Privacy Policy

Last updated: 2 August 2026

This Privacy Policy describes how your personal information is collected, used, disclosed, stored, and protected when you visit, register with, use, or make a purchase through www.complyencrypt.com (the "Site").

This Privacy Policy has been prepared in accordance with the European Union General Data Protection Regulation (EU) 2016/679 ("GDPR"), together with other applicable data protection laws.

1. Data Controller

For the purposes of the GDPR, ComplyEncrypt is the Data Controller responsible for processing your Personal Data.

If you have any questions regarding this Privacy Policy or wish to exercise your privacy rights, contact us at:

  • Email: info@complyencrypt.com
  • Postal Address: National Incubation Center, NED University, Karachi, Sindh 75270, Pakistan

2. Personal Information We Collect

When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies installed on your device.

Device & Automated Information

As you browse the Site, we collect information about:

  • Pages viewed and products viewed
  • Referring websites and search terms
  • User interactions with the Site, device type, and operating system

We collect Device Information using technologies such as cookies, log files, web beacons, tags, and pixels.

Additional Categories of Personal Data

We may also collect:

  • Identity & Contact Details: Name, email address, telephone number, billing address, delivery/shipping address, and country.
  • Financial & Transaction Information: Payment details, invoice information, and transaction history. Payment card details are processed securely by our third-party payment service providers. ComplyEncrypt does not store complete payment card information on its own systems unless specifically required for legal or accounting purposes.
  • Communication Data: Communication records, customer support correspondence, and verification information voluntarily supplied by users.

3. Cookies and Similar Technologies

The Site uses cookies and similar technologies to:

  • Remember user preferences
  • Improve website performance and functionality
  • Analyse website traffic and user engagement
  • Enhance user experience
  • Measure marketing effectiveness

Cookies generally do not contain information that directly identifies an individual. Users may control cookie preferences through browser settings or the cookie consent banner where applicable.

4. Legal Basis for Processing

Where required by the GDPR, ComplyEncrypt processes Personal Data under one or more of the following legal bases:

Legal BasisGDPR ArticleDescription / Examples
ConsentArticle 6(1)(a)Marketing communications, newsletters, optional analytics.
Performance of a ContractArticle 6(1)(b)Order processing, billing, service provision, customer support.
Compliance with Legal ObligationsArticle 6(1)(c)Tax compliance, accounting obligations, statutory requirements.
Legitimate InterestsArticle 6(1)(f)Fraud prevention, network security, service optimization, business analytics.

Whenever Legitimate Interests are relied upon, ComplyEncrypt ensures that such interests do not override the fundamental rights and freedoms of data subjects.

5. How We Use Personal Information

We use Personal Information to:

  • Process purchases, subscriptions, and transactions
  • Deliver products, encryption services, and digital tools
  • Arrange shipping, provide invoices, and communicate regarding orders
  • Respond to customer support enquiries
  • Detect fraud and prevent abuse
  • Improve website functionality and analyze usage
  • Comply with legal obligations
  • Send marketing emails, product updates, and promotional offers (where consent is provided)

6. Sharing Personal Information

We may share Personal Information with trusted third-party service providers who process data on our behalf, including:

  • Website hosting and cloud infrastructure providers
  • Email and customer support service providers
  • Analytics providers (e.g., Google Analytics)
  • Payment processors (e.g., Stripe Payments)
  • Marketing service providers

Payment Processors

Where payments are processed through Stripe or other payment processors, payment information is collected and processed directly by the provider acting as an independent data controller. Users are encouraged to review their respective privacy policies.

7. International Transfers

Personal Data may be transferred outside the European Economic Area ("EEA"). Where such transfers occur, ComplyEncrypt ensures appropriate safeguards are implemented, including:

  • European Commission Adequacy Decisions
  • Standard Contractual Clauses (SCCs)
  • Other lawful transfer mechanisms recognized under the GDPR

8. Data Retention

Personal Data is retained only for as long as necessary to fulfil the purposes described in this Privacy Policy. Certain information may be retained after service termination where required by tax laws, accounting regulations, contractual obligations, legal proceedings, or fraud prevention. Once retention periods expire, Personal Data will be securely deleted or anonymized.

9. Your GDPR Rights

If you are located within the European Economic Area, you have the following rights under the GDPR:

  • Right to be Informed: Clear, transparent information about processing.
  • Right of Access: Request copies of your personal data.
  • Right to Rectification: Request correction of inaccurate information.
  • Right to Erasure ("Right to be Forgotten"): Request deletion under certain conditions.
  • Right to Restrict Processing: Limit how your data is used.
  • Right to Data Portability: Obtain and transfer your personal data.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time.

Requests may be submitted through our Data Subject Access Request form or by email to info@complyencrypt.com. ComplyEncrypt will respond within one month of receipt of a valid request, extendable by up to two additional months for particularly complex requests.

10. Security

ComplyEncrypt implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Access to Personal Data is limited to authorized personnel subject to strict confidentiality obligations.

11. Children's Privacy

The Site is not intended for children under the age of 13 years (or older where specified by local law), nor for individuals who lack legal capacity. We do not knowingly collect Personal Data from children.

12. User Responsibilities & Complaints

Users agree not to use the Site for unlawful purposes. If you believe your Personal Data has been processed unlawfully, you have the right to lodge a complaint with your local supervisory authority in your EU Member State.

13. Contact Us

For questions regarding this Privacy Policy or to exercise your GDPR rights, please contact:

  • Title: Data Protection Officer, ComplyEncrypt
  • Email: info@complyencrypt.com
  • Postal Address: National Incubation Center, NED University, Karachi, Sindh 75270, Pakistan