Effective Date: 4 August 2026 | Last Updated: 4 August 2026
This Privacy Policy explains how SolutionByz ("we", "us", "our"), operating solutionbyz.com, collects, uses, shares, and protects personal information when you visit our website, enquire about our services, or use the digital products, software, tools, APIs, and subscription services we provide.
We serve clients internationally, and this policy is written to be compatible with the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Please read it together with our Cookie Policy and Terms of Service.
1. Our Role: Controller and Processor
We act in two distinct capacities depending on the context.
As a controller, we determine how and why personal data is processed — for example, data about our website visitors, prospects, clients, and contacts.
As a processor or service provider, we handle personal data on behalf of a client under their instructions — for example, when we manage a client's advertising account, build or host their website, operate their CRM integrations, or run automation workflows on their systems. In those cases the client is the controller and their own privacy notice governs the processing. This Privacy Policy describes our activities as a controller.
2. Information We Collect
2.1 Information You Provide
- Contact and identity data: name, business name, job title, email address, phone and WhatsApp number, country
- Enquiry and project data: details of your business, goals, budget, and requirements shared in forms, calls, proposals, and correspondence
- Account data: username and credentials where we provide a dashboard, portal, or application
- Transaction data: billing name and address, invoices, purchase history, subscription and renewal records. Card details are collected and processed directly by our payment providers — we do not store full payment card numbers
- Content you supply: brand assets, copy, images, product data, and any files or credentials you provide for a project
- Communications: messages sent by email, contact form, WhatsApp, chat, or during support and consultation
2.2 Information Collected Automatically
- Device and usage data: IP address, browser type and version, operating system, device identifiers, referring URLs, pages viewed, time on page, and interaction events
- Cookie and tracking data: identifiers set by cookies, pixels, and similar technologies — see our Cookie Policy
- Log and diagnostic data: server logs, error reports, API request metadata, and security event records
- Approximate location: derived from IP address at country or city level
2.3 Information from Third Parties
We may receive information from advertising and analytics platforms, lead generation sources, publicly available business directories, social media platforms, referral partners, and our payment processors. Where we receive data from third parties, we take reasonable steps to confirm it was lawfully obtained.
2.4 Sensitive Data and Children
We do not seek to collect special category or sensitive personal data, and we ask that you do not send it to us unless specifically required and agreed. Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal information from anyone under 16. If we learn that we have done so, we will delete it promptly.
3. How and Why We Use Your Information
We use personal information to respond to enquiries and provide quotations; deliver, maintain, and support our services and deliverables; create and administer accounts; process payments, invoices, subscriptions, and renewals; provide customer support; operate and secure our website and systems; detect and prevent fraud, abuse, and security incidents; analyse and improve our website, products, and service quality; send service and transactional communications; send marketing communications where permitted; maintain business records; and comply with legal, tax, and regulatory obligations.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to deliver services you have engaged us for, manage your account, and process payments
- Legitimate interests — to operate, secure, and improve our business, prevent fraud, conduct direct business-to-business marketing, and defend legal claims. We balance these interests against your rights and freedoms in each case
- Consent — for non-essential cookies, certain marketing communications, and any optional processing. You may withdraw consent at any time without affecting prior lawful processing
- Legal obligation — to comply with tax, accounting, and other statutory requirements
5. Marketing Communications
We may send you information about our services where you have consented or where we have a legitimate interest in contacting you in a business capacity. Every marketing email includes an unsubscribe link, and you may opt out at any time by using that link or emailing info@solutionbyz.com. Opting out of marketing does not stop essential service, billing, or security communications relating to an active engagement.
6. Cookies, Analytics and Advertising
We use cookies and similar technologies for essential site functionality, preferences, analytics, and advertising. Analytics providers include Google Analytics 4 and our e-commerce platform's built-in analytics. Advertising technologies may include Meta Pixel, Google Ads tags, TikTok Pixel, and comparable tools. Non-essential technologies are set only with your consent where consent is legally required, and you can change your preferences at any time. Full details are in our Cookie Policy.
7. Artificial Intelligence and Automated Processing
We use AI-assisted tools in parts of our work, including content generation, analysis, code assistance, and automation. Where we submit information to AI providers, we take reasonable steps to limit what is shared and to use providers that do not train their public models on our submissions, but we ask that you do not include sensitive personal data in materials sent to us. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Our AI-related disclaimers are set out in our Disclaimer.
8. How We Share Information
We do not sell your personal information for money. We share information only as described below:
- Service providers and sub-processors acting on our instructions — including hosting and cloud infrastructure, our e-commerce platform, email and CRM tools, analytics providers, payment processors, accounting software, communication platforms, and AI service providers. These parties are bound by contract to protect the data and use it only for the services they provide to us
- Advertising and analytics platforms — including Meta, Google, TikTok, and LinkedIn, where you have consented to advertising technologies
- Clients — where we act as a processor, information is returned to or held for the relevant client controller
- Professional advisers — lawyers, accountants, insurers, and auditors, under duties of confidentiality
- Legal and regulatory — where disclosure is required by law, court order, or to establish, exercise, or defend legal claims, or to protect rights, property, or safety
- Business transfers — in connection with a merger, acquisition, reorganisation, or sale of assets, subject to equivalent protection
Please note that some sharing of identifiers with advertising platforms for cross-context behavioural advertising may be treated as a "sale" or "sharing" under California law. See Section 12 for your opt-out rights.
9. International Data Transfers
We operate from Pakistan and use service providers located in the United States, the European Union, and other jurisdictions. Consequently, personal data may be transferred to and processed in countries whose data protection laws differ from those of your country of residence. Where personal data originating in the European Economic Area or the United Kingdom is transferred to a country without an adequacy decision, we rely on appropriate safeguards — principally Standard Contractual Clauses, supplemented by additional technical and organisational measures where required. You may request further information about these safeguards using the contact details below.
10. Data Retention
We retain personal information only for as long as necessary for the purposes described in this policy, or for as long as required by law. In general: enquiry data from prospects who do not become clients is retained for up to 24 months; client project records, contracts, and correspondence are retained for the duration of the engagement and for up to 7 years afterwards to meet contractual, tax, and legal requirements; financial and invoicing records are retained for the period required by applicable tax law; marketing contact data is retained until you unsubscribe or become inactive; and website analytics data is retained according to the settings of the relevant analytics platform. When information is no longer needed, we delete it or irreversibly anonymise it.
11. Your Rights Under GDPR
If you are located in the European Economic Area or the United Kingdom, you have the right to: request access to your personal data and a copy of it; request rectification of inaccurate or incomplete data; request erasure of your data in certain circumstances; request restriction of processing; object to processing based on legitimate interests, including direct marketing profiling; request portability of data you provided to us in a structured, machine-readable format; withdraw consent at any time; and not be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, contact us using the details in Section 15. We will respond within one month, which may be extended by a further two months for complex requests, and we will tell you if an extension applies. We may need to verify your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive. You also have the right to lodge a complaint with your local supervisory authority — in the United Kingdom, the Information Commissioner's Office — although we would appreciate the opportunity to resolve your concern directly first.
12. Your Rights Under CCPA and CPRA
If you are a California resident, you have the right to: know what categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties to whom it is disclosed; delete personal information we hold about you, subject to legal exceptions; correct inaccurate personal information; opt out of the sale or sharing of your personal information, including for cross-context behavioural advertising; limit the use and disclosure of sensitive personal information; and receive equal service and pricing without discrimination for exercising your rights.
We do not knowingly sell or share the personal information of consumers under 16 years of age. We honour recognised opt-out preference signals, including Global Privacy Control, as a valid opt-out request where legally required. You may designate an authorised agent to submit a request on your behalf, subject to verification. To submit a request, email info@solutionbyz.com with the subject line "California Privacy Request". We will confirm receipt within 10 business days and respond substantively within 45 days, extendable by a further 45 days where reasonably necessary.
13. Data Security
We implement appropriate technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss, or destruction. These include encryption in transit using TLS, access controls and the principle of least privilege, multi-factor authentication on administrative accounts, secure credential management, regular software updates, network and endpoint protection, and confidentiality obligations for personnel and contractors.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your own credentials confidential and for using strong, unique passwords. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals as required by applicable law and without undue delay.
14. Third-Party Websites
Our website may link to third-party sites and platforms. We are not responsible for their content or privacy practices, and this Privacy Policy does not apply to them. We encourage you to review the privacy notice of any site you visit.
15. Contact Us and Complaints
For any privacy question, to exercise your rights, or to raise a concern, please contact us:
SolutionByz
477C Johar Town, J Block, Lahore, Pakistan
Email: info@solutionbyz.com
Phone: +92 314 7574592
Website: solutionbyz.com
If you are in the EEA or UK and require a representative or data protection officer contact point, please write to the address above marked "Data Protection".
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technologies, or legal obligations. The revised version takes effect when posted on this page with an updated "Last Updated" date. Where changes are material, we will provide additional notice and, where required, seek fresh consent.
This Privacy Policy is provided for general informational purposes and does not constitute legal advice. We recommend having it reviewed by qualified legal counsel in each jurisdiction where you operate before relying on it.