Back to home

Yottacom Technologies — Legal

Privacy Policy

Yottacom Technologies is a business-to-business software and AI engineering firm. This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to our website at https://yottacom.net and to the professional services we deliver to client organisations.

Last updated: 10 August 2026

The short version

  • We sell digital services to businesses. We do not sell consumer products, and we do not sell, rent or trade personal data to anyone.
  • From our website we mainly collect what you type into our contact form — your name, business email and message — plus standard server logs.
  • We never see or store payment card numbers, CVV codes, PINs or OTPs. Card and wallet payments are captured and processed entirely by PayFast, a payment service provider licensed and regulated by the State Bank of Pakistan. We only receive a transaction reference, amount, status and date.
  • For data inside a client's own systems, the client remains the controller and we act only as a processor under written instructions.
  • You can ask us for a copy of your data, ask us to correct it, or ask us to delete it — email [email protected].

1. Who we are

“Yottacom”, “we”, “us” and “our” refer to Yottacom Technologies, the trading name of Yottacom Technologies SMC (Pvt) Ltd, a single-member private limited company registered in Pakistan with its office at 52, A3 Johar Town, Lahore, and of Yotta AI LLC, a limited liability company established in Myrtle Beach, South Carolina, USA.

For personal data collected through this website and through our own commercial activity — enquiries, proposals, contracts and invoicing — Yottacom Technologies SMC (Pvt) Ltd is the data controller for engagements contracted in Pakistan, including all payments processed locally through PayFast, and Yotta AI LLC is the data controller for engagements contracted through our United States entity.

2. Scope of this policy

This policy covers:

  • visitors to yottacom.net, including anyone who submits our contact form or otherwise contacts us;
  • representatives of prospective clients, clients, suppliers and partners whose business contact details we hold; and
  • the way we handle data belonging to our clients when we build, integrate, host or maintain software and AI systems for them.

This policy does not govern how our clients use their own products. Where we have built or operate a system for a client, that client's own privacy notice governs the relationship with its end users. Our obligations in those engagements are set out in the signed contract, statement of work and, where applicable, a data processing agreement.

Our services are directed at organisations, not consumers. We do not operate a public consumer marketplace, and we do not build advertising or data-broking profiles of website visitors.

3. Our two roles: controller and processor

It matters which role we are in, because it determines who decides what happens to the data and who you should approach to exercise your rights.

We are the controller

For data we decide to collect for our own purposes: contact form submissions, enquiry and proposal correspondence, client billing records, supplier records, recruitment enquiries sent to us, and website server logs.

We are a processor

For data inside a client's systems, datasets or production environments that we access in order to deliver an engagement. The client remains the controller. We act only on its documented instructions, and we do not use that data for our own purposes.

If you are an end user of a system we built for a client and you want your data accessed, corrected or deleted, please contact that organisation directly. If you contact us instead, we will not action the request ourselves; we will refer it to the client controller without undue delay and confirm to you that we have done so.

4. Personal data we collect

4.1 Information you give us directly

  • Contact form: your name, business email address, and the content of your message. Company name and phone number are optional and only collected if you enter them.
  • Direct correspondence: email threads, WhatsApp or phone conversations, LinkedIn messages, meeting notes and call scheduling details relating to a potential or active engagement.
  • Contract and billing information: the company's legal name and registered address, the named signatory and billing contact, purchase order references, tax or company registration numbers your organisation provides, and the bank or payment reference associated with a settled invoice.
  • Project materials: specifications, documents, sample data, credentials and access grants that a client chooses to share with us so that we can do the work. See section 6.
  • Job and internship enquiries: if you send us a CV, we hold the information in it for recruitment purposes only.

4.2 Information collected automatically

  • Server and hosting logs: IP address, browser user agent, date and time of the request, the page or asset requested, HTTP status, and referring URL. These are generated by our hosting infrastructure and are used for availability, debugging, abuse prevention and security investigation.
  • Error and performance diagnostics: technical traces generated when a page fails to load correctly.
  • Cookies and analytics: see section 8.

4.3 What we do not collect

We do not ask website visitors for national identity numbers, government identity documents, health information, biometric data, religious or political affiliation, or any other special-category data, and we ask that you do not include such information in a contact form message. We do not store payment card numbers or card security codes at any point (section 7). We do not purchase contact lists or scrape personal data to build marketing databases.

5. Why we use it, and our lawful basis

We only process personal data where we have a proper reason to do so. The table below sets out each purpose, the data involved, and the basis we rely on.

PurposeData usedLawful basis
Responding to enquiries submitted through our contact form, email, phone or LinkedInName, business email, company name, phone number (if given), message contentYour consent, given by choosing to contact us, and our legitimate interest in responding to business enquiries
Preparing proposals, statements of work (SOWs), estimates and commercial proposalsBusiness contact details, company details, requirements you share with usSteps taken at your request prior to entering into a contract
Delivering contracted services: development, AI/LLM engineering, integration, support and maintenanceNamed project contacts, system access details, and any data within the client environments we are engaged to work onPerformance of our contract with the client organisation
Invoicing, collecting payment and keeping accounting recordsBilling contact, company registered address, tax/registration numbers supplied by the client, invoice and transaction recordsPerformance of contract and compliance with tax and accounting obligations
Keeping our website available, secure and free of abuseIP address, user agent, request timestamps, referring URL, error tracesLegitimate interest in the security and integrity of our systems
Occasional service updates or follow-up about an engagement or an enquiry you startedBusiness email, nameLegitimate interest in client communication; consent where a message is promotional, and you can opt out at any time

Where we rely on your consent, you can withdraw it at any time by writing to [email protected]. Withdrawing consent does not affect processing already carried out, and it does not remove records we are required to keep for tax, accounting or contractual reasons.

6. Client project data and AI processing

A large part of our work involves building AI and LLM-based systems — chatbots, document intelligence, clinical and legal research assistants, sales and security agents, design and take-off automation, and workspace and project management tools. That work sometimes requires access to real client data. The following rules apply to every engagement.

  • Instruction only. We process client data solely to deliver the agreed scope. We do not mine it, resell it, or repurpose it for our own product development.
  • Data minimisation. We ask for the least data needed. Wherever a redacted, synthetic, masked or anonymised dataset is sufficient for development and testing, we use that instead of production data.
  • Model training. We do not use a client's data or documents to train, fine-tune or improve any model for another client, or for a general-purpose model, unless the client instructs us to do so in writing. Fine-tuning on client data happens only inside the scope the client has approved.
  • Third-party model providers. Where a solution calls a third-party model or inference API, the prompt content and any documents passed to it leave our environment and are handled by that provider. We identify the providers involved before the engagement begins, prefer configurations that exclude customer content from provider training, and record them as sub-processors in the engagement documentation.
  • Prompt and output logging. Systems we build may log prompts, model outputs, latency and error traces so that quality and safety can be evaluated. Retention and access for those logs are agreed with the client and configured in the client's own environment where the architecture allows.
  • Access control. Access to a client environment is limited to the engineers assigned to that engagement, granted for the period needed, and revoked at handover or termination. All personnel and contractors are bound by written confidentiality obligations.
  • Human oversight. For decision-support systems in sensitive domains such as legal, clinical and safety contexts, we design for human review rather than unsupervised automated decisions, and we document that expectation in the statement of work.
  • Return and deletion. On written request after an engagement ends, we return or delete client data held on our systems, subject to the timelines in section 11.

Where a client requires it, we will sign a data processing agreement or equivalent contractual terms recording these obligations, permitted sub-processors, security measures, breach notification and audit rights. Sector-specific obligations that apply to a client's industry are addressed in the engagement contract rather than in this general policy.

7. Payments, invoicing and card data

We bill for professional services against an agreed statement of work, typically on a milestone or monthly basis, in PKR or another currency stated on the invoice.

Yottacom does not collect, view, transmit or store payment card numbers, expiry dates, CVV/CVC codes, card PINs, banking passwords or one-time passcodes. Online card, wallet and Raast payments are captured and processed by PayFast, a payment service provider licensed and regulated by the State Bank of Pakistan and a Merchant Service Provider for Raast person-to-merchant payments. Payment credentials are entered on infrastructure operated by PayFast and its banking partners, and never pass through our servers.

What we do receive and keep is the transaction record:

  • the transaction or gateway reference identifier, amount, currency, date, time and payment status;
  • the invoice number and the client organisation the payment relates to;
  • the payer name and business email supplied at checkout, and, at most, a masked instrument descriptor such as the payment method type and the last four digits, where the processor returns it; and
  • for bank transfers, the remitting account name and reference as shown on our bank statement.

We use these records to reconcile payments, issue receipts, handle refund or chargeback queries under our Return and Refund Policy, and satisfy accounting and tax obligations. PayFast processes payment data as an independent controller for its own regulatory and fraud-prevention purposes, under its own terms and privacy policy, which we recommend you read before completing a payment.

If you ever receive a request that appears to come from Yottacom asking you to send full card details, a card PIN or an OTP by email, phone or chat, it is not from us. Please do not respond and tell us at [email protected].

8. Cookies and website analytics

Our website is a marketing and portfolio site. It does not require an account, and it does not use advertising cookies, cross-site tracking pixels or data-broker integrations.

  • Strictly necessary: cookies and local storage entries used to serve the site correctly, keep it secure, remember interface state such as a menu or theme preference, and protect the contact form against automated abuse.
  • Analytics, if enabled: where we use privacy-respecting, aggregate analytics to understand which pages are read and where traffic comes from, the data is used only in aggregate and is not used to identify you personally or to build a profile. We do not sell or share analytics data for advertising.
  • Embedded third-party content: pages that embed external media or link to LinkedIn may cause that provider to set its own cookies once you interact with it. That processing is governed by the provider's own policy.

You can block or delete cookies through your browser settings, and you can send an opt-out signal such as Global Privacy Control. Blocking strictly necessary cookies may stop parts of the site from working. If we later introduce non-essential cookies that require consent in your jurisdiction, we will ask for that consent before setting them.

9. Who we share data with (sub-processors)

We do not sell, rent or trade personal data. We share it only with service providers who help us operate, and only to the extent they need it. Each is bound by contract to protect the data and to use it only for the service they provide to us.

  • Cloud hosting and infrastructure providers — website hosting, application hosting, storage, content delivery and backup.
  • Business email, calendar and file storage providers — used for correspondence, proposals and document sharing.
  • Payment processing and banking partners — PayFast and our banks, for taking and reconciling payments (section 7).
  • AI model and inference providers — where an engagement requires it, and as disclosed to the client (section 6).
  • Engineering tooling — source control, issue tracking, CI/CD, error monitoring and communication tools used to build and support the software.
  • Professional advisers — accountants, auditors and lawyers, where they need access to records to advise us.
  • Authorities and legal counterparties — where disclosure is required by law or needed to establish or defend legal claims (section 17).
  • A successor entity — if our business or a part of it is reorganised, merged or transferred, data may pass to the successor, which remains bound by commitments equivalent to those in this policy.

Clients under a data processing agreement can request the current list of sub-processors that touch their engagement by writing to [email protected]. We will give reasonable notice of a material change to that list where the agreement requires it.

10. International transfers

We operate across two locations: the registered entity, Yotta AI LLC, is in the United States, and our engineering team is in Lahore, Pakistan. Personal data we hold as controller may therefore be accessed by authorised personnel in both countries, and may be stored in cloud regions in the United States, Europe or Asia depending on the provider and the engagement.

  • We transfer data between our own locations only for the purposes described in this policy, under internal access controls and confidentiality obligations.
  • Where a transfer to a service provider is involved, we rely on the provider's contractual data-protection terms, including standard contractual clauses or equivalent safeguards where the provider offers them.
  • Clients with data residency requirements can specify the region in which their data must be stored and processed, and the restrictions on cross-border access by our engineers, in the statement of work. Where we cannot meet a residency requirement, we say so before the engagement starts.

Data-protection law differs between jurisdictions. Regardless of where data is stored, we apply the commitments in this policy and in the applicable engagement contract.

11. How long we keep data

We keep personal data only as long as we need it for the purpose it was collected for, or as long as the law requires.

  • Contact form and enquiry correspondence: up to 24 months after our last substantive exchange, unless the enquiry becomes an engagement, in which case it is kept with the client record.
  • Client contracts, SOWs, invoices and payment records: for the life of the relationship and then for the period required by the tax, accounting and limitation rules that apply to us in the United States and Pakistan.
  • Website and hosting logs: normally up to 12 months, and longer only where a specific security incident is under investigation.
  • Client project data we hold as processor: for the duration of the engagement and any agreed support or warranty period. On written instruction after termination we return or delete it, ordinarily within 30 days, except where we must retain a copy by law.
  • Backups: encrypted backups follow their own rotation cycle, so deleted records may persist in backup media for a short additional period, typically no more than 90 days, after which they are overwritten.
  • Recruitment enquiries: up to 12 months from receipt, unless you ask us to delete your CV sooner.

When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

12. How we protect data

We apply technical and organisational measures proportionate to the sensitivity of the data we handle. These include:

  • encryption of data in transit using TLS/HTTPS across our website and service endpoints, and encryption at rest where our hosting and storage providers support it;
  • role-based, least-privilege access to systems and client environments, with multi-factor authentication on administrative and cloud accounts;
  • secrets and credentials kept in managed secret stores or environment configuration rather than in source code, with rotation when personnel or access change;
  • separation of development, staging and production environments, and a preference for masked or synthetic data outside production;
  • peer code review, dependency updates and monitoring of application errors and unusual access patterns;
  • written confidentiality obligations for every employee and contractor, with access revoked when an engagement or employment ends;
  • due-diligence review of the providers we rely on before we place data with them; and
  • an internal incident response process covering containment, assessment and notification. If a breach affects personal data we hold as controller, we will notify affected parties and any competent authority where the law requires it. If it affects data we process for a client, we will notify that client without undue delay, in line with the engagement contract.

We describe what we actually do rather than claim more: Yottacom does not currently hold a third-party security certification or completed external audit report, and we do not represent otherwise in any proposal. Where a client requires formal certification or an independent audit, we will say so honestly and agree the specific controls contractually instead. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

13. Your rights and how to exercise them

Subject to the law that applies to you, you may ask us to do the following with personal data we hold about you as controller:

  • Access — get confirmation of what we hold and a copy of it.
  • Correction — have inaccurate or incomplete information fixed.
  • Deletion — have data erased where we no longer have a valid reason to keep it.
  • Objection and restriction — object to processing based on our legitimate interests, or ask us to pause processing while a dispute is resolved.
  • Withdrawal of consent — withdraw consent where consent is the basis we rely on, including opting out of any non-essential email from us.
  • Portability — receive data you gave us in a structured, commonly used, machine-readable format, where that right applies.
  • Complaint — raise a complaint with the data-protection or consumer authority competent in your jurisdiction.

How to make a request

Email [email protected] with the subject line “Data Rights Request”, or call +92 300 6949063. Tell us what you want us to do and from which email address or form submission the data came, so that we can find it. We may ask a limited question or two to confirm you are the person the data relates to; we will not ask for identity documents unless the request is high-risk and we cannot verify it any other way.

We aim to respond substantively within 30 days. If a request is complex, we will tell you and give a revised timeframe. There is no charge for a reasonable request. We may decline or partially fulfil a request where the law allows — for example where records must be kept for tax purposes, where another person's data or a client's confidential information would be exposed, or where a request is manifestly excessive — and if we do, we will explain why.

If your request concerns data we process on a client's behalf, see the note at the end of section 3.

14. Automated decision-making

We do not make automated decisions that produce legal effects for website visitors or enquirers, and we do not profile visitors for advertising. Enquiries are read and answered by people.

We do build AI systems that generate recommendations, classifications and drafts for our clients. In those systems the client decides how outputs are used. Our engineering practice is to design for human review in consequential contexts, to document known limitations of a model, and to record evaluation and oversight expectations in the statement of work.

15. Children's data

Yottacom sells business-to-business professional services. Our website and services are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has submitted information to us through our website, contact [email protected] and we will delete it.

Where a client's own product is directed at or accessible to minors, responsibility for age assurance, parental consent and any related legal requirement rests with the client as controller, and is addressed in the engagement contract.

18. Changes to this policy

We may update this policy to reflect changes in our services, providers, or legal obligations. The “Last updated” date at the top of the page always shows the current version. If a change materially affects how we handle personal data, we will give notice on the website and, where the change affects an active engagement, notify the client contact directly. Continued use of the website after an update means you accept the revised policy.

19. How to contact us

For any privacy question, data rights request, or concern about how we have handled your information, reach us at:

Yottacom Technologies

Trading name of Yottacom Technologies SMC (Pvt) Ltd (Pakistan) and Yotta AI LLC (USA)

If you are not satisfied with our response, you may escalate to the data-protection or consumer-protection authority competent in your jurisdiction.

Last updated: 10 August 2026

Back to home