Codeora Vision (SMC-Private) Limited
Effective date: 29 August 2026 · Last updated: 29 August 2026
Codeora Vision (SMC-Private) Limited ("Codeora Vision", "we", "us", "our") is a single-member private limited company incorporated in Pakistan under Incorporation Number 0287521.
Registered office: Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan
We build and operate AI agent systems — voice agents, chatbots, retrieval-augmented knowledge systems, workflow automation, and outbound sales systems — for businesses. We work remotely, and our clients are primarily in the United States, Canada, Australia, and the United Arab Emirates.
For any question about this policy or about your personal data, email [email protected] or write to the registered office above.
This policy explains how we handle personal data when you visit codeoravision.com, contact us, enquire about our services, or become a client. It applies to our own use of personal data as a data controller.
It does not cover personal data we process on behalf of a client inside a system we have built for them. Section 3 explains that distinction, and the Data Processing Terms in Schedule 1 of our Terms of Service govern it.
When you visit our website, submit an enquiry, exchange emails with us, or engage us as a client, we decide why and how your personal data is used. In data protection terms we are the controller, and this policy governs that processing.
When we build and operate an AI system for a client — an AI receptionist handling patient calls, a chatbot answering customer queries, a knowledge system searching a firm's documents — the personal data flowing through that system belongs to our client. They decide why and how it is used. We act only on their documented instructions, as a processor.
That relationship is governed by the Data Processing Terms in Schedule 1 of our Terms of Service. Where the data includes protected health information subject to HIPAA, a Business Associate Agreement is put in place during scoping and executed before any such information is handled.
If you are an individual whose data was processed inside a client's system and you want to exercise a right over it, contact that organisation. If you contact us instead, we will pass your request to them and support their response.
When you submit our contact form we ask for:
We also receive whatever you choose to tell us in emails, on scoping and discovery calls, in documents you share during an engagement, and in any messages sent through LinkedIn, Upwork, or another channel.
When you visit the website, our hosting and security infrastructure records technical data including your IP address, browser type and version, device type, operating system, referring page, the pages you view, and the date and time of your visit. We also use Google Analytics 4. Our Cookie Policy describes this in detail and explains how to opt out.
We may collect business contact details from professional networks such as LinkedIn, from publicly available company websites, from professional and licensing directories, and from industry associations, in order to contact organisations we believe may benefit from our services. We target role-based and company addresses rather than personal addresses.
Do not send us special category data through the contact form or by email — health information, biometric data, or information about racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life, or sexual orientation. We do not need it to scope an engagement, and the form is not designed to receive it.
If you are exploring a healthcare or dental deployment, describe the workflow rather than sending sample records. Protected health information is handled only inside a scoped engagement, under a Business Associate Agreement, and never through the website.
| What we do | Why | Basis |
|---|---|---|
| Respond to your enquiry and run a scoping call | To answer the question you asked and work out whether we can help | Steps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries |
| Deliver an engagement | To build, deploy, calibrate, and support the system you engaged us for | Performance of a contract |
| Invoice and take payment | To get paid and keep accounting records | Performance of a contract, and legal obligation |
| Contact businesses we think we can help | To find clients | Our legitimate interest in marketing our services to businesses, balanced against your interests, and always with a working opt-out |
| Run and secure the website | To keep the site available and defend against attacks and abuse | Our legitimate interest in operating and protecting our systems |
| Analytics | To understand how the site is used and which pages are useful | Our legitimate interest in improving our website — see the Cookie Policy for how to opt out |
| Keep records of contracts and correspondence | To manage our business and defend legal claims | Our legitimate interest in maintaining business records, and legal obligation |
For visitors in the United Kingdom or European Economic Area, the "Basis" column above corresponds to Article 6(1)(b), (c), and (f) of the UK and EU GDPR respectively.
We send commercial messages to business contacts. Different rules apply depending on where you are, and we follow the strictest one that applies to you:
To stop hearing from us, use the unsubscribe link in any message or email [email protected]. You do not have to give a reason.
Our work involves large language models and voice infrastructure. Two things follow, and we would rather state them plainly than bury them.
The contact form is a standard form. It does not run your message through an AI model. What you write goes to our inbox.
Systems we build for clients pass data to model providers and voice infrastructure providers in order to function. Those providers are engaged as sub-processors under the applicable client agreement, on enterprise or business terms that exclude the use of submitted data for model training. Where a client's requirements demand it, we deploy into the client's own cloud environment or a dedicated boundary so their data never enters a shared service.
No system we build makes a final decision about an individual without a defined escalation path to a human. Uncertainty routing and human-in-the-loop fallback are part of every production build.
We share personal data only with the categories of recipient below, and only as far as necessary.
| Category | Examples | Purpose |
|---|---|---|
| Hosting and website infrastructure | Our web host, Cloudflare | Serving the website, security, bot mitigation |
| Analytics | Google Analytics 4 | Understanding how the website is used |
| Email and productivity | Our business email and document providers | Correspondence, proposals, document storage |
| Scheduling | Calendar and booking tools | Arranging scoping and review calls |
| Cloud infrastructure | Amazon Web Services, Google Cloud Platform | Hosting systems we build and operate |
| AI model providers | Anthropic, OpenAI, and other model providers | Powering agent systems, under terms excluding training on submitted data |
| Voice and telephony | Twilio, Vapi, Retell AI, ElevenLabs, Deepgram | Voice agent delivery where an engagement includes it |
| Observability | LangSmith | Monitoring and evaluating system behaviour |
| Payments and contracting | Payoneer, Upwork (for Direct Contracts) | Taking payment, contracting, and reconciling invoices |
| Professional advisers | Accountants, auditors, lawyers | Accounting, tax, and legal advice |
| Delivery partners | Contracted engineers working under written confidentiality obligations | Delivering engagements |
Where an engagement is contracted through Upwork Direct Contracts, Upwork processes your contracting and payment information under its own privacy policy, as an independent controller for that purpose.
We may also disclose personal data where we are legally required to, where necessary to establish, exercise, or defend legal claims, or in connection with a sale or reorganisation of our business — in which case the recipient would be bound by terms no less protective than these.
We operate from Pakistan. Our infrastructure providers operate globally. Personal data you give us will therefore be transferred outside your country, including to Pakistan and the United States.
Wherever your data goes, we apply the same protections: written confidentiality obligations, contractual restrictions on use, encryption in transit and at rest, and access controls.
You can request a copy of the safeguards we rely on by emailing [email protected].
| Data | Retention |
|---|---|
| Enquiries that do not lead to an engagement | 24 months from last contact, then deleted |
| Client contracts, scopes, and correspondence | 7 years from the end of the engagement, for accounting, tax, and limitation purposes |
| Invoices and financial records | As required by Pakistani company and tax law, currently a minimum of 6 years |
| Marketing contact records | Until you opt out, or 24 months of no engagement, whichever is sooner |
| Website server logs | Typically 30 to 90 days, depending on the provider |
| Google Analytics data | Retained per our GA4 configuration, currently 14 months |
| Data processed inside a client system | As set by the client in the applicable Data Processing Terms. Returned or deleted at the end of the engagement, at the client's election. |
California. Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct inaccurate information, and to limit the use of sensitive personal information. You have the right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
Other states. If you are in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with comprehensive privacy legislation, you have comparable rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising and profiling. We apply the same process to all of them.
Under PIPEDA you have the right to access the personal information we hold about you, to challenge its accuracy and have it corrected, and to withdraw consent subject to legal and contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada.
Under the Privacy Act 1988 and the Australian Privacy Principles you have the right to access the personal information we hold about you and to request correction. You may complain to us first, and then to the Office of the Australian Information Commissioner if you are not satisfied.
Where the UAE Personal Data Protection Law applies, you have rights of access, correction, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent where processing is based on it.
You have the right to be informed, to access, to rectification, to erasure in certain circumstances, to restrict processing, to data portability, to object to processing based on legitimate interests, and to object to direct marketing at any time. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out.
Email [email protected] with your request and enough information for us to identify you. We respond within 30 days and will tell you if we need longer. Exercising these rights is free. We may refuse requests that are manifestly unfounded or excessive, and will explain why if we do.
We apply the same security standards to our own data that we build into client systems:
No transmission over the internet is completely secure. We cannot guarantee absolute security, and we would not want to claim otherwise. If we become aware of a personal data breach affecting your data, we will notify you and the relevant authority where the law requires it, within the applicable time limits.
Our website and services are directed at businesses, not consumers, and not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
If you are unhappy with how we have handled your personal data, tell us first at [email protected] — we would rather fix it.
If you are still unhappy, you can complain to the relevant authority:
We update this policy when our practices or the law change. The effective date at the top tells you when the current version was published. Material changes will be flagged on the website before they take effect.
Codeora Vision (SMC-Private) Limited · Incorporation Number 0287521 Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan [email protected]