ProgrammXTransforming Ideas Into Reality
What we doHow we workOur workWhy us

On this page

Who we areWhat this notice coversIf you visit programmx.comIf we contacted youClients & prospectsData we handle for clientsJob applicantsSuppliersWho else sees your dataWhere your data is heldYour rightsIf you are unhappyChanges to this notice

Legal

Privacy Notice

Updated 4 August 2026

This notice explains what personal data ProgrammX holds, why we hold it, how long we keep it, and what you can ask us to do about it. It is written to be read, not to protect us. If anything here is unclear, email us and we will explain it in plain terms.

Who we are

ProgrammX Technologies (SMC-Private) Limited trades as ProgrammX. We build software, automation and blockchain systems for businesses.

Registered address: Plaza 49, Umar Commercial, Bahria Town, Lahore, Pakistan.

For anything in this notice, including any request about your data: hello@programmx.com

We are the data controller for the personal data described below, which means we decide why and how it is used. The one exception is data we handle on a client's instructions, which has its own section.

What this notice covers

Six groups of people, and you may fall into more than one: people who visit programmx.com, business contacts we approach about our services, clients and prospective clients, people whose data we handle on a client's behalf, job applicants, and suppliers.

If you visit programmx.com

How we measure usage.

We use Umami, an analytics tool we run on our own server rather than a service that collects data on our behalf. It sets no cookies and it does not follow you to other websites. It records the page you viewed, the site that referred you, your browser and device type, and your country.

Umami does not store your IP address. It combines your address with your browser details into a scrambled identifier that changes every day, then discards the address itself. We can count a visit. We cannot trace it back to you, and we cannot connect today's visit to yesterday's.

We do this to understand which pages are useful, on the basis of our legitimate interests in running a site that does its job. There is no advertising, no profiling, and nothing sold or shared with ad networks. We keep these usage records for 12 months. Our cookie and analytics statement at programmx.com/cookies has the detail.

Server logs.

Separately from analytics, the web server writes an access log, as web server software does by default. That log records IP addresses. We keep it so that it is there if we need to diagnose a fault or look into misuse of the site, on the basis of our legitimate interests in keeping the site working and secure. It is not used for analytics or for anything else, and it is deleted after 30 days, including any compressed copies.

There is no contact form on this site.

There is nothing here for you to fill in, and the site does not receive or store anything you type. The email addresses on it are ordinary links: selecting one asks your device to open your usual email program with a message already addressed to us, which you write and send yourself. Nothing reaches us until you send it, and it travels through your own email provider rather than through this website.

If you email us.

We keep what you send and our correspondence about it. We use it to reply and, if the enquiry goes further, to quote for the work. The basis is our legitimate interests in answering people who get in touch and, once you ask us to quote, steps taken at your request before entering a contract. Nothing you send is required by law, and you decide what goes in the message. We keep enquiries that do not turn into projects for 24 months from our last contact, then delete them.

If you book a call.

Our booking is handled by Cal.com. It asks for your name and your email address, and we ask how you originally heard about us. We use the first two to arrange and hold the meeting, on the basis of steps taken at your request before entering a contract, and we cannot hold a meeting without them. We use the third to understand which of our own activities actually reach people, on the basis of our legitimate interests in knowing how we are found; that one is optional and you can leave it blank, and it makes no difference to your booking. Cal.com holds the booking on its own systems in the United States or the European Union. We keep booking records for 24 months.

If we contacted you about our services

We approach businesses that we think have a use for what we build. If you received an email from us out of the blue, this section explains where your details came from.

What we hold.

Your name, your work email address, your job title, the company you work for and its size and country, the public web address of your professional profile, a record of any correspondence between us, and the technical record of whether our email was delivered, bounced or was reported as spam.

Where we got it.

Your name, role and employer come from your public professional profile, in most cases LinkedIn or LinkedIn Sales Navigator. Your work email address was found and checked using two services we subscribe to, Findymail and MillionVerifier. We only ever use business email addresses at company domains. We do not use personal or free email accounts, and we do not buy consumer data.

Why we are allowed to.

We rely on legitimate interests: introducing our services to businesses likely to have a use for them. Before we started sending to the United Kingdom we wrote a legitimate interests assessment weighing our interest against your privacy, dated 29 July 2026 and reviewed at least every six months and on any complaint. You can ask us for a summary of it and we will send it to you.

What we do not do.

We do not sell your details, and we do not share them with anyone for their own purposes. We do use the service providers described further down, who handle data only on our instructions.

How long we keep it.

If you do not reply, we delete your record within 12 months of first contacting you. If you do reply but nothing comes of it, we keep the correspondence for 24 months from our last contact and then delete it. If you tell us to stop, we keep the bare minimum — your email address on a suppression list — permanently, and for one reason only: so that no future campaign of ours can reach you again. That record exists to honour your objection, not to market to you.

Saying no.

You have an absolute right to object to direct marketing. There is no balancing test and we do not get to argue. If you reply to one of our emails asking us to stop, we action it the same working day. By any other route, including hello@programmx.com, within one week.

If you are a client or a prospective client

We hold the contact details of the people we work with, our correspondence, the contract, project records, and billing records. We use this to quote for work, to do it, to invoice for it, and to keep the accounting records the law requires. The basis is our contract with you or steps taken at your request before entering into one, our legitimate interests in running the relationship, and our legal obligations for tax and company records.

If you are engaging us, some of this data we have to have — we cannot contract with a company without a named contact and billing details, and we cannot invoice without them. Beyond that we do not require anything at the point of engagement. Once a project is running we necessarily hold the correspondence and the project records that come out of it, and that is part of doing the work rather than something separate you can opt out of.

Billing and accounting records are kept for 6 years. Correspondence and project records are kept for the life of the relationship and for two years after it ends, then deleted.

Data we handle for our clients

When we build or run a system for a client, that system often holds personal data belonging to the client's business — their customers, their users, their staff. In that situation the client decides why and how the data is used, and we act only on their instructions. We are a processor, not a controller, and this notice does not cover that data. If you think a client of ours holds data about you, ask them directly and they will point you to their own privacy notice.

What we commit to in that role: we work under a written agreement, we limit access to the people actually delivering the work, we do not use client data for any purpose of our own, and we return or delete it at the end of the engagement.

If you apply for a job with us

We hold your CV, your contact details, your work history, and our notes from any interview or exercise. Applications reach us by email — we do not run a careers portal or an application system, so there is no account to create and nothing is stored on the website. We use what you send to assess your application, on the basis of taking steps at your request before entering a contract and our legitimate interests in hiring well. You do not have to give us any of it, but we cannot assess an application without it.

If we do not hire you we keep your application for 6 months and then delete it. If you have told us we may keep it on file for future roles, we rely on your consent for that, we keep it for 12 months from your application, and we will ask you again if we still have it then. You can withdraw your permission at any time by emailing us, and withdrawing does not affect anything we did with your application while it was in place.

If you supply us

We hold contact and payment details for our suppliers and contractors. Where you are an individual contracting with us, the basis is our contract with you and our legal obligations for tax records. Where you are the named contact at a supplier company, the contract is with your employer rather than with you, so for your own details we rely on our legitimate interests in managing and paying our suppliers. We need a contact and payment details in order to work with a supplier and pay them; there is nothing else we ask for. We keep supplier records for the life of the relationship, and payment records for as long as tax law requires — the same period given above for accounting records.

Who else sees your data

We use a small number of service providers to run the business: email and office software, website and mail hosting, an outbound email platform, an email finding service, an email verification service, Cal.com for booking calls, accounting software, and project management tools. Each of them handles only what it needs to, under terms that restrict them to processing on our instructions and for the purposes we set.

We do not sell personal data. We do not share it with advertisers or data brokers. We do not use it to train AI models.

We will disclose data where the law requires it, and we will tell you if that happens wherever we are legally able to.

The current list of our service providers is available on request from hello@programmx.com.

Where your data is held

We are based in Pakistan and our team works there, so data we hold is accessed from Pakistan. Some of our service providers operate in the United States and the European Union, so data may be stored there too.

The United Kingdom has not formally assessed Pakistan as providing an equivalent standard of data protection. We think you should know that plainly rather than find it in a footnote.

Where we act as a processor for a client, the client is responsible for putting the appropriate transfer mechanism in place — typically the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. Where our own service providers are in the United States or the European Union, we rely on the standard contractual clauses in their data-processing terms.

For the business-contact data we collect ourselves and hold in Pakistan, we are the original controller: there is no onward transfer for us to put a mechanism around. We protect this data in practice by limiting access to the people delivering the work, encrypting it in transit, and binding any provider who processes it to written data-processing terms.

Your rights

You can ask us to give you a copy of the data we hold about you, correct it if it is wrong, delete it, restrict what we do with it, or send it to someone else in a portable form. You can object to us using it, and where that objection is about direct marketing we must stop. Where we rely on your consent for something, you can withdraw it at any time without affecting what was done beforehand.

We do not make decisions about you by automated means that have legal or similarly significant effects.

These rights come from UK and EU data protection law. Our practice is to deal with a request on its merits rather than to check first whether the law obliges us to, because sorting people by jurisdiction before answering a fair question is not a good use of anyone's time.

How to use them.

Email hello@programmx.com. We aim to respond within one week and we will always respond within one month, which is the period the law allows. There is no charge. We may need to ask you a question or two to find your records and be sure it is you.

If you are unhappy

Tell us first — hello@programmx.com — and we will try to put it right.

You can also complain to a data protection regulator. In the United Kingdom that is the Information Commissioner's Office, at ico.org.uk or 0303 123 1113. In the European Union it is the supervisory authority for your country. Complaining to us does not affect your right to complain to them.

Changes to this notice

If we change how we use personal data, we will update this page and change the date at the top. If the change is significant and we hold your contact details, we will tell you directly.

← Back to home

ProgrammX — Transforming Ideas Into Reality
programmx.com · hello@programmx.com · Lahore, Pakistan
PrivacyCookiesLinkedIn© 2026 ProgrammX Technologies (SMC-Private) Limited