Privacy Policy
The combined privacy policy for customers, vendors, riders, drivers and service workers, covering data collection, use, sharing, location, security and rights.
USER & CUSTOMER PRIVACY POLICY
1. INTRODUCTION & CONTROLLER IDENTITY
This User & Customer Privacy Policy governs how Apna Kaam collects, uses, stores, and protects the personal data of every person who downloads, visits, registers on, or uses the Apna Kaam Platform. We believe privacy is your right, not a privilege, and this Policy is written in plain language so you understand exactly what happens to your data.
1.1 Data Controller
Platform: Apna Kaam
Privacy Email: privacy@apnakaam.pk
Data Protection Officer: dpo@apnakaam.pk
Customer Support: support@apnakaam.pk
Grievance Officer: grievance@apnakaam.pk
2. LEGAL BASIS FOR DATA PROCESSING
2.1 Pakistani Legal Framework
- Prevention of Electronic Crimes Act (PECA) 2016 – data privacy and cybercrime protections
- Electronic Transactions Ordinance (ETO) 2002 – electronic records and contracts
- Consumer Protection Acts (Federal & Provincial) – consumer rights and remedies
- State Bank of Pakistan (SBP) Payment Systems Regulations – financial data
- Pakistan Telecommunication (Re-Organization) Act 1996 – communications data
2.2 International Frameworks
- EU GDPR Articles 6, 7, 9, 13, 17, 20, 22 – for users in the EEA or where GDPR applies
- California Consumer Privacy Act (CCPA) – for California-based users
- UAE Federal Decree-Law No. 45 of 2021 (PDPL) – for GCC users
- ISO/IEC 27001 – Information Security Management Standard
2.3 Lawful Bases
- Contractual Necessity – to provide the services you request
- Legal Obligation – compliance with Pakistani law and court orders
- Legitimate Interests – fraud prevention, platform safety, service improvement
- Consent – marketing, personalisation, and optional features
- Vital Interests – emergency situations involving risk to life
3. DATA WE COLLECT
3.1 Account & Identity Data
- Full name, mobile number (OTP-verified), email address (optional), profile photo (optional)
- Date of birth (age verification), gender (optional), encrypted password
3.2 Location Data
- Real-time GPS – ONLY when app is open and permission granted
- Delivery addresses you enter or save (Home, Work, custom)
- City-level approximate location for service availability checks
IMPORTANT: We do NOT track your location when the app is closed. Location data is never sold.
3.3 Order & Transaction Data
- Products/services ordered, booking dates, delivery addresses, order values, payment method, order status history
- Ratings and reviews you submit; complaints and dispute records
3.4 Payment Data
- Payment type; masked card details (last 4 digits only – full card data handled by PCI-DSS processors)
- JazzCash/Easypaisa account numbers, transaction IDs, refund records
We NEVER store your full card number, CVV, or banking PIN on our servers.
3.5 Communication & Technical Data
- In-app chat, support tickets, feedback; device type, OS, app version, IP address, session logs
3.6 Data We Do NOT Collect
- CNIC number | Biometric data | Contacts, photos, or files (unless you share them) | Microphone/camera without active consent
4. HOW WE USE YOUR DATA
- Delivering orders, bookings, delivery, and transport services
- Smart Match personalisation – suggesting relevant services based on your order history
- Real-time Rider/Service Worker tracking during active orders
- Payment processing, refunds, and fraud detection
- Account security, OTP verification, and impersonation prevention
- Legal compliance, court orders, and regulatory reporting
- Platform improvement through aggregated, anonymised analytics
- Marketing communications (with consent only – unsubscribe any time)
5. DATA SHARING & DISCLOSURE
We do not sell your data. We share it only as described below:
- Vendors – first name, delivery address, and order details for active orders only
- Riders – first name, pickup/drop-off address, order reference (personal mobile masked)
- Service Workers – booking address and service details for your active booking
- Payment Processors – JazzCash, Easypaisa, 1Link, Stripe (under DPAs)
- Cloud/SMS/Maps – AWS hosting, OTP providers, Google Maps API (anonymised)
- Law Enforcement – FIA, SBP, courts upon valid legal order
- Business Transfers – 30 days' notice given before any merger/acquisition data transfer
We NEVER share full payment details, full profile, or home address with Vendors or Riders.
6. LOCATION DATA – SPECIAL PROVISIONS
- 'While Using App' permission only – we never require Always On
- Live location shared with Riders only during active delivery, then immediately stopped
- You can enter addresses manually without enabling GPS
- We NEVER track you in the background, sell location data, or share it with advertisers
7. SMART MATCH & PERSONALISATION
Smart Match uses your order history, saved location, and anonymised platform patterns to suggest relevant services (e.g., ordering paint suggests painters). It does NOT use payment history or sensitive personal data. You can opt out in Settings > Privacy without losing access to core features.
8. DATA STORAGE, SECURITY & RETENTION
- AES-256 encryption at rest | TLS 1.3 in transit | MFA available | Role-based access controls
- Regular penetration testing | 24/7 intrusion detection | ISO/IEC 27035 incident response
- Active account data: retained while account is active
- Order & transaction records: 7 years (Pakistani tax law)
- Location history (order-level): 2 years | Technical logs: 90 days
- Marketing data: until consent withdrawn | Inactive accounts: deleted after 12 months + 90-day notice
9. YOUR RIGHTS
- Access – request a full copy of your data (Settings > Privacy > Download My Data)
- Rectification – correct inaccurate data at any time in Profile Settings
- Erasure – delete account and data (Settings > Account > Delete Account)
- Portability – receive data in JSON/CSV format
- Object – opt out of profiling and personalisation (Settings > Privacy)
- Restrict Processing – limit data use during dispute investigation
- Withdraw Consent – cancel marketing/optional data use any time
- Automated Decision Review – human review of any decision that significantly affects you
- Non-Discrimination – exercising rights will never reduce your service quality
Contact: privacy@apnakaam.pk | Response: 30 days maximum
10. COOKIES, CHILDREN, BREACH NOTIFICATION & CONTACT
10.1 Cookies
- Essential, session, preference, analytics, and security cookies only. No advertising cookies. No cross-site tracking.
10.2 Children
Not directed to under-13s. Users 13–17 require parental consent. Contact privacy@apnakaam.pk to report a minor's account.
10.3 Breach Notification
- Affected users notified within 72 hours via in-app, email, and/or SMS. Authorities notified as required by law.
10.4 Contact
Privacy: privacy@apnakaam.pk
DPO: dpo@apnakaam.pk
Grievance: grievance@apnakaam.pk
Document ID: APNAKAAM-PP-USER-V2.0-2025
VENDOR & MERCHANT PRIVACY POLICY
1. INTRODUCTION & CONTROLLER IDENTITY
This Vendor & Merchant Privacy Policy governs how Apna Kaam collects, uses, stores, and protects personal and business data provided by Vendors and Merchants who register and operate on the Platform. This Policy forms an integral part of your Vendor Agreement.
1.1 Data Controller
Privacy Email: privacy@apnakaam.pk
Data Protection Officer: dpo@apnakaam.pk
Vendor Support: vendors@apnakaam.pk
Grievance Officer: grievance@apnakaam.pk
2. LEGAL BASIS FOR DATA PROCESSING
2.1 Pakistani Legal Framework
- PECA 2016 – Sections 14, 16, 17 (data protection and identity crimes)
- Electronic Transactions Ordinance 2002 – electronic records and signatures
- Companies Act 2017 – data governance for corporate entities
- State Bank of Pakistan (SBP) Payment Systems Regulations – financial data
- Federal Board of Revenue (FBR) Tax Regulations – earnings and withholding tax
2.2 International Frameworks
- EU GDPR – Articles 6, 9, 13, 17, 20 | UAE PDPL (Decree-Law No. 45/2021) | ISO/IEC 27001
2.3 Lawful Bases
- Contractual Necessity | Legal Obligation | Legitimate Interests | Consent | Vital Interests
3. DATA WE COLLECT FROM VENDORS
3.1 Identity & Registration
- Full legal name, CNIC (verified copy), NTN/STRN, business name, profile photo, digital signatures
3.2 Contact & Location
- Primary mobile (OTP-verified), business address, GPS coordinates of store, delivery zones, email
3.3 Financial & Banking Data
- Bank account (IBAN, account title, bank/branch), JazzCash/Easypaisa accounts, transaction histories, commission settlement records, tax deduction records
3.4 Business & Product Data
- Product catalogue, pricing, service menu, operating hours, delivery policies, inventory (if provided)
3.5 Performance & Technical Data
- Order acceptance rates, customer ratings, complaint records, penalties, sales analytics
- Device type, IP address, app version, login timestamps, session logs
4. HOW WE USE VENDOR DATA
- Account creation, store display, and Smart Match visibility to Customers
- Order processing, Rider coordination, commission calculation, and payout settlement
- KYC/AML compliance, FBR tax reporting, SBP payment compliance
- Fraud prevention, Code of Conduct enforcement, dispute resolution
- Platform analytics (aggregated, anonymised) and Smart Match algorithm improvement
- Marketing and promotional communications (with consent)
5. DATA SHARING & DISCLOSURE
We do not sell Vendor data. We share only as follows:
- Customers – store name, product details, ratings, estimated delivery time (order-relevant only)
- Riders – pickup address, order ID, package details for delivery
- Payment Processors – JazzCash, Easypaisa, 1Link, Stripe (under DPAs)
- Law Enforcement – FIA, FBR, SBP, courts upon valid legal order
- City Operators (Franchise) – name, contact, performance metrics for their city only
City Operators are bound by strict confidentiality and cannot share your data with third parties.
6. DATA STORAGE, SECURITY & RETENTION
- AES-256 encryption at rest | TLS 1.3 in transit | RBAC | Regular audits | ISO/IEC 27035 response
- Active account data: duration of Vendor relationship
- Financial & transaction records: 7 years (FBR/Companies Act requirement)
- CNIC/identity records: 5 years post-closure | Communication logs: 3 years | System logs: 2 years
7. VENDOR RIGHTS & BREACH NOTIFICATION
- Access, Rectification, Erasure, Portability, Object, Restrict, Withdraw Consent, Non-Discrimination
- Automated decisions with significant effect (e.g., suspension) trigger right to human review
- Data breach: notification within 72 hours of confirmed breach, including nature, data types, and remedial actions
Contact: privacy@apnakaam.pk | DPO: dpo@apnakaam.pk | Response: 30 days
Dispute Resolution
- Step 1: grievance@apnakaam.pk (30 days) → Step 2: DPO escalation → Step 3: PTA / FIA / Consumer Protection Court
Document ID: APNAKAAM-PP-VENDOR-V2.0-2025
RIDER & DRIVER PRIVACY POLICY
1. INTRODUCTION & CONTROLLER IDENTITY
This Rider & Driver Privacy Policy governs how Apna Kaam collects, uses, and protects data about individuals who register as Riders or Drivers. Riders occupy a uniquely sensitive position because they share real-time GPS location data, vehicle information, and financial data during platform operations.
1.1 Data Controller
Privacy Email: privacy@apnakaam.pk
DPO: dpo@apnakaam.pk
Rider Support: riders@apnakaam.pk
Emergency / Safety: safety@apnakaam.pk
2. LEGAL BASIS FOR DATA PROCESSING
- PECA 2016 | Electronic Transactions Ordinance 2002 | Motor Vehicles Ordinance 1965
- NADRA Act 2000 (identity verification) | Labor Laws of Pakistan | SBP Payment Regulations
- EU GDPR | UAE PDPL | ILO Guidelines on Privacy of Workers | ISO/IEC 27001
- Lawful Bases: Contractual Necessity | Legal Obligation | Legitimate Interests | Consent | Vital Interests
3. DATA WE COLLECT
3.1 Identity & Registration
- Full name (as on CNIC), CNIC number and verified copy, date of birth, gender, home address, emergency contact
3.2 Vehicle & License Data
- Vehicle type, registration number, make/model/year/color, RC Book copy, driving licence (number, class, expiry), insurance policy, vehicle photos
3.3 Real-Time Location & GPS Data
- Precise GPS coordinates throughout active delivery/transport sessions
- Route history, speed data, pickup/drop-off locations, time-stamped logs
- Idle location when app is open and status is 'Available'
IMPORTANT: Location tracking is ONLY active when the Rider app is open and you are logged in. We do NOT track you when the app is closed.
3.4 Financial & Earning Data
- Bank account (IBAN, account title), mobile wallet numbers, daily/weekly/monthly earnings, base fare/per-km/tips/bonuses, COD handling records, payout history
3.5 Performance & Technical Data
- Deliveries completed, acceptance/completion rates, customer ratings, penalty records, session logs
- Device type, IP address, app version, connectivity/battery status, crash logs
4. HOW WE USE RIDER DATA
- Matching you with orders based on location and availability
- Sharing your real-time location with Customers ONLY during active orders (stops immediately on delivery)
- Calculating routes, ETAs, earnings, bonuses, and penalty deductions
- CNIC/licence/vehicle verification via NADRA, DLIMS, MTMIS
- Safety monitoring, emergency SOS response, fraud detection (including GPS spoofing)
- FBR earnings reporting, SBP payment compliance, labor law compliance
5. REAL-TIME LOCATION – SPECIAL PROVISIONS
- Customers see your location ONLY during active orders – from acceptance to delivery confirmation
- Vendors see your location only when you are en route to pickup
- We NEVER share location with advertisers, sell it, or use it to surveil off-platform activities
- Raw GPS logs: deleted after 90 days | Aggregated anonymised analytics: up to 3 years
6. DATA SHARING & DISCLOSURE
- Customers – name, photo, vehicle type, plate, real-time location during active orders
- Vendors – pickup confirmation, ETA, rider contact
- Payment Processors – JazzCash, Easypaisa, 1Link for earnings disbursement
- Maps & Navigation – Google Maps API (anonymised location queries)
- Law Enforcement – Traffic Police, FIA, FBR, courts upon valid legal order; emergency services in life-threatening situations
We NEVER share home address, CNIC details, bank details, or personal mobile number with Customers.
7. STORAGE, SECURITY, RETENTION & RIGHTS
- AES-256 at rest | TLS 1.3 in transit | Segregated biometric storage | RBAC | Regular audits
- Identity records: 5 years post-closure | Financial: 7 years | Trip records: 3 years | GPS logs: 90 days | Penalty records: 3 years
- Rights: Access, Rectification, Erasure, Portability, Object to Profiling, Withdraw Consent, Automated Decision Review, Non-Retaliation
- Automated penalties above PKR 500 or account suspension: automatic right to human review within 15 days
- Breach notification: 72 hours to affected Riders; authorities notified as required
Gig Economy Commitment
- We will not use your data to restrict work on other platforms or share performance data with non-platform third parties without consent
- We comply with any future Pakistani gig economy legislation granting additional worker protections
Contact
Privacy: privacy@apnakaam.pk
DPO: dpo@apnakaam.pk
Document ID: APNAKAAM-PP-RIDER-V2.0-2025
SERVICE WORKER PRIVACY POLICY
1. INTRODUCTION & CONTROLLER IDENTITY
This Service Worker Privacy Policy governs how Apna Kaam collects, uses, stores, and protects the personal and professional data of all individuals who register as Service Workers on the Platform. Service Workers are skilled professionals who accept bookings for home, business, or on-site service delivery — including but not limited to plumbers, electricians, barbers, cleaning professionals, AC technicians, carpenters, painters, tutors, and beauty service providers.
Service Workers handle sensitive in-person interactions with Customers at their homes or premises. This Policy reflects the heightened responsibility we take in managing your data and in maintaining Customer and Worker trust.
1.1 Data Controller
Privacy Email: privacy@apnakaam.pk
Data Protection Officer: dpo@apnakaam.pk
Service Worker Support: workers@apnakaam.pk
Safety & Emergency: safety@apnakaam.pk
Grievance Officer: grievance@apnakaam.pk
2. LEGAL BASIS FOR DATA PROCESSING
2.1 Pakistani Legal Framework
- Prevention of Electronic Crimes Act (PECA) 2016 – data privacy and digital identity protection
- Electronic Transactions Ordinance (ETO) 2002 – electronic contracts and records
- Labor Laws of Pakistan – rights of contractual, gig, and self-employed workers
- Factories Act 1934 / West Pakistan Shops and Establishments Ordinance 1969 – where applicable to trade workers
- National Vocational & Technical Training Commission (NAVTTC) – skill certification compliance
- State Bank of Pakistan (SBP) Payment Regulations – financial data processing
- Consumer Protection Acts (Federal & Provincial) – relating to service quality and liability
2.2 International Frameworks
- EU GDPR – Articles 6, 9, 13, 17 – for cross-border data or where applicable
- UAE Federal Decree-Law No. 45 of 2021 (PDPL) – for GCC operations
- ILO Guidelines on Privacy in the Workplace – gig and trade worker protections
- ISO/IEC 27001 – Information Security Management Standard
2.3 Lawful Bases
- Contractual Necessity – fulfilling the Service Worker Agreement and enabling bookings
- Legal Obligation – tax reporting, labour law compliance, background verification
- Legitimate Interests – fraud prevention, Customer safety, platform integrity
- Consent – marketing, optional profile features, skill certifications display
- Vital Interests – emergency safety situations during on-site service delivery
3. DATA WE COLLECT FROM SERVICE WORKERS
3.1 Identity & Registration Data
- Full legal name as on CNIC
- CNIC number and verified copy (front and back)
- Date of birth and gender
- Profile photograph (professional, clear, recent)
- Home address and current residential address
- Emergency contact name, relationship, and mobile number
3.2 Professional & Trade Data
- Primary service category and sub-categories (e.g., Electrician > Industrial Wiring)
- Years of experience in trade or profession
- Skill certifications and vocational qualifications (NAVTTC, C-DAC, City & Guilds, or equivalent)
- Tools and equipment ownership and type (for customer transparency)
- Service area – the geographic zones in which you are willing to accept bookings
- Availability schedule – days and hours you are available
- Portfolio or work samples (photos of completed work – optional but recommended)
- References or previous employer details (optional)
3.3 Contact & Location Data
- Primary mobile number (verified via OTP)
- Alternate contact number (optional)
- Email address (optional)
- Real-time GPS location – ONLY when you are on an active booking and the app is open
- Service location – the Customer's address shared with you for active bookings only
- Travel route to booking location (during active booking for Customer tracking)
3.4 Financial & Earning Data
- Bank account details (account title, IBAN, bank name, branch code)
- JazzCash / Easypaisa account numbers
- Booking fee records, earnings, and platform commission deductions
- Payout history and settlement records
- Tax-related records (withholding tax, FBR reporting where applicable)
3.5 Performance & Activity Data
- Number of bookings accepted, completed, and cancelled
- Customer ratings (1–5 stars) and written reviews received
- Response time to booking requests
- Complaint and dispute records
- Platform penalty and disciplinary records
- No-show and late arrival incidents
- Active hours and session logs
3.6 Background Verification Data
- CNIC verification status (via NADRA)
- Criminal background check consent and result (clear / flagged)
- References verification status
- Skill certification verification status
3.7 Technical Data
- Device type, operating system, and app version
- IP address and login timestamps
- App session logs and crash reports
4. HOW WE USE SERVICE WORKER DATA
4.1 Core Platform Operations
- Account creation, identity verification, and profile display to Customers on the Platform
- Smart Match – connecting you with Customers who need your specific skill category in your service area
- Booking management – processing, confirming, and tracking service bookings
- Sharing your real-time location with Customers during active bookings so they can track your arrival
- Calculating booking fees, processing payments, and settling your earnings
4.2 Safety & Customer Protection
- Conducting background checks (CNIC via NADRA, criminal record check) before and during registration
- Verifying skill certifications to protect Customers from unqualified service
- Monitoring for safety incidents and managing emergency responses during on-site bookings
- Maintaining a complete record of your professional conduct on the Platform
4.3 Compliance & Legal
- Identity verification and KYC (Know Your Customer) compliance
- FBR tax reporting for earnings above applicable thresholds
- Responding to valid law enforcement requests
- Maintaining audit trails as required by Pakistani law
4.4 Platform Improvement
- Analysing service quality and booking pattern data (aggregated, anonymised)
- Improving the Smart Match algorithm for better service-to-customer matching
- Developing new trade categories and service features based on demand data
4.5 Worker Development (With Consent)
- Notifying you of available training programmes, certifications, or upskilling opportunities
- Highlighting high-performing workers for promotional placement on the Platform
5. REAL-TIME LOCATION – SERVICE WORKER SPECIFIC PROVISIONS
Location data for Service Workers is handled with special care given the in-person nature of your work:
- Your live location is shared with the booking Customer ONLY during the active booking period – from the time you accept and confirm travel until the job is marked complete
- Customers see your approximate location and ETA while you are en route to their premises
- Your home address is NEVER shared with Customers
- Your location is NOT tracked when you are offline or between bookings
- We do NOT share your location with advertisers or any commercial third parties
- Location data for active bookings is retained for 90 days for dispute resolution purposes, then deleted
6. DATA SHARING & DISCLOSURE
6.1 Within Platform Ecosystem
- Customers – your professional name, profile photo, service category, ratings, service area, and live location during active bookings
- Platform administrators – for dispute resolution, safety investigations, and quality management
6.2 Third-Party Service Providers
- Payment Processors – JazzCash, Easypaisa, 1Link for earnings disbursement (under DPAs)
- Cloud Infrastructure – AWS or equivalent for secure data hosting
- SMS/OTP Providers – account verification and booking alerts
- Background Check Partners – NADRA-authorised channels for CNIC and criminal check
- Skill Certification Verifiers – NAVTTC or equivalent bodies for qualification verification
6.3 Legal & Regulatory Disclosure
- FIA Cyber Crime Wing – upon valid legal order
- FBR – earnings data per tax law
- Provincial Labour Departments – worker rights and compliance matters
- Courts of competent jurisdiction – per valid court orders
- Emergency services – in life-threatening situations during on-site service
6.4 What We NEVER Share
- Your home address is NEVER shared with Customers
- Your CNIC details are NEVER shared publicly
- Your bank account or financial details are NEVER shared with Customers
- Your personal mobile number is masked in Customer-facing communications
7. DATA STORAGE, SECURITY & RETENTION
7.1 Security Measures
- AES-256 encryption for data at rest | TLS 1.3 for data in transit
- Background check results stored in a segregated, access-controlled secure vault
- Role-based access controls – staff access your data only on need-to-know basis
- Regular third-party security audits and penetration testing
7.2 Retention Schedule
- Identity data (CNIC, background check): 5 years post-account closure (legal requirement)
- Financial / earnings records: 7 years (FBR and tax law requirements)
- Booking and service records: 3 years
- Real-time GPS logs (active bookings): 90 days
- Customer reviews and ratings: permanent (part of your professional profile)
- Penalty and disciplinary records: 3 years
- Inactive accounts: data reviewed after 2 years of inactivity, deleted after 90-day notice
8. SERVICE WORKER RIGHTS
8.1 Your Rights
- Access – request a full copy of all data we hold about you (workers@apnakaam.pk)
- Rectification – correct inaccurate professional or personal data through the Worker App or support
- Erasure – request account deletion (subject to legal retention periods for financial/identity data)
- Portability – receive your profile, booking history, and earnings data in JSON/CSV format
- Object – object to profiling used for booking ranking or marketing
- Restrict Processing – request data use limitation during dispute investigation
- Withdraw Consent – cancel optional consents (marketing, skill certification display) any time
- Automated Decision Review – any automated account action (suspension, penalty above PKR 500) triggers right to human review within 15 days
- Non-Retaliation – exercising privacy rights will not reduce your booking priority or rating
8.2 Background Check Rights
- You will be informed of the outcome of your background check before onboarding completion
- If your application is rejected based on background check results, you have the right to request the reason and to submit a formal appeal
- Background check data is processed only by NADRA-authorised channels and is not accessible to platform operations staff
Contact: privacy@apnakaam.pk | workers@apnakaam.pk | Response: 30 days
9. AUTOMATED DECISION-MAKING & SMART MATCH
- Booking Match Algorithm – assigns customer bookings based on your service category, location, availability, ratings, and response time
- Performance Scoring – automatically calculates your worker score from booking metrics
- Fraud Detection – flags unusual patterns in booking behaviour
- Penalty System – automatic flag for no-shows, late arrivals, or misconduct
Algorithmic transparency: your performance score is visible in the Worker App at all times. Any automated penalty above PKR 500 or account action triggers an automatic right to human review. You may contest any automated decision within 15 days of notification.
10. GIG WORKER PROTECTIONS & COMMITMENTS
- We will not use your data to restrict you from working on other platforms
- We will not share your performance data with non-platform third parties without your explicit consent
- We provide transparent performance metrics so you understand how your score is calculated
- We comply with any future Pakistani legislation regarding gig economy worker rights and data protections
- We inform you of any government inquiry specifically relating to your individual profile, within the limits of the law
11. FRANCHISE / CITY OPERATOR ACCESS
In Franchise cities, City Operators may access your name, contact, active/inactive status, and general performance metrics for their city only. They are strictly prohibited from accessing CNIC details, financial data, sharing your data with third parties, or retaining your data after their Franchise Agreement ends.
12. DATA BREACH NOTIFICATION
- Affected workers notified within 72 hours of a confirmed breach
- Notification details: data type affected, likely consequences, remedial steps taken
- Significant breaches reported to relevant Pakistani authorities as required by law
- If financial data is compromised, we coordinate with payment processors to protect your accounts
13. DISPUTE RESOLUTION & CONTACT
13.1 Internal
- Step 1: workers@apnakaam.pk or grievance@apnakaam.pk – response within 48 hours, resolution within 30 days
- Step 2: Escalate to DPO at dpo@apnakaam.pk
13.2 External
- Pakistan Telecommunication Authority (PTA) | FIA Cyber Crime Wing | Provincial Labour Departments | Consumer Protection Courts
13.3 Contact
Service Worker Support: workers@apnakaam.pk
Privacy: privacy@apnakaam.pk
DPO: dpo@apnakaam.pk
Safety: safety@apnakaam.pk
Document ID: APNAKAAM-PP-WORKER-V2.0-2025
By registering or using any part of the Apna Kaam Platform, you acknowledge that you have read, understood, and agreed to the applicable Privacy Policy contained in this document.
Apna Kaam | One Tap, It’s Done | www.apnakaam.pk | privacy@apnakaam.pk
