LEGAL
Last updated: 1 August 2026
Comprehensive privacy policy detailing how Credosis collects, processes, and protects personal and business data.
Welcome to the privacy policy of Credosis ("we," "our," or "us"). We are an AI-first software agency based in Dhaka, Bangladesh, providing AI automation, intelligent chatbot development, custom ERP/CRM systems, SaaS development, and full-stack software engineering to clients worldwide.
This Privacy Policy applies to all visitors to our website (www.credosis.com) and to all clients who engage our services. It outlines how we collect, process, store, and protect your personal and business information.
We are strictly committed to complying with all applicable data protection regulations, including the Bangladesh Personal Data Protection Act, 2026 (PDPA 2026), and other relevant international legal frameworks.
For the purposes of this Privacy Policy, and in accordance with the PDPA 2026 terminology:
"Personal Data" refers to any information that can be used directly or indirectly to identify a natural person.
"Sensitive Personal Data" includes, but is not limited to, health records, biometric data, financial information, and geo-location data, which require higher levels of protection.
"Data Fiduciary" means the entity determining the purpose and means of processing Personal Data. In our engagements, Credosis generally acts as the Data Fiduciary regarding website visitors and as a Data Processor for our clients.
"Data Processor" refers to the entity that processes Personal Data on behalf of a Data Fiduciary.
"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
"Processing" means any operation performed on Personal Data, such as collection, recording, structuring, storage, alteration, retrieval, use, transmission, or erasure.
We collect information in three main categories to provide and improve our services:
1. Direct Information: When you contact us or engage our services, we may collect your name, email address, phone number, company name, job title, and specific project requirements via our contact forms and engagement contracts.
2. Passive Information: When you visit our website, we automatically collect certain technical information, including your IP address, browser type, device information, pages visited, and referral URLs, through the use of cookies and analytics technologies.
3. Client Engagement Information: During the delivery of our services, we may collect and process business data, technical specifications, source code, and other project materials shared by you to facilitate the engagement.
We process the information we collect for granular and specific purposes, including:
Delivering our services and fulfilling our contractual obligations to clients.
Communicating with you regarding project updates, inquiries, and customer support.
Analyzing website usage and engagement to improve our platform, user experience, and service offerings.
Conducting security monitoring to prevent unauthorized access, fraud, and cyber threats.
Marketing our services to you, subject to your preferences and consent.
Ensuring legal compliance and enforcing our terms and agreements.
We process your Personal Data strictly in accordance with Section 5 of the Bangladesh PDPA 2026 based on one or more of the following lawful grounds:
Explicit Consent: Where you have voluntarily, specifically, and explicitly opted in for processing (e.g., subscribing to newsletters). Consent is fully revocable at any time.
Contractual Necessity: Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into a contract.
Legitimate Interests: Where processing is necessary for our legitimate business interests, provided these do not override your fundamental rights and freedoms.
Legal Obligations: Where we must process your data to comply with applicable laws and regulatory requirements.
Vital Interests: Where processing is necessary to protect the vital interests of the Data Subject or another natural person.
Please note that any secondary processing, such as the training of AI models, requires separate, affirmative consent.
Our website uses cookies and similar tracking technologies to ensure functionality and improve your experience. These technologies are categorized as follows:
Strictly Necessary Cookies: Essential for the core operation of our website, enabling secure login and basic navigation.
Functional Cookies: Allow us to remember your preferences and settings to enhance your browsing experience.
Analytics and Performance Cookies: Help us understand how visitors interact with our website, allowing us to measure and improve performance using industry-standard analytics tools.
Marketing Cookies: Used to track visitors across websites to display relevant and engaging advertisements.
You can manage your cookie preferences through your browser settings or via our website's consent management banner.
As an AI-first agency, we prioritize the confidentiality and integrity of your proprietary data.
Client proprietary data, source code, and business information provided to us during engagements are NEVER used to train, fine-tune, or improve our own or third-party AI models.
When building client solutions, we engage third-party AI APIs strictly through enterprise-tier, zero-retention agreements. This ensures that the third-party providers do not store, retain, or use your data for model training after processing.
No client data is retained by third-party AI providers once the designated processing operation is complete.
We may use aggregated, de-identified usage metadata—strictly stripped of all Personally Identifiable Information (PII) and proprietary data—to monitor system performance and improve the overall quality of our services.
To effectively deliver our services, we may engage trusted third-party sub-processors across the following categories:
Cloud hosting providers, analytics platforms, payment processors, email and communication services, and AI API providers.
We ensure that all our sub-processors are contractually bound to uphold equivalent data protection standards, ensuring the confidentiality, security, and integrity of the data they process on our behalf.
We implement robust technical and organizational measures to safeguard your data against unauthorized access, loss, or alteration.
Technical Measures: We employ encryption for data in transit and at rest, enforce strict access controls, conduct regular security audits, and follow secure software development practices to mitigate risks.
Organizational Measures: We provide comprehensive data security training to our staff, enforce strict Non-Disclosure Agreements (NDAs), and ensure that data access is restricted on a strict need-to-know basis.
We retain data only for as long as is necessary to fulfill the purposes for which it was collected. Our retention periods by category are:
Website Analytics: Retained for up to 24 months.
Contact Form Submissions: Retained for up to 36 months.
Client Project Data: Retained for the duration of the active engagement plus 12 months, unless otherwise stipulated in our contractual agreement.
Financial and Legal Records: Retained for the periods strictly required by applicable law.
You maintain the right to request early deletion of your data, subject to any superseding legal or contractual obligations.
In compliance with Section 20 of the PDPA 2026, we maintain a stringent data breach response protocol.
In the event of a data breach that poses a significant risk to your rights and freedoms, we will notify the National Data Management Authority (NDMA) within 72 hours of becoming aware of the incident.
We will also promptly notify all affected individuals, providing a clear description of the nature of the breach, the potential consequences, and the remedial measures we are taking to mitigate any adverse effects.
Credosis does not sell, rent, or trade your personal data to third parties under any circumstances.
We limit information sharing exclusively to:
Service delivery via authorized sub-processors who assist in operating our business.
Legal compliance, responding to lawful requests from public authorities, or meeting national security requirements.
Protection of our rights, property, or the safety of our users and the public.
Business transfers, such as a merger, acquisition, or sale of assets, in which case you will receive prior notice before your personal data is transferred or becomes subject to a different privacy policy.
Given our global client base and modern technology stack, your data may be transferred to and processed on servers located outside of Bangladesh for cloud hosting and service delivery.
To ensure the protection of your data during international transfers, we implement robust safeguards. For our European clients, we utilize Standard Contractual Clauses (SCCs). Furthermore, we impose strict contractual data protection obligations on all international partners and exclusively use enterprise-tier AI API agreements with zero-retention policies.
By using our services, you acknowledge that our primary infrastructure may be hosted on international cloud platforms that adhere to the highest global security standards.
Under the PDPA 2026, you hold specific fundamental rights regarding your Personal Data:
You have the right to request access to the personal data we hold about you. You may request correction of any inaccurate or incomplete data.
You have the right to request the deletion of your personal data under specific conditions. You can withdraw your consent for processing at any time, without affecting the lawfulness of processing based on prior consent. You also have the right to data portability.
To exercise any of these rights, please contact us at hello@credosis.com. We are committed to responding to all legitimate requests within 30 days.
If you are a resident of the European Union or European Economic Area, you hold additional rights under the General Data Protection Regulation (GDPR).
These include the right to erasure (the "right to be forgotten"), the right to restrict processing, the right to object to processing (particularly for direct marketing), and the right to data portability.
You also possess the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal data violates the GDPR.
A Data Processing Agreement (DPA) incorporating Standard Contractual Clauses (SCCs) is available upon request for our EU/EEA clients. For inquiries, please contact our Data Protection Officer.
If you reside in California, you are granted specific rights under the California Consumer Privacy Act (CCPA).
You have the right to know the categories and specific pieces of Personal Information we have collected about you over the past 12 months.
You have the right to request the deletion of your Personal Information. You hold the right to opt-out of the sale of your Personal Information; however, please note that Credosis does not sell Personal Information.
We will not discriminate against you for exercising any of your CCPA rights.
Our website and services are not directed at, nor do we knowingly collect personal data from, individuals under the age of 16.
If we become aware that we have inadvertently collected personal data from a child under 16 without verified parental consent, we will take immediate steps to promptly and securely delete that information from our systems.
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our legal obligations, business practices, or technology.
In the event of material changes, we will notify you by prominently posting a notice on our website or by sending a direct communication to your registered email address.
Your continued use of our website or services following the implementation of changes constitutes your acceptance of the updated Privacy Policy. Previous versions of this policy remain available upon request.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.
Credosis Dhaka, Bangladesh
Website: www.credosis.com General Inquiries: hello@credosis.com
For any questions, contact us at hello@credosis.com