Pak E-Stamp
Document security

Data Handling Policy

How PakEstamp approaches document data minimisation, access, storage, retention, secure processing and incident handling.

Last updated: 25 August 2026

Data minimisation

PakEstamp should request only information reasonably necessary to understand, prepare, process, deliver or support the customer's e-stamp request.

Sensitive document information

Legal-document workflows may involve names, CNIC details, addresses, transaction values, property information and copies or extracts of supporting documents. Customers should send information only through PakEstamp's designated channels and avoid sharing unrelated sensitive information.

Access controls

Customer records and documents should be accessible only to authorised personnel and approved service providers who require access for processing, payment confirmation, delivery, support, security or compliance.

Storage and transfer

Where third-party platforms are used for messaging, hosting, analytics, payment confirmation or delivery, information may be processed under those providers' own security and privacy terms. PakEstamp should avoid placing confidential document contents in public website code, public links or unsecured shared folders.

Retention and disposal

Documents and related records should be retained only as long as reasonably necessary for service delivery, legitimate record-keeping, dispute handling, fraud prevention and applicable legal obligations, after which they should be deleted, anonymised or securely disposed of where appropriate.

Incident handling

If PakEstamp becomes aware of a material security incident affecting customer information, it should investigate, contain the issue, preserve necessary records and notify affected parties or authorities where required by applicable law.

Questions about how a specific order's information is handled can be sent to info@pakestamp.com.