Legal

Privacy Policy

How UniVenture Solutions handles information when you visit, create an account, or use DI Gateway.

Effective date: 7 August 2026
Last updated: 8 August 2026

This Privacy Policy explains how UniVenture Solutions (SMC Private Limited) (we, us, or our) collects, uses, discloses, protects, and retains personal information when operating DI Gateway, including the public website at digateway.pk, user accounts, support channels, and the DI Gateway FBR Digital Invoicing service (together, the Service).

DI Gateway is independent software. It is not affiliated with, endorsed by, or operated by Pakistan's Federal Board of Revenue (FBR). FBR processes information under its own legal authority and policies.

1. Who is responsible for information

UniVenture Solutions (SMC Private Limited) operates DI Gateway and is responsible for account, website, security, service-administration, and support information collected for its own operational purposes.

For company, customer, item, sales-invoice, and related business information submitted by a customer organization, that organization decides why the information is used and remains responsible for having authority to provide it. UniVenture Solutions (SMC Private Limited) processes that information to provide the Service and follow the organization's authorized instructions.

Privacy questions and requests may be sent to privacy@digateway.pk. General support requests may be sent to support@digateway.pk.

2. Information we collect

Depending on how the Service is used, we may collect:

  • Account and contact information: name, email address, Pakistan mobile number in normalized international format, authentication/verification records, organization membership, role, support preferences, and account status.
  • Organization and taxpayer information: business name, address, province, registration status, NTN, CNIC where legitimately required, business activity, sector, and authorized FBR environment details.
  • Invoice and business records: customer and item records, HS Codes, UOMs, tax details, invoice dates and values, invoice lines, FBR scenarios, validation results, FBR-issued references, submission status, and activity history.
  • Integration credentials: Sandbox or Production tokens and related technical credentials needed to connect the Service with FBR. These credentials are restricted from ordinary public display and must not be submitted through public forms or email.
  • Support information: messages, files, diagnostic details, and correspondence provided when support is requested.
  • Technical and security information: IP address, device and browser information, session identifiers, timestamps, route and error information, security events, and audit records needed to operate and protect the Service.
  • Website information: pages requested, referrer and basic server logs. The launch website uses essential cookies for authentication and security. Non-essential analytics or advertising cookies will not be enabled without updating this Policy and implementing any required notice or consent.

We do not intentionally request payment-card details through the current Service. If paid plans are introduced, payments should be handled by an identified payment provider and the applicable disclosures will be updated before collection begins.

3. How information is collected

We collect information:

  • directly from account holders, customer organizations, and their authorized users;
  • automatically from browsers, devices, servers, and security systems when the Service is used;
  • from FBR or related government systems when the Service submits, validates, or retrieves a result on an authorized user's instructions; and
  • from service providers and professional advisers when reasonably necessary for security, support, legal, or operational purposes.

4. Why we use information

We use information to:

  • create and administer accounts, organizations, workspaces, and permissions;
  • provide company setup, customer and item records, invoice preparation, validation, transmission, response handling, retry, and activity-history features;
  • transmit authorized invoice information to the active FBR environment and return the resulting status or reference;
  • authenticate users, prevent unauthorized access, detect abuse, investigate incidents, and preserve auditability;
  • provide support, respond to enquiries, and troubleshoot the Service;
  • maintain, test, monitor, and improve reliability and usability;
  • communicate service, security, policy, and administrative notices;
  • comply with applicable legal, tax, regulatory, court, and law-enforcement obligations; and
  • establish, exercise, or defend legal rights.

Our reasons for processing include performing the Service agreement, following authorized customer instructions, meeting legal obligations, protecting legitimate security and operational interests, and obtaining consent where consent is appropriate.

5. When information is shared

We may disclose only the information reasonably necessary to:

  • FBR and related government systems: to validate or transmit digital invoices and receive results on an authorized user's instructions.
  • Infrastructure and service providers: providers supporting hosting, storage, backups, email delivery, security, monitoring, and customer support, subject to appropriate confidentiality and data-handling obligations.
  • Professional advisers: lawyers, accountants, auditors, insurers, and consultants who require the information for legitimate professional work.
  • Authorities and legal recipients: where disclosure is required by applicable law, a valid legal process, regulatory obligation, or a necessary response to fraud, security threats, or harm.
  • Business-transfer recipients: in connection with a merger, acquisition, financing, reorganization, or sale of relevant assets, subject to confidentiality and continued protection of the information.

We do not sell personal information. We do not permit a service provider to use customer invoice information for its own advertising.

6. International processing

Some infrastructure or service providers may process information outside Pakistan. Where that occurs, we will use reasonable contractual, security, and access safeguards appropriate to the information and the applicable legal requirements. Customers requiring a specific hosting location or transfer arrangement must agree that requirement with us in writing before using the Service for affected data.

7. Retention and deletion

We retain information only for as long as reasonably required to provide the Service, maintain security and audit records, comply with legal or tax-document retention obligations, resolve disputes, and enforce agreements.

Retention periods depend on the record type. Account and workspace information is generally retained while the account is active and for a reasonable period afterward. Invoice, FBR response, audit, and security records may need to be retained longer where required by law, contract, a legal hold, or legitimate fraud-prevention needs. Backups are removed through controlled rotation rather than immediate deletion from every backup copy.

When an authorized customer requests account closure, we will explain available export and deletion steps. We may retain information that must be preserved by law, is necessary to document completed FBR submissions, or cannot yet be deleted from a protected backup. Any retained information remains subject to this Policy.

8. Security

We use administrative, technical, and organizational safeguards intended to protect information against unauthorized access, alteration, disclosure, or loss. These include role-based access, organization-level authorization, restricted credentials, audit records, environment separation, backup controls, and secure transport where supported by the deployed service.

No internet service is completely secure. Customers must protect account credentials, restrict access to authorized personnel, maintain accurate organization membership, and promptly report suspected compromise to support@digateway.pk.

9. Your choices and requests

Subject to applicable law, contractual responsibilities, and the rights of other people, an individual may request:

  • confirmation of whether we hold their personal information;
  • access to or correction of inaccurate information;
  • deletion of information no longer required;
  • a usable export of information associated with their account;
  • restriction of or objection to particular processing; or
  • withdrawal of consent where processing depends on consent.

Requests should be sent to privacy@digateway.pk. We may verify identity and authority before acting. Requests involving a customer organization's invoice or customer records may be referred to that organization. Some requests may be limited where retention or processing is required for tax, legal, security, audit, or FBR-submission purposes.

Service emails needed for account, security, invoice-operation, or policy administration cannot be opted out of while the relevant account remains active. Optional marketing messages, if introduced, will provide an unsubscribe method.

10. Cookies

DI Gateway uses cookies and similar browser storage that are necessary for authentication, session continuity, security, and requested functionality. We do not currently place third-party advertising cookies on the public website. If optional analytics are introduced, we will identify the provider, purpose, retention, and available consent or opt-out controls before activation.

11. Children

The Service is intended for businesses and adults authorized to act for them. It is not directed to children, and we do not knowingly collect personal information from a child through the public website. Contact privacy@digateway.pk if information is believed to have been submitted by a child without proper authorization.

12. FBR and third-party services

FBR systems, government portals, and third-party websites operate under their own terms and privacy practices. This Policy covers UniVenture Solutions and DI Gateway; it does not control how FBR or another independent third party processes information after lawful transmission to that party.

13. Changes to this Policy

We may update this Policy to reflect changes in the Service, law, providers, or data practices. The updated version will show a new effective or last-updated date. Where a change materially affects existing users, we will provide reasonable notice through the Service, email, or another appropriate channel.

14. Contact

UniVenture Solutions (SMC Private Limited)
Haripur City, Haripur, Khyber Pakhtunkhwa, Pakistan
Privacy: privacy@digateway.pk
Support: support@digateway.pk