Legal
Privacy Policy
What Ahmedonics collects when you use this website, the Hub and our products, why we collect it, who else sees it, how long we keep it and how to ask us about it.
Who we are
Ahmedonics Technologies (Private) Limited ("Ahmedonics", "we") is an engineering technology company registered in Pakistan. We run the website at ahmedonics.com and the Hub, the platform behind it that we and our clients use for projects, files, invoices, support and paperwork. We decide how the information described on this page is used, and you can reach us about any of it at contact@ahmedonics.com.
This policy is written in plain language on purpose. Where it says we do something, the code that runs this site does it; where we have not made a decision yet, it says so rather than promising something we cannot show.
What this policy covers
- The public website, including the free engineering tools and guides and the downloads page.
- The Hub (
/hub/): client portal accounts, staff accounts and everything they hold — projects, files, quotations, invoices, payments, support tickets and documents sent for signature. - Links we send you that need no account: shared files and folders (
/s/…), deliveries and downloads (/d/…) and signing pages (/sign/…). - The Hub API, the MCP endpoint and OAuth connectors that let assistants and other software work with a Hub account on its owner's behalf.
- The update and licensing services that software and hardware products we ship call home to.
Hosted cloud products run under their own brand carry their own privacy notice on their own site; the commitments on our cloud page apply to all of them as a minimum. Information about our employees and job applicants is handled under internal HR policies, not this page.
What we collect, and why
Browsing the website
Reading a page sends us nothing beyond what every web server records: your IP address, the time, the address requested and your browser's identification string. Those server logs exist for security and fault-finding. We run no analytics service and no advertising, and we set no tracking cookies. The engineering tools calculate entirely inside your browser: the numbers you type are never sent to us.
Contact enquiries
The contact form asks for your name, e-mail address, what the enquiry is about and your message, with company and phone number optional. With it we record the technical context of the submission — your IP address and browser, the page you first landed on, the site that referred you and any campaign parameters (utm_…) in the link you followed — so that we can reply, follow the enquiry up as a sales lead in our CRM and see which pages bring genuine enquiries. The message is e-mailed to our team and stored as a lead in the Hub. Submissions our spam filter drops are not stored: only a line in the server log (address and reason) records the attempt.
Client accounts
Creating an account, on the site or at our invitation, records your name, e-mail address, company and phone number (optional) and a password, which is stored only as a salted Argon2id hash. We confirm the address by a link sent to it. While you use the account we keep sign-in history (time, IP address, browser and outcome), your active sessions, and, if you switch them on, an encrypted authenticator secret and hashed recovery codes for two-factor authentication, hashed personal API tokens and the connected applications you have authorised. You can see your sessions and sign-in history under My account.
Projects, files, invoices and payments
Working with us means a client record: the company or individual, its contacts, billing and shipping addresses, tax and registration numbers, and our notes. Around it sit the quotations, invoices and payment records we issue — for a payment, how you paid (bank transfer, cheque, cash or card), the amount, date and reference. We do not take card payments through this website and never see or store card numbers. Projects hold their status, members, the files we share with you (name, versions, checksums, who uploaded what and when), and the files you upload when your record allows it. A delivery sent to you by link is logged when it is downloaded, so we know it reached you; files on the public downloads page are only counted.
Support tickets
A ticket holds its subject, every message, the project it concerns and any attachments. We e-mail the other side whenever a public message is added; our internal notes stay internal.
Documents sent for electronic signature
When we send a contract, agreement or approval for signature, the signing page records the name you type as your signature, the e-mail address the confirmation code was sent to, the time, the IP address and browser used and the consent you gave. Some documents also ask for identity details — a CNIC number, phone number and, for witnesses, a postal address — because the document needs them. The frozen text, its events and the sealed PDF are kept as the record of what was signed.
Shared links
Every view, download and wrong password on a shared link is logged with the IP address and browser, so that the person who created the link can see how it was used and so that misuse can be traced.
Installed products and devices
Software we license activates by sending its product identifier, the licence key, the operating system, a random installation identifier generated on your machine, an optional device fingerprint hashed on your machine before it leaves, the device name and the application version. Checking for updates sends the product, current version, platform, architecture, update channel, the same installation identifier and, for hardware, its revision and serial number; after an update the product reports whether it succeeded. This is what lets us count seats, deliver the right build and roll updates out gradually. Devices we supply for attendance or monitoring send the events they exist to record, to the customer that operates them.
The API and connectors
Every action taken through a personal API token or a connected application is written to the audit log under the account that authorised it, with the time and IP address, exactly as if it had been taken in the browser.
Visiting our premises
Visitors are signed in with a name and, optionally, company, phone number, purpose and the person they are visiting, so that we know who is in the building.
Why we are allowed to use it
We use information because you asked us for something (an enquiry, an account, a download), because we have a contract with you or your organisation and need it to do the work and get paid, because we need it to keep the service secure and working, or because the law requires us to keep records — accounting and tax records in particular. We do not use your information for advertising, and we do not sell it or rent it to anyone.
Who else sees it
We keep processing inside our own systems wherever we can. The organisations that may handle information on our behalf are:
- Our hosting provider, whose servers run the website, the Hub, its database and its backups.
- E-mail delivery: messages such as confirmation links, password resets, ticket updates and invoices are sent from our own domain through our hosting provider or a mail relay we have configured.
- Cloudflare Turnstile, when it is switched on for the contact and registration forms: Cloudflare receives your IP address and browser signals to tell people from bots. Nothing from the form itself goes to Cloudflare.
- Google Drive, when the mirror is connected: copies of Hub files (project files, deliveries, downloads, engineering files, company documents, receipts and payment proofs) are kept in our Google Drive as a second copy. The Hub remains the authoritative store.
- ClickUp, our task system: when we create a task from an enquiry, the contact details and message are copied into that task.
- Object storage compatible with Amazon S3, when configured, for files and backup copies.
- Banks, professional advisers and authorities, to the extent needed to receive your payment, to take advice or to comply with a legal obligation.
Each of these services is switched on deliberately in the Hub's settings, and only the information that service needs leaves us. The signed-in owner can see which are active. Some of these providers operate outside Pakistan; where they do, we rely on their published privacy and security commitments.
Cookies and local storage
We use no analytics or advertising cookies, which is why this site shows no cookie banner. What we do set:
| Name | When | Purpose and lifetime |
|---|---|---|
ahub | Only when you sign in to the Hub | Your session. HttpOnly, Secure and SameSite; ends after two hours without activity or twelve hours in total, or when you sign out. |
sh… | Only after you enter the password on a protected shared link | Remembers that you unlocked that one link so you are not asked again; limited to /s/; gone when you close the browser. |
ahmedonics.attribution (local storage, not a cookie) | On your first visit | The page you landed on, the referring site and any utm_… parameters, kept in your own browser and read only if you later send the contact form, so we know which page brought the enquiry. Nobody else can read it; clear your browser's site data to remove it. |
Cloudflare Turnstile, when enabled on a form, may set its own cookie or local storage under challenges.cloudflare.com as part of its check; see Cloudflare's privacy policy. If we ever add analytics or advertising we will update this section first and, where the law requires it, ask before setting anything.
How long we keep it
The rule is: as long as the purpose above needs it, then as long as the law requires, then gone. Some of these periods are already enforced by the software; others are decisions we review by hand and have not yet turned into automatic deletion.
- Sessions are deleted when they expire. Confirmation and password-reset links are deleted a week after they are used or expire. Rate-limit counters are deleted when their window ends.
- Database backups are kept for fourteen days on a rolling basis, plus the copies our hosting provider keeps.
- Enquiries stay in our CRM while there is a prospect of working together; archived enquiries remain in the database until we purge them on review.
- Accounts and their sign-in history are kept while the account is active and, after it is disabled, for as long as the audit trail of what it did needs to make sense.
- Quotations, invoices, payments and signed documents are business and tax records and are kept for the period Pakistani law requires; signed documents and their event trail are never deleted, because their value is that they cannot be altered.
- Files are versioned and never overwritten; a file is removed when the project or record it belongs to is closed out and we no longer have a reason to hold it.
- Audit and security logs (who did what, sign-in attempts, shared-link access) are kept for as long as they are useful for security investigation; we have not yet fixed a deletion schedule for them.
You can ask us to delete information about you at any time (below); we will do so unless one of the record-keeping reasons above prevents it, and we will tell you which.
How we protect it
Everything travels over HTTPS. Passwords are hashed, credentials and secrets are encrypted at rest, tokens and licence keys are stored only as hashes, and files live outside the web root under random names and are streamed only after the request is authorised. Access is role-based with record-level rules, so a client sees only what is shared with them; sensitive actions are written to an append-only audit log; and two-factor authentication is available to every account. Our security page describes these controls in detail, and responsible disclosure explains how to tell us about a weakness.
Your choices and rights
Whatever law applies to you, we offer the same to everyone:
- See what we hold about you and correct it.
- Get a copy of your information in a usable format.
- Delete it, or close your account, subject to the records we must keep.
- Object to a particular use, or withdraw a consent you gave.
Ask by e-mail to contact@ahmedonics.com, from the address on your account where possible, or open a support ticket in the Hub. We will confirm who you are before acting, acknowledge within one working day and tell you how long the rest will take. If you are a contact of a client organisation rather than the client yourself, we may need to involve that organisation.
Some things you can do yourself under My account in the Hub: change your password, switch two-factor authentication on or off, sign out other devices, revoke API tokens and connected applications, and choose whether to receive the daily digest. Name and e-mail changes go through us so that records stay consistent.
Children
Our services are for businesses and for adults acting for them. We do not knowingly collect information from anyone under eighteen; if you believe we have, tell us and we will delete it.
Changes to this policy
When we change what we collect or how we use it, we change this page first and update the date at the top. For changes that matter to account holders — a new category of information, a new processor, a new use — we also e-mail the address on the account before the change takes effect.
Contact
Questions, requests and complaints about privacy: contact@ahmedonics.com with "Privacy" in the subject, or the contact page. If you are not satisfied with our answer you may also complain to the authority responsible for data protection where you live.