Milestone Consults ("we," "our," or "us") is committed to protecting the privacy and security of your personal and financial information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our portfolio management and financial advisory services or visit our website.
As a SECP-certified financial services firm operating in Pakistan, we adhere to the Securities and Exchange Commission of Pakistan (SECP) regulations, the Prevention of Electronic Crimes Act 2016 (PECA), and applicable data protection standards.
1. Information Collection
We collect information necessary to provide our financial advisory and portfolio management services. This includes:
- Personal Identification: Full name, CNIC number, date of birth, nationality, and contact details (address, phone number, email).
- Financial Information: Income details, bank account information, investment history, tax identification number (NTN), and risk tolerance assessments.
- KYC Documentation: Know Your Customer documents as mandated by SECP regulations, including proof of identity, proof of address, and source of funds declarations.
- Transaction Records: Details of investments, withdrawals, portfolio changes, and payment history.
- Technical Data: IP address, browser type, device information, and usage patterns when accessing our website or client portal.
- Communication Records: Correspondence via email, phone, or in-person meetings related to your account.
2. How We Use Your Data
Your information is used for the following purposes:
- Providing portfolio management, investment advisory, and financial planning services.
- Conducting KYC verification and anti-money laundering (AML) checks as required by SECP.
- Processing transactions, managing your investment portfolio, and executing trades on the Pakistan Stock Exchange (PSX).
- Generating portfolio statements, performance reports, and tax documentation.
- Communicating service updates, market insights, and account notifications.
- Complying with regulatory reporting obligations to SECP, FBR, and other relevant authorities.
- Improving our services, website functionality, and client experience.
3. Financial Data Protection
Given the sensitive nature of financial data, we implement additional safeguards:
- Financial records are stored in encrypted databases with restricted access limited to authorized personnel only.
- Portfolio and transaction data is segregated from general marketing data systems.
- All financial data handling complies with SECP's Asset Management Companies Rules and relevant NBFC regulations.
- Client investment information is never used for proprietary trading or shared with unauthorized third parties.
- Regular internal audits ensure compliance with data handling protocols and SECP guidelines.
4. Data Security
We employ industry-standard security measures to protect your information:
- SSL/TLS encryption for all data transmitted between your device and our servers.
- Multi-factor authentication for client portal access.
- Regular security assessments and vulnerability testing of our systems.
- Physical security controls at our offices in Lahore, Pakistan.
- Employee training on data protection and confidentiality obligations.
- Incident response procedures in compliance with PECA 2016 requirements.
While we take extensive measures to protect your data, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any breach in accordance with applicable laws.
5. Third-Party Services
We may share your information with trusted third parties only when necessary:
- Regulatory Bodies: SECP, FBR, and other government authorities as required by law.
- Custodian Banks: Licensed banks that hold your investment assets in segregated accounts.
- Stock Exchange: Pakistan Stock Exchange (PSX) and Central Depository Company (CDC) for trade execution and settlement.
- Auditors: External auditors conducting statutory audits as mandated by SECP.
- Technology Providers: Secure hosting, analytics, and communication platforms that process data on our behalf under strict confidentiality agreements.
We do not sell, rent, or trade your personal information to marketing companies or unrelated third parties.
6. Cookie Policy
Our website uses cookies to:
- Ensure the proper functioning of our website and client portal.
- Remember your preferences and login sessions.
- Analyze website traffic and usage patterns to improve our services.
- Provide relevant content based on your browsing behavior.
You can manage cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our client portal and website features.
7. Your Rights
Under applicable Pakistani laws, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of your data, subject to regulatory retention requirements (SECP mandates retention of client records for a minimum of 10 years).
- Objection: Object to processing of your data for marketing purposes.
- Portability: Request your data in a structured, commonly used format.
- Complaint: Lodge a complaint with SECP or relevant authorities if you believe your data rights have been violated.
To exercise any of these rights, please contact us at contact@milestoneconsults.com. We will respond to your request within 30 business days.
8. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
This Privacy Policy may be updated from time to time. We will notify clients of any material changes via email or through our client portal. Continued use of our services after changes constitutes acceptance of the updated policy.