Loading App...
Global Data Protection & Trust Framework

Privacy & Global Data Protection

Exhaustive disclosure of our technical operations, legal bases, global compliances, and user rights under international data protection laws and Bangladeshi statutes.

Last Revised: July 30, 2026Version: 3.0 (Enterprise Compliant)

1. Preamble & Business Scope

This Privacy and Global Data Protection Policy outlines the parameters, principles, and architectures used by Pakiza Software Limited (hereinafter "Pakiza," "we," "our," or "us") to govern data privacy. As the specialized technology arm of the Pakiza Group—a major manufacturing and Ready-Made Garments (RMG) conglomerate in Bangladesh—we serve enterprise clients across the globe.

This Policy applies globally to all systems, SaaS platforms, local network client-server tools, RMG ERP modules, smart utility billing portals, mobile applications (iOS and Android), and public B2B marketing pages developed or hosted by Pakiza Software Limited.

By licensing our software, loading our mobile modules, or interacting with our APIs, you accept the conditions laid down in this policy. If you represent an organization, you warrant that you are authorized to bind your users to this data framework.

2. Regulatory Compliances (National & International)

To ensure our business operations and software products are applicable and legally compliant everywhere, Pakiza Software maintains compliance with both local laws and global data frameworks:

A. Bangladeshi National Legislation

Operating under the jurisdiction of the People's Republic of Bangladesh, we actively comply with:

  • Information and Communication Technology (ICT) Act, 2006 (Section 63): Mandates confidentiality of all electronic messages, decryption codes, and secure data access pipelines.
  • Cyber Security Act, 2023: Dictates the security standards of digital portals, preventing database breaches, system intrusions, and hacking.
  • Data Protection Act (DPA) Drafts: We align our core database infrastructures to conform with the upcoming national DPA standards, including local storage of critical national databases and active consent requirements.

B. Global Standards Alignment

To serve clients in North America, Europe, and Asia, our software models are engineered to comply with:

  • General Data Protection Regulation (GDPR - EU 2016/679): We act as a Processor for European customer data. We secure data using Standard Contractual Clauses (SCCs) for cross-border transit.
  • California Consumer Privacy Act (CCPA) / CPRA: We provide consumers with explicit mechanisms to opt out of the sale of personal information, retrieve files, or request data deletion.

3. Controller vs. Processor Classifications

Data protection responsibilities depend on the context of data collection. We categorize our roles as follows:

Pakiza as a Data Controller

We act as a Data Controller for our marketing leads, corporate website analytics, administrative credentials (system admins, account managers), and corporate invoice records. In this mode, we decide what data to collect and how it is processed.

Pakiza as a Data Processor

We act as a Data Processor for all data entered into our ERP, POS, and HRMS systems by our corporate clients (factories, retail stores). Under this setup, the client is the Data Controller. We process this data strictly under the instructions of the client, as defined in our service contract.

4. Information We Collect

We collect and process personal data under clear guidelines:

A. Client Profile & Admin Data (Controller Mode)

Collected when setting up software licensing or corporate portals:

  • Names, work emails, corporate phone numbers, job roles, billing addresses.
  • Payment details, VAT/TDS registrations, business tax numbers.
B. Factory & Employee Data (Processor Mode)

Data managed inside our HRMS & ERP solutions by corporate clients:

  • Employee profiles: Name, National ID (NID) numbers, birth dates, salaries, bank credentials.
  • Work statistics: Roster times, punch-in/out stamps, overtime calculations.
  • Supply chain data: Fabric orders, yarn stock, dye logs, commercial invoices.
C. Technical Metadata (Controller/Processor Mode)

Collected automatically during API or portal utilization:

  • Device IP addresses, browser configurations, access times, click logs, and app crash logs.

5. Mobile Store Requirements (Google Play & Apple App Store)

Pakiza Software Limited deploys enterprise mobile applications (for example, employee roster apps, retail helper tools) to the Google Play Store and Apple App Store. In compliance with developer agreements, we disclose:

  • Device Permissions: Our applications request specific permissions (such as camera access for barcodes, local storage for document logs, and push notification tokens) dynamically. These permissions are only accessed for core app features.
  • Device Diagnostics: We collect non-personal analytics (model names, OS versions, application crashes) via Firebase SDK to maintain app stability. We do not run third-party SDKs that collect advertising identifiers (IDFA/GAID) without consent.
  • Account Deletion: Direct settings panels inside our mobile applications allow users to request profile deletion. Upon request, mobile-cached credentials and session tokens are deleted within 24 hours.

6. Cookies, SDKs & Digital Advertising

We use cookies, tracking pixels, and software SDKs on our public website to evaluate performance and run targeted ad campaigns:

Google Tag Manager & Analytics

Used to evaluate visitor flows, measure site speeds, and identify interface issues. This data is kept anonymous.

Meta/Facebook Pixel & LinkedIn Insight Tag

We run targeted B2B advertisements on Meta and LinkedIn networks. These tags help us evaluate the performance of our ads and show relevant software recommendations to professionals who have previously visited our platforms.

You can manage cookie settings in your browser or opt out of personalized tracking using Google Ad settings and Meta Ad parameters.

7. Legal Grounds & Intent for Processing

We process personal and organizational data under clear legal bases:

  • Contractual Necessity: To fulfill software licenses, deliver ERP services, compute factory payrolls, and invoice clients.
  • Legitimate Interests: To run vulnerability scans, verify license terms, optimize site performance, and protect our systems from cyber threats.
  • Legal Obligations: To comply with tax audit regulations from the National Board of Revenue (NBR) in Bangladesh, and respond to official judicial mandates.
  • Consent: For running retargeting ad campaigns, newsletters, and browser cookies.

8. Data Security & Storage Architectures

We implement zero-trust parameters to safeguard all customer databases:

Transit Shield

TLS 1.3 protocol guarding all API gateway queries and connections.

AES-256 Storage

Disk-level encryption rendering database logs unreadable to hijackers.

MFA Verification

Access requires Multi-Factor Tokens to prevent credential leakage.

9. Data Retention & Erasure Policies

We retain data in compliance with corporate SLAs and local tax and labor laws in Bangladesh:

  • Financial & Invoicing logs: Retained for 7 years to meet Bangladesh National Board of Revenue (NBR) audit rules.
  • Biometric Employee logs: Attendance templates are deleted within 30 days of employee termination or SLA cancellation.
  • Backup Archives: Database backups are automatically overwritten or deleted after 90 days.

10. Global Subject Rights (GDPR/CCPA/DPA)

Under global frameworks, users possess explicit rights regarding their identity data:

  • Right of Access: Request digital exports of the data we hold on you.
  • Right of Rectification: Edit incorrect metadata or credentials in our databases.
  • Right of Erasure ("Right to be Forgotten"): Request database wipes of account logs, subject to contract retention obligations.
  • Right to Object: Halt processing of personal logs for advertising or automated decision-making.

11. DPO & Corporate Contact Information

For inquiries regarding data compliance, biometric templates, or GDPR rights inside our systems, please reach out to our corporate security team in Dhaka:

Compliance Emailinfo@pakizasoftware.com
Phone Hotline+880 1713-060417
Corporate OfficeKhan ABC Tradeplex, House: 37, Floor: 11 (B-11), Road: 2, Dhanmondi, Dhaka 1205
Registered OfficeHouse: 97, Road: 11/A, Dhanmondi, Dhaka-1209, Bangladesh