Privacy & Cookies Statement
Our privacy commitment, in plain terms
We are a professional firm of advocates. We do not sell personal data, use it for advertising or profile visitors. Limited service providers process information only to operate this website, deliver communications and support engagements as described below.
Effective date: 26 July 2026 · Last reviewed: 5 September 2026
- We do not use analytics, advertising, targeting, social media, or profiling cookies.
- We do not track you across sites, build audience profiles, or share data with data brokers, marketing networks or ad platforms.
- We do not sell, rent, license or otherwise monetise any personal data. Ever.
- We primarily collect information that you voluntarily submit through our consultation request form, together with limited technical information generated when the website and its security controls operate.
- An initial enquiry does not by itself create an advocate–client relationship or legal professional privilege. Once an engagement is confirmed, we protect confidential information in accordance with applicable law and professional duties.
- Closed matter files are retained only for the period required or reasonably necessary for professional, legal, tax, conflict management and claims defence purposes, and are securely deleted when that period ends.
1. Who we are & how to reach us
This Privacy & Cookies Statement (the "Statement") describes how MHSK & Partners, a firm of advocates, corporate and policy consultants based in Islamabad, Pakistan (the "Firm", "we", "us" or "our") collects, uses and safeguards personal data through this website, our online forms and our engagements with clients and prospective clients.
For any privacy-related question, request or complaint, please use our secure enquiry form, contact us on WhatsApp, or write by post to the Firm at Islamabad, Pakistan. We aim to respond to every enquiry within one working day and to every formal data-subject request within thirty days (or such shorter period as the applicable law requires).
2. Categories of data we do (and do not) collect
2.1 Data you voluntarily provide
The personal data that the Firm asks you to provide is limited to:
- Consultation-request data, the fields of our consultation intake form: full name, email address, country of residence, WhatsApp/telephone number (optional), the nature of your matter, the relevant city or jurisdiction, urgency level, a brief factual summary you elect to disclose, and the service package (if any) you selected.
- Data you provide during an engagement, once you become a client and we execute an engagement letter, we necessarily collect information reasonably required to advise on and pursue your matter: identity documents (for anti-money-laundering compliance), factual information about the matter, documents, correspondence and records supplied by you or on your behalf.
2.2 Data automatically observed by the hosting infrastructure
Our website is served by Netlify, a reputable static site hosting provider whose global edge network handles ordinary web server functions. As with every website you visit, the request that your browser makes carries technical data that is briefly held for security and diagnostic purposes only: your Internet Protocol (IP) address, the timestamp of the request, the requested URL, the referring URL (if any), and your browser's User Agent string. This is aggregate operational data. We do not associate it with any individual identity, do not use it for profiling or advertising, and we do not export it to any external analytics platform.
2.3 What we do not collect
The Firm does not collect, and does not permit any third party to collect through this website for advertising, behavioural analysis or profiling purposes:
- Behavioural analytics or usage-pattern data for marketing purposes;
- Cross-site tracking data or device fingerprints;
- Advertising, targeting, retargeting or interest-based profiling data;
- Social media plugin identifiers or external pixel signals;
- Location data beyond the country-level information you voluntarily enter;
- Sensitive personal data (religion, race, sexual orientation, health, trade-union membership, biometric data or criminal records) except to the strict extent that a specific engagement makes it necessary and you have expressly disclosed it.
We have not deployed Google Analytics, Facebook Pixel, LinkedIn Insight, Meta Ads, TikTok, Hotjar, Mixpanel or any equivalent tracking or profiling technology on this website. If that position ever changes, this Statement will be updated in advance, and any such technology will be gated behind an opt-in consent choice.
3. Purposes for which we use data
We use personal data solely for the following purposes:
- To respond to your consultation request, to schedule the session, communicate scheduling and payment instructions, and confirm the terms on which we may act.
- To provide legal services under a duly executed engagement letter, to advise, draft, correspond, appear, file, and otherwise conduct the matter you have retained us for.
- To comply with legal, professional and regulatory obligations, including bar-council rules, anti-money-laundering and know-your-client regulations, tax reporting, court orders and lawful process.
- To maintain a conflict-of-interest register, see Section 6 below.
- To secure and operate the website, including detection and prevention of security incidents.
We do not use personal data for automated decision making that produces legal or similarly significant effects, and we do not use artificial-intelligence tools to profile you.
4. Legal basis for processing
To the extent the EU General Data Protection Regulation, the UK GDPR, or any equivalent law applies to a given processing activity, we rely on the following legal bases:
- Performance of a contract, to respond to your consultation enquiry and to perform our obligations under an engagement letter.
- Consent, where you voluntarily submit special-category information relevant to your matter. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
- Legal obligation, to comply with bar rules, AML/KYC requirements, tax filings, court orders and other mandatory laws.
- Legitimate interests, to secure the website, prevent fraud and misuse, and maintain a conflict-of-interest register (which is itself a professional-conduct obligation).
5. Retention and deletion
We keep personal data only for as long as it is required or reasonably necessary for the purpose for which it was collected and for applicable professional, legal, tax, conflict management and claims defence obligations. It is securely deleted or anonymised when that period ends:
- Consultation enquiries that do not result in an engagement, deleted 12 months from the date of enquiry, unless you ask us to delete earlier.
- Client matter files, including privileged communications, documents and work product, retained throughout the engagement and for the period thereafter required or reasonably necessary under professional conduct, limitation, tax, audit and claims defence requirements. The file is then securely deleted or anonymised, subject to the conflict check record described in Section 6.
- Conflict-check register, indefinite, but limited to name, contact details and a very short factual note, as described in Section 6.
- Server logs, retained by our hosting provider for the limited operational period determined by its current service and account settings, for security and diagnostic purposes.
- Financial records (invoices, receipts), retained for the periods required by tax and audit law in the jurisdiction in which the invoice was raised.
6. Legal professional privilege & conflict checks
Confidentiality and legal professional privilege depend on the applicable law, circumstances, purpose and participants. An initial enquiry does not by itself create an advocate–client relationship or establish privilege. Once an engagement is confirmed, the Firm protects confidential information in accordance with applicable professional duties and any engagement-specific arrangements.
Information may be disclosed where you authorise it, where disclosure is required by law or lawful process, where reasonably necessary to establish, exercise or defend legal rights, or where authorised local counsel and service providers require it to perform the agreed engagement. In each case, disclosure is limited to what is reasonably necessary and subject to applicable confidentiality and professional obligations.
On disposal, settlement, judgment, withdrawal or other closure of your matter, the file is closed and access remains restricted. It is retained only for the period required or reasonably necessary for professional conduct, limitation, tax, audit, conflict management and claims defence purposes, after which it is securely deleted or anonymised.
The only information the Firm retains indefinitely thereafter is a conflict-of-interest record comprising: your name, one contact detail, a short factual descriptor of the matter (typically two to three lines), and the closure date. This record is retained for the sole purpose of enabling the Firm to identify, before accepting any new matter, whether that new matter would place the Firm in conflict with a former or existing client. This retention is itself a professional obligation. You may request in writing that we anonymise or remove your entry from this register, and we will do so unless retention is required by a bar or regulatory rule.
7. Limited disclosures and service providers
The Firm does not sell, rent, license or disclose personal data for advertising, profiling or data brokerage. Limited processing or disclosure occurs only where necessary to operate the website, communicate with you, conduct an engagement, comply with law or protect legal rights:
- Hosting and server-side form handling, Netlify, Inc. provides the website hosting, content-delivery network and serverless function through which consultation requests are processed.
- Email delivery and mailbox storage, the Firm's configured business-email provider processes consultation requests and ordinary email communications delivered to the Firm's mailboxes.
- Email transit, ordinary internet email infrastructure may process messages in transit. We recommend against sending highly sensitive material by ordinary email; alternative secure channels are available on request.
- Legal compulsion, where compelled by court order, subpoena, regulatory demand, or other lawful process.
- Defence of legal claims, where necessary to establish, exercise or defend the Firm's legal rights.
- Corporate transaction, in the unlikely event of a merger, restructure or transfer of the Firm's assets, personal data may be transferred to a successor entity, which will be bound by protections at least equivalent to this Statement.
We do not participate in data-broker exchanges, advertising networks, "data-cooperative" arrangements or any similar scheme.
8. Cookies & similar technologies
This website uses strictly necessary technical storage only. There are no advertising, analytics, social media, targeting or profiling cookies. There are no external trackers.
The limited first-party browser storage used by the website is:
You may revisit your choice at any time through the Cookie preferences link in the footer, or clear these values through your browser settings. Rejecting cookies does not restrict access to the website. The site does not set optional analytics, advertising, targeting or profiling cookies.
9. International data transfers
Our website is hosted on Netlify's global infrastructure. When you submit the consultation form, the information passes through a Netlify serverless function and is then delivered to the Firm through its configured business-email provider. Those providers may process data in the United States and other countries in which they operate.
Where data protection law requires safeguards for an international transfer, we use the contractual and legal transfer mechanisms available under the relevant provider terms and applicable law. Information about the safeguards applicable to a particular request is available from the Firm on request.
10. Data security
We implement technical and organisational measures reasonably designed to protect personal data against unauthorised access, disclosure, alteration or destruction, including:
- Encryption in transit via HTTPS (TLS 1.2 or higher) across the entire website;
- Access to consultation-request emails restricted to authorised personnel of the Firm;
- Server-side handling of the form and protected environment variables for email-service credentials;
- A minimum-collection principle, we ask for only the data necessary for the purpose, and no more;
- Periodic review of the Firm's information-security posture.
No electronic system is perfectly secure. In the unlikely event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected individuals and the relevant supervisory authority within the timeframes required by applicable law.
11. Your rights, by jurisdiction
Depending on where you are resident, you may have some or all of the following rights in respect of personal data we hold about you:
- Right of access, to obtain a copy of the personal data we hold about you.
- Right of rectification, to correct inaccurate or incomplete personal data.
- Right of erasure ("right to be forgotten"), to have your personal data deleted, subject to lawful exceptions.
- Right to restrict processing, to limit the way we use your data in certain circumstances.
- Right to data portability, to receive your data in a portable, machine-readable format, or to have it transmitted to another controller.
- Right to object, to processing based on legitimate interests, and to direct marketing at any time.
- Right to withdraw consent, where processing is based on consent.
- Right to non-discrimination, we will not deny service, charge different prices, or provide a different level of service because you exercised a privacy right.
- Right to lodge a complaint, with your local data protection authority (see Section 21).
To exercise any of these rights, use the secure enquiry form and select Privacy or data rights request. We may need to verify your identity before acting on a request.
12. California Consumer Privacy notice (CCPA / CPRA)
If you are a California resident and the California Consumer Privacy Act 2018, as amended, applies to the Firm or the relevant processing activity, you may have specific rights including:
- Right to know what personal information is collected, used, shared or sold.
- Right to delete personal information we hold about you, subject to statutory exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing for cross contextual behavioural advertising, although this is inapplicable here because we do not sell personal information or share it for cross contextual behavioural advertising, and we have not done so in the preceding twelve months.
- Right to limit use of sensitive personal information, again inapplicable, because we do not collect sensitive personal information for any purpose other than to provide the legal service you have retained us to provide.
- Right of non-discrimination for exercising any of these rights.
To exercise a California right, contact us as set out in Section 21. Where the CCPA applies, we will verify and respond to the request within the time required by that law.
13. United Arab Emirates notice (Federal Decree Law No. 45 of 2021)
If you are a data subject in the United Arab Emirates and the Personal Data Protection Law (Federal Decree Law No. 45 of 2021), together with applicable implementing measures, applies to the relevant processing activity, you may have rights including access, correction, deletion, restriction, portability and objection. You may exercise any applicable right by writing to us and, where available, raise a complaint with the competent UAE data protection authority.
14. EU / UK GDPR notice
If you are a data subject in the European Economic Area, the United Kingdom or Switzerland and the relevant data protection law applies to the Firm or the processing activity, you may have the rights described in Section 11 above and the right to complain to the competent supervisory authority. A list of EEA data protection authorities is available at edpb.europa.eu/about-edpb/about-edpb/members. Information about the United Kingdom Information Commissioner's Office is available at ico.org.uk.
15. Canada notice (PIPEDA and provincial equivalents)
If you are a data subject in Canada and PIPEDA or an applicable provincial privacy statute applies to the Firm or the relevant processing activity, you may have rights under that law. Information about the Office of the Privacy Commissioner of Canada is available at priv.gc.ca.
16. Pakistan notice
If you are a data subject in Pakistan, the Prevention of Electronic Crimes Act 2016 and applicable data protection principles under Pakistani law govern our handling of your data. Once the pending Personal Data Protection Bill is enacted in the form ultimately adopted by Parliament, we will update this Statement to reflect its provisions and any recognised statutory rights, including any rights of access, correction, deletion and complaint to the designated regulator.
17. Children's privacy
Our services are directed at legally competent adults and, in respect of minors, only through their lawful guardians. We do not knowingly collect personal data from any person under the age of 16 (or, in the United States for COPPA purposes, under the age of 13) without the consent of a parent or lawful guardian. If you believe a minor has provided us with personal data without appropriate consent, please contact us and we will delete it.
18. Browser privacy signals
This website does not use advertising, behavioural profiling or cross-site tracking technology. Accordingly, Do Not Track and Global Privacy Control signals do not change the website's behaviour because no such tracking is initiated. These browser signals do not affect the limited processing required to deliver the website, protect it from abuse, remember your cookie preference or respond to an enquiry you choose to submit.
19. External links
This website contains links to external websites, including official judicial portals and government service portals identified in the Overseas Pakistanis Section. Those websites are not operated by us and are governed by their own privacy statements. We are not responsible for their privacy practices. We recommend that you review the applicable privacy statement before providing any personal data to an external site.
20. Changes to this Statement
We may amend this Statement from time to time to reflect changes in law, technology or the Firm's practices. When we do, we will update the "Effective date" above and, where changes are material, take reasonable steps to bring the update to your attention (for example, through a notice on the website or by a notice prominently displayed on the website). We encourage you to review this page periodically.
21. Complaints & contact
To make a privacy enquiry, exercise a right, or raise a complaint, please contact us in the first instance:
MHSK & Partners
Advocates, Corporate & Policy Consultants
Principal Office at Islamabad · Pakistan
Cross border capability: UK · USA · Canada · UAE
Secure enquiries: Privacy and data rights form
WhatsApp: +92 347 5377337
If, after contacting us, you remain of the view that your privacy rights have not been respected, you may lodge a complaint with the data protection authority in your jurisdiction, including any authority listed in Sections 13 to 16 above.