Privacy Policy

Privacy Policy

1. Introduction

Gerry's Information Technology is an Internet Service Provider (ISP) licensed by the Pakistan Telecommunication Authority (PTA) under the Pakistan Telecommunication (Re-organization) Act, 1996. We are committed to protecting the privacy and security of our subscribers' personal data in accordance with applicable laws, including the Prevention of Electronic Crimes Act (PECA) 2016, the Critical Telecom Data and Infrastructure Security Regulations (CTDISR) 2025, and other directives issued by the PTA.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our internet and related services.

2. Data We Collect

To provide you with reliable internet services, we collect the following types of personal and traffic data:

  • Account Information: Name, CNIC/ID number, billing address, phone number, and email address required for service activation and invoicing.
  • Technical Data: IP address assigned to your connection, MAC addresses of devices, and connection logs.
  • Traffic Data: As required under Section 29 of PECA, we retain traffic data—which includes the origin, destination, route, time, duration, and type of service associated with your communication, primarily to identify the physical address (for fixed lines) or mobile number (for wireless services) used for the session.1
  • Usage Data: Data regarding the volume of data consumed for billing and network management.
  • Location Data: General location data to facilitate service delivery and lawful intercept requirements.

Note: We do not monitor the specific content of your communications (e.g., the websites you visit, search terms, or the contents of emails sent via webmail services like Gmail or Yahoo) unless required to do so for specific, legally mandated purposes.2

3. Legal Basis for Processing

We process your personal data to comply with legal obligations, including:

  • Regulatory Compliance: Meeting the data retention and security standards set forth by the PTA, including the CTDISR-2025.
  • Network Management: Ensuring the security, stability, and quality of our network.
  • Billing and Customer Service: Processing payments, responding to inquiries, and managing your account.
  • Lawful Interception: Complying with lawful requests from state-authorized security organizations, as mandated by our license terms.3

4. Data Localization and Storage

In compliance with the Critical Telecom Data and Infrastructure Security Regulations (CTDISR) 2025 and data localization directives, all personal data and critical telecom data of Pakistani users must be stored exclusively on servers located within the borders of Pakistan.4 We will not transfer your personal data to servers located outside of Pakistan without prior, explicit approval from the PTA.

Data Retention

We retain your data for the minimum period required by law, as stipulated under the Prevention of Electronic Crimes Act (PECA) for traffic data.5 We may retain data for longer periods if necessary to comply with legal proceedings or security investigations.

5. Data Security Measures

We implement robust security measures in compliance with the Zero Trust Security Model and CTDISR-2025 to protect your data:6

  • Encryption: Encryption of data at rest and in transit.
  • Access Control: Role-based access mechanisms and mandatory multi-factor authentication for all personnel accessing customer data.7
  • Cybersecurity Framework: We maintain a proactive cybersecurity governance framework, including Asset Management, Risk Management, and Insider Threat Detection.8
  • Incident Response: We have designated a Chief Information Security Officer (CISO). Any severe cyber incident that compromises your data will be reported to the PTA within 24 hours.9

Disaster Recovery

We maintain a disaster recovery and business continuity plan to ensure data integrity.


References

  1. Prevention of Electronic Crimes Act (PECA) 2016, Section 29.
  2. Applies only where disclosure is required under a lawful court order or PTA/security-agency directive.
  3. As mandated under PTA license terms and applicable law enforcement provisions.
  4. Critical Telecom Data and Infrastructure Security Regulations (CTDISR) 2025.
  5. Prevention of Electronic Crimes Act (PECA) 2016, data retention provisions.
  6. CTDISR-2025 cybersecurity and Zero Trust Security Model requirements.
  7. CTDISR-2025 access control provisions.
  8. CTDISR-2025 cybersecurity governance framework requirements.
  9. CTDISR-2025 incident reporting requirements (24-hour reporting window).