Privacy Policy
Version 1.0. Effective date and date of last revision: 30 August 2026.
This Privacy Policy describes the manner in which AirOverflow (Private) Limited, having its registered office at the Business Incubation Center, Air University, E-9, Islamabad 44230, Islamic Republic of Pakistan (the "Company", "we", "us" or "our"), collects, records, stores, uses, discloses, transfers, retains and erases personal data relating to identified or identifiable natural persons ("you") in connection with the AirOverflow Arena platform (the "Platform"). The Company acts as data controller in respect of the processing described in clause 3. Where you access the Platform under the administration of a corporate or institutional tenant ("Organisation"), that Organisation acts as controller and the Company acts as processor in respect of the processing described in clause 6, and the terms of the applicable data processing agreement prevail over this Policy to the extent of any inconsistency.
1. Scope
This Policy applies to processing carried out through the Platform, including its web interfaces, application programming interfaces, virtualised laboratory environments, the Outpost virtual workstation, competitive and assessment modules, and associated support channels. It does not apply to third party services which you may reach by hyperlink and which operate under their own policies.
2. Categories of personal data processed
(a) Identity and account data: username, given name and family name where supplied, electronic mail address, hashed authentication credentials, multi factor authentication enrolment status, organisational affiliation, role and permission assignments, and profile material you elect to publish.
(b) Transactional data: subscription tier, purchase records, provider customer and checkout identifiers, invoice status and discount code redemption. Primary payment instrument data, including full card numbers, is collected and processed directly by our payment provider and is not received or stored by the Company.
(c) Usage and telemetry data: internet protocol address, browser and device characteristics, timestamps of authentication and of session activity, pages and endpoints requested, challenge submissions and their outcome, competitive rating history, course progress and assessment results.
(d) Laboratory data: configuration and runtime state of virtual machines, containers and virtual private network endpoints provisioned to you, files you place within them, and network flow records associated with them.
(e) Supervision data: where an Administrator initiates a monitoring session over your Outpost, and where you have affirmatively consented to that session, screen output recordings, filesystem state and keystroke input captured for the duration of that session. Where organisational policy mandates recording of a session, that fact is displayed to you before the session begins.
(f) Audit data: records of privileged and security relevant actions, including the identity of the actor, the affected subject, the action performed and the time of performance.
(g) Communications data: support correspondence, bug reports, comments and notifications.
3. Purposes and lawful bases of processing
The Company processes the categories described above for the following purposes and on the following bases. Performance of a contract with you: provisioning and operating your account, delivering laboratory environments and courseware, maintaining competitive rankings, and administering subscriptions and purchases. Compliance with a legal obligation: retention of transaction records, response to lawful requests from competent authorities, and taxation. Legitimate interests pursued by the Company or by a third party, being the security, integrity, availability and abuse resistance of the Platform, the prevention and investigation of misuse described in clause 5 of the Terms and Conditions, the establishment, exercise or defence of legal claims, and the improvement of service quality, in each case balanced against your rights and freedoms. Consent: capture of screen, filesystem and keystroke data under clause 2(e), and any optional communication for which consent is separately requested. Where processing rests on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Monitoring of laboratory sessions
Monitoring of an Outpost session is not enabled by default and does not commence merely because an Administrator has requested it. Upon such a request the Platform presents a notice identifying the categories of data to be captured, being the complete Outpost screen, filesystem and keystrokes, and requires your affirmative response. Where you decline, no capture occurs, the Outpost session is terminated, and the refusal is recorded in the audit log together with the identity of the requesting Administrator. Where you accept, capture is limited to the duration of the monitoring session and ceases upon its termination. Captured material is accessible only to Administrators of the Platform and, where you are enrolled under an Organisation, to Administrators of that Organisation, and each access is itself recorded in the audit log. Keystroke capture is confined to input directed to the monitored laboratory environment and does not extend to other applications, browser tabs or devices.
5. Recipients and disclosures
Personal data may be disclosed to: infrastructure and hosting providers engaged to operate compute, storage, content delivery and electronic mail services; the payment provider for the purpose of processing transactions; the Organisation under whose administration your account is placed, in respect of your activity within that Organisation; professional advisers under duty of confidence; and competent authorities where disclosure is required by law or is necessary for the establishment, exercise or defence of legal claims. The Company does not sell personal data and does not disclose it for independent advertising purposes. Processors are engaged under written contract imposing obligations of confidentiality, security and processing only on documented instruction.
6. Processing on behalf of an Organisation
Where your account is administered by an Organisation, that Organisation determines the purposes and means of processing in respect of enrolment, assessment, supervision and reporting, and the Company processes such data only on the Organisation's documented instruction. Requests to exercise the rights described in clause 10 in respect of that processing should be addressed to the Organisation, and the Company will assist the Organisation in responding.
7. International transfers
Personal data may be transferred to and processed in jurisdictions other than your own, including jurisdictions in which our infrastructure providers operate. Where such a transfer occurs, the Company implements appropriate safeguards, which may include contractual clauses affording protection substantially equivalent to that of the jurisdiction of origin, together with supplementary technical measures including encryption in transit and access control.
8. Retention
Account and identity data are retained for the duration of the account and for a period of ninety (90) days following its closure, save where a longer period is required for the establishment, exercise or defence of legal claims. Transaction records are retained for the period prescribed by applicable taxation and company law. Usage and telemetry data are retained for twelve (12) months. Laboratory data are destroyed with the environment upon its termination. Supervision data captured under clause 4 are retained for twelve (12) months from capture, or for such shorter period as the Organisation directs, and are then erased. Audit data are retained for twenty four (24) months. Upon expiry of the applicable period, data are erased or irreversibly anonymised.
9. Security measures
The Company implements technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest of credentials and integration secrets, hashing of authentication credentials using a computationally expensive function, role based access control with least privilege, isolation of laboratory environments from the control plane, restriction of privileged operations to authenticated Administrators, audit logging of privileged actions, and periodic review of access rights. No system is impervious to compromise, and the Company does not warrant absolute security. In the event of a personal data breach likely to result in a risk to your rights and freedoms, the Company will notify the competent authority and, where the risk is high, will notify you without undue delay.
10. Your rights
Subject to the conditions and exceptions of applicable law, you have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, portability of data you have provided, and objection to processing carried out on the basis of legitimate interests. Where processing rests on consent, you have the right to withdraw it. Requests should be addressed to the contact point in clause 13 and will be answered within thirty (30) days, which period may be extended where the request is complex. The Company may require verification of identity before acting. You have the right to lodge a complaint with the competent supervisory authority in your jurisdiction.
11. Cookies and local storage
The Platform uses cookies and browser local storage which are strictly necessary for authentication, session continuity, security and the retention of interface preferences. Authentication tokens are stored for the purpose of maintaining your session. The Platform does not employ third party advertising or cross site tracking technologies. Rejection of strictly necessary storage will prevent the Platform from functioning.
12. Automated decision making and children
The Platform performs automated evaluation of challenge submissions and automated calculation of competitive ratings and course progress. Such processing does not produce legal effects concerning you or similarly significantly affect you within the meaning of applicable data protection law, and human review is available on request. The Platform is not directed to persons under the age of eighteen (18) years, and the Company does not knowingly process the personal data of such persons. Where the Company becomes aware that it has done so, it will erase that data without undue delay.
13. Contact and amendment
Enquiries and requests under this Policy should be addressed to AirOverflow (Private) Limited, Business Incubation Center, Air University, E-9, Islamabad 44230, Pakistan, or by electronic mail to cc@airoverflow.com. The Company may amend this Policy from time to time. Material amendments will be notified by electronic mail or by prominent notice within the Platform not less than fourteen (14) days before they take effect, and the version and date at the head of this document will be revised accordingly.