In brief: VAST uses the information you submit to answer your message or project inquiry, protects the website against abuse, and measures website performance using limited first-party, pseudonymous analytics. VAST does not sell personal information and does not currently operate a public consumer mobile app through this website.
1. Scope and who we are
VAST ("VAST", "we", "us", or "our") is a software-development company based in Beirut, Lebanon. We design and develop websites, business systems, integrations, automation, and software solutions for organizations in Lebanon and the Gulf region.
This policy applies to the public VAST website at www.vastlb.com, including its contact and project-inquiry forms. It does not govern software that VAST builds or operates for a client when that client determines why and how personal information is processed. In those cases, the client's privacy notice and contractual instructions normally apply.
2. Information we collect
| Category | Examples | How it is received |
|---|---|---|
| Contact details | Name, email address, optional phone number, and optional company name. | Directly from you when you submit a form or contact us. |
| Inquiry details | Your message, selected service or solution, selected package, commercial model, and consent timestamp. | Directly from you and from the page or package you selected. |
| Limited website analytics | A pseudonymous visitor identifier, page path and title, referrer host, campaign tags, device type, browser family, and visit time. | Automatically from your browser when eligible public pages load. |
| Security information | A one-way hash derived from an IP address for short-term form rate limiting, session identifiers, and security or server logs when needed. | Automatically when you interact with the website. |
| Correspondence | Emails, WhatsApp messages you choose to send, follow-up notes, proposals, and related business communications. | Directly from you and through the communication service you select. |
VAST does not request payment-card details, government identification numbers, health information, student records, or account passwords through the public website forms. Please do not place sensitive or confidential information in a general inquiry.
3. How and why we use information
We use personal information only for relevant business and website purposes, including to:
- receive, review, and respond to contact messages and project inquiries;
- understand the requested service, solution, package, or commercial model;
- prepare follow-up communications, proposals, or pre-contract discussions;
- operate, secure, troubleshoot, and improve the website;
- prevent duplicate submissions, spam, abuse, and unauthorized access;
- measure page performance and general audience activity using limited pseudonymous analytics;
- maintain appropriate business records and protect legal rights; and
- comply with applicable legal, regulatory, tax, or law-enforcement obligations.
Depending on the situation and applicable law, these activities are based on taking steps at your request before a possible contract, our legitimate interests in operating and protecting our business and website, compliance with legal obligations, or your consent where we specifically ask for it. A privacy acknowledgement on a form confirms that you have seen this policy; it is not consent to unrelated advertising.
VAST does not use the public website to make decisions about people based solely on automated processing, and we do not sell or rent personal information.
4. Website analytics, sessions, and external services
First-party analytics
The website records limited visit information for administrative key performance indicators. Before storage, a keyed one-way process pseudonymizes the visitor's network address and browser information. The analytics database does not retain the raw IP address or complete user-agent string. Known bots, non-page requests, and local or private network addresses are excluded where the system can identify them.
Essential session cookie
The public contact forms may set a temporary first-party session cookie named vast_contact. It supports form security and expires when the browser session ends. It is not used for advertising. The protected admin area uses a separate essential session cookie for authorized VAST administrators.
Google Fonts
Some public pages request font files from Google Fonts. Your browser therefore makes a direct request to Google domains and may disclose technical connection information such as your IP address and browser headers. Google states that the Google Fonts Web API is unauthenticated and does not set or log cookies. Google's own privacy terms govern its handling of those requests. The privacy page you are reading uses system fonts and does not require Google Fonts.
WhatsApp and external links
If you choose the WhatsApp option, your browser or device opens WhatsApp and you decide whether to send the prepared message. WhatsApp then processes information under its own terms and privacy policy. Other external websites linked from VAST are also governed by their own policies.
5. Sharing and international processing
We may disclose relevant information only where reasonably necessary to:
- hosting, database, email, infrastructure, security, and IT service providers that support the website and our communications;
- professional advisers such as lawyers, accountants, auditors, or insurers;
- competent courts, regulators, public authorities, or law-enforcement bodies where required or permitted by law;
- a buyer, investor, or successor involved in a legitimate corporate transaction, subject to appropriate confidentiality; or
- another party when you direct us or provide valid consent.
Some service providers may process information in countries other than Lebanon. Where applicable law requires safeguards for an international transfer, we will use appropriate contractual, organizational, or other lawful measures.
6. How long we keep information
- Contact and project inquiries: kept for as long as reasonably needed to answer the request, manage a potential or active business relationship, maintain appropriate business records, and establish or defend legal claims.
- Website analytics: configured for a 180-day retention period unless an administrator selects another lawful period. Records may remain slightly longer until routine cleanup runs.
- Rate-limit records: intended for short-term anti-abuse checks and removed after the relevant security window during routine cleanup.
- Server, email, and backup records: retained according to operational, security, recovery, and legal requirements, then deleted or overwritten under the relevant service schedule.
Retention may be extended when information is needed for a legal hold, dispute, security investigation, regulatory request, or another applicable legal obligation.
7. Your choices and privacy rights
Subject to applicable law and any relevant exceptions, you may ask VAST to:
- confirm whether we hold personal information about you and provide access to it;
- correct information that is inaccurate or incomplete;
- delete information that is no longer needed or lawfully required;
- restrict or object to certain processing;
- provide information you supplied in a reasonably usable format where applicable; or
- withdraw consent for future processing where consent is the legal basis.
You may also complain to a competent privacy, consumer-protection, or judicial authority where you have that right. To protect you, we may need to verify your identity before acting on a request. Some rights are not absolute, and we may retain information where the law permits or requires it.
You can block or delete cookies through your browser settings. Blocking the essential contact-form cookie may prevent the form from working correctly.
8. Security
VAST uses reasonable technical and organizational safeguards designed to protect information, including access controls, protected administration, prepared database statements, limited data collection, pseudonymization, rate limiting, and restricted configuration files. No internet transmission or storage system can be guaranteed to be completely secure.
9. Children
The VAST website is a business-to-business company website and is not directed to children. The public forms are not intended for anyone under 16. Although VAST may market software for schools, the public VAST website does not request student records. If you believe a child has submitted personal information, contact us so we can review and remove it where appropriate.
10. Changes to this policy
We may update this policy when the website, our services, or applicable requirements change. The latest version will appear on this page with a revised effective date. Material changes may also be communicated through the website or directly where appropriate.
11. Contact VAST
For privacy questions or requests, contact:
VAST
Beirut, Lebanon
Email: [email protected]
Telephone: +961 03 190044
Please write "Privacy request" in the email subject and describe the information or request clearly.