Design & development studio
What we keep about you, why, for how long, and how to have it removed.
This policy explains what Andisheh Mandegar Rayan Co., trading as Niasa, collects about you, why it collects it, who it is shared with, how long it is kept, and what you can ask us to do about it.
It is written for this specific website. Every clause below points at something that actually exists in the product — if a form or a tool is added or removed, this page is updated with it.
Your data is held by the company that runs this site:
Legal name: Andisheh Mandegar Rayan Co.
Trading name: Niasa
Address: Hezareh Creative House, Boostan Norooz Shomali Complex, Nelson Mandela Blvd, Argentine Square, Tehran, Iran
Email: info@niasa.io
Phone: +98 21 9130 6194
Use those details for any question, request or complaint about your data.
Nothing is collected “just in case”. Each item below is attached to a specific feature of the site.
Consultation and contact form — name, phone number, email (optional), project topic and your message.
Newsletter form — email address only.
Questions on service pages — name, a phone number or email, and your question. The question and our answer may be published after review; your phone number and email never are.
Blog comments — display name, email and the comment. The name and comment are published after approval; the email is not.
Job applications — name, phone, email, the role you are applying for, anything you write in the form, and the CV file you upload.
IP address and browser type — stored when a form is submitted, to stop bulk submissions and spam. It is not used to identify you.
Page speed measurements — load time, layout stability and interaction delay, sampled and carrying no personal identifier. Only the page URL and the device class are stored alongside them.
Visit statistics — through Google Tag Manager and whatever measurement tools are configured inside it. If the cookie consent banner is switched on, these tools do not run until you accept.
Approximate country and city — derived from the IP address and only to city level, so we know where our audience is. Full IP addresses are not kept in the traffic reports.
Card or banking details. Payments happen outside this website, through licensed gateways.
Sensitive personal data — religious belief, political opinion, health status and the like.
Data about children under 18. This site is written for businesses.
To reply to you. We cannot answer a consultation request without a phone number.
To perform a contract. Once a project starts, your contact details are part of that project's file.
To handle a job application. Your CV is read only for the role you applied to.
To keep the site safe. IP logging and rate limiting are what stop the forms being abused.
To improve the site. Speed measurements and visit statistics tell us which page is slow or unclear.
This site uses three kinds:
Essential — your language, light or dark theme, and whether you have already seen the intro animation. These stay in your own browser and are never sent to the server.
Analytics — to count visits and page paths. Subject to your consent where the banner is enabled.
Advertising — only if a campaign is running, and again subject to your consent.
You can clear or block cookies in your browser settings. Blocking the essential ones means your language and theme reset on every visit.
We do not sell or rent your data. It reaches these processors only, and only as far as each one needs:
Melipayamak — SMS delivery. Only your phone number and the message text are passed on.
Telefonchy — our business telephony system. If you call us or request a call, your number and call details are recorded there.
Google — via Google Tag Manager, for visit measurement.
Our hosting provider — the server the site and its database run on.
Outside that list, your data leaves us in one situation only: when a competent legal authority lawfully requires it.
Consultation requests — up to three years after last contact; projects tend to come back.
Project records — up to ten years, as tax and accounting rules require.
Newsletter subscription — until you unsubscribe.
CVs — one year after the role closes, unless you ask us to delete it sooner.
Form IP addresses — six months at most, for abuse investigation only.
Speed samples — raw samples are deleted once rolled up; only the daily summary survives.
At any time you may:
ask what data we hold about you and get a copy of it;
ask us to correct anything that is wrong;
ask us to delete your data, as far as no legal retention rule applies;
unsubscribe from the newsletter — the link is in the footer of every email;
have a published comment or question taken down.
Send the request to info@niasa.io. We answer within one working week, and before acting on a deletion request we confirm your identity using the same phone number or email the record was created with.
What we actually do:
All site traffic runs over HTTPS.
Admin passwords are stored hashed, never in plain text.
Admin access is role-based; each user sees only the sections they need.
Uploaded files are checked against their real content before being stored, not against their file extension.
Forms are rate-limited and the origin of every request is checked.
The database is backed up on a schedule.
No system is perfectly secure. If a breach occurs that puts your data at risk, we will tell you as soon as we reasonably can.
Our portfolio and articles link out to other websites. Their privacy practices are their own and we are not responsible for them.
If a feature is added that collects something new, this page is updated before that feature goes live. The last review date is always shown at the top of this page.
Any question about this policy: info@niasa.io or +98 21 9130 6194.