Privacy Policy

How we collect, use, and protect your personal data. Compliant with Pakistan's PDPA 2023 and international best practices.

Bizbuddy is a product and registered trademark of B&B Technologies, Karachi, Pakistan.

PDPA 2023 Compliant

Governed by Pakistan's primary data protection law

We Never Sell Data

Your data is never sold, rented, or traded to anyone

Full Transparency

Every data use is disclosed — no hidden tracking

Your Rights Protected

Access, correct, or delete your data within 30 days

Plain Language Summary

Quick Read

We NEVER sell your data.

We do not sell, rent, trade, or otherwise transfer any personal data to third parties for their own commercial use. This is absolute and unconditional.

Personal Data: Any information that identifies or can be used to identify a natural person, directly or indirectly, as defined under Section 2 of the PDPA 2023.

Platform: The Bizbuddy SaaS application, website, APIs, WhatsApp automation interface, AI order processing engine, delivery integrations, POS interface, and all associated services accessible via bizbuddyco.com.

Data Controller: Bizbuddy, the entity that determines the purpose and means of processing Personal Data collected through the Platform and website.

AI Engine: The automated natural language and voice processing system embedded in the Platform that interprets, processes, and routes food orders placed by Consumers.

WhatsApp Channel: The Meta WhatsApp Business API integration through which Consumers interact with a Client's AI-powered ordering system via the Platform.

From Restaurant Clients (B2B)

Data CategoryExamplesLegal Basis
Business IdentityBusiness name, address, NTN/STRNContractual necessity
Account CredentialsEmail, hashed password, session tokensContractual necessity
Contact DataOwner name, phone, WhatsApp numberContractual necessity
Menu and Operational DataMenu items, pricing, categories, hoursContractual necessity
Device and Technical DataIP address, browser, OS via AnalyticsConsent

From End Consumers (Via WhatsApp)

Order data, WhatsApp phone number, delivery address, conversation text, and voice message content (converted to text only; raw audio is deleted immediately after processing). Bizbuddy acts as a Data Processor for consumer data. The Restaurant Client is the Data Controller.

From Website Visitors (Automatically)

IP address, browser type, pages visited, session duration, referral source via Google Analytics and Meta Pixel. This data is transferred to Google LLC and Meta Platforms Inc. servers in the USA.

For Restaurant Clients

  • Create, manage, and maintain your Platform account and Subscription
  • Deliver AI-powered WhatsApp order automation and all subscribed features
  • Process payments, generate invoices, and maintain billing records
  • Send essential service communications, security alerts, and policy changes
  • Comply with legal and tax obligations under Pakistani law
  • Outbound messages to consumers outside the 24-hour WhatsApp conversation window are sent only through Meta-approved message templates, in full compliance with Meta's WhatsApp Business Platform policies.

We expressly do NOT

  • Sell, rent, trade, or transfer any personal data to third parties for commercial use
  • Use consumer order data for marketing, advertising, or profiling
  • Train our AI Engine on identifiable personal data without explicit consent
  • Share data with government authorities except where required by lawful order
Service ProviderRoleLocation
Meta (WhatsApp Business API)Message delivery infrastructureUSA
Meta PixelAdvertising and analyticsUSA
Google Analytics (Google LLC)Website analyticsUSA
Vercel Inc.Platform and POS hostingUSA
Thermal Printer APIReceipt generationLocal device only

We implement the following security measures:

  • Encryption of all data in transit using TLS/SSL protocols
  • Encryption of stored data at rest using AES-256 or equivalent
  • Role-based access controls ensuring only authorized personnel access specific data
  • Regular security assessments and vulnerability monitoring
  • Automated backup systems and disaster recovery protocols
  • Formal incident response procedures in compliance with PDPA 2023 breach notification requirements
Data CategoryRetention Period
Client Account DataActive Subscription plus 5 years
Consumer Order Data2 years from order date
Payment and Invoice Records6 years (FBR compliance)
Website Server Logs90 days
Voice Messages (raw audio)Deleted immediately after AI processing

Right of Access

Request a copy of all personal data we hold about you.

Right to Correction

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data, subject to legal retention obligations.

Right to Withdraw Consent

Withdraw consent for analytics or advertising processing at any time.

How to Exercise Your Rights

Email info@bizbuddyco.com. We acknowledge within 5 business days and respond substantively within 30 days.

This Privacy Policy is governed by the laws of the Islamic Republic of Pakistan, including the PDPA 2023 and PECA 2016. Any disputes shall be subject to the exclusive jurisdiction of the courts of Karachi, Sindh, Pakistan.

City:Karachi, Sindh, Pakistan

Other Legal Documents