Privacy notice
We are a security company, so we hold as little as possible: what you cannot breach is what we never collected. This site sets no cookies, runs no analytics, and loads nothing from a third party. The contact form is the only place we receive personal data.
Scope
This notice covers this website only: the pages you are reading and the contact form on them.
It does not cover client engagements. Anything we access, find, or are given while testing under contract is governed by that engagement's agreement and NDA, handled under the rules we agree with you before testing starts, and never published without your written consent. Nor does it cover the vulnerability reports we send vendors — those follow our disclosure policy.
Who is responsible
Starfish Security is operated by Phuoc Pham, registered in Đà Nẵng, Vietnam. He decides why and how the data described here is processed, and is the contact point for any question or request about it.
Because we are established in Vietnam, our handling of personal data is governed by Vietnam's Law on Personal Data Protection (Law No. 91/2025/QH15), in force since 1 January 2026. Where your own country's law reaches us as well — the GDPR if you are in the EU or UK, for instance — it applies to your data on top of that, not instead of it.
What we collect
Only what you type into the contact form: your name, email address, and message, plus your company and the engagement type if you choose to fill them in. That is the entire list. There is no account to create, nothing to log into, and no hidden field that collects anything else.
The form does contain one hidden field, and it is not for you. Automated spam fills it in; browsers used by people leave it empty. If it arrives filled, the submission is discarded immediately and nothing is sent or stored.
As with any website, the server that delivers these pages records ordinary technical request data such as IP address, timestamp and user agent, for security and to keep the site running. These pages are served by GitHub Pages, so that technical log data is processed by GitHub as our hosting provider; we do not receive it, we do not combine anything with form submissions, and we do not use logs to identify visitors.
Why we use it
To read your message, reply to it, and scope the engagement you are asking about. That is the only purpose. We process the details because you asked us to get in touch and because doing so is a necessary step towards a possible contract between us; the server logs we keep because a public website has to be defended.
We do not use your message to train anything, and we do not repurpose it for marketing. You will not be added to a mailing list by writing to us.
What this site does not do
No analytics. There is no Google Analytics, Plausible, PostHog, Segment or equivalent on this site. We do not measure your visit.
No cookies. The site sets none at all — not for tracking, not for preferences. That is why you were never asked to dismiss a cookie banner.
No third-party scripts. Nothing on these pages is loaded from someone else's domain, so no third party learns that you came here.
No fonts from Google. Our typefaces are compiled into the site and served from our own domain, so your browser never requests them from Google.
No CAPTCHA. Spam is filtered by a hidden field that real people never fill in, not by a service that profiles you to decide whether you are human.
No advertising, no profiling, no sale of data. We do not build a profile of you, and we never sell or rent your details or share them for anyone's marketing.
Who else handles it
Two suppliers, and no one else. The pages themselves are served by GitHub Pages, our hosting provider. When you submit the form, your message travels through FormSubmit, a form-delivery service that turns it into an email to our inbox. Both process your data to provide those services to us, not for purposes of their own.
If delivery fails (the service is down, or your network blocks it), the site does not quietly swallow your message: it hands you a pre-filled mailto: link instead, and the message travels from your own mail client straight to info@starfishsec.com. In that case it never passes through this website at all.
We keep no database. There is no copy of your enquiry on this website — only the email it became. Beyond that, we disclose your data to no one, unless we are legally compelled to.
How long we keep it
An enquiry that does not turn into work is deleted 90 days after the conversation ends. That is the whole retention period: we are not keeping your message on the chance it becomes useful later.
If the enquiry does become an engagement, the correspondence is kept for the life of that engagement, because we need the record of what was agreed and what was authorised, and is then deleted on the schedule set out in the engagement agreement. Either way, you can ask us to delete it sooner at any point.
Your rights
Whatever your local law entitles you to, we will do the following on request: tell you what we hold about you, correct it if it is wrong, delete it, send you a copy, or stop using it. Email info@starfishsec.com and we will answer within 30 days. There is no charge and no form to fill in.
If you think we have handled your data badly, tell us first — we would much rather fix it than have you chase us. But the complaint route is yours either way: in Vietnam that is the Department of Cybersecurity and High-Tech Crime Prevention (A05) at the Ministry of Public Security, and if your own country's data-protection law covers you, your national authority under that law.
Keeping this site safe
We would be poor advertisements for our own work if this site were sloppy. It is a fully static site: served over HTTPS, it stores nothing in your browser, and it has no login, no database and no server-side code of its own — which is the shortest way to say that there is very little here to attack.
Found a flaw in it anyway? Tell us. Good-faith research on this site is welcome under our disclosure policy, which commits us to acknowledge within 14 days, keep you posted, and credit you when we publish.
Questions or changes
Ask us anything about this notice at info@starfishsec.com. If we change how we handle your data we will update this page and move the version and date below, so you can see that something changed.
Notice version 1.1, effective 2026-09-08 (hosting moved to GitHub Pages; form delivery via FormSubmit). Changes are published on this page.