What we collect, why we collect it, and the control you keep over it. Written to be read, not to be skimmed past.
Ecomsy (SMC-PRIVATE) LIMITED is the controller of the personal data described here. We built our data practices around four commitments rather than the legal minimum.
If we do not need a piece of information to do the job, we do not ask for it. Our forms are deliberately short and every optional field is marked as optional.
Your information is not sold, rented, traded or handed to data brokers. It is not a product line for us and never will be.
No dense legal walls designed to be abandoned halfway. If a practice cannot be explained simply, we treat that as a sign the practice needs rethinking.
You can ask what we hold, request a copy, correct it or have it deleted. One email is enough, and we do not make you justify the request.
Everything below comes from one of three places: you give it to us, our systems record it automatically, or a service we use passes it on.
Our services are intended for adults and for businesses. We do not knowingly collect personal data from children under 16. If you believe a child has provided us information, contact us and we will delete it promptly.
Every purpose below has a lawful basis behind it. We do not repurpose data for something you would not reasonably expect.
| Purpose | What it involves | Lawful basis |
|---|---|---|
| Responding to enquiries | Replying to your message, preparing a quote and discussing your project. | Steps before a contract |
| Delivering projects | Building, testing and supporting the work you engaged us for. | Performance of a contract |
| Billing and records | Issuing invoices, processing payments and meeting accounting obligations. | Contract and legal obligation |
| Support and tickets | Handling live chat, tickets and follow-up so issues are traceable. | Legitimate interests |
| Improving the site | Understanding which pages help visitors and where the site falls short. | Legitimate interests or consent |
| Security | Detecting abuse, preventing fraud and protecting accounts and infrastructure. | Legitimate interests |
| Marketing updates | Occasional emails about services or offers, only if you opted in. | Consent |
Enquiries that do not become projects are kept for up to 24 months in case you return. Project and billing records are retained for the period required by tax and company law, typically several years. Support conversations are kept while they remain useful for context, and applications are kept for up to 12 months unless you ask us to remove them sooner.
Security is layered rather than a single measure. These are the practical protections behind our site and systems.
The entire site runs over HTTPS, so information you submit is encrypted between your browser and our servers rather than travelling in the clear.
Internal systems sit behind authenticated accounts with role-based permissions, so team members only reach the data their job requires.
Payments are handled entirely by Stripe. Because card details are captured on their infrastructure, a breach of our systems could not expose them.
Security headers, a content security policy, rate limiting and spam protection reduce the attack surface of the public site and its forms.
Documents uploaded through our systems are stored outside public reach and served only to authenticated users, never through a guessable public link.
No system on the internet is perfectly secure, and any company claiming otherwise is overselling. What we can commit to is using appropriate safeguards, keeping them current, and telling you promptly if a breach ever affects your data rather than quietly hoping it goes unnoticed.
These rights apply regardless of where you are. You do not need to give a reason, and exercising them costs nothing.
Ask what personal data we hold about you and receive a copy of it.
Have inaccurate or incomplete information about you corrected.
Ask us to erase your data where we have no ongoing legal or contractual need to keep it.
Object to processing based on legitimate interests, including any direct marketing.
Ask us to pause processing while a concern or dispute is being resolved.
Receive the data you gave us in a common, machine-readable format.
Email info@ecomsy.com.pk with what you would like. We aim to respond within 30 days and will confirm your identity first, so that nobody else can request your data by pretending to be you. Marketing emails also carry an unsubscribe link in every message, which takes effect immediately.
The things people most often want to know before sharing their details with us.
No. We do not sell, rent or trade personal data, and we do not pass it to data brokers or advertising networks for their own use. The only organisations that touch your data are the service providers we use to run the business, such as our host and Stripe, and they act on our instructions.
No, and this is deliberate. When you pay an invoice you are redirected to Stripe's own secure checkout, where the card details are entered. Those details never pass through or rest on our servers, so we only ever see confirmation that a payment succeeded and the amount.
Your chat is visible to our support team so they can help you, and it is processed by Anthropic's Claude to generate replies. It is not published or shared beyond that. As with any chat, please do not send passwords, card numbers or sensitive personal information.
Email info@ecomsy.com.pk and ask. We will verify who you are, then delete what we are not legally required to keep. Some records, particularly invoices and accounting entries, must be retained for a period set by tax law, and we will tell you clearly if that applies to anything in your request.
Only if you opted in. Requesting a quote gets you replies about that enquiry, not a newsletter subscription. If you do opt in, every message carries an unsubscribe link that works immediately.
We keep enquiries for up to 24 months, because people often return months later and it helps to have the earlier context. After that it is removed, and you can ask us to delete it sooner at any point.
Primarily on our hosting infrastructure, with some data processed by providers who operate internationally, such as our payment processor and AI provider. Where data crosses borders, we rely on providers who commit to recognised safeguards for the information they handle for us.
We update this page when our practices change and revise the date shown here. Material changes will be highlighted on the site rather than slipped in quietly. Questions or concerns can go to info@ecomsy.com.pk, and we would genuinely rather hear from you than have you assume the worst.