PRIVACY POLICY
Valid as from, August 17th, 2026
INTRODUCTION: PRIVACY POLICY
This privacy policy (the “policy”) sets out how Programmers Force (hereinafter “PF” “we” or “us”) uses and protects your personal data. This privacy policy is provided in a layered format so you can click through to the specific areas set out below.
1. Important information and who we are
This Privacy Policy explains how PF collects, uses, and protects your personal data when you use our website. This includes any information you provide when you create an account, subscribe to our newsletter, or purchase products or services.
Our website and services are not intended for children, and we do not knowingly collect or process personal data relating to individuals under the age of 18. If we become aware that we have inadvertently collected personal data from a child under the applicable age limit, we will take immediate steps to delete such data from our systems.
Controller
We process personal data in accordance with applicable data protection laws, including the EU GDPR and UK GDPR. Where we act as a processor on behalf of a controller, we process personal data only on documented instructions and in line with the applicable agreement. We also comply with relevant U.S. data protection laws, including the CCPA, where applicable.
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing compliance with this Privacy Policy and applicable data protection laws. If you have any questions about this Policy or wish to exercise your legal rights, please contact us using the details provided below.
2. The types of personal data we collect about you
Personal data means any information relating to an individual from which that person can be identified, directly or indirectly.
We may collect, use, store, and transfer different categories of personal data, which we group as follows:
- Identity Data: first name, last name, username or similar identifier, title, date of birth, gender, and marital status.
- Technical Data: internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, platform, device identifiers, and other technology on the devices you use to access our website.
- Usage Data: information about how you interact with and use our website, products, and services.
- Marketing and Communications Data: your preferences in receiving marketing from us and third parties, and your communication preferences.
For example, we may combine Usage Data from multiple users to calculate the percentage of users accessing a particular feature. This helps us analyse trends, improve our website, and enhance our products and services.
3. How do we collect your personal data ?
We may also collect, use, and share account data from and about you including through:
Your interactions with us. You may give us your personal data by filling in online forms or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:
- apply for our products or services;
- create an account on our website;
- subscribe to our service or publications;
- request marketing to be sent to you;
- enter a competition, promotion or survey; or
- give us feedback or contact us.
Automated technologies or interactions. As you interact with our website, we will automatically collect technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive technical data about you if you visit other websites employing our cookies.
Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources.
Technical Data is collected from the following parties:
- analytics providers;
- advertising networks
- search information providers
Contact, Financial and Transaction Data is collected from providers of technical payment and delivery services.
Identity and Contact Data is collected from data brokers or aggregators.
4. How do we use your personal data?
Legal basis
The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:
- Performance of a contract with you: Where we need to perform the contract we are about to enter into or have entered into with you.
- Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and enable us to give you the best and most secure customer experience. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
- Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis.
- Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter.
Purposes for which we will use your personal data
We have set out below, in a table format, a description of all the ways we plan to use the various categories of your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.
Compliant privacy and security measures
For sensitive data, such as biometric information, explicit reference to the privacy and security measures in place to protect this data must be included, in accordance with applicable data protection regulations, such as the General Data Protection Regulation (GDPR) and ISO/IEC 27001. These measures include:
- Data Encryption: All sensitive personal data, including biometric data, will be encrypted both in transit and at rest using industry-standard encryption protocols to prevent unauthorized access.
- Access Control: Access to sensitive personal data will be restricted to authorized personnel only. This will be enforced through role-based access controls (RBAC), ensuring that only employees who need to access the data for legitimate business purposes will be granted access.
- Data Anonymization: Where possible, sensitive data will be anonymized to further protect user privacy. This ensures that data cannot be linked to an individual without additional information that is securely stored separately.
- Secure Data Storage: All data will be stored in secure, compliant environments with adequate physical and logical security measures. This includes using secure cloud services or on-premises storage systems that adhere to the highest industry standards.
- Data Minimization: Only the minimum necessary amount of personal data will be collected and retained. This is in line with the principles of data minimization under the GDPR.
- Audit Logs: All access to sensitive data will be logged and monitored to detect any unauthorized access attempts. These logs will be kept for a specified retention period and regularly reviewed to ensure compliance.
- Third-Party Contracts: If third-party vendors or subprocessors are involved in handling sensitive data, the company will ensure that they are contractually bound to comply with data protection requirements. This includes signing Data Processing Agreements (DPAs) that enforce security and privacy standards equivalent to those required by GDPR and ISO 27001.
These measures are designed to comply with the highest standards of privacy and security, ensuring that sensitive data, particularly biometric data, is adequately protected in accordance with GDPR, ISO 27001, and other relevant regulations.
| Purpose/Use | Type of data | Legal basis |
|---|---|---|
| To register you as a new customer | (a) Identity (b) Contact |
Performance of a contract with you to let you avail our services |
| To process and deliver your order including: (a) Manage payments, fees and charges (b) Collect and recover money owed to us |
(a) Identity (b) Contact (c) Financial (d) Transaction (e) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us) |
| To manage our relationship with you which will include: (a) Notifying you about changes to our terms or privacy policy (b) Dealing with your requests, complaints and queries |
(a) Identity (b) Contact (c) Profile (d) Marketing and Communications |
(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you) |
| To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) | (a) Identity (b) Contact (c) Technical |
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise) (b) Necessary to comply with a legal obligation |
| To deliver relevant website content and online advertisements to you and measure or understand the effectiveness of the advertising we serve to you | (a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical |
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy) |
| To use data analytics to improve our website, products/services, customer relationships and experiences and to measure the effectiveness of our communications and marketing | (a) Technical (b) Usage |
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy) |
| To send you relevant marketing communications and make personalised suggestions and recommendations to you about goods or services that may be of interest to you based on your profile data | (a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and Communications |
Necessary for our legitimate interests (to carry out direct marketing, develop our products/services and grow our business) or consent, having obtained your prior consent to receiving direct marketing communication. |
| To carry out market research through your voluntary participation in surveys | Necessary for our legitimate interests (to study how customers use our products/services and to help us improve and develop our products and services). |
Direct marketing
When your personal data is collected through our website, you will be given the option to indicate your preferences for receiving direct marketing communications from PF via email, text message, phone, or post.
We may also send you marketing communications if you have requested information from us or purchased our services, and you have not opted out of receiving such communications, where permitted by applicable law.
In addition, we may analyse your Identity, Contact, Technical, Usage, and Profile Data to better understand your preferences and interests, so that we can provide you with relevant and tailored marketing communications.
Third-party marketing
We do not share your personal data with third parties for their own direct marketing purposes without your prior express consent.
We may share your personal data with trusted third-party service providers where necessary to deliver our services, in accordance with applicable data protection laws and appropriate safeguards.
Consent mechanism and opt out
Users must be provided with an explicit opt-in mechanism for activities that require consent, particularly for marketing purposes or other data processing activities. The following requirements will be adhered to:
- Opt-In Consent: Users must provide explicit consent through an opt-in process. This means that users will actively indicate their agreement to data processing, such as checking an unchecked box or clicking an affirmative button, especially for marketing or non-essential data processing.
- No Pre-Ticked Boxes: Pre-ticked boxes will not be used for obtaining consent. The user must have the option to actively consent to the processing of their personal data.
- Granular Consent: Users will be given the option to choose which types of processing they consent to (e.g., for marketing, profiling, or analytics) rather than giving blanket consent for all activities.
- Clear and Accessible Information: Before obtaining consent, users will be provided with clear and concise information regarding the purposes for which their data will be used, how long it will be stored, and who will have access to it. This information will be easily accessible and transparent.
- Easy Withdrawal of Consent: Users will have the ability to easily withdraw their consent at any time. The process for withdrawing consent will be simple, and users will be provided with a clear option to do so, such as through their account settings or a direct communication channel (e.g., email or website form).
- Record of Consent: The organization will maintain a record of consent for all users who provide consent, including the date and time of consent, the specific activities the user consented to, and the method by which consent was obtained.
These measures ensure that consent is obtained and managed in a manner that complies with GDPR and other applicable data protection laws, giving users control over their personal data and processing activities.
5. Disclosures of your personal data
We may share your personal data where necessary with the parties set out below for the purposes set out in the table Purposes for which we will use your personal data above.
- Internal Third Parties
- External Third Parties
- Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. In the event of a sale, transfer, or merger of our business, the new owners may use your personal data in accordance with this Privacy Policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
6. International transfers
The personal data is transferred across international borders, ensuring compliance with relevant data protection laws such as the General Data Protection Regulation (GDPR) and other applicable regulations. Specifically, the policy should include the following measures to safeguard personal data during international transfers:
- International Transfers: Personal data may be transferred to countries outside the European Economic Area (EEA), the United States, or other jurisdictions. These transfers may occur when processing data through third-party service providers, cloud services, or other business partners.
- Safeguards for Transfers: Where personal data is transferred outside the EEA or other jurisdictions with adequate data protection laws, the company will implement one or more of the following safeguards:
- Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision by the European Commission, we will use Standard Contractual Clauses (SCCs), as approved by the European Commission, to ensure data protection standards are upheld.
- Binding Corporate Rules (BCRs): In cases where data is transferred within the same corporate group, Binding Corporate Rules (BCRs) will be used, ensuring that the data protection principles are followed across the group.
- Adequacy Decisions: For transfers to countries or regions that the European Commission recognizes as providing adequate protection for personal data (e.g., Switzerland, Canada, Japan), the company will ensure that these transfers meet the applicable requirements under the GDPR.
- Data Security Measures: All international data transfers will be protected by robust data security measures, such as encryption, anonymization, or pseudonymization, to ensure that data remains secure during the transfer process.
- Transparency and Communication: Users will be informed if their personal data is being transferred internationally, including details on the countries involved and the safeguards in place. This information will be included in the privacy policy or directly communicated to users when appropriate.
- Retention of Rights: Users will retain the right to access their personal data and exercise their rights under applicable laws, even after the data is transferred internationally.
These measures are implemented to ensure that personal data is handled in accordance with GDPR and other international data protection regulations, while maintaining the privacy and security of user data.
PF may share your personal data with authorised sub-contractors, which may involve transferring your data outside the PK to provide our services effectively while ensuring its protection.
Whenever your personal data is transferred internationally, we implement appropriate safeguards to ensure it receives a similar level of protection as within Pakistan.
7. Data security
We have established robust security measures to prevent accidental loss, unauthorised access, use, alteration, or disclosure of your personal data. Access is limited to employees, agents, contractors, and other third parties who need it to perform their duties. These parties process your personal data only under our instructions and are bound by confidentiality obligations.
We also maintain procedures to detect and respond to any suspected data breaches and will notify you and any relevant regulator if required by law.
8. Data retention
How long will you use my personal data for?
We only retain your personal data for six (6) months only. However, we may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
The company is committed to ensuring that personal data is not kept for longer than necessary and is processed in accordance with data protection laws. The following outlines our data retention practices, including the duration of data retention, the rationale for retention periods, and actions taken once data retention periods have expired.
- Rationale for Retention: Personal data is retained for the following purposes:
- To provide services and maintain business operations
- To comply with legal obligations, such as tax, accounting, and regulatory requirements
- To address any disputes or claims
- For statistical or historical purposes, where applicable and as permitted by law
- Expiry and Deletion: Once the retention period expires, personal data will either be:
- Anonymized, ensuring that it can no longer be linked to an identifiable individual; or
- Deleted, using secure methods to ensure that the data is permanently removed from our systems and backups.
- Exceptions to Deletion: There may be circumstances in which the company is required to retain personal data for a longer period than initially specified. These exceptions may include:
- Legal obligations: In some cases, the company may be required to retain personal data to comply with legal or regulatory obligations, such as tax laws, financial reporting, or anti-money laundering (AML) regulations.
- Contractual obligations: If the retention of personal data is necessary for the performance of a contract, it will be retained for as long as required to fulfill the contract terms.
- Litigation or disputes: Personal data may be retained for the duration of any legal dispute or investigation, or in anticipation of potential litigation.
- Review and Monitoring: The company will regularly review and update its data retention practices to ensure that personal data is only retained for the appropriate duration and is handled in compliance with applicable laws.
9. Your legal rights
You are provided certain rights under data protection laws in relation to your personal data.
You have the right to:
- You have the right to request access to the personal data we hold about you, commonly known as a “subject access request.” This allows you to receive a copy of your personal data and verify that we are processing it lawfully.
- You have the right to request correction of any personal data we hold about you. This allows you to have incomplete or inaccurate information updated, though we may need to verify the accuracy of the new data you provide.
- You have the right to request the erasure of your personal data in certain circumstances. This allows you to ask us to delete or remove data when there is no legitimate reason for us to continue processing it. You may also request erasure if you have successfully exercised your right to object to processing, if your data has been processed unlawfully, or if we are required to delete it to comply with applicable law. Please note that we may not always be able to fulfil your request for legal or regulatory reasons. In such cases, we will inform you at the time of your request.
- Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) as the legal basis for that particular use of your data (including carrying out profiling based on our legitimate interests). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
- You also have the absolute right to object any time to the processing of your personal data for direct marketing purposes (see OPTING OUT OF MARKETING in 4 for details of how to object to receiving direct marketing communications).
- Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your personal data (see the table in section 4 for details of when we rely on your consent as the legal basis for using your data). However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
- Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:
- If you want us to establish the data's accuracy;
- Where our use of the data is unlawful but you do not want us to erase it;
- Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or
- You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
If you wish to exercise any of the rights set out above, please contact us (see Contact details (9)
No fee usually required
You will not be required to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee or refuse to comply with requests that are clearly unfounded, repetitive, or excessive.
What we may need from you
To protect your personal data, we may need to ask you for specific information to verify your identity before fulfilling your request to access, correct, or erase your data, or to exercise any of your other rights. This helps ensure that personal data is not disclosed to anyone who is not entitled to receive it.
We may also contact you for additional information to help us process your request more efficiently.
Time limit to respond
We aim to respond to all legitimate requests within one (1) month. In some cases, such as when a request is complex or you have submitted multiple requests, it may take longer. If this occurs, we will inform you and keep you updated on the progress of your request.
10. Contact details & 11. Complaints
If you have any questions about this Privacy Policy, how we use your personal data, or if you wish to exercise your privacy rights, please contact __________________________
12. Changes to the privacy policy and your duty to inform us of changes
We regularly review and update our Privacy Policy to ensure it remains accurate and up to date.
It is important that the personal data we hold about you is correct and current. Please notify us of any changes to your personal information during your relationship with us, such as a new address or email.