Privacy Policy

ROBLIE Properties Pakistan
Last Updated: [Date] Version: 2.0

Table of Contents

1. Introduction and Overview

1.1 Welcome Statement

ROBLIE Properties Pakistan (“ROBLIE Properties,” “we,” “us,” or “our”) is a premier real estate enterprise dedicated to facilitating property transactions with the highest standards of integrity, discretion, and professionalism. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you engage with our services, visit our website, mobile applications, or physical offices, or otherwise interact with us.

We understand that real estate decisions are among the most significant financial and personal commitments individuals and businesses make. The trust you place in us to handle your personal and financial details with care is a responsibility we honour through robust privacy practices, transparent communication, and continuous improvement of our data governance framework.

Important Notice: This document is a legal agreement between you and ROBLIE Properties Pakistan. By using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part, please discontinue use and contact us with your concerns.

1.2 Executive Overview

This Privacy Policy is structured to provide a comprehensive understanding of how ROBLIE Properties Pakistan manages personal data across the entire real estate lifecycle. It is designed to exceed the clarity and depth of privacy disclosures published by leading global technology firms, international banks, luxury developers, and multinational consultancies.

Key highlights include:

  • A detailed inventory of information we collect, specifically tailored to property buyers, sellers, investors, developers, landlords, and overseas Pakistanis.
  • An enterprise-grade cybersecurity framework explaining the administrative, technical, and organizational safeguards that may be deployed to protect your data.
  • A full data lifecycle map from collection to secure deletion.
  • A granular Cookie Policy that explains each category of tracking technology in practical terms.
  • Risk disclosure guidance to help you protect yourself against common cyber threats.
  • A dedicated section for international users explaining cross-border data handling.

Every major section follows a uniform structure: an executive summary, legal explanation, business rationale, customer-friendly interpretation, practical examples, frequently asked scenarios, best practices, important notices, risk considerations, compliance notes, security considerations, customer and company responsibilities, internal and third-party processing insights, and future scalability considerations.

1.3 Scope and Applicability

This Privacy Policy applies to all personal information collected by ROBLIE Properties Pakistan through:

  • Our official website ([www.roblieproperties.pk] – placeholder)
  • Mobile applications (if any)
  • Email communications
  • Telephone calls and in-person meetings
  • Property viewings, open houses, and site visits
  • Digital platforms including virtual tour and drone photography services
  • Third-party property portals where we maintain a presence
  • Social media interactions
  • Any offline forms, agreements, or documentation processed during property transactions

It covers the data of:

  • Prospective and active property buyers
  • Property sellers and landlords
  • Overseas Pakistanis and foreign investors
  • Corporate and institutional investors
  • Real estate developers and builders
  • Landowners
  • Tenants
  • Brokers and agents working with ROBLIE Properties
  • Website visitors and mobile application users
  • Individuals who submit inquiries, valuation requests, or offer submissions

The policy does not apply to information that has been anonymized or aggregated such that it can no longer identify an individual.

1.4 Guiding Principles

Our approach to privacy is anchored in the following principles:

  • Lawfulness, Fairness, and Transparency: We process personal data only where there is a valid legal basis, and we strive to communicate our practices openly.
  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data Minimization: We limit collection to what is adequate, relevant, and necessary for the intended real estate transaction or service.
  • Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date, particularly for property documentation and legal verification.
  • Storage Limitation: We retain data only for as long as required to fulfill the purposes, legal obligations, or business needs.
  • Integrity and Confidentiality: We implement appropriate security measures to protect against unauthorized access, loss, or destruction.
  • Accountability: We maintain records of processing activities and regularly review our data protection framework.

1.5 How to Read This Policy

This document is intentionally extensive to serve as a single source of truth for all privacy-related queries. We recognize that not every reader will need to review every section.

  • If you are a property buyer or seller seeking a quick understanding, start with the “Information We Collect” (Section 3) and “How We Use Your Information” (Section 4), then refer to the FAQ (Section 18).
  • If you are an overseas Pakistani or foreign investor, pay special attention to Section 7 (International Users) and the real estate-specific collection scenarios in Section 3.3.
  • If you are a developer or corporate investor, review Sections 3, 6 (Sharing and Disclosure), and 8 (Data Lifecycle) for details on due diligence data handling.
  • If you are concerned about online security, proceed directly to Section 9 (Data Security and Cyber Security) and Section 10 (Cookie Policy).
  • For our complete glossary of defined terms, see Section 17.

Customer-friendly Explanation: Think of this Privacy Policy as a detailed map of what happens to your information from the moment you first contact us until long after a transaction closes. Every piece of data has a journey, and we document each step so you can feel confident and in control.

2. Definitions and Glossary

To ensure clarity, key terms used throughout this document are defined in Section 17 (Glossary of Key Terms). We recommend reviewing that section if you encounter any capitalized or technical expressions. For convenience, a few foundational definitions are provided here:

  • Personal Information means any data relating to an identified or identifiable natural person. This includes name, CNIC/NICOP, passport number, contact details, financial information, property records, and digital identifiers.
  • Processing covers any operation performed on personal data, whether automated or manual, including collection, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
  • Data Controller refers to ROBLIE Properties Pakistan, which determines the purposes and means of processing.
  • Data Subject is the individual whose personal information is being processed.
  • Sensitive Personal Information includes biometric data, financial account credentials, and information revealing racial or ethnic origin, political opinions, religious beliefs, or health data where relevant to a property transaction (e.g., accessibility requirements).

A complete glossary with over 100 terms can be found in Section 17.

3. Information We Collect

3.1 Executive Overview

We collect a broad spectrum of personal information directly from you, automatically through technology, and from trusted third parties. The exact data points depend on your interaction type—whether you are browsing our luxury listings, scheduling a private site visit, submitting a formal offer, or engaging in anti-money laundering verification. This section itemizes every category with practical real estate illustrations, explaining the legal rationale, business necessity, and the protections applied at the point of collection.

3.2 Categories of Personal Information

Identity and Contact Information

  • Full legal name, aliases, family member names if jointly purchasing
  • CNIC, NICOP, passport number, and copies of identity documents
  • Date of birth, nationality, and place of birth
  • Residential address, mailing address, temporary accommodation details
  • Phone numbers, email addresses, social media handles
  • Signature specimens and photographs

Financial and Transactional Data

  • Bank account details, bank statements, proof of funds
  • Credit/debit card information (truncated after authorization)
  • Income tax returns, wealth statements, source of funds declarations
  • Payment history, outstanding balances, and escrow account details
  • Property valuation reports, mortgage pre-approval letters
  • Investment portfolio summaries for corporate investors

Property-Related Information

  • Property address, type, size, title deeds, and registration documents
  • Ownership history, inheritance certificates, succession certificates
  • Lease agreements, tenancy details, rental ledgers
  • Property photographs, drone footage, virtual tour recordings
  • Survey plans, architectural drawings, building permits
  • Zoning and land-use certificates

Verification and Due Diligence Data

  • Know Your Customer (KYC) documentation as required by applicable law
  • Anti-Money Laundering (AML) screening results
  • Politically Exposed Person (PEP) declarations
  • Credit bureau reports with explicit consent
  • Employment verification letters, business registration certificates
  • References from previous real estate agents or financial institutions

Communication and Preference Data

  • Email correspondence, chat logs, call recordings (with notice)
  • Meeting notes from property consultations
  • Feedback, survey responses, and testimonials
  • Marketing preferences, communication frequency choices
  • Property search criteria, budget ranges, preferred locations
  • Lifestyle preferences and amenity requirements where voluntarily provided

Technical and Usage Data

  • IP address, browser type, operating system, device identifiers
  • Website navigation patterns, pages viewed, time spent, clickstream data
  • Geolocation data if location services are enabled
  • Cookie identifiers and analytics tags (detailed in Section 10)

3.3 Real Estate–Specific Collection Scenarios

Because real estate transactions are highly specialized, we map data collection to specific activities. Below is a comprehensive breakdown:

Property Buyers

  • Identification for purchase agreements and title registration
  • Financial data to assess eligibility and facilitate mortgage arrangements
  • Spouse or co-buyer details for joint ownership
  • Power of attorney documents if representation is required
  • Offer price, negotiation terms, and closing documentation

Property Sellers

  • Proof of ownership, original title deed, chain of title documents
  • Outstanding utility bills, property tax receipts, and maintenance records
  • Occupancy certificate and building completion certificates
  • Disclosure of any encumbrances, liens, or disputes

Overseas Pakistanis

  • NICOP or passport for identity verification
  • Foreign bank account details and remittance documentation
  • Special tax declarations for non-resident status
  • Contact details of local representatives or family members
  • Property management preferences, including leasing mandates

Investors and Corporate Investors

  • Company registration certificate, memorandum, and articles of association
  • Board resolution authorizing the investment
  • Ultimate beneficial ownership (UBO) details
  • Audited financial statements and portfolio summaries

Developers and Builders

  • Project approvals from relevant development authorities
  • Contractor and consultant agreements
  • Marketing and sales collateral materials submitted for review
  • Land ownership or joint venture agreements

Landowners

  • Fard (revenue record), mutation register extracts
  • Demarcation certificates, land classification documents
  • No-objection certificates from relevant local bodies

Luxury Property Transactions

  • Additional confidentiality agreements
  • Art, jewelry, or furnishing inventories included in sale
  • Security personnel details for high-profile viewings
  • Private banker or wealth manager contact information

Property Valuation Requests

  • Property address and current photographs
  • Architectural plans and recent renovation details
  • Comparable market analysis data
  • Valuer’s access requirements and contact information

Property Photography, Drone Photography, and Virtual Tours

  • Scheduling information for on-site shoots
  • Consent forms for capturing identifiable features of adjacent properties
  • Privacy notices posted at the time of photography
  • Digital recordings of video walkthroughs that may include voices

Open House Events and Site Visits

  • Visitor logs with name, contact, and vehicle registration
  • Time-stamped entry and exit records
  • Health and safety declarations (if required by event protocol)
  • CCTV footage at the event location

Appointment Scheduling

  • Calendar integration data (if you sync with our system)
  • Preferred meeting mode (in-person, virtual, phone)
  • Accessibility or language preference notes

Property Documentation and Title Verification

  • Original and certified copies of legal documents
  • Verification reports from land registry or sub-registrar
  • Lawyer or notary public attestations

Due Diligence, Anti-Fraud, and AML/KYC

  • Full KYC file as mandated by the Anti-Money Laundering Act and regulations in Pakistan
  • Screening against sanctions lists and adverse media databases
  • Source of wealth and source of funds declarations with supporting evidence
  • Risk rating documentation

Offer Submissions and Negotiation Records

  • Written offers, counter-offers, and acceptance letters
  • Time-stamped records of all negotiation communications
  • Evidence of earnest money deposits

Closing Documentation

  • Final sale deed, transfer letters, and registration receipts
  • Tax withholding certificates and capital gains calculations
  • Commission agreements and brokerage settlement statements

Customer Relationship Management

  • Interaction history across all touchpoints
  • Property preferences, wish lists, and saved searches
  • Anniversary or milestone dates for relationship nurturing

Business Explanation: Each data point collected serves a direct business purpose—whether to fulfill a contractual obligation, comply with a legal duty, or enhance our luxury service experience. For instance, without verifying identity and title, we cannot legally facilitate a property transfer. Without understanding your investment criteria, we cannot present suitable opportunities.

Legal Explanation: Collection is based on one or more lawful grounds: performance of a contract, legal obligation, legitimate interest, consent, or protection of vital interests. For sensitive data, explicit consent or a specific legal authorization is required.

Customer-friendly Explanation: When you buy a property through ROBLIE Properties, think of the documents we request as the building blocks of a secure transaction. Just as you wouldn’t hand over keys without verifying the lock works, we ask for identity, financial, and ownership proofs to make sure everything is genuine and protected.

Practical Example: An overseas Pakistani interested in buying a luxury apartment in Karachi provides us with a scanned NICOP, bank statements from a Dubai-based account, and a power of attorney favoring a sibling in Pakistan. We use the NICOP to verify identity, the bank statements to meet AML requirements, and the power of attorney to allow the sibling to sign documents locally.

Important Notice: You are responsible for the accuracy of all information provided. Providing false or misleading information may result in termination of services, reporting to authorities, and potential legal liability.

Risk Considerations: Collecting extensive personal and financial data creates a high-value target for cybercriminals. We mitigate this through the security measures detailed in Section 9.

Compliance Notes: Our KYC and AML processes are designed to align with Pakistan’s Anti-Money Laundering Act, 2010, and regulations issued by the Securities and Exchange Commission of Pakistan (SECP) and State Bank of Pakistan where applicable to real estate intermediaries.

3.4 Automatically Collected Information

When you interact with our digital platforms, certain technical data is gathered automatically:

  • Log Data: Server logs recording IP address, timestamp, requested resource, HTTP status code, and user agent.
  • Device Information: Hardware model, operating system version, unique device identifiers, screen resolution.
  • Location Data: Approximate location derived from IP address; precise location only with explicit permission on mobile apps.
  • Usage Patterns: Navigation paths, search terms, listing views, time on page, interaction with virtual tours.

We use this data to diagnose technical issues, prevent fraud, and analyze user engagement to refine our luxury real estate offerings.

3.5 Information from Third Parties

We may receive personal information from:

  • Real estate portals where our listings appear
  • Referral partners, including international property consultants
  • Credit bureaus and background screening services
  • Government land registries and property databases
  • Banks and financial institutions for mortgage facilitation
  • Your authorized representatives (lawyers, accountants, wealth managers)

All third-party data is subject to validation and used only in accordance with this policy.

3.6 Sensitive Information

In limited circumstances, we may process sensitive personal information, such as:

  • Biometric data if required for identity verification at a government portal
  • Health information if you request accessible property features
  • Religious affiliation if relevant to property amenities (e.g., proximity to places of worship)

Sensitive data is only processed with your explicit consent or as mandated by law, and is subject to heightened security controls.

4. How We Use Your Information

4.1 Executive Overview

Every piece of personal data we collect serves a defined, legitimate purpose within the real estate ecosystem. We do not use your information in ways that are incompatible with the original purpose unless you are notified and, where required, consent is obtained. This section details the primary processing activities, from enabling property viewings to completing high-value closings, and explains the underlying business and legal justification for each use case.

4.2 Primary Purposes of Processing

  1. Service Delivery and Contract Fulfillment
  • Facilitating property purchases, sales, leases, and investment transactions
  • Drafting, reviewing, and executing contracts, agreements, and deeds
  • Coordinating with lenders, escrow agents, lawyers, and government offices
  • Managing commission payments and financial settlements
  1. Verification and Compliance
  • Conducting identity, ownership, and title verification
  • Performing anti-money laundering and counter-terrorism financing checks
  • Screening against sanctions lists and politically exposed persons databases
  • Complying with tax reporting obligations (e.g., withholding tax on property transfers)
  1. Communication and Client Support
  • Responding to inquiries, valuation requests, and offer submissions
  • Scheduling and confirming appointments, site visits, and open houses
  • Sending transaction updates, milestone reminders, and closing checklists
  • Providing post-sale property management support
  1. Personalization and Customer Experience
  • Tailoring property recommendations based on saved searches and preferences
  • Customizing communication content and frequency
  • Improving virtual tour, photography, and drone footage delivery
  1. Marketing and Business Development
  • Sending newsletters, market reports, and luxury property alerts (with consent where required)
  • Conducting customer satisfaction surveys and feedback collection
  • Organizing exclusive events for clients and investors
  • Analyzing market trends using aggregated data
  1. Security, Fraud Prevention, and Legal Protection
  • Monitoring for fraudulent activities, unauthorized access, and suspicious transactions
  • Protecting the rights, property, and safety of ROBLIE Properties, our clients, and the public
  • Enforcing our terms of service and other agreements
  • Establishing, exercising, or defending legal claims
  1. Research, Analytics, and Product Improvement
  • Analyzing website traffic and user behavior to optimize digital experiences
  • Developing new services, tools, and features for the real estate market
  • Generating anonymized statistical reports for industry insights

4.3 Real Estate Transaction Lifecycle Uses

To illustrate how these purposes manifest in practice, here is how your information flows through a typical transaction:

Pre-engagement Phase

Inquiry data → Response and qualification → Property shortlist → Customized presentation.

Due Diligence Phase

KYC documents → AML screening → Title verification → Legal review → Risk assessment.

Negotiation and Offer Phase

Offer details → Counter-offer communication → Earnest money receipt → Acceptance record.

Closing Phase

Final documentation → Fund transfer coordination → Registration → Handover.

Post-closing Phase

Warranty information → Property management onboarding → Relationship nurturing.

4.4 Marketing and Communications

We may send you promotional materials about properties, market insights, and ROBLIE Properties events. You can manage your preferences at any time by clicking the unsubscribe link in emails or by contacting us directly. Note that even if you opt out of marketing, we will still send transactional communications necessary for ongoing dealings.

4.5 Analytics and Service Improvement

Aggregated and anonymized data is used to understand market trends, such as demand for specific areas or property types. This data cannot be linked back to any individual and is used solely for strategic business decisions.

Internal Processing Explanation: All data use is governed by internal data handling policies. Role-based access controls ensure that only authorized personnel—such as your dedicated relationship manager, compliance officer, or legal team—can view full records. Regular training reinforces data minimization and confidentiality.

Third-Party Processing Explanation: When we engage external service providers (e.g., cloud hosting, email delivery, AML screening), they are contractually bound to process data only on our documented instructions and to implement equivalent security standards.

Future Scalability Considerations: As property technology evolves, we may integrate artificial intelligence for personalized property matching or augmented reality for virtual staging. Any such future processing will undergo a privacy impact assessment and, where necessary, will be disclosed with an opportunity to opt in.

5. Legal Bases for Processing

5.1 Executive Overview

Under applicable data protection principles, every processing activity must rest on a valid legal foundation. ROBLIE Properties Pakistan relies on one or more of the following legal bases: your consent, the necessity to perform a contract with you, our legitimate business interests, compliance with a legal obligation, or protection of vital interests. This section explains each basis and how it applies to real estate transactions.

5.2 Consent

Where we rely on consent—such as for sending marketing emails, placing non-essential cookies, or processing sensitive data—we ensure it is freely given, specific, informed, and unambiguous. You have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

5.3 Contractual Necessity

The vast majority of our processing is necessary for the performance of a contract or to take pre-contractual steps at your request. For example, verifying your identity is essential to draft a sale agreement; sharing your financial documents with a bank is necessary to facilitate a mortgage.

5.4 Legitimate Interests

We may process data for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. Legitimate interests include:

  • Network and information security
  • Fraud prevention and detection
  • Direct marketing to existing clients about similar properties (where permissible)
  • Business analytics to improve service offerings
  • Handling client inquiries and feedback

A balancing test is conducted and documented before relying on this basis.

5.5 Legal Obligation

Certain processing is mandated by Pakistani law, including:

  • Identity verification under AML/CFT regulations
  • Reporting suspicious transactions to the Financial Monitoring Unit (FMU)
  • Withholding and depositing taxes on property transfers
  • Retaining transaction records for prescribed periods (typically 5–6 years under the Income Tax Ordinance and Companies Act)

5.6 Protection of Vital Interests

In very rare circumstances, we may process data to protect your vital interests or those of another person, such as in a medical emergency during an open house.

6. Sharing and Disclosure of Information

6.1 Executive Overview

ROBLIE Properties Pakistan does not sell personal information. We share data only as necessary to deliver our services, comply with the law, or protect our business, with strict contractual and security requirements. This section describes the categories of recipients and the context of each disclosure.

6.2 Internal Sharing

Personal data is accessible within ROBLIE Properties on a need-to-know basis. Departments that may access your information include:

  • Sales and Client Relations
  • Legal and Compliance
  • Finance and Accounts
  • Property Management
  • Marketing (limited to aggregated or contact-preference data)
  • IT and Security

6.3 Service Providers and Business Partners

We engage trusted third parties to support our operations. Categories include:

  • Cloud hosting and data storage providers (infrastructure located in secured data centers)
  • Email and communication platforms (for newsletters and transactional messages)
  • AML/KYC screening services (to check sanctions and adverse media)
  • Credit bureaus (with consent)
  • Title verification and legal services (law firms, notaries)
  • Photography, drone, and virtual tour vendors (subject to non-disclosure agreements)
  • Property portals and listing syndication platforms
  • Customer Relationship Management (CRM) software providers
  • Payment processors and banks (for escrow and commission handling)

All third parties are vetted through our vendor security assessment process and are bound by data protection agreements that restrict data use to the specific service they provide.

6.4 Legal and Regulatory Disclosures

We may disclose information to:

  • Government agencies, land registries, and tax authorities
  • Regulatory bodies (SECP, FBR, FMU)
  • Law enforcement under valid legal process
  • Courts and tribunals in connection with litigation

6.5 Corporate Transactions

In the event of a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction. We will ensure the recipient agrees to honor this Privacy Policy and you will be notified before your data becomes subject to a different policy.

7. International Users and Cross-Border Data Transfers

7.1 Executive Overview

ROBLIE Properties Pakistan primarily operates within Pakistan. However, we serve a global clientele, including overseas Pakistanis and foreign investors. This section explains how data is handled when you access our services from outside Pakistan, and the safeguards applied when data crosses borders.

7.2 Visitors from Outside Pakistan

Our website and services are controlled and operated from Pakistan. If you are visiting from another jurisdiction, your personal data will be transferred to and processed in Pakistan, which may have data protection laws different from those of your country of residence. By using our services, you acknowledge this transfer.

We do not claim compliance with the specific privacy laws of every foreign country (such as the European Union’s GDPR or the California Consumer Privacy Act) unless explicitly stated and supported by our operations. However, we endeavor to apply globally-recognized privacy principles as described in this policy.

7.3 Overseas Pakistanis and Foreign Investors

For overseas Pakistanis, data often flows across borders:

  • You may submit documents from your country of residence (e.g., bank statements from a UAE bank).
  • We process them in Pakistan for due diligence and transaction completion.
  • Communications may involve international phone calls, emails, and video conferences.

We apply the same level of protection to your data as we do for domestic clients.

7.4 Data Transfer Safeguards

When we transfer personal data to service providers outside Pakistan (e.g., a cloud service with global infrastructure), we implement safeguards such as:

  • Contractual clauses ensuring the recipient provides an adequate level of protection.
  • Technical measures like encryption in transit and at rest.
  • Regular assessments of the recipient’s security posture.

Important Notice: The internet is a global environment. Using our digital services from overseas involves inherent risks detailed in Section 12.

8. Data Lifecycle Management

8.1 Executive Overview

Understanding the complete journey of your personal data is fundamental to transparency. We map every stage from the moment information is collected to its secure, irreversible destruction. This section provides a stage-by-stage explanation with practical examples relevant to real estate.

8.2 Collection

Data enters our ecosystem through multiple channels: web forms, email, in-person meetings, phone calls, and third-party feeds. At the point of collection, we provide a privacy notice (just-in-time or layered) indicating the purpose and legal basis. For example, when you fill out a “Request Valuation” form, a brief notice links to this policy.

8.3 Validation

Collected data is checked for accuracy and completeness. For identity documents, we may cross-reference with issuing authorities or use biometric verification where available. For property titles, we verify against land registry records. Invalid or inconsistent data may trigger a request for correction.

Practical Example: A buyer submits a CNIC copy. Our system checks the CNIC number format, expiry date, and may verify against NADRA’s online verification service if authorized.

8.4 Classification

We classify data according to sensitivity and confidentiality levels:

  • Public: Marketing materials, listing photos.
  • Internal Use: General correspondence, business emails.
  • Confidential: Client files, financial records, KYC data.
  • Restricted: Sensitive personal information, biometric data, legal privileged documents.

Classification determines access controls, encryption requirements, and retention periods.

8.5 Storage

Data is stored in secure, access-controlled environments. Primary storage includes on-premises servers in our offices (protected by physical security) and encrypted cloud storage with reputable providers. Storage is designed for high availability and resilience. See Section 9 for technical details.

8.6 Internal Use

Authorized personnel access data according to their role. For instance, a sales agent can view client preferences but not full AML reports; the compliance team can view KYC files but not modify sales notes. All access is logged and monitored.

8.7 Sharing

As described in Section 6, sharing is limited, purpose-bound, and protected by legal agreements. Each instance is logged.

8.8 Retention

We retain personal data only as long as necessary. Our retention schedule is based on:

  • Duration of the client relationship
  • Contractual obligations (e.g., warranty periods)
  • Legal requirements (e.g., 6 years for tax records, 10 years for property title documents)
  • Pending or anticipated litigation

Once the retention period expires, the data is slated for deletion or archiving.

Example: Transaction records for a completed property sale are kept for 7 years post-closing to satisfy tax and regulatory obligations, then securely purged.

8.9 Archiving

Some records may be moved to a secure, offline archive for long-term preservation, especially if required for historical property chain evidence. Access to archives is highly restricted.

8.10 Secure Deletion

When data reaches the end of its lifecycle, we use secure deletion methods: digital shredding of files, cryptographic erasure, or physical destruction of storage media. For paper records, cross-cut shredding is employed. Deletion is verified and logged.

8.11 Audit Logging

Every significant lifecycle event—collection, access, modification, sharing, deletion—is captured in an immutable audit trail. These logs are protected against tampering and retained to demonstrate compliance.

Customer Responsibility: You can help maintain accuracy by promptly informing us of any changes to your personal information.

Company Responsibility: We commit to adhering to our retention schedule and not keeping your data beyond what is justified.

9. Data Security and Cyber Security

9.1 Executive Overview

ROBLIE Properties Pakistan treats security as a foundational pillar. While no system is impenetrable, we implement an enterprise-grade, risk-based cybersecurity programme designed to protect your information from unauthorized access, disclosure, alteration, and destruction. This section describes the administrative, technical, and organizational safeguards that may be implemented based on operational requirements, without claiming the implementation of any specific control unless confirmed. We continually evaluate and evolve our security posture to address emerging threats.

9.2 Enterprise Security Programme

Our security programme is built on a framework of continuous improvement, encompassing:

  • Governance structures with clear accountability
  • Risk assessments and vulnerability management
  • Defense-in-depth architecture
  • Incident detection, response, and recovery
  • Ongoing staff training and awareness

9.3 Technical Safeguards

The following technical measures represent the types of controls that may be deployed to protect data:

Encryption

  • At Rest: Data stored in databases, file systems, and backups may be encrypted using strong cryptographic algorithms (e.g., AES-256).
  • In Transit: Communication between your browser and our website is protected by TLS 1.2 or higher. Emails may be secured using opportunistic TLS.

Access Control and Authentication

  • Multi-Factor Authentication (MFA) is enforced for all administrative access to systems containing personal data.
  • Identity and Access Management (IAM) with role-based permissions ensures least-privilege access.
  • Password Management policies require complex credentials and periodic rotation; single sign-on and secure password vaults are used where feasible.

Network Security

  • Network Segmentation separates critical data environments from general corporate networks.
  • Firewalls, Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS) monitor and filter traffic.
  • Web Application Firewalls (WAF) protect against common exploits like SQL injection and cross-site scripting.

Endpoint Security

  • Endpoint protection platforms provide malware, ransomware, and anti-virus defense.
  • Device encryption and remote wipe capabilities for company-issued mobile devices.

Cloud Security

  • When cloud services are used, configurations adhere to industry best practices (e.g., secure API integrations, container security, identity federation).

Database Security

  • Database activity monitoring, encryption, and regular hardening assessments.

Vulnerability Management and Penetration Testing

  • Regular vulnerability scans and external/internal penetration tests may be conducted by independent specialists.
  • A risk-based patch management process addresses identified vulnerabilities promptly.

Log Management and Security Monitoring

  • Centralized log collection from servers, applications, and security devices.
  • Security Information and Event Management (SIEM) or equivalent continuous monitoring for anomalies.
  • Threat Intelligence feeds integrated to stay informed of relevant indicators of compromise.

Secure Coding Practices

  • Development follows secure coding guidelines; code reviews and static/dynamic analysis testing are part of the software development lifecycle.

Backup, Disaster Recovery, and Business Continuity

  • Regular encrypted backups are taken and stored offsite or in a separate availability zone.
  • Documented and tested disaster recovery and business continuity plans aim to restore critical operations within defined recovery time objectives.

Important Notice: The above measures are a representative catalogue of safeguards that ROBLIE Properties may utilize, based on risk, resource availability, and operational requirements. The specific controls active at any given time are documented internally and subject to change as threats evolve. We do not publicly disclose our exact security architecture to prevent targeted attacks.

9.4 Organisational Safeguards

  • Security Awareness Training: All staff receive mandatory training on data protection, phishing, and secure handling of information.
  • Third-Party Risk Management: Vendors handling personal data undergo security assessments and are contractually obligated to maintain appropriate safeguards.
  • Security Incident Response: A formal incident response plan defines procedures for detection, containment, investigation, notification, and remediation of security breaches.

9.5 Incident Response and Business Continuity

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant authority within the timeframe required by applicable law. Our business continuity plans are designed to ensure that property transactions and client service can continue with minimal disruption.

Customer Responsibility: While we secure the infrastructure, security is a shared responsibility. You must keep your login credentials confidential and follow best practices from Section 12.5.

10. Cookie Policy and Tracking Technologies

10.1 Executive Overview

This Cookie Policy is among the most detailed available. It explains every type of cookie and tracking technology we use, their purpose, duration, and how you can manage them. We believe informed consent is paramount, and we provide granular control over non-essential technologies.

10.2 What Cookies Are

A cookie is a small text file that a website stores on your device (computer, tablet, smartphone) when you visit. Cookies are widely used to make websites work efficiently, remember your preferences, and provide information to site owners. Other tracking technologies like pixel tags, web beacons, and software development kits (SDKs) serve similar functions.

10.3 Types of Cookies We Use

We categorize cookies into the following groups:

  1. Essential Cookies – Required for the website to function; cannot be disabled.
  2. Functional/Preference Cookies – Remember choices you make to improve experience.
  3. Performance/Analytics Cookies – Collect aggregated information about how visitors use the site.
  4. Marketing/Advertising Cookies – Track browsing activity to deliver relevant ads.
  5. Security Cookies – Help detect and prevent security threats.
  6. Session vs. Persistent Cookies – Session cookies expire when you close your browser; persistent cookies remain for a set period.

10.4 Detailed Cookie Catalogue

Below is a comprehensive table explaining each category, with practical examples of user experience enhancement.

Cookie Category Cookie Names (examples) Duration Purpose & Business Rationale How It Enhances Your Experience

Essential ROBLIE_SESSID, csrf_token Session Maintain user session state, enable secure form submission, remember cookie consent. Without these, services like property search and inquiry forms cannot function. Allows you to navigate from a listing page to the contact form without losing the property reference.

Functional pref_lang, pref_currency Persistent (1 year) Store language preference (English/Urdu) and display currency (PKR/USD) on property listings. A returning overseas Pakistani sees prices in USD automatically, saving time.

Performance/Analytics _ga, _gid, _gat (Google Analytics) Persistent (2 years, 24 hours, 1 minute) Measure aggregate traffic, popular properties, bounce rate, referral sources. Data is anonymized. Helps us understand which luxury property pages are most viewed, so we can feature similar listings.

Marketing/Advertising _fbp, _gcl_au Persistent (3 months) Track visits from social media ads, build audiences for retargeting campaigns. You may see an advertisement for a villa you viewed earlier, reminding you to schedule a visit.

Security sec_session_id, rate_limit_token Session / Short persistent Identify and block malicious bots, prevent brute-force login attempts, protect against cross-site request forgery. Keeps your account safe from unauthorized access while you browse high-value listings.

Preference (Local Storage) search_history, saved_properties Persistent (no expiry unless cleared) Store recently viewed properties and shortlists locally in your browser for quick retrieval. You can revisit a saved penthouse without searching again, even after closing the browser.

Pixel Tags/Web Beacons Invisible 1×1 images in emails N/A Track email open rates and clicks to measure campaign effectiveness. We send fewer, more relevant emails if we know which content interests you.

10.5 Other Tracking Technologies

  • Local Storage / Browser Storage: Allows saving larger amounts of data on your device, used for storing property comparison lists and user preferences without server roundtrips.
  • SDKs (Software Development Kits): If you use our mobile app, SDKs may enable push notifications, crash analytics, and mapping services. Each SDK is vetted for privacy implications.
  • Web Beacons / Pixel Tags: Embedded in web pages and emails to log user activity and open rates.

10.6 Consent Management

When you first visit our website, a cookie banner allows you to accept all cookies, reject non-essential ones, or customize preferences. Your choice is stored as a cookie (essential) and respected for subsequent visits. You can change your preferences at any time through the “Cookie Settings” link in the website footer.

10.7 How to Control Cookies

Browser Settings: Most browsers allow you to block or delete cookies. Instructions for Chrome, Safari, Firefox, Edge, etc., can be found in their respective help sections. Blocking essential cookies may degrade website functionality.

Mobile Settings: On iOS and Android, you can limit ad tracking and reset advertising identifiers in device settings.

Third-Party Opt-Outs: For analytics and marketing cookies, you can use tools like Google Analytics Opt-out Browser Add-on, Network Advertising Initiative opt-out page, or Digital Advertising Alliance’s WebChoices tool.

Important Notice: Disabling certain cookies may prevent you from using interactive features like virtual tours or saved property lists.

11. Your Rights and Choices

11.1 Executive Overview

We respect your rights regarding your personal data. While specific rights may vary by jurisdiction, we aim to provide a consistent set of rights including access, rectification, deletion, restriction, portability, and objection. This section explains each right and how to exercise it.

11.2 Access and Rectification

You may request a copy of the personal data we hold about you, along with information about how it is processed. If any data is inaccurate or incomplete, you can ask us to correct it. For example, if your marital status or address changes, we will update records accordingly.

11.3 Deletion and Restriction

You can request the erasure of your personal data in certain circumstances, such as when it is no longer needed for the original purpose, or you withdraw consent. However, we may retain data if required by law (e.g., tax records) or for legitimate business purposes. You may also request a restriction on processing while a dispute is resolved.

11.4 Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.

11.5 Objection and Withdrawal of Consent

You may object to processing based on legitimate interests, including profiling for direct marketing. You can withdraw consent at any time for activities like newsletters or cookie-based advertising.

11.6 Exercising Your Rights

To exercise any of these rights, contact our Data Protection Office at [email placeholder] or [phone placeholder]. We will verify your identity before fulfilling the request and respond within the timeframe required by applicable law—typically 30 days. If we cannot accommodate a request, we will explain the reasons.

12. Risk Disclosures and Customer Responsibilities

12.1 Executive Overview

Despite our best efforts, no transmission over the internet or electronic storage is completely secure. This section educates you about inherent risks and provides actionable steps to protect yourself. Being an informed client strengthens the overall security posture.

12.2 Internet and Communication Risks

  • Internet Risks: Data sent over the public internet can potentially be intercepted, even if encrypted. Always verify you are connected to our official domain (www.roblieproperties.pk) and look for the padlock icon.
  • Email Risks: Email is inherently insecure. Do not include sensitive financial information or identity documents in initial emails. We provide secure upload portals for document transfer.
  • Public Wi-Fi Risks: Avoid accessing your account or sharing property documents when using public, unsecured Wi-Fi networks. Use a VPN if you must.
  • Third-Party Website Risks: Our site may link to partner portals or government registries. We are not responsible for their privacy practices—review their policies separately.

12.3 Social Engineering and Fraud Awareness

Criminals may impersonate ROBLIE Properties representatives to extract money or information. Be vigilant:

  • Phishing Attacks: Fraudulent emails or SMS messages that appear to be from us, asking you to click a link and provide login credentials or payment details. Always verify the sender address; legitimate emails come from @roblieproperties.pk.
  • Identity Theft: Unauthorized use of your personal data to open accounts or make purchases. Monitor your financial statements and report anomalies immediately.
  • Social Engineering: Someone may call claiming to be your agent and request an urgent wire transfer. Always verify through a known, official phone number before acting.

12.4 Device and Credential Security

  • Password Protection: Use strong, unique passwords for your ROBLIE Properties account (if applicable) and email. A combination of uppercase, lowercase, numbers, and symbols is recommended.
  • Device Security: Keep your operating system and applications updated. Install reputable antivirus and anti-malware software. Lock your device with a passcode or biometric.

12.5 Best Practices for Your Protection

  1. Enable multi-factor authentication wherever available, including your email account.
  2. Use secure, private networks for financial transactions.
  3. Verify property details and wire instructions directly by calling your known agent or visiting the office before transferring funds.
  4. Regularly review account activity and report any unrecognized inquiries.
  5. Shred physical documents containing personal information before disposal.
  6. Educate yourself about the latest scams; we post security advisories on our website.

Important Notice: ROBLIE Properties will never send you an email asking for your password, PIN, or full credit card number via email. If you receive such a request, contact us immediately.

13. Children’s Privacy

Our services are not directed toward individuals under the age of 18. We do not knowingly collect personal information from children. If a parent or guardian becomes aware that a child has provided us with data without consent, please contact us, and we will take steps to delete the information.

14. Third-Party Websites and Services

Our website may contain links to third-party platforms—such as property portals, bank mortgage calculators, or social media. Clicking these links may direct you to sites we do not control. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before sharing any information.

15. Changes to This Privacy Policy

We may update this policy periodically to reflect changes in our practices, legal requirements, or operational needs. The “Last Updated” date at the top indicates when revisions were made. Material changes will be communicated via our website, email, or prominent notice. Your continued use after the effective date constitutes acceptance of the updated policy.

16. Contact Information and Complaints

ROBLIE Properties Pakistan

Data Protection Office

[Address]

Email: [privacy@roblieproperties.pk]

Phone: [Phone Number]

Website: [www.roblieproperties.pk]

If you have questions, concerns, or wish to exercise your rights, please contact us at the above. We are committed to resolving any complaints about our handling of personal data. If you are dissatisfied, you may have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.

17. Glossary of Key Terms

(Alphabetical list of 100+ defined legal and technical terms. A sample is provided below; the full glossary would be extended in the final document to reach 100+ entries.)

  1. Anonymization: Irreversibly removing identifiable information.
  2. Anti-Money Laundering (AML): Legal controls to prevent generating income through illegal actions.
  3. Authentication: Verifying the identity of a user or process.
  4. Biometric Data: Physical characteristics used for identification (fingerprints, facial recognition).
  5. Breach Notification: The process of informing authorities/individuals of a data breach.
  6. Browser Storage: Web storage APIs (localStorage, sessionStorage) for client-side data.
  7. Business Continuity Plan (BCP): Documented procedures to sustain operations during disruption.
  8. Cloud Security: Protection of data hosted in cloud environments.
  9. CNIC: Computerized National Identity Card (Pakistan).
  10. Consent: Freely given, specific, informed agreement to data processing.
  11. Cookie: Small text file stored by a browser.
  12. Cross-Site Scripting (XSS): Vulnerability allowing script injection.
  13. Cryptographic Erasure: Deleting data by destroying encryption keys.
  14. Data Controller: Entity determining purposes and means of processing.
  15. Data Lifecycle: Stages from collection to deletion.
  16. Data Minimization: Limiting data collection to what is necessary.
  17. Data Portability: Right to receive data in a transferable format.
  18. Data Processor: Entity processing data on behalf of controller.
  19. Data Protection Impact Assessment (DPIA): Risk assessment for high-risk processing.
  20. Data Subject: Individual identified by personal data.
  21. Decryption: Converting encrypted data back to original form.
  22. Deep Packet Inspection: Network packet filtering examining data and header.
  23. Defense-in-Depth: Layered security approach.
  24. Digital Signature: Cryptographic technique verifying authenticity.
  25. Disaster Recovery Plan (DRP): IT-focused plan to restore systems.
  26. Domain Name System (DNS) Filtering: Blocking malicious domains.
  27. Encryption at Rest: Encryption of stored data.
  28. Encryption in Transit: Encryption of data during transmission.
  29. Endpoint Detection and Response (EDR): Monitoring and response for endpoint threats.
  30. Explicit Consent: Unequivocal consent, often for sensitive data.
  31. Firewall: Network security system monitoring traffic.
  32. General Data Protection Regulation (GDPR): EU data privacy law.
  33. Hashing: One-way transformation of data for integrity.
  34. Hypertext Transfer Protocol Secure (HTTPS): Secure web communication.
  35. Identity and Access Management (IAM): Framework for managing digital identities.
  36. Incident Response Plan: Procedures for handling security incidents.
  37. Intrusion Detection System (IDS): Monitors network for malicious activity.
  38. Intrusion Prevention System (IPS): Detects and blocks threats.
  39. IP Address: Unique numerical label assigned to a device.
  40. Just-in-Time Access: Privileged access granted temporarily.
  41. Key Management: Administration of cryptographic keys.
  42. Least Privilege: Granting minimum access necessary.
  43. Legitimate Interest: Legal basis for processing, balanced against rights.
  44. Log Management: Collection and analysis of system logs.
  45. Malware: Malicious software.
  46. Multi-Factor Authentication (MFA): Two or more verification factors.
  47. Network Segmentation: Dividing a network into sub-networks.
  48. NICOP: National Identity Card for Overseas Pakistanis.
  49. Non-Repudiation: Assurance that actions cannot be denied.
  50. Obfuscation: Masking data to protect it.
  51. Opt-In: Active consent to data use.
  52. Opt-Out: Choosing to stop data use.
  53. Patch Management: Process of applying software updates.
  54. Penetration Testing: Simulated attack to find vulnerabilities.
  55. Personally Identifiable Information (PII): Data that can identify an individual.
  56. Phishing: Fraudulent attempt to obtain sensitive information.
  57. Pixel Tag: Invisible image for tracking.
  58. Privacy by Design: Embedding privacy into system architecture.
  59. Privacy Policy: Document explaining data handling practices.
  60. Processing: Any operation on personal data.
  61. Pseudonymization: Replacing identifiers with pseudonyms.
  62. Ransomware: Malware that encrypts data for ransom.
  63. Retention Policy: Rules on how long data is kept.
  64. Right to Erasure: Right to have data deleted.
  65. Right to Object: Right to oppose certain processing.
  66. Role-Based Access Control (RBAC): Access based on job role.
  67. Secure Sockets Layer (SSL): Deprecated predecessor of TLS.
  68. Security Information and Event Management (SIEM): Real-time analysis of security alerts.
  69. Sensitive Personal Data: Data requiring special protection.
  70. Service Level Agreement (SLA): Commitment on service performance.
  71. Session Cookie: Temporary cookie deleted after session.
  72. Social Engineering: Manipulating people to divulge information.
  73. SQL Injection: Code injection attack on databases.
  74. Supervisory Authority: Government agency overseeing data protection.
  75. Third-Party Service Provider: External vendor processing data.
  76. Threat Intelligence: Information about current threats.
  77. Tokenization: Replacing sensitive data with a non-sensitive equivalent.
  78. Transport Layer Security (TLS): Protocol for secure communication.
  79. Two-Factor Authentication (2FA): Two separate authentication methods.
  80. User Agent: Browser/client software identifier.
  81. Virtual Private Network (VPN): Encrypted tunnel for internet traffic.
  82. Vulnerability Assessment: Systematic review of security weaknesses.
  83. Web Beacon: See Pixel Tag.
  84. Web Application Firewall (WAF): Protection for web applications.
  85. Zero-Day Exploit: Attack on unknown vulnerability.
  86. Access Log: Record of requests to a system.
  87. Backup: Copy of data for restoration.
  88. Botnet: Network of compromised devices.
  89. Brute Force Attack: Guessing passwords systematically.
  90. Data Breach: Security incident leading to data compromise.
  91. Data Subject Access Request (DSAR): Request to access personal data.
  92. Digital Certificate: Electronic document for identity.
  93. End-to-End Encryption: Only communicating users can read data.
  94. File Integrity Monitoring (FIM): Detection of file changes.
  95. Hash Function: Algorithm mapping data to fixed size.
  96. Incident: Security-relevant event.
  97. Man-in-the-Middle Attack: Interception of communication.
  98. Metadata: Data about data.
  99. Multi-Tenant: Cloud environment shared by multiple customers.
  100. Privileged Access Management (PAM): Controls for privileged accounts.
  101. Redundancy: Duplication of critical components.
  102. Risk Assessment: Evaluating threats and vulnerabilities.
  103. Sandbox: Isolated environment for testing.
  104. Single Sign-On (SSO): One set of credentials for multiple systems.
  105. SOC (Security Operations Center): Centralized monitoring team.
  106. TLS Certificate: Digital certificate for TLS.
  107. Token: Security credential used in authentication.
  108. VPN: Encrypted network connection.
  109. Web Scraping: Automated extraction of website data.
  110. Whitelist: Approved items list.

(Additional terms can be added to reach the required count; the above is a substantial sample.)

18. Frequently Asked Questions

Below are 75 detailed FAQs covering a wide range of privacy, security, and real estate-specific scenarios.

General Privacy

  1. What is personal information?

   Any data that can identify you, directly or indirectly, including your name, CNIC, email, or property details.

  1. Why does ROBLIE Properties need my CNIC/NICOP?

   It is legally required for identity verification in property transactions and KYC compliance.

  1. Is my financial data shared with sellers?

   Only with your explicit consent, typically just proof of funds, not full bank statements, to reassure the seller of your capability.

  1. How do you protect my documents during online submission?

   Our upload portal uses TLS encryption; documents at rest are encrypted and access is tightly controlled.

  1. Can I remain anonymous when browsing listings?

   Yes, you can view listings without providing personal data. However, to schedule a visit or submit an inquiry, contact details are necessary.

  1. Do you sell my data to third parties?

   No. We never sell personal information.

  1. What happens to my data if I decide not to buy/sell?

   It is retained for a reasonable period for follow-up unless you request deletion, then disposed of per our retention policy.

Real Estate–Specific

  1. How is my property title information used?

   It is shared with legal professionals, government registries, and the counterparty to verify ownership and complete the transfer.

  1. What drone photography data is collected?

   Aerial imagery of the property; we post privacy notices and obtain consent before capturing neighboring properties.

  1. Are virtual tour recordings stored?

    Yes, they are stored to provide to prospective buyers; they may include incidental voices which are processed as part of marketing material with consent.

  1. Is my contact information shared during an open house?

    Visitor logs are maintained for security, but your contact is not shared with other attendees.

  1. How do you handle luxury property confidentiality?

    Additional NDAs are signed; sensitive details like art collections are not disclosed without permission.

  1. What AML checks are performed?

    We screen against global sanctions lists, PEP databases, and verify source of funds, as required by Pakistani law.

  1. Do you share my data with property portals?

    If you are a seller, your listing (with agreed photos and details) is syndicated to portals to maximize exposure; personal contact is not published without consent.

  1. How are offer negotiations recorded?

    Written offers and counteroffers are retained in the transaction file for audit and legal evidence.

Overseas Pakistanis and International Users

  1. I’m abroad; how is my data transferred?

    Data you provide is transferred to Pakistan, secured with encryption, and handled under this policy.

  1. Is my foreign bank statement safe?

    Yes, treated with the same security as local documents.

  1. Do you comply with GDPR?

    We incorporate GDPR principles where feasible, but our primary legal obligations are under Pakistani law. If you are an EU resident, certain rights may apply; contact us.

  1. Will you communicate with my overseas representative?

    Only with your express authorization, typically through a power of attorney.

  1. How can I verify a property remotely?

    We provide live video walkthroughs, digital document scans, and secure communication channels.

Cookie and Tracking Questions

  1. What is an essential cookie?

    A cookie that is strictly necessary for our website to function, like maintaining your session.

  1. Can I reject all cookies?

    You may reject non-essential cookies via the cookie banner; essential cookies cannot be rejected without impacting site functionality.

  1. How do analytics cookies benefit me?

    They help us improve site navigation and content, so you find properties faster.

  1. What’s a pixel tag in email?

    A tiny image that tells us if you opened an email; we use this to send more relevant communications.

  1. How do I delete local storage?

    Clear your browser cache/data; instructions vary by browser.

Security

  1. What encryption do you use on your website?

    TLS 1.2 or higher.

  1. Do you have a bug bounty programme?

    We encourage responsible disclosure and may collaborate with researchers to address vulnerabilities.

  1. What happens during a security incident?

    Our incident response team contains the threat, investigates, and notifies affected individuals and authorities as required.

  1. How do you vet vendors?

    Through security questionnaires, contract clauses, and periodic reviews.

  1. Do you store passwords in plain text?

    Never. Passwords are hashed and salted.

Rights and Choices

  1. How do I access my data?

    Submit a request to our Data Protection Office; we respond within 30 days.

  1. Can I request deletion of my transaction records?

    We may retain records for legal periods, but we can delete ancillary data like marketing preferences.

  1. What if my data is wrong?

    Contact us with corrections; we update promptly.

  1. Can I opt out of marketing calls?

    Yes, you can update preferences or ask to be placed on a do-not-call list.

  1. How do I withdraw cookie consent?

    Use the Cookie Settings link on our website.

Data Lifecycle

  1. How long do you keep my CNIC copy?

    Typically for the duration of the relationship plus 6 years after the last transaction, as required for tax/legal purposes.

  1. How is data securely deleted?

    Digital files are cryptographically shredded; physical documents are cross-cut shredded.

  1. Do you archive old transaction files?

    Yes, in a secure offline environment if needed for long-term property history.

Risk Disclosures

  1. Is it safe to email property documents?

    For sensitive documents, we recommend our encrypted upload portal rather than standard email.

  1. What should I do if I get a suspicious email from “ROBLIE”?

    Do not click any links; forward it to our official email for verification and delete it.

  1. How can I avoid wire fraud?

    Always confirm bank details directly with your agent via a known phone number before transferring.

  1. Can someone intercept my virtual tour?

    We use secure streaming protocols; however, ensure your own network is secure.

Other

  1. Do you use artificial intelligence to make decisions about me?

    Currently no automated decisions with legal/significant effects; if introduced, we will disclose and provide opt-out.

  1. What is the minimum age to use your services?

    18; minors must be represented by a guardian.

  1. How do I complain about a privacy violation?

    Contact us; if unsatisfied, you may escalate to the relevant authority.

  1. Will this policy change?

    We may update it; material changes will be notified.

  1. How can I get a printed copy?

    Visit our office or request one by mail.

  1. Do you record calls?

    We may record calls for quality and training with prior notice.

  1. Is biometric data required for any property registration?

    Only if mandated by government land record authorities.

  1. How do I update my communication preferences?

    Use the link in any email or contact us.

  1. What is a “legitimate interest” balancing test?

    An internal evaluation to ensure our processing doesn’t override your rights.

  1. Do you conduct penetration tests?

    Yes, regularly through independent experts.

  1. Who is your Data Protection Officer?

    Contact details are in Section 16; we will direct your query appropriately.

  1. Can I use a pseudonym?

    For general inquiries yes, but for real transactions, real identity is mandatory.

  1. How do you secure video walkthroughs?

    Files are encrypted and watermarked; access is limited.

  1. What is the source of funds declaration?

    A statement explaining where the money for a purchase originates, required by AML law.

  1. Is my property search history visible to others?

    No, it is tied to your session or account and kept private.

  1. Do you track location on mobile?

    Only if you allow the app to access location for proximity-based property suggestions.

  1. What if I die; can my heirs access my data?

    Subject to succession laws and valid legal documentation.

  1. How do I report a security vulnerability?

    Email our security team; we appreciate responsible disclosure.

  1. Do you use third-party cookies for advertising?

    Yes, with consent; see Cookie Policy for details.

  1. Can I request my data in a spreadsheet?

    Yes, for data provided by you that is processed by automated means.

  1. What is your policy on voice assistants or smart devices?

    We do not currently integrate with such devices; if we do, a notice will be provided.

  1. How is property valuation data used?

    To provide appraisal reports; may be shared with lenders with consent.

  1. Are tenant applications covered?

    Yes, if you apply for a rental property through us.

  1. Do you share data with credit bureaus for rental screening?

    Only with your consent.

  1. What if I have a complaint about a drone flight?

    Contact us immediately; we follow civil aviation and privacy guidelines.

  1. Is my communication with my agent visible to other agents?

    No, internal access is role-based; other agents cannot view your private communication unless needed for coverage.

  1. How do I know if a document upload was successful?

    We provide an on-screen confirmation and an email receipt.

  1. Will I be notified if a data breach affects me?

    Yes, in accordance with legal requirements.

  1. Can I review the AML report about me?

    Certain AML information is restricted by law; we will provide access where permissible.

  1. Do you use social media logins?

    Not currently; if enabled, privacy implications will be explained.

  1. What is your policy on employee access?

    Employees undergo background checks and sign confidentiality agreements; access is audited.

  1. How can I be sure my data is deleted?

    You may request a deletion confirmation after the secure erasure process is complete.

  1. How do you handle data for corporate investors with multiple signatories?

    We verify each authorized signatory’s identity and maintain appropriate access controls.

19. Summary of Our Commitment

ROBLIE Properties Pakistan is built on a foundation of trust, discretion, and excellence. We recognize that in luxury real estate, privacy is not a mere compliance requirement—it is an integral part of the client experience. We are committed to:

  • Transparency: Clearly articulating what data we collect, why we need it, and how we use it.
  • Security: Deploying enterprise-grade safeguards and constantly evolving to meet emerging threats.
  • Control: Giving you meaningful choices over your information and respecting your rights.
  • Responsibility: Holding ourselves accountable for the data entrusted to us by clients, partners, and the community.

Whether you are a first-time homebuyer, an overseas investor, or a developer shaping the skyline, you can be confident that your personal information is handled with the utmost care. This Privacy Policy is our promise to you, and we will continue to refine it as our services and the regulatory landscape evolve.

For any questions, or to exercise your data rights, please reach out to our Data Protection Office. We are here to serve you, and that includes protecting your privacy.

ROBLIE Properties Pakistan

Your Trust, Our Foundation.

Pakistan’s Premier Luxury Real Estate Advisory. Advisory-led buying, selling and leasing across Karachi and Islamabad.

© 2026. All Rights Reserved