Procurement pack
Vendor information, in one page you can forward
Everything finance, legal and IT normally ask for before an overseas supplier can be approved — supplier details, tax position, data protection mechanism, sub-processors, security posture and payment terms. Including the things I do not have.
Anas Bin Masud is a sole trader based in Islamabad, Pakistan, supplying fixed-scope web development and technical SEO. Data transfers are covered by a pre-signed DPA incorporating the UK IDTA or EU Standard Contractual Clauses. No VAT is charged; payment is 40% on scope acceptance and 60% on completion.
Supplier details
| Trading name | Anas Bin Masud |
|---|---|
| Also known as | Anas Rajpoot (the name on the linked GitHub, LinkedIn and email accounts) |
| Structure | Sole trader / individual supplier — not an incorporated company |
| Operating since | 2022 (first paid client site) |
| Registered location | Islamabad, Islamabad Capital Territory, Pakistan |
| Primary contact | anasrajpoot766@gmail.com |
| Telephone / WhatsApp | +92 346 5348466 |
| Working hours | Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern |
| Language of business | English |
Commercial terms
| Quoting model | Fixed scope, fixed price against a written brief. Not hourly. |
|---|---|
| Currencies | USD by default; GBP, CAD, EUR or PKR on request |
| Payment terms | 40% on acceptance of scope, 60% on completion. Larger projects split across milestones. |
| Payment methods | Bank transfer or Wise. Purchase-order references carried on invoices where you need them. |
| Note on card payments | Stripe does not support Pakistan as a merchant country, so fees are not collected by card. Stripe integrations are built and tested against your own account, which you own throughout. |
| Tax status | Not registered for UK VAT or EU VAT. No VAT charged; reverse charge normally applies for registered buyers. |
| Withholding tax | Tell me at quoting stage if your jurisdiction requires withholding, so the quote accounts for it rather than the invoice surprising both of us. |
Legal and data protection
Every document below is published rather than sent on request, so your legal team can read them before anyone books a call.
| Data processing agreement | Pre-signed and published. Covers roles, security measures, breach notification and sub-processors. |
|---|---|
| International transfer mechanism | UK IDTA for UK personal data, EU Standard Contractual Clauses (2021/914) for EEA data. Pakistan holds no adequacy decision, so this is required rather than optional. |
| Sub-processors | Named list, published and versioned. Notification before any addition. |
| Privacy policy | What this site collects, why, and for how long. |
| Security posture | Written statement of technical and organisational measures. |
| Accessibility | Conformance statement, including what is not yet conformant. |
Security posture
Written plainly, including the two rows that say no. A supplier page that claims certifications it does not hold fails the first check procurement runs.
| Code storage | Git repositories, private by default. Client repositories under client ownership where requested. |
|---|---|
| Credential handling | Never committed to source control. Passed through a channel you nominate; environment variables in deployment. |
| Access principle | Least privilege — I ask for the narrowest access that lets the work happen, and ask for it to be revoked at handover. |
| Device security | Full-disk encryption, screen lock, current OS and browser patching. |
| Multi-factor authentication | Enabled on every account used for client work. |
| This website | Zero cookies, zero third-party requests, static HTML, no user accounts and no stored personal data beyond enquiry emails. |
| Professional indemnity insurance | Not currently held. If your procurement process requires cover at a stated level, say so with the brief and I will confirm in writing whether I can meet it before you commit. |
| Certifications | None held — no ISO 27001, no Cyber Essentials. Stated plainly rather than implied, because it is the kind of claim procurement verifies. |
Business continuity, honestly stated
I am one person. The continuity risk of a solo supplier is real and it is not solved by a paragraph in a document, so it is managed structurally instead: your code lives in a repository you own, your hosting and domain are in your name, credentials are handed over as they are created rather than at the end, and every build ships with written handover documentation aimed at whoever maintains it next.
The test of that arrangement is simple, and you should apply it to any supplier: if I stopped replying tomorrow, could another developer pick this up? On my projects the answer is yes, deliberately.
Geographic and operational facts
- Operating from Islamabad, Pakistan (PKT (UTC+5))
- Markets served: United Kingdom, Canada, Ireland, Pakistan
- Service radius for in-person meetings: approximately 60 km from Islamabad
- Remote delivery for all other markets, with call windows held to suit your timezone
- Response time: within one business day
Procurement questions
- Are you a registered company?
- No. I operate as a sole trader based in Islamabad, Pakistan. Invoices are issued in my own name, numbered sequentially, and suitable for your bookkeeping. If your process requires an incorporated counterparty, tell me early — that is a legitimate constraint and it is better established before scoping than after.
- Can our legal team review your terms before we engage?
- Yes, and everything is already published: the DPA, the sub-processor list, the security statement and the accessibility statement are all readable without asking me for anything. That is deliberate — an offshore supplier who cannot produce these on request is the risk your process exists to catch.
- How do you handle our data during a project?
- By touching as little of it as possible. Where a build involves personal data I work against anonymised or sample data wherever it is technically sufficient, request production access only when it is genuinely required, and have it revoked at handover. The DPA sets this out formally.
- What happens to our data when the project ends?
- Client project data is deleted from my working environment within 30 days of final handover, other than what I am obliged to retain for tax records — which is correspondence and invoices, not your customer data. Confirmation in writing on request.
- Do you subcontract any of the work?
- No. Every project is delivered by me personally. If that ever changed for a specific engagement, you would be told before it happened and it would need your written agreement, because a supplier quietly subcontracting is exactly what your due diligence is protecting against.
- Will you complete our supplier onboarding questionnaire?
- Yes. Send it with the brief. Most of the answers are on this page already, which usually turns a three-week approval into a same-week one.
Need something specific for your supplier onboarding?
Send the questionnaire with your brief. Most of it is answered on this page, which usually turns a multi-week approval into a same-week one.
- Response
- Replies within 1 business day
- Hours
- Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
- Booking
- Booking projects from October 2026