Privacy Policy
How We Handle Personal Data in AI and Workforce Services
EICRA Soft Limited is a Dhaka-based technology and services company. Our main business is agentic AI business automation, alongside AI assurance, data analytics, IT and engineering, and Employer of Record and workforce services. This policy explains what personal data we collect, why we use it, who else can see it, where it goes, how long we keep it and what you can ask us to do about it.
It is written in plain English on purpose. If your legal or security team needs a signed Data Processing Agreement, transfer clauses or a sub-processor list, ask and we will send them before any data moves.
1. Scope and roles 2. Data we collect 3. Why we use it 4. AI and your data 5. Who we share with 6. International transfers 7. Retention and security 8. Your rights 9. Cookies FAQ
Scope, roles and who we are
Which services this policy covers, and whether we are the controller or the processor for each one.
1.1Who is responsible for your data
EICRA Soft Limited, registered in Bangladesh under RJSC number E67073(4565)/07, at JCX Business Tower, Plot 1136/A, Japan Street, Block I, Level 5, Suite G, Bashundhara R/A, Dhaka 1229, Bangladesh, is responsible for the personal data described in this policy. Telephone +880 1917 746550. Written enquiries go through the contact page.
1.2Services this policy covers
This policy applies to the eicra.com website and to every service we supply: the AI Services menu in full, and EOR and workforce services.
1.3Controller or processor
The role we play depends on the activity, and it changes what you can ask us directly.
Personal data we collect
We collect what the service needs and nothing beyond it. There is no data broker purchase, no scraping and no profile building.
2.1What we collect and where it comes from
We do not ask for special-category data (health, biometrics, religion, political opinion, trade union membership) and do not want it in an automation unless it is expressly scoped, contracted and safeguarded first. If your source data contains it, tell us at scoping so it can be excluded or protected.
Why we use personal data, and on what basis
Every use below has a purpose and a lawful basis. Where GDPR or UK GDPR applies to you, the basis column is the one we rely on.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not make decisions producing legal or similarly significant effects on a person by automated means without a human checkpoint.
AI systems and your data
The section most buyers actually want to read. This is what happens to data once it touches a model.
4.1Your data is never used to train models
Client data is used only to deliver the agreed services. It is never used to train, fine-tune, evaluate or improve any model for EICRA or for a third party. Where a model provider offers a setting that excludes customer data from provider training, we enable it and record that in the scope.
4.2Model providers
Delivery may use third-party AI model providers. The scope names them before work starts, so you know which company processes your data before you agree to anything. Where the architecture allows, the workflow runs on credentials in your own name, which means your contract with that provider governs the processing directly.
4.3Prompts, outputs and logs
- Prompts and outputs are logged so a failure can be explained after the fact and an auditor can trace a decision.
- Logs are kept for the period stated in the scope, normally ninety days, unless a longer audit period is agreed in writing.
- Logs are access-controlled and visible only to the named delivery team and to you.
- Where a workflow can run without personal data in the prompt, it is built that way — masking, tokenising or referencing a record ID instead of the record.
4.4Human oversight
Every production AI system we deliver includes a human checkpoint wherever a mistake would affect a person, a payment or a legal position, together with a confidence threshold, an exception queue and an alert to a named reviewer. If you instruct us in writing to remove that checkpoint, the instruction is recorded in the scope and responsibility for unreviewed output passes to you.
4.5What we will not build
- Automated decisions with legal or similarly significant effect on a person without a human checkpoint and a route to human review.
- Systems that profile individuals for advertising or scoring without a lawful basis and a documented assessment.
- Scraping or enrichment of personal data from sources a person would not expect.
- Anything processing special-category or children’s data without express scoping, contract and safeguards.
Who else can see the data
A short list, named in writing before work starts, with a right to object to any addition.
The sub-processor list is provided at signing. No new sub-processor is added without prior written notice and your right to object. We do not sell or rent personal data to anyone.
International data transfers
Work is performed in Bangladesh. If you are outside Bangladesh, that is a transfer, and these are the instruments that cover it.
Bangladesh has not been granted an adequacy decision by the UK or the EU. That is precisely why we execute the instruments above rather than relying on adequacy, and it is a fair question to ask any offshore supplier.
How long we keep data, and how we protect it
Nothing is kept indefinitely except where Bangladeshi law requires it.
7.2Security measures
- Least-privilege access through named accounts; no shared logins.
- Credentials held in your own vaults and accounts wherever the architecture allows.
- Our access removed at handover or on termination.
- Encryption in transit, and at rest where the platform supports it.
- Confidentiality obligations on every person who works on your engagement.
- Breach notification to you without undue delay after we become aware, with the facts known at that time.
7.3Return and deletion
On termination, or on your written request at any time, client data held for delivery is returned or deleted, subject to retention required by law or by a legitimate legal hold. Backups are overwritten on their normal cycle rather than surgically edited, and remain protected until then.
Your rights, and how to use them
What you can ask for, how to ask, and how quickly we answer.
8.1What you can ask for
- Access — a copy of the personal data we hold about you.
- Correction — fix data that is wrong or incomplete.
- Deletion — erase data we no longer have a basis to keep.
- Restriction — pause processing while a dispute is resolved.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — where consent is the basis, withdraw it at any time without affecting past processing.
- Complain — to your national data protection authority, or in Bangladesh to the competent authority.
Where we act as processor for a client, requests about that client’s data go to the client as controller. Tell us anyway and we will pass it on and support the response.
8.2How to make a request
Send the request through the contact page or by telephone on +880 1917 746550, stating what you want and enough detail for us to find your records. We reply within thirty days. If the request is complex we will say so and give a revised date rather than go quiet. There is no charge unless a request is manifestly excessive or repetitive.
Cookies, tracking and changes to this policy
What the website itself stores, and how you will know when this policy changes.
9.1Cookies
This site uses cookies that are necessary for it to work — session handling, security and remembering your preferences. Where enabled, it also uses analytics cookies to count visits and see which pages are read. Analytics data is aggregated and is not used to build advertising profiles or sold to anyone.
You can block or delete cookies in your browser settings. Blocking essential cookies will stop parts of the site from working. Where a consent banner is shown, your choice is stored and can be changed at any time.
9.2Links to other sites
Pages here may link to other websites, including model providers and platform documentation. We are not responsible for their privacy practices; read their policies before giving them data.
9.3Changes to this policy
We may update this policy and will publish the revised version on this page with a new effective date and version number. Material changes affecting an active engagement are notified to the client contact in writing rather than left to be discovered.
FAQ
Privacy questions buyers ask first
Short, checkable answers to the questions a security or legal team sends before signing.
What personal data does EICRA collect?
For business enquiries we collect the contact details you send us: name, work email, phone, company and the content of your message. For delivery we access the client data inside the systems we automate, which may contain personal data about your staff or customers. For EOR and workforce services we collect employee records required by Bangladeshi employment and tax law.
Is EICRA a data controller or a data processor?
Both, depending on the activity. For our own website visitors and business contacts we are the controller. For client data processed inside an automation or an EOR engagement we act as processor on your written instructions under a Data Processing Agreement.
Do you use client data to train AI models?
No. Client data is used only to deliver the agreed services. It is never used to train, fine-tune or improve any model for EICRA or for a third party, and where a model provider offers a setting that excludes customer data from provider training, we enable it.
Which third parties can see our data?
Only named sub-processors required for delivery: the AI model provider used in your build, the automation platform your workflow runs on, hosting and communication tools, and statutory bodies for EOR filings. The list is provided at signing and no new sub-processor is added without prior written notice and your right to object.
How are international data transfers handled?
For UK clients we execute the ICO International Data Transfer Agreement or the UK Addendum. Where EU GDPR applies we use the EU Standard Contractual Clauses. For Singapore clients we contract to PDPA transfer-limitation obligations. Processing takes place in Bangladesh unless the scope says otherwise.
How long do you keep data?
Enquiry data is kept for up to twenty-four months. Client data is kept for the life of the engagement and returned or deleted on request afterwards. AI prompt and output logs are kept for the period stated in the scope, normally ninety days, unless a longer audit period is agreed. Employment and tax records are kept for the period Bangladeshi law requires.
What rights do I have over my data?
You can ask for access, correction, deletion, restriction, portability or objection, and you can withdraw consent at any time. Where we act as processor, requests go to the client who is the controller and we support them. Requests are answered within thirty days through the contact page.
Does this website use cookies or tracking?
The site uses cookies needed to run the site and, where enabled, analytics cookies to measure traffic. Analytics data is aggregated and is not used to build advertising profiles. You can block or delete cookies in your browser; essential cookies are required for the site to work.
Need our DPA, NDA or transfer clauses before you share data?Tell us which country you contract from and we will send the templates your legal team needs — before any scoping call, not after.