Privacy Policy

Codeora Vision (SMC-Private) Limited

Effective date: 29 August 2026 · Last updated: 29 August 2026


 

1. Who we are

Codeora Vision (SMC-Private) Limited ("Codeora Vision", "we", "us", "our") is a single-member private limited company incorporated in Pakistan under Incorporation Number 0287521.

Registered office: Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan

We build and operate AI agent systems — voice agents, chatbots, retrieval-augmented knowledge systems, workflow automation, and outbound sales systems — for businesses. We work remotely, and our clients are primarily in the United States, Canada, Australia, and the United Arab Emirates.

For any question about this policy or about your personal data, email [email protected] or write to the registered office above.



2. What this policy covers

This policy explains how we handle personal data when you visit codeoravision.com, contact us, enquire about our services, or become a client. It applies to our own use of personal data as a data controller.

It does not cover personal data we process on behalf of a client inside a system we have built for them. Section 3 explains that distinction, and the Data Processing Terms in Schedule 1 of our Terms of Service govern it.


 

3. Two different roles

3.1 As a controller

When you visit our website, submit an enquiry, exchange emails with us, or engage us as a client, we decide why and how your personal data is used. In data protection terms we are the controller, and this policy governs that processing.

3.2 As a processor

When we build and operate an AI system for a client — an AI receptionist handling patient calls, a chatbot answering customer queries, a knowledge system searching a firm's documents — the personal data flowing through that system belongs to our client. They decide why and how it is used. We act only on their documented instructions, as a processor.

That relationship is governed by the Data Processing Terms in Schedule 1 of our Terms of Service. Where the data includes protected health information subject to HIPAA, a Business Associate Agreement is put in place during scoping and executed before any such information is handled.

If you are an individual whose data was processed inside a client's system and you want to exercise a right over it, contact that organisation. If you contact us instead, we will pass your request to them and support their response.


 

4. Personal data we collect

4.1 Data you give us

When you submit our contact form we ask for:

  • Your name
  • Your company
  • Your work email address
  • Your phone number (optional)
  • The capability you are exploring and your industry
  • Anything you write in the free-text message field

We also receive whatever you choose to tell us in emails, on scoping and discovery calls, in documents you share during an engagement, and in any messages sent through LinkedIn, Upwork, or another channel.

4.2 Data collected automatically

When you visit the website, our hosting and security infrastructure records technical data including your IP address, browser type and version, device type, operating system, referring page, the pages you view, and the date and time of your visit. We also use Google Analytics 4. Our Cookie Policy describes this in detail and explains how to opt out.

4.3 Data from other sources

We may collect business contact details from professional networks such as LinkedIn, from publicly available company websites, from professional and licensing directories, and from industry associations, in order to contact organisations we believe may benefit from our services. We target role-based and company addresses rather than personal addresses.

4.4 Data we do not want

Do not send us special category data through the contact form or by email — health information, biometric data, or information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, or sexual orientation. We do not need it to scope an engagement, and the form is not designed to receive it.

If you are exploring a healthcare or dental deployment, describe the workflow rather than sending sample records. Protected health information is handled only inside a scoped engagement, under a Business Associate Agreement, and never through the website.



5. Why we use it

What we doWhyBasis
Respond to your enquiry and run a scoping callTo answer the question you asked and work out whether we can helpSteps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries
Deliver an engagementTo build, deploy, calibrate, and support the system you engaged us forPerformance of a contract
Invoice and take paymentTo get paid and keep accounting recordsPerformance of a contract, and legal obligation
Contact businesses we think we can helpTo find clientsOur legitimate interest in marketing our services to businesses, balanced against your interests, and always with a working opt-out
Run and secure the websiteTo keep the site available and defend against attacks and abuseOur legitimate interest in operating and protecting our systems
AnalyticsTo understand how the site is used and which pages are usefulOur legitimate interest in improving our website — see the Cookie Policy for how to opt out
Keep records of contracts and correspondenceTo manage our business and defend legal claimsOur legitimate interest in maintaining business records, and legal obligation

For visitors in the United Kingdom or European Economic Area, the "Basis" column above corresponds to Article 6(1)(b), (c), and (f) of the UK and EU GDPR respectively.



6. Marketing and how to stop it

We send commercial messages to business contacts. Different rules apply depending on where you are, and we follow the strictest one that applies to you:

  • United States — every message identifies us, gives a valid postal address, and carries a working unsubscribe link. Opt-outs are honoured within 10 business days, usually immediately.
  • Canada — under CASL we rely on implied consent from an existing business relationship or a conspicuously published business address, we identify ourselves in every message, and we provide a working unsubscribe mechanism honoured within 10 business days.
  • Australia — under the Spam Act 2003 we identify ourselves, include a functional unsubscribe facility, and honour opt-outs within 5 business days.
  • United Arab Emirates — we follow applicable TDRA rules on unsolicited commercial communications.

To stop hearing from us, use the unsubscribe link in any message or email [email protected]. You do not have to give a reason.



7. What we do not do

  • We do not sell personal data. We have never sold personal data and we do not share it for cross-context behavioural advertising.
  • We do not add enquirers to an automated marketing sequence without asking first.
  • We do not use client data, client documents, or personal data processed inside a client system to train any public or third-party AI model.
  • We do not use personal data to make decisions about you by automated means that produce legal or similarly significant effects.


8. AI systems and your data

Our work involves large language models and voice infrastructure. Two things follow, and we would rather state them plainly than bury them.

8.1 On our own website

The contact form is a standard form. It does not run your message through an AI model. What you write goes to our inbox.

8.2 In systems we build

Systems we build for clients pass data to model providers and voice infrastructure providers in order to function. Those providers are engaged as sub-processors under the applicable client agreement, on enterprise or business terms that exclude the use of submitted data for model training. Where a client's requirements demand it, we deploy into the client's own cloud environment or a dedicated boundary so their data never enters a shared service.

No system we build makes a final decision about an individual without a defined escalation path to a human. Uncertainty routing and human-in-the-loop fallback are part of every production build.



9. Who we share it with

We share personal data only with the categories of recipient below, and only as far as necessary.

CategoryExamplesPurpose
Hosting and website infrastructureOur web host, CloudflareServing the website, security, bot mitigation
AnalyticsGoogle Analytics 4Understanding how the website is used
Email and productivityOur business email and document providersCorrespondence, proposals, document storage
SchedulingCalendar and booking toolsArranging scoping and review calls
Cloud infrastructureAmazon Web Services, Google Cloud PlatformHosting systems we build and operate
AI model providersAnthropic, OpenAI, and other model providersPowering agent systems, under terms excluding training on submitted data
Voice and telephonyTwilio, Vapi, Retell AI, ElevenLabs, DeepgramVoice agent delivery where an engagement includes it
ObservabilityLangSmithMonitoring and evaluating system behaviour
Payments and contractingPayoneer, Upwork (for Direct Contracts)Taking payment, contracting, and reconciling invoices
Professional advisersAccountants, auditors, lawyersAccounting, tax, and legal advice
Delivery partnersContracted engineers working under written confidentiality obligationsDelivering engagements

Where an engagement is contracted through Upwork Direct Contracts, Upwork processes your contracting and payment information under its own privacy policy, as an independent controller for that purpose.

We may also disclose personal data where we are legally required to, where necessary to establish, exercise, or defend legal claims, or in connection with a sale or reorganisation of our business — in which case the recipient would be bound by terms no less protective than these.



10. International transfers

We operate from Pakistan. Our infrastructure providers operate globally. Personal data you give us will therefore be transferred outside your country, including to Pakistan and the United States.

Wherever your data goes, we apply the same protections: written confidentiality obligations, contractual restrictions on use, encryption in transit and at rest, and access controls.

  • From Canada — we process personal information outside Canada. Under PIPEDA we remain accountable for it and use contractual means to provide a comparable level of protection. You have the right to know that this happens, which is why it is stated here.
  • From Australia — under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, and we remain accountable for it.
  • From the United Arab Emirates — where the UAE Personal Data Protection Law applies, transfers are made on the basis of appropriate contractual safeguards or your consent.
  • From the United Kingdom or European Economic Area — Pakistan is not covered by a UK or EU adequacy decision. Where we receive UK or EEA personal data, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment.

You can request a copy of the safeguards we rely on by emailing [email protected].



11. How long we keep it

DataRetention
Enquiries that do not lead to an engagement24 months from last contact, then deleted
Client contracts, scopes, and correspondence7 years from the end of the engagement, for accounting, tax, and limitation purposes
Invoices and financial recordsAs required by Pakistani company and tax law, currently a minimum of 6 years
Marketing contact recordsUntil you opt out, or 24 months of no engagement, whichever is sooner
Website server logsTypically 30 to 90 days, depending on the provider
Google Analytics dataRetained per our GA4 configuration, currently 14 months
Data processed inside a client systemAs set by the client in the applicable Data Processing Terms. Returned or deleted at the end of the engagement, at the client's election.


12. Your rights

12.1 United States

California. Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct inaccurate information, and to limit the use of sensitive personal information. You have the right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.

Other states. If you are in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with comprehensive privacy legislation, you have comparable rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising and profiling. We apply the same process to all of them.

12.2 Canada

Under PIPEDA you have the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent subject to legal and contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada.

12.3 Australia

Under the Privacy Act 1988 and the Australian Privacy Principles you have the right to access the personal information we hold about you and to request correction. You may complain to us first, and then to the Office of the Australian Information Commissioner if you are not satisfied.

12.4 United Arab Emirates

Where the UAE Personal Data Protection Law applies, you have rights of access, correction, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent where processing is based on it.

12.5 United Kingdom and European Economic Area

You have the right to be informed, to access, to rectification, to erasure in certain circumstances, to restrict processing, to data portability, to object to processing based on legitimate interests, and to object to direct marketing at any time. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out.

12.6 How to exercise them

Email [email protected] with your request and enough information for us to identify you. We respond within 30 days and will tell you if we need longer. Exercising these rights is free. We may refuse requests that are manifestly unfounded or excessive, and will explain why if we do.



13. Security

We apply the same security standards to our own data that we build into client systems:

  • Encryption in transit using TLS 1.3 and at rest using AES-256 on systems we control
  • Role-based access control and multi-factor authentication on business systems
  • Audit logging of access to client systems and client data
  • Written confidentiality obligations on every person who works on an engagement
  • Data minimisation — we ask for what a scope requires and no more

No transmission over the internet is completely secure. We cannot guarantee absolute security, and we would not want to claim otherwise. If we become aware of a personal data breach affecting your data, we will notify you and the relevant authority where the law requires it, within the applicable time limits.



14. Children

Our website and services are directed at businesses, not consumers, and not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.



15. Complaints

If you are unhappy with how we have handled your personal data, tell us first at [email protected] — we would rather fix it.

If you are still unhappy, you can complain to the relevant authority:

  • United States — the California Privacy Protection Agency or your state Attorney General
  • Canada — the Office of the Privacy Commissioner of Canada
  • Australia — the Office of the Australian Information Commissioner
  • United Arab Emirates — the UAE Data Office
  • United Kingdom — the Information Commissioner's Office
  • European Economic Area — the supervisory authority in your member state


16. Changes

We update this policy when our practices or the law change. The effective date at the top tells you when the current version was published. Material changes will be flagged on the website before they take effect.



Codeora Vision (SMC-Private) Limited
· Incorporation Number 0287521 Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan [email protected]