This Privacy Policy explains how Walee Alnazawy (Private) Limited, operating the Khushaamdeed premium meet & assist and concierge service at Islamabad International Airport (“we”, “us”, “our”), collects, uses, shares and protects your personal data when you book or use our services through our app, website or booking portal (the “Platform”).
For the purposes of data-protection law, Walee Alnazawy (Private) Limited is the data controller. Our registered office is at Plot No. 2, Commercial Area, Street No. 7, Sector G-10/2, Islamabad, Pakistan.
We are committed to protecting your privacy and handling your data in line with applicable Pakistani law and, as a matter of best practice, the principles of the EU General Data Protection Regulation (“GDPR”). This Policy should be read together with our Customer Terms & Conditions.
Depending on the service tier and how you use the Platform, we may collect the following categories of personal data:
Identity and contact data — your name, title, nationality, date of birth (where required), email address and phone number.
Booking and travel data — flight details, travel dates, arrival/departure, service tier, special-assistance requirements, and (for Platinum pick-and-drop) address details.
Travel-document references — passport / CNIC / visa reference details where required for facilitation. (Our staff do not physically handle your documents; see the Terms & Conditions.)
Biometric and identity-verification data — a Unique Passenger Identification (UPID) and facial-recognition (Face-ID) data used to verify your identity at the airport. This is special-category (sensitive) data and is treated with additional care (see clause 4).
Payment and transaction data — payment method, transaction records, invoices and receipts. Card details are processed by our payment provider; we do not store full card numbers.
Special-assistance / health-related data — only where you provide it so we can arrange wheelchair or medical coordination.
Technical and usage data — device, app/website usage, log and cookie data, and operational movement logs generated during service delivery.
We use your personal data only where we have a lawful basis to do so. The table below sets out our main purposes and the corresponding lawful bases.
| Why we use your data (purpose) | Data involved | Lawful basis |
|---|---|---|
| Take, manage and fulfil your booking | Name, contact, flight & passenger details, tier selected | Performance of a contract (GDPR Art. 6(1)(b)) |
| Verify your identity at the airport (UPID + Face-ID) | Biometric / facial-recognition data, identity document references | Your explicit consent (Art. 9(2)(a)); and compliance with airport security / legal obligations (Art. 9(2)(g)) |
| Process payments and issue receipts/invoices | Payment and transaction data | Performance of a contract; legal obligation (Art. 6(1)(c)) for tax/accounting |
| Comply with airport, security, immigration & customs requirements | Booking, identity and movement data | Legal obligation (Art. 6(1)(c)); public interest / official authority (Art. 6(1)(e)) |
| Coordinate with airlines, GHAs and lounges | Booking and flight details | Performance of a contract; legitimate interests (Art. 6(1)(f)) |
| Handle complaints, refunds and disputes | Booking, contact and incident data | Performance of a contract; legitimate interests; legal obligation |
| Service improvement, security monitoring & audit | Usage logs, operational records (aggregated where possible) | Legitimate interests (Art. 6(1)(f)); legal/regulatory obligation |
| Marketing & service updates (where you opt in) | Name, contact, booking history | Your consent (Art. 6(1)(a)) — withdrawable at any time |
The Service uses UPID and Face-ID to confirm your identity at the airport, for service delivery, security and transaction traceability. Facial-recognition data is biometric data and a special category of personal data.
We process this data on the basis of your explicit consent, which you give when you book and complete identity enrolment, and, where applicable, on the basis of airport security and legal obligations.
You can withdraw your consent to biometric processing at any time by contacting us (clause 14). Withdrawal does not affect processing already carried out, and may mean we can no longer provide the identity-verification element of the Service for future bookings.
We do not use your Face-ID data to make any decision producing legal or similarly significant effects about you, other than confirming that you are the person who made the booking.
We share personal data only where necessary, and with appropriate safeguards, with:
Pakistan Airports Authority (PAA) and relevant government agencies — including the Airport Security Force (ASF), Federal Investigation Agency (FIA – Immigration), Pakistan Customs and the Anti-Narcotics Force (ANF), strictly on a need-to-access basis, where required by the airport regulatory framework, security protocols or law.
Airlines, Ground Handling Agents (GHAs) and lounges — to coordinate your facilitation, check-in and lounge access.
Payment service providers — to process your payment securely.
IT, hosting, cloud and software providers — who process data on our behalf as processors under written contracts (see clause 6 on international transfers).
Professional advisers and authorities — lawyers, auditors, insurers, or regulators, where required.
We do not sell your personal data. Where third parties act as our processors, they may use your data only on our instructions and must keep it secure.
Your data is primarily stored and processed in Pakistan. However, some of our hosting, cloud, payment or analytics providers may process data on servers outside Pakistan.
Where personal data is transferred internationally, we put in place appropriate safeguards, such as: transfer to a country recognized as providing an adequate level of protection; standard contractual clauses or equivalent data-transfer agreements with the recipient; and/or your explicit consent to the transfer.
We do not transfer your biometric (Face-ID) data abroad except where strictly necessary for the verification technology, and then only with the safeguards above. [Confirm whether any biometric processing occurs outside Pakistan.]
Note: airport security and PAA requirements may require certain data to be retained and accessed within Pakistan; we comply with those requirements where they apply.
In line with the GDPR principle of storage limitation, we keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, security and audit requirements, and then securely delete or anonymize it.
| Data category | How long we keep it | Why |
|---|---|---|
| Biometric data (UPID / Face-ID) | Deleted or irreversibly anonymized shortly after completion of your airport journey, and no later than [30 days], unless a longer period is required by law or airport security | Storage limitation (Art. 5(1)(e)); data minimization |
| Booking & service records | Retained for [24 months] after the service date for operations, complaints and audit | Contract; legitimate interests |
| Payment, invoice & tax records | Retained for the period required by Pakistani tax and accounting law (typically [6 years]) | Legal obligation |
| Complaint & incident records | Retained for [24 months] after resolution | Legitimate interests; legal obligation |
| Marketing preferences | Until you withdraw consent or object, then suppressed | Consent |
We implement appropriate technical and organizational security measures, including encryption of data in transit and at rest where appropriate, access controls on a need-to-know basis, secure authentication, audit logging, staff confidentiality obligations and security clearances, and supplier due diligence. No system can be guaranteed completely secure, but we work to protect your data and to respond promptly to any incident.
Subject to applicable law and to airport-security and legal limits, you have the right to:
Be informed about how we use your data (this Policy).
Access the personal data we hold about you.
Rectify inaccurate or incomplete data.
Erase your data (“right to be forgotten”), where there is no overriding legal or security reason to keep it.
Restrict or object to our processing in certain circumstances.
Data portability — receive certain data in a portable, machine-readable format.
Withdraw consent at any time, where we rely on consent (including for biometric data and marketing).
Complain to a data-protection authority (see clause 14).
To exercise any right, contact us using the details in clause 14. We will respond within one (1) month (extendable for complex requests, in which case we will tell you). We may need to verify your identity first. These rights are subject to lawful exemptions, including where data is held for airport security, regulatory or legal-compliance purposes.
The Service is booked by adults. Where a booking includes a minor (under 18), we process the minor's data only as necessary to deliver the Service, and on the basis of the consent and authority of a parent or guardian, who is responsible for accepting this Policy on the minor's behalf. We do not knowingly collect children's data other than as part of such a booking.
We use facial recognition (Face-ID) solely to verify your identity against your booking. We do not carry out automated decision-making that produces legal or similarly significant effects about you within the meaning of GDPR Article 22. A human is involved in any decision affecting your access to the Service.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will, in line with GDPR standards, notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours, and we will inform affected individuals without undue delay where the breach is likely to result in a high risk to them.
Our app and website use cookies and similar technologies to operate the Platform, remember your preferences, and understand usage. Where required, we ask for your consent to non-essential cookies. [Insert link to a separate Cookie Policy, suggest using Walee’s standard Cookie Policy as well as Website/App Terms of Use]
Changes. We may update this Policy from time to time. We will post the updated version on the Platform and, where changes are significant, notify you. The version in force at the time governs our processing.
Contact / Data Protection Officer. For any privacy question or to exercise your rights, contact our Data Protection contact at: [email] | [phone] | [postal address]. Operator: Walee Alnazawy (Private) Limited, Plot No. 2, Commercial Area, Street No. 7, Sector G-10/2, Islamabad, Pakistan.
Complaints. You may complain to us first so we can put things right. You may also complain to the competent data-protection authority — in Pakistan, the Pakistan Telecommunication Authority, if you are in the EU/UK, your local supervisory authority.
By booking and using Khushaamdeed, you acknowledge that you have read and understood this Privacy Policy.