Privacy Policy
How A & A Labs handles personal data collected through this website and our client services.
Version 1.0 · effective . Previous versions are available on request from legal@aa-labs.co.
This policy covers personal data that A & A Labs handles through this website and through our client services work. Our products have their own policies — for omvio, see the omvio Privacy Policy.
1. Who we are
A & A Labs is a technology provider registered in Pakistan. We are the controller for the personal data described here.
2. What this website collects
- Nothing, by default. Browsing this site sets no cookies, loads no third-party scripts and makes no requests to advertising or analytics networks. Fonts are served from our own domain rather than a font CDN, specifically so that reading a page here does not report your visit to anyone else.
- Server logs. Our hosting records standard request logs — IP address, timestamp, requested URL, user agent — for security and troubleshooting. Retained for 90 days.
- Anything you send us. If you email us or submit a form, we hold what you wrote and your contact details in order to reply.
If we later add privacy-respecting analytics, this section and the Cookie Policy will be updated first.
3. Enquiries and client relationships
- What we collect: name, business email, phone number, company, and the content of your enquiry or project correspondence.
- Why: to respond, to scope and deliver work, to invoice, and to keep the records a business is required to keep.
- Legal basis: steps prior to entering a contract, performance of a contract, legal obligation, and our legitimate interest in running a business.
- Retention: enquiry correspondence for 24 months from last contact; contractual and financial records for 7 years.
4. Data in systems we build
When we build or maintain software for a client, we may be given access to systems containing that client’s personal data. In that work the client is the controller and we are a processor, acting only on their documented instructions under a written agreement. We do not use client data for our own purposes, and we do not retain copies beyond what the engagement requires.
5. Who we share data with
We do not sell personal data. We share it only with:
- hosting and email providers acting as our processors;
- our accountants and professional advisers, where necessary;
- authorities, where we are legally required to.
6. Your rights
You may request access to, correction of, deletion of, or a portable copy of your personal data, and you may object to or ask us to restrict processing. Write to privacy@aa-labs.co and we will respond within 30 days. If you are in the UK or EEA you may also complain to your local supervisory authority.
7. Marketing
We send occasional emails about our work only to people who asked for them or with whom we have a business relationship. Every one carries an unsubscribe link, and unsubscribing is immediate and permanent.
8. International transfers
Our providers may process data outside your country. Where that involves a transfer out of the UK or EEA we rely on Standard Contractual Clauses and the UK Addendum, together with encryption in transit and at rest.
9. Security
Described in Security Practices. Report a vulnerability to security@aa-labs.co.
10. Changes
Changes are posted here with a new version and effective date. Material changes are announced on the site before they take effect.
11. Contact
privacy@aa-labs.co · Data protection contact: dpo@aa-labs.co