Legal

Privacy Policy

We collect the minimum personal data we need, tell you exactly what we do with it, and never sell it. This policy sets out the detail required by the UK GDPR — including the lawful basis for every purpose, our retention periods, and how to exercise your rights.

In effect from Version 3.4

This Privacy Policy explains how Acceron Technologies (Private) Limited ("Acceron", "we", "us") collects, uses, shares and protects personal data. It covers visitors to acceron.com, people who enquire about our services, our clients and their nominated contacts, suppliers, and applicants for employment.

We are the data controller for the personal data described in this policy. We process personal data in accordance with Pakistani law, including the Prevention of Electronic Crimes Act 2016, and — because our clients expect an international standard of care — we hold ourselves to the standards of the UK and EU General Data Protection Regulation as a matter of policy, whether or not they apply to us by law.

Where we process personal data on behalf of a client as part of delivering our services, the client is the controller and we act as processor under a written data processing agreement. This policy does not govern that processing — the client's own privacy notice does.

Version 3.4. We will notify you of material changes by email where we hold your contact details, and in every case by updating the effective date above.

  1. 01Who we are — the data controller

    Acceron Technologies (Private) Limited is a private limited company incorporated in Pakistan under Securities and Exchange Commission of Pakistan (SECP) registration number 0184729, with its registered office at Building 35, Block L, Johar Town, Lahore, 54782, Pakistan.

    We have appointed a Data Protection Officer who is responsible for overseeing this policy and answering questions about it. You can contact the Data Protection Officer at [email protected], by telephone on +92 322 624 5527, or by writing to the Data Protection Officer at our registered office.

    We operate from a single delivery centre in Lahore, Pakistan. Personal data described in this policy is accessed by our personnel in Pakistan, subject to the safeguards described in the international transfers section below. Where we process personal data on behalf of a client, we work inside that client’s own cloud tenancy in the region they nominate.

  2. 02Personal data we collect

    1. 2.1 Information you give us

      When you complete our contact form, email us, telephone us or meet us, we collect your name, job title, employer, business email address, telephone number, city, the nature of your enquiry, the type of engagement you have in mind, your timeframe, and anything else you choose to tell us.

      If you become a client, we additionally collect billing contact details, purchase order references, authorised signatory details and the contact details of the personnel you nominate to work with us.

      If you apply for a role, we collect your CV, work history, qualifications, right-to-work information, references and interview notes. Recruitment data is covered by a separate candidate privacy notice provided at the point of application.

    2. 2.2 Information we collect automatically

      When you visit acceron.com we collect the pages you view, the approximate region derived from your IP address, the referring website, your device type, browser and operating system, and the date and time of your visit. This is collected by our own first-party analytics — we do not use Google Analytics or any advertising network.

      Our servers record your IP address in access logs for security and abuse prevention, including rate-limiting the contact form. These logs are retained for 30 days.

      We do not use cookies for advertising, profiling or cross-site tracking, and we do not sell or share personal data with data brokers.

    3. 2.3 Information from other sources

      We may collect business contact information from publicly available sources such as your company website, a public company register, LinkedIn or a conference attendee list, where we have a legitimate interest in contacting you about services relevant to your professional role.

      Where a client introduces us to a colleague or partner organisation, we receive that person's business contact details from the client. We will identify the source if you ask us.

    4. 2.4 Special category data

      We do not seek to collect special category personal data — such as data revealing health, religious belief, political opinion or ethnicity — from website visitors or enquirers. Please do not include such information in an enquiry form.

      Where we hold special category data about our own personnel, for example health information supporting a workplace adjustment, we process it only where employment law requires or permits it, and in accordance with our internal HR privacy notice.

  3. 03Purposes of processing

    We use personal data for the following purposes, and no others:

    • Responding to your enquiry, preparing a proposal or quotation, and arranging and holding meetings.
    • Providing the services set out in a contract, including project delivery, managed support, incident response and service reporting.
    • Managing our client relationship, including account management, service reviews and gathering feedback.
    • Invoicing, collecting payment, credit control and maintaining accounting records.
    • Sending you engineering and technology insights by email, where you have opted in or where you are an existing client and have not objected.
    • Improving our website and services by understanding, in aggregate, which content visitors find useful.
    • Protecting our systems and yours, including detecting and preventing fraud, abuse and security incidents.
    • Complying with our legal and regulatory obligations, including tax, anti-money-laundering, anti-bribery and health and safety requirements.
    • Establishing, exercising or defending legal claims, and responding to regulatory enquiries.
    • Recruiting and assessing candidates for employment.
  4. 05Cookies and similar technologies

    We use the minimum number of cookies necessary to make the website work. We do not use advertising cookies, tracking pixels, social media plug-ins or fingerprinting.

    Strictly necessary cookies are set without consent because the site cannot function without them. They are: a session cookie that maintains security when you submit the contact form, and a preference cookie recording your light or dark colour scheme choice. The preference cookie expires after 12 months; the session cookie expires when you close your browser.

    We use first-party, cookieless analytics that aggregates page views without assigning a persistent identifier to you.

    Because we set no non-essential cookies, we do not display a consent banner. If that changes, we will ask for your consent before setting any such cookie, and you will be able to decline without losing access to any part of the site.

    You can block or delete cookies through your browser settings. Blocking the strictly necessary cookies may prevent the contact form from working.

  5. 06Analytics and website measurement

    Our website analytics are provided by a self-hosted, privacy-preserving platform operating within our own infrastructure in Pakistan. It records page URL, referrer, approximate location, device class and timestamp.

    It does not set a tracking cookie, does not collect a device fingerprint, does not track you across other websites, and does not build a profile of you. IP addresses are truncated before storage and are not retained in analytics records.

    Aggregated analytics data is retained for 26 months and is used only to understand which pages are useful and where the site performs poorly.

  6. 07Third parties and sub-processors

    We share personal data only where necessary, and only with organisations that are contractually bound to protect it. We never sell personal data.

    The categories of recipient are:

    • Cloud infrastructure and hosting providers, who store data in the region you or your contract specifies.
    • Email and collaboration providers, used for correspondence and document sharing.
    • A transactional email provider, used to deliver enquiry notifications and service alerts.
    • Accounting, invoicing and payment providers, for billing and financial records.
    • Professional advisers — legal, accounting, insurance and audit — where they need the information to advise us.
    • Approved sub-processors named in your data processing agreement, where we act as processor for a client.
    • Regulators, law enforcement and courts, where we are legally required to disclose.
    • A purchaser or successor of our business, in the event of a merger, acquisition or reorganisation, subject to equivalent protections.
  7. 08Marketing communications

    If you opt in, we send approximately one email a month containing engineering and technology insights. We do not sell or rent our mailing list, and we do not send third-party advertising.

    Where you are an existing client or have previously enquired about a similar service, we may send you relevant information about our services on the basis of our legitimate interest in that existing business relationship. You may object at any time and we will stop.

    Every marketing email contains a one-click unsubscribe link that takes effect immediately and without requiring you to log in or explain. You may also email us to object.

    Unsubscribing from marketing does not stop service and administrative messages relating to a contract you hold with us — for example incident notifications, invoices or changes to these policies.

    We keep a suppression record of unsubscribed addresses indefinitely, because that is the only way to ensure we do not contact you again.

  8. 09Data retention

    We keep personal data only for as long as we need it, then delete or anonymise it. Our retention schedule is:

    • Enquiries that do not lead to a contract — 24 months from the last contact, then deleted.
    • Client contract records, statements of work and correspondence — 7 years after the end of the contract, to support warranty, tax and limitation-period requirements.
    • Accounting and invoicing records — 6 years from the end of the relevant tax year, as required by the Companies Act 2017 and the Income Tax Ordinance 2001.
    • Client personal data processed as part of a delivered service — for the period specified in the applicable data processing agreement, and returned or securely destroyed within 30 days of the end of that period.
    • Marketing subscription records — until you unsubscribe, plus 24 months. Suppression records are kept indefinitely.
    • Website access logs — 30 days.
    • Aggregated analytics — 26 months.
    • Unsuccessful job applications — 12 months, unless you consent to us keeping your details longer.
    • Security incident and audit records — 6 years, to demonstrate compliance and support any investigation.
  9. 10International transfers

    We are based in Pakistan and serve clients across Pakistan. Personal data described in this policy is held on cloud infrastructure in Pakistan and accessed by our personnel in Pakistan.

    For clients, the region in which data is stored is a contractual commitment. You choose it, and we will not move your data to another region without your prior written agreement.

    Pakistan is not currently the subject of a UK or EU adequacy decision. We therefore do not rely on adequacy, and instead put appropriate safeguards in place for every transfer.

    Where personal data originating in the United Kingdom or European Union is accessed from Pakistan, we contract on the EU Standard Contractual Clauses or the UK International Data Transfer Addendum as applicable, supported by a documented transfer risk assessment. Supplementary measures include encryption in transit and at rest with keys held in your own region, access limited to named and background-checked personnel, time-boxed and logged production access, and pseudonymised data wherever the task allows.

    Copies of the transfer mechanisms we rely on are available on request, subject to redaction of commercially confidential terms.

  10. 11Your rights

    Under data protection law you have the following rights. We will not charge you for exercising them, and we will not treat you differently for having done so.

    • Right of access — to be told whether we hold personal data about you and to receive a copy of it, together with information about how we use it.
    • Right to rectification — to have inaccurate personal data corrected and incomplete data completed.
    • Right to erasure — to have personal data deleted where we no longer have a lawful reason to keep it. This does not override our legal obligation to retain accounting records.
    • Right to restrict processing — to have us pause processing while a dispute about accuracy or lawfulness is resolved.
    • Right to data portability — to receive personal data you provided to us, in a structured, commonly used and machine-readable format, where processing is based on consent or contract.
    • Right to object — to object to processing based on legitimate interests, and an absolute right to object to direct marketing, which we will always honour.
    • Right to withdraw consent — at any time, where we rely on consent.
    • Rights relating to automated decision-making — we do not make decisions about you by solely automated means that have legal or similarly significant effects, and we do not carry out profiling for marketing purposes.
  11. 12How to exercise your rights

    Send your request to [email protected], or write to the Data Protection Officer at Acceron Technologies (Private) Limited, Building 35, Block L, Johar Town, Lahore, 54782, Pakistan. You do not need to use a particular form of words.

    We will acknowledge your request within 5 working days and respond substantively within one calendar month. If your request is complex or you have made several requests, we may extend that period by up to two further months, and we will tell you why within the first month.

    We may ask you for information to confirm your identity before we disclose personal data, which is a safeguard for your benefit. We will only ask for what is proportionate.

    If we cannot act on your request, we will explain why and tell you how to complain.

  12. 13Security measures

    We hold ISO/IEC 27001:2022 certification and a current SOC 2 Type II attestation. Our information security management system covers all delivery and managed service operations, and is audited annually by an accredited third party.

    The technical and organisational measures we apply include:

    • Encryption of personal data in transit using TLS 1.3, and at rest using AES-256.
    • Multi-factor authentication on every system that can access client data, with phishing-resistant methods for privileged accounts.
    • Role-based access control on a least-privilege basis, with access reviewed quarterly and revoked on the day a person changes role or leaves.
    • Segregated environments, so production data is never used in development or testing without pseudonymisation.
    • Secrets held in a managed vault, never in source code, with automated scanning to detect accidental commits.
    • Continuous vulnerability scanning of dependencies, containers and cloud configuration, with defined remediation windows by severity.
    • Annual independent penetration testing of our own systems, plus quarterly testing for clients on our Scale and Enterprise plans.
    • Centralised, tamper-evident audit logging, with alerting on privileged and anomalous activity.
    • Documented and rehearsed incident response, with tabletop exercises at least twice a year.
    • Background screening of all personnel with access to client environments, and mandatory annual data protection and security training completed by 100% of staff.
  13. 14Personal data breaches

    We maintain a documented incident response process covering detection, containment, assessment, notification and post-incident review.

    Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where we are the controller, you directly — without undue delay and in any event within 72 hours of becoming aware of it.

    Where we act as processor for a client, we notify that client within 24 hours of becoming aware of a breach — well inside the 72 hours their own regulator allows them — so they have time to meet their obligation.

    In twelve years of operation and across more than 320 delivered platforms, we have had no personal data breach requiring notification to a supervisory authority.

  14. 15Children

    Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 18.

    If you believe a child has provided us with personal data, please contact our Data Protection Officer and we will delete it.

  15. 16Complaints and supervisory authorities

    If you are unhappy with how we have handled your personal data or a request, please tell us first at [email protected]. Our Data Protection Officer will investigate and respond within 20 working days. Most concerns are resolved at this stage.

    You also have the right to complain to the data protection supervisory authority in your own country at any time, without contacting us first. Which authority that is depends on where you live or work.

    If you are in the United Kingdom, that is the Information Commissioner’s Office (ico.org.uk/make-a-complaint). If you are in the European Economic Area, it is the authority for your country of residence or place of work. If you are in Pakistan, complaints about the misuse of personal data may be made to the Federal Investigation Agency Cybercrime Wing under the Prevention of Electronic Crimes Act 2016.

    Where we act as processor for a client, complaints about that processing are normally handled by the client as controller. We will cooperate fully with any resulting investigation and will not obstruct or delay it.

    Complaining to a supervisory authority does not affect any other legal remedy available to you, including the right to seek compensation through the courts.

  16. 17Changes to this policy

    We review this policy at least annually and whenever our processing changes materially.

    Where a change materially affects how we use your personal data, we will notify you by email if we hold your address, and we will always update the version number and effective date at the top of this page.

    Previous versions are retained for seven years and are available on request.

  17. 18How to contact us

    Data Protection Officer, Acceron Technologies (Private) Limited, Building 35, Block L, Johar Town, Lahore, 54782, Pakistan.

    Email: [email protected]. Telephone: +92 322 624 5527. Business hours: Monday to Friday, 09:00 – 18:00 (PKT, UTC+5).

    The same address handles general enquiries, data protection requests and matters relating to our Terms and Conditions; messages are routed internally within one business hour.

    Securities and Exchange Commission of Pakistan (SECP) registration number: 0184729. National Tax Number: 7429183-6. Pakistan Software Export Board registration: PSEB/IT/2014/04831.

Company and contact details

Registered company
Acceron Technologies (Private) Limited
Company number
0184729 (Securities and Exchange Commission of Pakistan (SECP))
National Tax Number
7429183-6
PSEB registration
PSEB/IT/2014/04831
Registered office
Acceron Technologies (Private) Limited, Building 35, Block L, Johar Town, Lahore 54782, Pakistan
General enquiries
[email protected]
Legal notices and data protection
[email protected]
Business hours
Monday to Friday, 09:00 – 18:00 (PKT, UTC+5). Saturday, 10:00 – 14:00 (PKT) — enquiries and priority triage. Managed Support clients: 24 hours a day, 365 days a year for Managed Support clients.

All charges referred to in this document are stated in Pakistani Rupees (PKR) and are exclusive of sales tax on services, withholding tax and any other levy, unless expressly stated otherwise.