Effective date: 24 August 2026
This policy explains what personal data Asaan Digital (the βServiceβ), operated by Jawad Solutions (Private) Limited (βweβ, βusβ, or βourβ), collects, why we hold it, who we share it with, and what you can ask us to do about it. It applies to https://asaan-digital.com and to the Service. Terms used here have the meaning given in our Terms of Service.
Asaan Digital is an electronic invoicing platform. Its purpose is to submit sales tax invoices to Pakistani revenue authorities on your instruction, which means it necessarily handles tax identifiers and the details of your customers. This policy is specific about that, because a general statement would not tell you what you need to know.
For data about you as our customer β your account, your workspace, your billing β we decide why and how it is processed. We are the controller of that data, and this policy governs it.
For data about your customers β the buyers named on the invoices you file β you decide what to collect and what to file. We process it on your instruction and for no purpose of our own. You are the controller; we act for you. This policy tells you how we handle it, but your obligations to your own customers are yours, including telling them how their data is used.
Account data. Your name, email address, phone number, password (stored hashed, never in readable form), and any second-factor settings. If you sign in through another provider, we receive the basic profile that provider releases. We record when you were last active.
Business and tax registration data. Your workspace name, and the tax details you register: your NTN, STRN or PNTN, registered business name and address, province, registration type, business activity and sector, and whether you are a retailer.
Outlet data. For each outlet you register: its name and trade name, address, the authority and environment it files to, and its network identifiers where the authority requires them, such as a MAC address or IP address.
Authority credentials. The tokens, keys, and point-of-sale identifiers each revenue authority has issued to you. These are encrypted at rest. We use them only to transmit invoices and related requests on your instruction. We record which administrator changed a credential and when.
Usage and technical data. IP address, browser and device information, the pages you visit, and diagnostic data, so we can operate and secure the Service.
Every invoice you file may contain, depending on the transaction and the authority's requirements:
You may also save customers to reuse, which stores the same details plus an email address where you provide one. A CNIC identifies a person directly, so treat it accordingly: collect it only where the authority requires it for that transaction.
We also keep a submission log for each attempt to file: the request we sent, the response the authority returned, the status code, and how long it took. These logs contain the invoice contents, including buyer details. They exist so that a rejected or failed filing can be diagnosed and proven, and so that there is a record of what was sent to an authority and when.
We do not sell personal data. We do not use your data or your customers' data to train machine learning models. We do not use it for advertising or profiling, and we do not run behavioural advertising or remarketing of any kind.
Revenue authorities. Filing an invoice sends it to the authority you chose β FBR, PRA, or KPRA. This is the purpose of the Service. Once an authority receives an invoice, that authority holds it under its own rules, and we cannot withdraw or delete it.
Service providers. We use others to run the Service: hosting and infrastructure, email delivery, SMS delivery for phone verification, error and performance monitoring, and network connectivity for reaching authority endpoints. They may process personal data only on our instruction and only to provide their service to us.
Payment providers. Where a payment is taken online, it is handled by a payment provider and we never see or store your card number. At present, plans are arranged and paid for offline, so no online payment processor handles your data.
People you invite. Anyone you invite into your workspace β a colleague, accountant, or tax consultant β can see the data in it according to the role you give them.
Legal and corporate. We may disclose data where the law requires it, to respond to a valid request from a court or public authority, or to protect our rights, our users' safety, or the security of the Service. If the business is ever sold or merged, data may transfer to the buyer; we will tell you before it becomes subject to a different policy.
We never share one customer's workspace data with another customer.
The Service and its data are hosted in [hosting_country β to be completed] . Some service providers we rely on may process limited data outside that country; where they do, we take reasonable steps to ensure it stays protected to the standard described here.
After your account closes, your fiscal records stay available for export for at least 30 days so you can meet your own record-keeping obligations.
Authority credentials are encrypted at rest, so a database backup or replica that escapes the application does not hand over the ability to file in your name. Passwords are hashed. Access to production data is limited to staff who need it. Two-factor authentication is available and we recommend enabling it. Editing a live credential is locked by default and an administrator must open a time-limited window to change it, which we record.
No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and is likely to put you at risk, we will tell you and the relevant authority without undue delay.
We use cookies that are necessary to run the Service: to keep you signed in, to remember your preferences and language, and to protect against cross-site request forgery. Blocking these will stop parts of the Service working.
Where analytics are enabled, we use them only to understand how the Service is used in aggregate, never to advertise to you. You can control cookies through your browser settings. We do not currently respond to βDo Not Trackβ browser signals, as there is no agreed standard for how to do so.
You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict how we use it, or provide it in a portable electronic format. You can object to processing we carry out for our legitimate interests, and withdraw consent to marketing at any time.
Much of this you can do yourself: your account settings let you change your own details, and you can export your invoice records from the Service. For anything else, contact us at the address below. We may need to verify your identity first.
Two limits are worth stating plainly. We cannot delete an invoice already accepted by a revenue authority β it is held by that authority under its own rules. And we cannot delete fiscal records before the statutory retention period ends, because the law requires us to keep them.
If you are one of our customer's customers and want your data corrected or removed, contact the business that issued your invoice. They control that data; we act on their instruction.
The Service is for businesses and is not directed at children. You must be at least 18 years old to hold an account. We do not knowingly collect data from children, and will delete it if we find we have.
We may update this policy. If a change is material, we will tell you by email or a notice in the Service before it takes effect, and we will update the effective date at the top of this page.
For any question about this policy or to exercise a right described above:
Jawad Solutions (Private) Limited
[address β to be completed]
Email: support@asaan-digital.com