Skip to content
XPERTIK

Reference document

Privacy and terms of use

How we handle the information you share with us, how we protect it, and the rules for using xpertik.pro.

Version
2026.10
Effective
October 9, 2026
Replaces the July 1, 2023 version
Download the PDFVersion 2026.10 · PDF in French · 60 KB

In short

xpertik.pro sets no cookies and uses no tracking, analytics or advertising tools. The only personal data we collect is what you enter in the free assessment form, to handle your request. It is never sold. You can access, correct or ask us to delete it at any time by writing to secure-contact@xpertik.pro.

01Purpose and scope

This document explains how XPERTIK handles personal information collected on xpertik.pro (French and English versions), the security measures that protect it, and the terms for using the site.

It does not apply to client engagements (assessments, threat intelligence, training, AI advisory), which are governed by the contracts and confidentiality agreements specific to each engagement. Nor does it apply to third-party sites the site may link to.

02Who we are

Controller
XPERTIK Tech Firm
Address
247 bis, Lalue, John Brown Avenue, Port-au-Prince, Haiti HT6120
Privacy and security contact
secure-contact@xpertik.pro · +509 3735-6161

03Information we collect

Information you give us

When you fill in the free assessment form, we collect only: your organization (name, industry, number of employees, website or portal address, optional); your needs (services of interest, whether an incident is ongoing, optional free-text description); your contact details (full name, job title (optional), work email, phone, preferred contact method); and your consent to this processing.

Please do not send any sensitive data through this form (passwords, banking details, technical details of an active vulnerability). If an incident is ongoing, call us directly.

Technical data

Like any website, our host keeps technical logs (IP address, browser type, date and page requested) needed to run and secure the service. When a visitor’s browser blocks an unauthorized resource, a security report is recorded; URL parameters that could contain personal information are removed from it.

What we don’t do

No cookies, no analytics, no advertising pixels or embedded social media buttons. No user accounts, no online payments, no file uploads. We never sell, rent or transfer your data, and we make no automated decisions about you.

04Why we use it

Responding to your request and scheduling the assessment
Your request and consent; steps prior to a possible contract
Keeping the site secure and preventing abuse
Legitimate interest in protecting the service and its users
Meeting our legal obligations
Legal obligation

We do not send marketing messages. We only contact you to follow up on your request.

05Who has access

Your information is available only to the XPERTIK team handling your request and, only as far as needed, to the technical providers and partners who help us deliver our services. All are bound by confidentiality and may not use your information for any other purpose.

We may also disclose information when the law requires it (court order, request from a competent authority), strictly limited to what is requested.

06Transfers outside Haiti

Because some providers are based abroad, your information may be processed outside Haiti. We only use providers that are contractually committed to protecting and securing the data they process on our behalf.

07How long we keep it

Assessment requests with no follow-up
3 years after the last contact, then deleted
Requests that led to an engagement
Length of the business relationship, plus legally required periods
Technical logs and security reports
Limited period set by the host, for security purposes only

08How we protect your data

As a cybersecurity firm, we hold the site to the standards we recommend to our clients:

  • HTTPS encryption enforced, with HSTS (preloaded) and older TLS versions disabled.
  • A strict Content Security Policy (CSP): only authorized code can run in your browser, and every blocked attempt is reported and logged.
  • Headers that protect against clickjacking, content sniffing and referrer leaks.
  • A form protected against bots, cross-site request forgery (CSRF) and injection, with submission rate limits.
  • An encrypted receiving mailbox, email authentication for the domain (SPF, DKIM, DMARC) and a signed domain (DNSSEC).
  • Continuous monitoring of software components and prompt patching of known vulnerabilities.

No measure can guarantee absolute security. If a data breach likely to affect you occurred, we would inform you as soon as possible.

09Your rights

At any time, you can ask us to:

  • give you access to the information we hold about you and a copy of it;
  • correct it if it is inaccurate;
  • delete it;
  • restrict its use, or object to it;
  • withdraw your consent, without affecting processing already carried out.

Write to secure-contact@xpertik.pro. We reply within 30 days. To protect your data, we may ask you to confirm your identity. Exercising these rights is free.

10Questions and complaints

For any question or complaint about how your information is handled, contact us first at secure-contact@xpertik.pro: we will look into it and tell you what we have done. You remain free to refer the matter to the competent authority.

11Reporting a vulnerability

If you find a security flaw affecting xpertik.pro, write to secure-contact@xpertik.pro describing the issue and how to reproduce it. Our security contact details are published at xpertik.pro/.well-known/security.txt.

We handle good-faith reports confidentially and keep you informed of the fix. Please do not disclose the flaw before it is fixed, do not access data that is not yours, and do not disrupt the service.

12Terms of use

Purpose

The site presents XPERTIK, its services and its publications. By using it, you accept these terms.

Acceptable use

You agree to use the site fairly. In particular, the following are prohibited: any attempt to gain unauthorized access to, disrupt or overload the service; automated form submissions; code injection; and any use of the form for marketing, phishing or fraud. Good-faith vulnerability research reported as described in section 11 is not considered misuse.

Content

Information on the site is provided for general guidance. It is neither personalized advice nor a contractual commitment, and it does not replace an assessment tailored to your organization. Our services are subject to a dedicated proposal.

Intellectual property

The text, XPERTIK and CyberTrust logos, images and layout of the site belong to XPERTIK or are used with permission. Any reproduction without prior written consent is prohibited.

Links to other sites

The site may link to third-party sites. XPERTIK is not responsible for their content or privacy practices; please review their own policies.

Liability

XPERTIK works to keep the site available and accurate but cannot guarantee it absolutely. XPERTIK is not liable for any damage resulting from a service interruption or from use of the information published.

Governing law

These terms are governed by Haitian law. Failing an amicable settlement, any dispute falls under the competent courts of Port-au-Prince.

13Changes and version history

We may update this document as the site, our practices or regulations change. The current version is always dated and numbered; we flag significant changes on the site.

2026.10 · October 9, 2026
Complete overhaul: aligned with the new site (no cookies or trackers), retention periods, security measures, vulnerability disclosure and terms of use brought together in one document.
2023.07 · July 1, 2023
Initial version.

14Contact us

XPERTIK Tech Firm · 247 bis, Lalue, John Brown Avenue, Port-au-Prince, Haiti HT6120

secure-contact@xpertik.pro · +509 3735-6161