Privacy
Policy
Who we are
IASIA is a software studio based in Phnom Penh, Cambodia. We design and build web platforms, mobile applications, and the systems behind them. This policy covers this website only. Software we build for clients is governed by that client’s own policy, not by this one.
For anything in this policy, the person responsible is Sochetra Phy, who can be reached at contact@iasia.co.
What this site collects
Very little, and none of it automatically. This is a static website: there is no account to create, no profile to build, and no tracking script running in the background as you read.
- Nothing, by default
- Reading this site leaves no record with us. We do not run analytics, advertising pixels, session recording, or fingerprinting.
- Your cookie choice
- Whether you pressed Accept or Reject, stored in your own browser so we do not ask again on every visit.
- What you type into the contact form
- Your name, email address, company if you give one, and what you write about your project — and only once you press Send.
- Server logs
- Our host records requests, including IP addresses, as any web server does. We do not use these logs to build a picture of individual visitors.
The contact form
The form on the contact section sends what you type to us so that we can reply. We use it for that and nothing else: no newsletter, no mailing list, no sharing with anyone selling anything.
Submissions are delivered through Formspree, a form-handling service, which passes the message to our inbox. Formspree processes the message in transit and holds a copy under its own privacy policy.
The embedded demos
The working demos on this site run inside frames served from this same domain. They are self-contained illustrations built for this website: the names, balances, patients, shipments and prices in them are invented. Nothing you type into a demo is transmitted anywhere or kept after you close the page.
Third parties
We keep these to the minimum a site like this can run on.
- Our hosting provider serves the pages and keeps standard server logs.
- Formspree receives contact-form submissions and forwards them to us.
We do not sell, rent, or trade personal information, and we do not share it for advertising.
Why we are allowed to hold it
Where the GDPR or a comparable law applies to you, our grounds are these: we handle what you send through the contact form in order to answer you, which is a legitimate interest and, in practice, the reason you wrote; we keep your cookie choice because you gave it; and we keep server logs to run and secure the site.
How long we keep it
- Enquiries
- Kept while we are talking, and for two years afterwards so we can pick a conversation back up. Ask and we will delete yours sooner.
- Cookie choice
- Held in your browser until you clear this site’s data.
- Server logs
- Rotated on our host’s schedule, typically within a few weeks.
Your rights
You can ask us for a copy of anything we hold about you, ask us to correct it, or ask us to delete it. You can object to how we are using it, and you can ask us to send it to you in a portable form. You do not need a lawyer or a particular form of words — an email saying what you want is enough.
Write to contact@iasia.co and we will answer within thirty days. If you are in a jurisdiction with a data-protection authority and we have not resolved things, you have the right to complain to it.
Security
The site is served over HTTPS, and form submissions are encrypted in transit. Enquiries live in our email, protected by two-factor authentication. This is proportionate to what we hold, which is correspondence rather than payment details or identity documents — we do not ask for those here and you should not send them through this form.
Children
This site sells business services and is not directed at children. We do not knowingly collect information from anyone under sixteen. If you believe a child has sent us something, write to us and we will delete it.
Where the data goes
We are in Cambodia. Our hosting and form provider operate servers outside Cambodia, which means an enquiry you send may be processed in another country, including in the United States and the European Union. Where the GDPR requires a safeguard for that transfer, we rely on our providers’ standard contractual clauses.
Changes to this policy
If we change how any of this works — most likely by adding measurement — we will update this page and change the date at the top before the change takes effect. We will not quietly start collecting something this policy says we do not.
How to reach us
Email contact@iasia.co. A question about this policy reaches the same person who built the site.
See also the Terms of Service.
This policy describes what this website actually does today. It is written to be read rather than to be impressive, and it is not legal advice. If IASIA takes on work that involves handling personal data on a client’s behalf, that engagement gets its own agreement rather than relying on this page.