Privacy Policy
Last updated January 15, 2026 · draft-2026-01
Draft awaiting professional review
What we collect and why
We collect only what a specific purpose requires:
- Account data — name, email, phone, language. To create and secure your account.
- Business data — your intended activity, structure, ownership and location. To work out which registrations apply.
- Identity data — national ID or passport details, date of birth, nationality, address evidence. Because we are required to identify our customers and their beneficial owners.
- Documents — what you upload and what we receive back from an authority.
- Financial data — quotes, invoices, payment status. We do not receive or store your card or bank credentials; those go to the payment gateway.
- Technical data — IP address and device information, kept in hashed form in security and audit records.
Every question in the questionnaire that touches on identity, ownership or funding carries a "Why we ask" explanation on the page itself.
How we protect it
- Documents are held in private storage. There is no public link to any customer document, ever.
- Download links are short-lived and every upload, view, download and replacement is logged with who did it and when.
- Access is enforced in the database itself, not only in the interface: a customer's data is reachable only by their own organisation, their assigned case team, and an authorised partner.
- Staff accounts require two-factor authentication.
- Identity numbers are stored as a last-four fragment plus a one-way token, not as readable numbers.
- Data is encrypted in transit and encrypted at rest by our infrastructure provider.
We do not claim end-to-end encryption, because we do not implement it: our staff can read what they are authorised to read in order to do the work.
How long we keep it
Retention is set per record category and shown in the product:
- AML/KYC records are retained for a statutory period after the relationship ends and cannot be deleted on request during that period.
- Financial records are retained for the accounting and tax retention period.
- Standard case documents are retained while the relationship is active plus a contractual limitation period.
- Transient working copies are deleted once superseded.
*Placeholder: the exact statutory periods must be confirmed by Bangladesh counsel and a chartered accountant before launch. The product stores them as configuration so they can be set correctly without a code change.*
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Requests are made from Settings in your workspace and are recorded.
Where a legal retention obligation applies, we will hold the deletion for that record, tell you which records are held and why, and delete them when the obligation ends. That is a legal limit, not a refusal.
Where your data is processed
Our infrastructure providers may process data outside Bangladesh. The current list of processors, their role and their processing location is maintained in our internal processor register and is available on request.
*Placeholder: the processor register and any cross-border transfer safeguards must be completed and reviewed before launch.*