Partner Privacy Policy

Last updated: August 2026

This Partner Privacy Policy explains how Zertix Studio ("Deskio AI", "we", "us", "our") collects, uses, stores, and protects personal information belonging to individuals and entities participating in the Deskio AI Partner (Referral) Program (the "Program"). It is a separate, partner-specific document from our general Privacy Policy, which covers the AI receptionist platform and its business/customer data. If you are a Partner, this document — together with the Partner Agreement and Partner Terms of Service — governs how your data is handled. Where this policy and the general Privacy Policy overlap on a topic neither of them modifies (such as how we secure our infrastructure generally), both apply; where they conflict specifically about Partner data, this policy controls.

1. Scope of This Policy

This policy applies to information we collect about you when you create a Partner account, complete identity and payout verification, use the Partner dashboard, or otherwise interact with the Program at /partners and related pages. It does not apply to the businesses and end customers who use the underlying Deskio AI assistant — their data is governed by our general Privacy Policy. It also does not apply to your own prospective clients' data once you are outreaching to them independently, outside of what you submit to us; see Section 19 below on confidentiality obligations regarding that information.

2. Information We Collect From Partners

3. Identity & Age Verification Documents

Before you can receive a payout, the Program requires you to submit a valid CNIC (for Pakistani Partners) or passport (where applicable), along with front and back document images. This exists to confirm you are the real, legal owner of the bank account you're asking us to pay, and to confirm you meet the Program's minimum age requirement described in our Partner Terms of Service. We collect and retain the CNIC number and the associated document images solely for this identity-verification and payout-integrity purpose — they are never used for any unrelated purpose, and the database enforces that each CNIC number can only ever be associated with one Partner account, preventing the same identity document from being reused across multiple accounts.

4. Banking & Payout Information

Your bank name, account title, IBAN/account number, and payout full name are collected only so that a legitimate payout can be sent to you, and so that name, CNIC, and bank details can be cross-checked against each other for consistency before funds are released. You confirm this information yourself through your Partner dashboard, and the payout flow requires an explicit acknowledgement that the details you provide are accurate before a request can be submitted. We do not use your banking details for any purpose other than processing Program payouts, verifying your identity in connection with a payout, and investigating suspected payout fraud.

5. How We Use Partner Information

We use the information described above to: operate your Partner account and dashboard; calculate, track, and display your commissions and referral activity; verify your identity and eligibility before releasing a payout; detect and investigate suspected fraud or Program-rule violations (see Section 9); respond to your support requests; and comply with applicable legal, tax, or recordkeeping obligations. We do not use your Partner data to build an advertising profile of you, and we do not use it to make automated decisions that produce legal or similarly significant effects about you without the ability for you to request human review through /contact.

6. Legal Bases for Processing

Where data protection law that recognizes "legal bases" for processing applies to you (for example, the GDPR for individuals in the European Economic Area, or the UK GDPR for individuals in the United Kingdom), we process your Partner data on the following bases: performance of the Partner Agreement (account operation, commission calculation, payouts); compliance with a legal obligation (identity verification, financial recordkeeping, responding to lawful requests); and our legitimate interests in preventing fraud, keeping the Program secure, and enforcing our Partner Terms of Service, balanced against your own rights and expectations. We describe this consistent with GDPR/CCPA principles as a matter of good-faith design intent; it is not a claim that Zertix Studio holds a formal GDPR or CCPA compliance certification, registration, or audit from any regulator.

7. We Do Not Sell or Rent Your Data — No Marketing Sharing

We do not sell, rent, or share your Partner data — including your name, CNIC, banking/IBAN details, contact information, or uploaded identity documents — with any third party for that third party's own marketing, advertising, or resale purposes. Full stop. Your information is used solely for the purposes described in this policy: operating your Partner account, verifying your identity, processing your payouts, and preventing fraud. If this ever needs to change for a legitimate operational reason (for example, engaging a payment processor to handle payouts directly on our behalf), we will update this policy first and that processor would be bound to use your data only for the service it's providing us, never for its own marketing purposes.

8. Internal Access Controls

Access to sensitive Partner data — your CNIC number, uploaded identity documents, and banking/IBAN details — is restricted to Deskio AI's administrative team through the internal, admin-only Admin Panel, itself gated behind a separate administrator session that is distinct from the Partner login session. Partners cannot see each other's sensitive information, and a Partner Manager assigned oversight of other Partners (see the Partner Agreement, Section 5) does not gain any visibility into those managed Partners' CNIC, uploaded documents, or banking details through that role — Partner Manager status affects override commission only, not data access. This scoping is enforced at the application level, not merely as an internal policy.

9. Fraud Prevention Data & Signals

To protect the integrity of the commission structure, we compute automated fraud signals when a Referred Client is attributed to a Partner, comparing signals such as matching phone numbers, matching IP addresses, and matching names between the Partner's own account and the Referred Client's account. This exists to catch self-referral and self-dealing (a Partner referring themselves or a business they control), not to build a behavioral profile of legitimate Partners. A commission flagged by this process is placed into an admin review queue rather than paid out immediately; an administrator reviews it and either clears the flag or voids the commission. We retain the fraud-signal outcome (which signals fired, and the reviewing administrator's decision) as an audit trail, since demonstrating why a commission was withheld or voided may itself be necessary to defend that decision later.

10. Data Retention

We retain Partner account, identity-verification, payout, and commission-history data for as long as your Partner account remains open, so that your dashboard accurately reflects your referral and payout history. After an account is closed, we retain a more limited set of records — enough to satisfy tax, accounting, anti-fraud, and legal recordkeeping obligations, and to defend against or bring a claim relating to your participation in the Program — for a period consistent with those obligations, after which the data is deleted or irreversibly anonymized. Uploaded CNIC/passport document images are retained only as long as needed for the verification purpose they were collected for and applicable recordkeeping requirements; they are not repurposed once verification is complete.

11. Where and How Data Is Stored

Partner data — account records, uploaded identity documents, and payout information — is stored in our hosted application database and file storage, protected by the same authentication, encryption-in-transit, and access-control practices described in our general Privacy Policy's Security section. Uploaded CNIC document images are stored as sanitized file bytes tied to your account and are only retrievable through the admin-gated download path described in Section 8, not through any general-purpose file link.

12. International Data Transfers

The Program is currently operated for, and limited to, Partners referring businesses located in Pakistan, and our infrastructure providers may process data in locations outside Pakistan as part of normal cloud hosting. Where we or our infrastructure providers process Partner data outside your home country, our intent and practice is to apply a comparable level of protection to that data regardless of where it is processed, consistent with the spirit of frameworks like GDPR's international-transfer principles. We describe this as our operating intent, not as a claim that specific mechanisms such as Standard Contractual Clauses have been formally executed with every provider — if you'd like more detail about a specific transfer relevant to your account, contact us at /contact.

13. Data Security Measures

We apply reasonable technical and organizational safeguards designed to protect Partner data, including authenticated, role-scoped access (Partner sessions, admin sessions, and Partner Manager permissions are kept distinct, as described in Section 8), CSRF protection on state-changing Partner dashboard actions, hashed password storage, and monitoring for suspicious account activity. No system is perfectly secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur, but we treat CNIC and banking data as our highest-sensitivity Partner data category and scope access to it accordingly.

14. Your Data Subject Rights

You may ask us to: provide access to the personal data we hold about your Partner account; correct inaccurate information (much of this you can also update directly from your Account settings); delete your data, subject to the retention exceptions described in Section 10; or ask us questions about how your data is processed. To exercise any of these rights, contact us through /contact with enough detail for us to locate and verify your account — we don't currently operate a separate self-service data-request portal, so this contact path is the real, working mechanism for these requests, and we will respond within a reasonable time.

15. European Users (GDPR) & UK Users

If you are located in the European Economic Area, Switzerland, or the United Kingdom, the GDPR or UK GDPR (as applicable) may give you additional rights over your Partner data, including the rights described in Section 14 above, the right to restrict or object to certain processing, the right to data portability, and the right to lodge a complaint with your local data protection authority. Because the Program is presently Pakistan-focused and processes data as described in Section 12, these rights are honored on request via /contact even where you are not strictly a "data subject" under those regulations, as a matter of consistent practice rather than a claim of formal regulatory registration in your jurisdiction.

16. California Residents (CCPA/CPRA)

If you are a California resident participating in the Program, the CCPA (as amended by the CPRA) would give you rights to know what categories of personal information we collect and why, to request deletion, to request correction, and to not be discriminated against for exercising those rights. As stated in Section 7, we do not sell or share Partner personal information for cross-context behavioral advertising, so there is no "opt out of sale/sharing" action needed. Exercise any of these rights via /contact; we may need to verify your identity before fulfilling a request involving sensitive data like your CNIC or banking details.

17. Children's Privacy & Minimum Age

The Program is not directed at, and may not be used by, anyone under 18 years of age — this is a hard eligibility requirement enforced through the identity-verification process described in Section 3 and our Partner Terms of Service. We do not knowingly collect Partner data from anyone under 18. If we discover that a Partner account was created by, or identity documents submitted belong to, someone under 18, we will close the account, decline to release pending commission, and delete the associated verification documents once any legal or fraud-review retention need has passed.

18. Breach Notification

If we confirm a security incident that compromises Partner personal data — particularly CNIC numbers, uploaded identity documents, or banking/IBAN details — we will investigate, contain it, and notify affected Partners without undue delay, describing what happened and what we recommend you do (for example, monitoring your bank account or re-verifying your identity documents). Where applicable law requires notification to a specific regulator or authority, we will assess and follow that obligation based on the nature and location of the incident.

19. Referred Client & Prospect Information You Learn

In the course of referring businesses to Deskio AI, you may learn non-public information about a prospective or Referred Client — for example, details they share with you during outreach. That information belongs to the client or prospect, not to you, and you must treat it as confidential under Section 9 of the Partner Agreement and Section 8 of our Partner Terms of Service. You may not use it for any purpose beyond the legitimate referral activity it was shared for, and you may not disclose it to anyone else.

20. Cookies & Tracking Technologies

The Partner-facing pages use a small, specific set of cookies — for your login session, for CSRF protection, for referral attribution, and for a cookie-consent preference — described in full in our Partner Cookie Policy. We do not use advertising or cross-site tracking cookies on Partner pages.

21. Changes to This Policy

We may update this Partner Privacy Policy from time to time as the Program evolves. We will post the updated policy here with a new "Last updated" date. Material changes affecting how we handle your CNIC, banking details, or other sensitive information will be given reasonable notice before taking effect. Continued participation in the Program after a change takes effect constitutes acceptance of the updated policy.

22. Contact

Questions, requests, or concerns about this Partner Privacy Policy or how your Partner data is handled can be directed to Zertix Studio via our Contact page.