Legal
Privacy Policy
Last updated: July 26, 2026
This Privacy Policy explains how Web World Center collects, uses, stores, and shares information when people visit our website, contact us, order or use services, register for training, or communicate with our team.
1. Scope and our role
This policy applies to Web World Center's public website, billing application, customer communications, hosting and domain services, support, courses, and workshops. It should be read with our Terms and Conditions and Acceptable Use Policy.
Web World Center normally decides how customer-account, billing, enquiry, and support information is used. For personal information contained in a customer's hosted website, application, database, or email, the customer normally decides the purpose and Web World Center provides the hosting infrastructure and related technical services.
2. Information we may collect
Depending on the service or interaction, we may collect:
- Identity and contact information such as name, email address, telephone or WhatsApp number, postal address, company, and registered account contacts.
- Enquiry and support information, including requested services, messages, tickets, email, WhatsApp communications, troubleshooting details, and authorized access instructions.
- Account and billing information, including customer number, IP address, orders, services, invoices, payment status, payment reference, billing history, and account activity.
- Domain information required by the applicable registry or registrar, including registrant and administrative contact details.
- Technical and security information such as IP address, browser and device details, requested pages, timestamps, server logs, login records, error records, and suspected abuse or security events.
- Information supplied for courses and workshops as described below.
- Customer-hosted content where access is necessary for requested support, infrastructure administration, security or abuse investigation, or legal compliance.
Please do not send passwords, complete card details, security codes, sensitive identity documents, or other unnecessary confidential information through ordinary email, WhatsApp, or website enquiry forms.
3. Courses, students, and institutional workshops
Individual course or workshop registration may include a student's name, contact details, selected course, attendance, payment, progress, and certificate-related information that is reasonably needed to administer the training.
An institutional workshop request is handled separately and may include the institution's name, address, official contacts, principal or director, contact person, proposed date, participation method, expected student count, and related planning information. Individual student records are not required at the initial institutional-enquiry stage unless they are needed later for registration, attendance, safeguarding, or certification.
Where a student is below the legal age to provide an authorization that is required for the relevant activity, the parent, guardian, or responsible institution must provide or confirm the necessary authorization. We aim to collect only the student information reasonably required for the course or workshop.
4. Payment information
Card payments are processed by external national or international payment providers. Web World Center does not receive or store a complete payment-card number or CVV/security code. We may receive and retain limited transaction information such as the payment status, amount, date, method, masked or partial reference, processor response, and invoice number.
Bank, wallet, and other payment providers process information under their own terms and privacy practices. Customers should enter payment information only through the approved billing or payment channel.
5. How we use information
We use personal information where reasonably necessary to:
- respond to enquiries and provide quotations;
- create and administer accounts, orders, invoices, renewals, payments, and services;
- register, renew, transfer, secure, or manage domains and related services;
- provide support and communicate about service, billing, security, abuse, and legal matters;
- administer courses, workshops, attendance, and certificates;
- protect accounts, customers, infrastructure, and the public from fraud, abuse, attacks, and unauthorized access;
- maintain, troubleshoot, improve, and measure the website and services;
- meet accounting, contractual, regulatory, registry, court, and other legal requirements; and
- send relevant promotions to existing customers or people who requested them, subject to opt-out rights.
Depending on the circumstances and applicable law, processing may be based on performing a requested service or contract, consent, legitimate service and security needs, compliance with legal obligations, or the establishment and protection of legal rights.
6. Website forms, email, support, and WhatsApp
Information submitted through website forms is used to respond to the request and is sent to our business communication systems. Form pages may use a temporary session identifier for security, CSRF protection, validation, and returning form errors. Failed-form values may remain temporarily in the session and are cleared after successful submission or session expiry.
Email, tickets, and WhatsApp messages may be retained as service or business records. Selecting a WhatsApp link transfers the visitor to the WhatsApp service, which processes information under its own terms and privacy practices.
7. Cookies, security services, and optional analytics
We use necessary session and security technologies to operate forms, protect the website, prevent abuse, route traffic, and maintain service reliability. Our security and network providers may process IP addresses, request details, and security signals for these purposes.
We may enable privacy-conscious website analytics, including Google Analytics through a tag management system, to understand page usage and measure actions such as enquiries, WhatsApp clicks, email clicks, and order journeys. When enabled, non-essential analytics will follow the available consent choice. We do not intentionally send names, email addresses, telephone numbers, form messages, full payment details, or customer-hosted content to analytics.
The analytics choice may be stored in the visitor's browser storage so the website can remember whether analytics was accepted or rejected. This preference is not used as a customer-account identifier.
We do not use analytics for personalized advertising, remarketing, or uploading identifiable customer data unless that practice is separately reviewed, disclosed, and permitted. A visitor who rejects optional analytics can continue using the public website and essential service functions.
8. When information may be shared
We do not sell personal information, publish customers in a public directory, or provide customer information for unrelated third-party marketing. We may share only the information reasonably necessary with the following categories:
- billing, payment, banking, and fraud-prevention providers;
- hosting, network, data-center, backup, email, security, and support providers;
- domain registries, registrars, PKNIC, ICANN-related service providers, and domain dispute authorities;
- SSL, licensing, software, and other vendors required to deliver an ordered service;
- analytics, tag-management, and communication platforms when enabled or selected by the user;
- accountants, auditors, legal advisers, insurers, and other professional advisers under appropriate duties; and
- courts, regulators, law-enforcement bodies, upstream providers, or affected parties where disclosure is legally required or reasonably necessary to protect rights, safety, services, or infrastructure.
Providers and vendors may change as services and business requirements change. They receive only the information reasonably required for their role, subject to available contractual, technical, and organizational safeguards.
9. International processing
Web World Center serves customers across different countries and uses infrastructure and service providers in the USA, UK, Pakistan, and other locations where an ordered service or provider operates. Personal information may therefore be stored, accessed, or processed outside the customer's country.
Where applicable, we use reasonable contractual, access-control, security, and provider selection measures for international processing. Registry, registrar, payment, and legal requirements may independently determine where particular information is processed.
10. Access to customer-hosted content
Web World Center does not routinely inspect customer-hosted websites, databases, files, or email content. Authorized personnel may access hosted content when the customer requests support and gives permission, or where access is reasonably necessary for infrastructure administration, service restoration attempts, security or abuse investigation, fraud prevention, protection of other users, or legal compliance.
Customers are responsible for the privacy and legality of personal information they collect through their own hosted websites and applications, including providing their own privacy notices where required.
11. Retention
Our normal retention approach is:
- ordinary enquiries that do not become customer accounts: up to 24 months;
- customer, account, invoice, payment, domain, contract, and transaction records: normally up to six years after the last transaction or account closure;
- closed support tickets and relevant email or WhatsApp service records: normally up to three years;
- web-server, access, and security logs: normally up to 12 months; and
- failed-form session information: until it is cleared after submission or the session expires.
Information may be retained longer where reasonably required for taxation, accounting, registry obligations, an active service, fraud, a chargeback, security investigation, dispute, court process, legal hold, or another lawful requirement. Information may be deleted or anonymized earlier when no longer required. Residual copies may remain until routine system and operational-copy deletion cycles complete; this does not create a customer-backup promise.
12. Security and personal-data incidents
We use reasonable technical and organizational safeguards appropriate to the service, including restricted administrative access, transport encryption where supported, session security, input validation, access logging, infrastructure protection, and provider controls. No Internet service or storage system can be guaranteed completely secure.
If a confirmed personal-data incident creates a material risk to affected people, we will investigate, contain the incident, and notify affected people or competent authorities where applicable law requires notification. Unsuccessful attacks, blocked requests, or events that do not expose personal information do not necessarily require customer notification.
13. Privacy choices and requests
Subject to applicable law and reasonable identity verification, a person may request access to their personal information, correction of inaccurate information, deletion of information no longer required, withdrawal of optional consent, or an end to promotional communications. We aim to respond to a valid request within 30 days or the period required by applicable law.
A deletion request does not require removal of invoices, transaction records, domain records, security evidence, fraud records, disputes, active-service information, or other information that must reasonably be retained for legal, contractual, accounting, registry, or security purposes. We may request confirmation from the registered email address, registered WhatsApp number, or another reliable verification method.
14. Minors
Our hosting and business services are general services and we do not normally ask customers to provide a date of birth. A minor may use or order a service, but if the person is below the legal age to enter the relevant contract, the order and use must be authorized by a parent, legal guardian, or responsible organization. That adult or organization accepts responsibility for the account, payment authorization, supervision, and compliance with the service terms.
For courses and workshops involving minors, we may rely on the responsible institution, parent, or guardian to provide or confirm necessary authorization. If a parent or guardian believes that a minor's information was supplied without proper authority, they may contact us so the circumstances can be reviewed.
15. Service notices and promotions
Service, billing, renewal, security, abuse, and legal notices are necessary communications for an active account and are not treated as optional marketing. Promotional email, SMS, or WhatsApp may be sent to existing customers or people who requested or accepted such communication. We do not use purchased or scraped marketing lists.
A recipient may opt out of promotional communications by using an available unsubscribe method or contacting us. An opt-out does not stop necessary account and service notices.
16. External websites and services
Our website may link to customer portals, payment providers, registries, social networks, WhatsApp, and other external services. Their privacy practices are controlled by their respective operators. Customers should review those policies before providing information.
17. Policy changes and contact
We may update this policy when services, providers, security practices, or legal requirements change. The current version and revision date will be published on this page. Material changes will be communicated where reasonably practical.
Privacy questions and verified privacy requests may be sent to [email protected]. Please do not include passwords, CVV codes, or complete payment-card details in the request.