedures, service quality, accessibility, and client experience. |
De-identified or limited project and usage information where practicable. |
Legitimate interests; consent where required. |
|
Send optional service updates or marketing messages. |
Contact information and communication preferences. |
Consent or legitimate interests where permitted, with an opt-out. |
Where we rely on consent, you may withdraw it for future processing. Withdrawal does not make earlier lawful processing invalid and may not affect information that must be retained or processed on another lawful basis.
We do not sell or rent personal information. We do not use client drafts or project materials to create targeted advertising profiles.
5. Project materials and sensitive information
Writing and research projects may contain personal information about authors, participants, employees, customers, patients, students, interviewees, or other individuals. Before sending material, you should consider whether names, contact details, identification numbers, signatures, images, audio, raw interview data, health details, or other identifiers are necessary for the service.
Where practicable, anonymise or pseudonymise project materials before sharing them. Use participant codes instead of names, remove direct identifiers, and avoid sending passwords or access credentials in ordinary email.
You remain responsible for ensuring that you are permitted to disclose project materials to us and that any required participant notice, consent, confidentiality agreement, ethical approval, institutional permission, licence, or other authority is in place.
|
MINIMUM NECESSARY INFORMATION Share only the information needed for the agreed task. For an initial enquiry, a concise description is usually sufficient. Sensitive data should not be sent until we have confirmed an appropriate transfer method and the project genuinely requires it. |
6. Cookies, server logs, and external resources
6.1 Essential technologies and server logs
Like most websites, our hosting environment may process technical information needed to deliver pages, maintain security, diagnose errors, prevent abuse, and produce basic operational statistics. This may include IP address, date and time, requested page, browser type, device information, referrer, and response status.
6.2 Cookies and similar technologies
The website may use cookies or similar local technologies that are strictly necessary for security, accessibility, form operation, session management, or user preferences. We will not knowingly place non-essential advertising or analytics cookies without providing any notice or consent mechanism required by applicable law.
Your browser may allow you to block or delete cookies. Blocking essential technologies can prevent parts of a website or form from working correctly.
6.3 Google Fonts
The website currently references Google Fonts to display its typography. When fonts are loaded from Google’s servers, a visitor’s browser may send technical request data to Google, such as the IP address, requested font resource, browser or operating-system information, and referring page. Google applies its own terms and privacy practices to that processing.
The website administrator may choose to host font files locally to reduce third-party requests. If analytics, advertising, embedded video, live chat, payment widgets, or other tracking technologies are introduced, this policy and any cookie notice should be updated before or when those technologies are deployed.
7. How we share information
We disclose personal information only when reasonably necessary for the purpose described in this policy. Recipients may include:
- employees, project leads, editors, researchers, writers, proofreaders, designers, analysts, and other authorised specialists who need the information for the agreed service;
- hosting, email, cloud storage, file-transfer, collaboration, communications, security, backup, accounting, invoicing, and customer-support providers;
- banks, payment providers, and fraud-prevention services where a payment channel is used;
- professional advisers, insurers, auditors, accountants, and legal representatives where reasonably necessary;
- a buyer, successor, investor, or restructuring adviser in connection with a genuine business sale, merger, financing, reorganisation, or transfer, subject to appropriate confidentiality; and
- courts, regulators, law-enforcement bodies, tax authorities, government agencies, or other persons where disclosure is required by law, lawful process, or necessary to protect rights, safety, security, or evidence.
We do not authorise service providers or project specialists to use personal information for unrelated purposes. They are expected to protect confidentiality and handle information consistently with their role, contractual commitments, and applicable law.
8. Specialists, contractors, and service providers
Your Writing Hub may use carefully selected independent specialists and service providers to perform parts of a project or support business operations. We aim to provide each recipient only the information reasonably required for the assigned task.
For example, a subject specialist may need the project brief and relevant draft but may not need billing records. An accountant may need invoice and transaction information but not the underlying manuscript. Access is assigned according to role and operational need.
Where appropriate, we use confidentiality, data-protection, non-disclosure, security, or service terms with recipients. However, no contractual or technical measure can eliminate every risk, and you should avoid sending information that the project does not require.
9. International data transfers
Your information may be accessed or stored in Pakistan and in other countries where our specialists or technology providers operate. Those countries may have privacy laws that differ from the laws in your location.
Where a transfer is subject to a legal safeguard requirement, we will use an appropriate mechanism where reasonably available, such as contractual protections, provider commitments, adequacy arrangements, consent, or another lawful transfer basis. We also seek to minimise the information transferred and restrict access to the relevant purpose.
You may contact us for general information about material cross-border arrangements applicable to your data. We may need to protect confidential commercial terms and the security details of our systems.
10. Data retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, revision support, client relationship management, accounting, taxation, security, dispute resolution, legal claims, professional obligations, and compliance with applicable law.
Retention periods vary according to the type of record. In deciding how long to retain information, we consider:
- whether an enquiry became an accepted project and whether continued contact is reasonably expected;
- the duration of the project, revision window, warranty or correction period, and client relationship;
- the sensitivity, quantity, and continuing usefulness of project files;
- invoice, tax, accounting, fraud-prevention, and legal limitation requirements;
- the need to maintain suppression records so that an opt-out request is respected; and
- backup cycles, system integrity, security investigations, and the feasibility of deletion from archived systems.
When information is no longer required, we will take reasonable steps to delete, anonymise, securely dispose of, or restrict it. Deletion from active systems may not immediately remove residual copies from secure backups; those copies remain protected and are overwritten or expire according to the relevant backup cycle.
11. Data security
We use reasonable administrative, organisational, and technical measures designed to protect personal information against unauthorised access, loss, misuse, alteration, disclosure, or destruction. Measures may include role-based access, confidentiality duties, device and account security, authentication controls, encrypted connections or storage where appropriate, secure backups, software updates, incident response, and provider due diligence.
Security also depends on how information is sent and stored by clients. Use strong passwords, verify recipient addresses, avoid public links for confidential documents, limit access permissions, and tell us promptly if you believe an account, file, or message has been compromised.
No internet transmission, email system, storage platform, or security control is completely risk-free. We cannot guarantee absolute security, but we will respond to suspected incidents proportionately and make any legally required notifications.
12. Confidentiality and academic materials
We treat non-public project information as confidential and limit access to people who need it to assess, manage, or deliver the work. Confidentiality does not apply to information that is lawfully public, independently developed without use of the confidential information, received lawfully from another source without a duty of confidence, or required to be disclosed by law.
Academic drafts, coaching notes, research plans, data, feedback, and related materials are used to provide the requested support and maintain appropriate administrative records. We do not publish a client’s work, identity, testimonial, or project outcome as a sample or promotional item without permission.
We may use aggregated or properly de-identified operational information to understand workload, service categories, common support needs, or quality trends, provided it does not reasonably identify a client, author, participant, institution, or confidential project.
13. Your privacy rights and choices
Depending on your location, relationship with us, and the law that applies, you may have rights concerning your personal information. These may include the right to:
- request confirmation of whether we process your personal information and obtain access to relevant information;
- ask us to correct inaccurate information or complete information that is materially incomplete;
- request deletion of information that is no longer required or is being processed unlawfully, subject to lawful retention grounds;
- request restriction of processing in certain circumstances;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent for future processing where consent is the basis relied upon;
- receive certain information in a portable format where a portability right applies; and
- complain to a competent data-protection, consumer-protection, or other regulatory authority.
To protect privacy and prevent fraud, we may ask for reasonable information to verify identity, authority, and the scope of a request. An authorised representative may submit a request where permitted, but we may require evidence of authority.
Rights are not absolute. We may refuse or limit a request where the law permits, including where information must be retained for legal obligations, contracts, payment records, security, the rights of another person, legal claims, academic or professional integrity, or freedom of expression. We will explain the reason where required.
We aim to respond within the timeframe required by applicable law or, where no specific timeframe applies, within a reasonable period.
14. Marketing communications
We may send service-related communications that are necessary to answer an enquiry, administer a quotation, deliver a project, provide revision support, issue an invoice, maintain security, or notify you about material policy or service changes. These are not optional marketing messages.
We will send promotional emails or other non-essential updates only where permitted. You may opt out at any time by using an unsubscribe method provided in the message or contacting us. An opt-out does not prevent essential project or transaction communications.
We may retain a minimal suppression record, such as your email address and opt-out status, so that we do not add you back to a marketing list unintentionally.
15. Children and young users
The website and paid services are intended for people who can lawfully engage a service or for an authorised parent, guardian, institution, or adult representative acting for a younger person. We do not knowingly use children’s personal information for behavioural advertising or sell it.
A parent or guardian should supervise any enquiry made by a person who is not legally able to contract. If you believe a child has submitted unnecessary personal information without appropriate authority, contact us so that we can review and, where appropriate, delete or restrict it.
16. Third-party websites and services
The website may link to email, telephone, payment, file-transfer, cloud-storage, social-media, font, or other third-party services. A link does not mean that we control or endorse the third party’s privacy practices.
When you use a third-party service, that provider may independently collect and use information under its own privacy policy and terms. Review those documents before providing sensitive information or authorising an account connection.
If a third-party platform is required for a project, we will identify it where reasonably practicable. You may raise a concern before using it so that we can consider an available alternative, although an alternative may affect cost, timing, functionality, or service availability.
17. Automated decision-making
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects for clients. Project acceptance, specialist matching, scope assessment, quotations, and quality decisions involve human review.
We may use automated tools for routine administration, spam filtering, security detection, file scanning, formatting, search, transcription, or quality-support functions. Where such a tool processes client information, we seek to limit the information supplied and use it only for an appropriate service or operational purpose.
18. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, website technology, providers, legal obligations, security practices, or data-handling procedures. The current version will be posted with a revised “Last updated” date.
Where a change materially affects how we use information already collected, we will provide additional notice or seek consent where required. Earlier versions may be retained for record-keeping and accountability.
19. Questions and complaints
Contact us first if you have a privacy question, concern, or complaint. Provide enough detail for us to identify the relevant interaction or project, but do not send unnecessary sensitive information in the initial message.
We will assess the issue, verify identity where necessary, investigate relevant records, and respond within a reasonable period. If you remain dissatisfied, you may have the right to contact a competent authority or seek another remedy available under applicable law.
Nothing in this policy restricts a right or remedy that cannot lawfully be excluded.
20. Contact us
Privacy enquiries, rights requests, complaints, and withdrawal of marketing consent may be sent using the following details:
|
BUSINESS |
Your Writing Hub |
|
|
info@yourwritinghub.com |
|
TELEPHONE |
+18085825169 |
|
LOCATION |
Karachi, Pakistan |
Please use the subject line “Privacy Request” where practical. We may communicate electronically unless you request and we agree to another reasonable method.