Skip to main content

Privacy Policy

Last updated January 15, 2026 · draft-2026-01

Draft awaiting professional review

This document is a working draft prepared to support the platform. It has not yet been reviewed and approved by qualified Bangladesh counsel and must not be relied on as final terms.

What we collect and why

We collect only what a specific purpose requires:

  • Account data — name, email, phone, language. To create and secure your account.
  • Business data — your intended activity, structure, ownership and location. To work out which registrations apply.
  • Identity data — national ID or passport details, date of birth, nationality, address evidence. Because we are required to identify our customers and their beneficial owners.
  • Documents — what you upload and what we receive back from an authority.
  • Financial data — quotes, invoices, payment status. We do not receive or store your card or bank credentials; those go to the payment gateway.
  • Technical data — IP address and device information, kept in hashed form in security and audit records.

Every question in the questionnaire that touches on identity, ownership or funding carries a "Why we ask" explanation on the page itself.

Who we share it with

  • Government authorities, as part of an application you have instructed us to make.
  • Partner professionals, only for a case they are assigned to, only the information that matter needs, and only after you have authorised that specific sharing. The product shows you which partner and for what purpose.
  • Processors who host or operate the platform on our instruction: our cloud database and storage provider, our email provider, and our payment gateway.

We do not sell personal data, and we do not use it for advertising.

How we protect it

  • Documents are held in private storage. There is no public link to any customer document, ever.
  • Download links are short-lived and every upload, view, download and replacement is logged with who did it and when.
  • Access is enforced in the database itself, not only in the interface: a customer's data is reachable only by their own organisation, their assigned case team, and an authorised partner.
  • Staff accounts require two-factor authentication.
  • Identity numbers are stored as a last-four fragment plus a one-way token, not as readable numbers.
  • Data is encrypted in transit and encrypted at rest by our infrastructure provider.

We do not claim end-to-end encryption, because we do not implement it: our staff can read what they are authorised to read in order to do the work.

How long we keep it

Retention is set per record category and shown in the product:

  • AML/KYC records are retained for a statutory period after the relationship ends and cannot be deleted on request during that period.
  • Financial records are retained for the accounting and tax retention period.
  • Standard case documents are retained while the relationship is active plus a contractual limitation period.
  • Transient working copies are deleted once superseded.

*Placeholder: the exact statutory periods must be confirmed by Bangladesh counsel and a chartered accountant before launch. The product stores them as configuration so they can be set correctly without a code change.*

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Requests are made from Settings in your workspace and are recorded.

Where a legal retention obligation applies, we will hold the deletion for that record, tell you which records are held and why, and delete them when the obligation ends. That is a legal limit, not a refusal.

Where your data is processed

Our infrastructure providers may process data outside Bangladesh. The current list of processors, their role and their processing location is maintained in our internal processor register and is available on request.

*Placeholder: the processor register and any cross-border transfer safeguards must be completed and reviewed before launch.*