SmartLink
  • Home
  • Privacy Policy
Legal

Privacy Policy

How SmartLink Services collects, uses, shares and protects personal information, both on this website and in the course of delivering client work.

In short

What this policy is for.

This policy explains what personal information we hold, why we hold it, who we share it with and what you can ask us to do about it. It covers two different situations that are worth separating.

The first is this website. If you browse the site, fill in a form or accept cookies, that is covered below under website data.

The second is client work. When we implement or support a system, we frequently process personal data that belongs to our client rather than to us, such as employee or customer records inside an ERP. In that situation the client decides why the data is processed and we act on their instructions. That relationship is governed by the contract and, where relevant, a data processing agreement, and this policy does not replace either.

01

Who we are and how to reach us

SmartLink Services is an enterprise software delivery firm based in Karachi, Pakistan. We design, build, migrate, integrate and support business systems for organisations in Pakistan and internationally.

For anything relating to this policy, including access requests, corrections, deletion requests and complaints, use the contact details published on our contact page. A person handles these rather than an automated queue.

If you are contacting us on behalf of an organisation we already work with, mentioning the engagement helps us route the request to the right team quickly.

  • Written enquiries are answered by a person
  • Use the contact page for data requests
  • Name the engagement if you are an existing client
02

Information we collect through this website

When you submit a form we collect what you type into it, which is normally your name, organisation, email address, phone number and the description of what you need. We collect this because you asked us to contact you, and we use it for that purpose.

We also collect limited technical information automatically, such as pages viewed, approximate location derived from your IP address, referring site, and browser and device type. This is used to understand which pages are useful and to keep the site working.

We do not ask for payment card details on this website, and we do not collect special category data such as health or biometric information through it. If a form ever appears to ask you for either, do not complete it and tell us.

  • Form submissions: what you type, used to reply to you
  • Analytics: pages, approximate location, device and referrer
  • No card details are collected on this site
  • No special category data is requested
03

Why we process it

Enquiry data is processed so that we can respond to you and, if it goes further, prepare a proposal. That is either your consent or the steps taken at your request before entering a contract.

Analytics data is processed to improve the site. Where consent is required for the cookies that enable it, we ask for that consent through the cookie banner and you can withdraw it at any time.

Where we hold information because we have to, such as records supporting invoices and tax filings, the basis is our legal obligation. We do not use enquiry data to build profiles for advertising, and we do not sell it.

  • Enquiries: to respond and to prepare proposals
  • Analytics: to improve the site, with consent where required
  • Accounting records: retained to meet legal obligations
  • We do not sell personal information
04

Data we handle inside client systems

A large part of our work involves systems that contain other people's personal data. During an implementation, a migration or a support call, our engineers may need access to production data or a copy of it.

We work to the principle of least access. People get the access the task requires and no more, access is time bound where practical, and privileged actions are logged. Where a copy of production data is needed for testing, we prefer masked or reduced data sets and will say so in the plan.

For engagements involving protected health information under HIPAA, we operate under a business associate agreement and apply access controls, encryption in transit and at rest, and audit logging accordingly.

  • Least access, time bound where practical
  • Privileged actions are logged
  • Masked or reduced data preferred for test environments
  • Business associate agreement where HIPAA applies
05

Who we share information with

We share personal information with service providers who help us operate, such as hosting, email, analytics and customer relationship tools. They act on our instructions and are bound by contract.

We share information with professional advisers, such as accountants and lawyers, where that is necessary, and with authorities where we are legally required to.

We do not sell personal information, and we do not share client data between clients. Where a subcontractor is involved in delivery, this is disclosed to the client and covered by the same obligations we accept ourselves.

  • Service providers, under contract and on our instructions
  • Professional advisers where necessary
  • Authorities where legally required
  • Never sold, never shared between clients
06

International transfers

We are based in Pakistan and work with clients in several countries, so information may be transferred across borders. Where a client requires data to remain in a particular country, that is treated as a design constraint and reflected in the architecture and the hosting choice.

Where transfers of personal data are subject to specific legal safeguards under our client's jurisdiction, those safeguards are put in place contractually before the transfer happens.

If data residency matters to you, raise it early. It is much easier to design for than to retrofit.

  • Data residency treated as a design constraint
  • Contractual safeguards agreed before transfer
  • Raise residency requirements during discovery
07

How long we keep it

Enquiries that do not lead to work are kept for a limited period so we can pick up the thread if you come back, then deleted.

Client records are kept for the life of the relationship and afterwards for as long as we need them for contractual, accounting, tax and legal purposes.

Access to client production data is removed at the end of an engagement as part of the handover checklist, and any working copies we hold are deleted. If you want written confirmation of that, ask and we will provide it.

  • Unsuccessful enquiries deleted after a limited period
  • Client records kept while legally and contractually required
  • Access removed at handover as a checklist item
  • Written confirmation of deletion on request
08

Your rights

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to restrict how we use it, and object to particular uses. Where we rely on consent, you can withdraw it at any time.

We will confirm your identity before acting on a request, because acting on an unverified request is itself a risk to you.

If we process your data on behalf of one of our clients, the right route is usually to contact that client, since they decide what happens to it. We will help them respond and will tell you who to approach.

  • Access, correction, deletion, restriction and objection
  • Consent can be withdrawn at any time
  • Identity confirmed before a request is actioned
  • Requests about client systems are routed to the client
09

Security

We apply access control by role, multi factor authentication on administrative accounts, encryption in transit and at rest for the systems we run, logging of privileged actions, and separation between development, testing and production environments.

No system is perfectly secure, and we will not claim otherwise. What we can commit to is that controls are designed in rather than added afterwards, and that if something goes wrong we tell the affected parties promptly rather than quietly.

If you believe you have found a vulnerability in this website or in something we built, contact us and we will look into it. Reports made in good faith are welcome.

  • Role based access and multi factor authentication
  • Encryption in transit and at rest
  • Environments separated, privileged actions logged
  • Good faith vulnerability reports are welcome
10

Changes to this policy

We update this policy when what we do changes, or when we find a section that is not clear enough. The current version is always the one published here.

Material changes will be reflected on this page rather than communicated only by email, so this page is the reliable source.

If a change affects an existing engagement, it is handled through the contract rather than by updating a web page.

  • This page is the current version
  • Material changes are published here
  • Contractual changes go through the contract
Contact

Questions about this policy.

If anything here is unclear, or you want to exercise a right described on this page, write to us and we will respond. Contact details are on the contact page and in the footer of every page on this site.

This version is current as of September 2026.

Need to reach a person about this?

Policy questions, data requests and complaints all go to the same place, and a person reads them.