Effective Date: October 1, 2026
Last Updated: October 1, 2026
1. Introduction
Welcome to Minimal (SMC-PVT) LTD ("Company," "we," "us," or "our"). We provide GoHighLevel (GHL) ecosystem architecture, automation, optimization, maintenance, and technical consulting services to digital agencies and business clients worldwide.
We respect your privacy and are committed to protecting personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us.
Because our client base is global, this policy is designed to comply with international privacy standards, including the General Data Protection Regulation (GDPR / UK GDPR), the California Consumer Privacy Act (CCPA / CPRA), and applicable global privacy laws.
2. Information We Collect
We collect information in three ways: directly from you, automatically through your interaction with our website, and through third-party platform integrations.
A. Information You Provide Directly
Contact & Identity Data: Name, business email address, phone number, company name, job title, and mailing address provided when you fill out forms, schedule a diagnostic call, or contact us.
Service & Account Credentials: Technical configuration details, system requirements, API keys, administrative access credentials, or sub-account permissions necessary to provide GoHighLevel setup and operations services.
Billing & Payment Information: Payment card details, billing address, and transaction history.
B. Information Collected Automatically
Device & Usage Data: IP address, browser type, operating system, referring URLs, device identifier, pages viewed, links clicked, and time spent on our website.
Tracking Technologies: Cookies, web beacons, and embedded scripts (such as LeadConnector/GoHighLevel scripts and Google Analytics) to monitor performance and optimize conversion flows.
C. Client Data Handled as a Processor
When providing GHL technical services, we may process end-user data stored within your GoHighLevel sub-accounts, CRM pipelines, or webhooks. In such cases, you (the client) act as the Data Controller, and we act as the Data Processor under our service contract or Data Processing Addendum (DPA).
3. How We Use Your Information
We use the collected data for the following operational and business purposes:
Service Delivery: To configure, optimize, build, and maintain your GoHighLevel sub-accounts, funnels, webhooks, and automation workflows.
Client Communication: To respond to inquiries, schedule discovery calls, send project updates, deliver customer support, and invoice for services.
Site Improvement: To monitor performance, troubleshoot technical errors, analyze user engagement, and enhance site functionality.
Marketing & Promotions: To send newsletters, updates, and promotional content (you may opt out at any time).
Legal Compliance & Security: To prevent fraudulent activity, enforce our service terms, and satisfy applicable legal or regulatory duties.
4. Legal Bases for Processing (GDPR / UK GDPR)
For individuals located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing personal data include:
Performance of a Contract: Used when delivering GHL setups, technical consulting, and ongoing support to your agency.
Legitimate Interests: Used for site analytics, fraud prevention, service security, and direct B2B marketing.
Legal Obligation: Used for payment processing and tax record compliance.
Consent: Used when sending opt-in marketing newsletters or placing non-essential tracking cookies.
5. Sharing & Disclosure of Information
We do not sell, rent, or trade personal information to third parties. We disclose data strictly as necessary under the following circumstances:
Service Providers & Third-Party Processors: We share data with trusted vendors that assist in operating our business. This includes GoHighLevel / LeadConnector for CRM, funnel hosting, and automation workflows; Stripe for handling all secure payment processing and transactions; and scheduling/analytics tools required to run our operations.
Business Transfers: In the event of a merger, acquisition, re-organization, or sale of assets, client data may be transferred as part of the transaction.
Legal Requirements: When required by law, subpoena, or government order to protect legal rights, user safety, or system security.
6. International Data Transfers
As a global operations service based in Lahore, Pakistan, your data may be transferred to, stored, and processed in countries other than your country of residence (including the United States and Pakistan). Whenever personal data originates from the EEA or UK, we ensure appropriate safeguards—such as Standard Contractual Clauses (SCCs)—are in place to protect your data.
7. Data Retention
We retain personal information only as long as necessary to fulfill the purposes outlined in this policy, complete service engagements, resolve disputes, and fulfill legal, tax, or accounting requirements.
Active Client Technical Credentials: Retained during the service engagement and deleted or revoked within 30 days of contract completion, unless requested earlier.
Lead & Marketing Data: Retained until you opt out or request erasure.
Financial & Billing Records: Retained for up to 7 years to comply with tax and audit laws.
8. Your Data Privacy Rights
Depending on your geographic location, you may have the following rights regarding your personal data:
Right to Access & Portability: Request a copy of the personal data we hold about you.
Right to Rectification: Request corrections to inaccurate or incomplete information.
Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
Right to Restrict or Object: Object to data processing based on legitimate interests or direct marketing.
Right to Withdraw Consent: Revoke consent for marketing communications or cookie usage at any time.
To exercise any of these rights, contact us at [email protected].
9. Data Security
We implement reasonable technical, administrative, and physical safeguards designed to protect personal data against unauthorized access, loss, alteration, or disclosure. This includes strict access controls and administrative credential management. However, no transmission over the Internet or storage mechanism can be guaranteed to be 100% secure.
10. Children's Privacy
Our website and services are strictly targeted to business professionals and agencies. We do not knowingly collect or solicit personal information from children under the age of 18.
11. Changes to This Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Any changes will be posted on this page with an updated "Effective Date."
12. Contact Us
If you have questions, concerns, or privacy requests regarding this policy, please reach out:
Company Name: Minimal (SMC-PVT) LTD
Email: [email protected]
Location: Lahore, Pakistan