Privacy Policy | AI Automation & EOR Data Handling — EICRA
24082
privacy-policy,wp-singular,page-template,page-template-full_width,page-template-full_width-php,page,page-id-24082,wp-theme-bridge,bridge-core-3.3.5,sp-easy-accordion-enabled,qi-blocks-1.5.3,qodef-gutenberg--no-touch,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode_grid_1300,footer_responsive_adv,hide_top_bar_on_mobile_header,qode-smooth-scroll-enabled,qode-theme-ver-30.8.9.2,qode-theme-bridge,qode_header_in_grid,wpb-js-composer js-comp-ver-9.0.1,vc_responsive
 

Privacy Policy

Privacy Policy

How We Handle Personal Data in AI and Workforce Services

EICRA Soft Limited is a Dhaka-based technology and services company. Our main business is agentic AI business automation, alongside AI assurance, data analytics, IT and engineering, and Employer of Record and workforce services. This policy explains what personal data we collect, why we use it, who else can see it, where it goes, how long we keep it and what you can ask us to do about it.

It is written in plain English on purpose. If your legal or security team needs a signed Data Processing Agreement, transfer clauses or a sub-processor list, ask and we will send them before any data moves.

1. Scope and roles 2. Data we collect 3. Why we use it 4. AI and your data 5. Who we share with 6. International transfers 7. Retention and security 8. Your rights 9. Cookies FAQ

Scope, roles and who we are

Which services this policy covers, and whether we are the controller or the processor for each one.

1.1Who is responsible for your data

EICRA Soft Limited, registered in Bangladesh under RJSC number E67073(4565)/07, at JCX Business Tower, Plot 1136/A, Japan Street, Block I, Level 5, Suite G, Bashundhara R/A, Dhaka 1229, Bangladesh, is responsible for the personal data described in this policy. Telephone +880 1917 746550. Written enquiries go through the contact page.

1.2Services this policy covers

This policy applies to the eicra.com website and to every service we supply: the AI Services menu in full, and EOR and workforce services.

Services covered by this privacy policy
Group Services
Automation and Agents Workflow Automation · AI Integrations · Human-in-the-Loop · Agentic AI Consulting · AI Agent Development · AI Orchestration · Dedicated Development Team
AI Marketing AI Content Editing · Prompt Strategy · Custom Writing Prompts · Brand Personality Design · Email Marketing Personalisation · Campaign Management · Ad Bidding and Automation
AI Assurance Output and Model Validation · AI Code and Quality Verification · Risk and Governance Documentation · EU AI Act Documentation · Evidence and Traceability Documentation · AI Oversight for Payroll, AP and EOR · Error and Incident Documentation
Data Analytics Data Analytics · Data Visualisation · Data Science and Machine Learning · Data Engineering for AI-Ready Data · Data Quality and Cleansing
IT and Engineering Software Development · API Integration · Legacy Modernisation · AI Code Cleanup · Application Modernisation · Maintenance and Support
EOR and Workforce Employer of Record, staffing, work permits, payroll administration, corporate registration and related workforce services

1.3Controller or processor

The role we play depends on the activity, and it changes what you can ask us directly.

Our data protection role by activity
Activity Our role What that means
Website visitors and enquiries Controller We decide why and how the data is used, and you exercise your rights directly with us
Client data inside an automation or AI build Processor We act on your written instructions under a Data Processing Agreement; rights requests go to you as controller and we support you
Job applicants and our own staff Controller Handled under Bangladeshi employment law
EOR employees engaged for a client Controller and processor Controller for statutory employment and tax duties in Bangladesh; processor for the client-specific instructions layered on top

Personal data we collect

We collect what the service needs and nothing beyond it. There is no data broker purchase, no scraping and no profile building.

2.1What we collect and where it comes from

Categories of personal data, and their source
Category Examples Source
Enquiry and contact data Name, work email, phone, company, country, the message you send You, through the contact form, email or a call
Engagement data Named contacts, scope documents, approvals, correspondence, invoices You, during scoping and delivery
Client system data Records inside the CRM, ERP, help desk, mailbox or spreadsheet we automate, which may contain data about your staff, customers or suppliers Your systems, under your instruction and access
AI prompt and output logs Inputs sent to a model, outputs returned, confidence scores, exception and approval events Generated automatically while a workflow runs
Employment data (EOR) Identity documents, contracts, salary, bank details, attendance, leave, tax and provident fund records The employee and the client employer
Technical data IP address, browser and device type, pages viewed, referring page Automatically, when you use the website

We do not ask for special-category data (health, biometrics, religion, political opinion, trade union membership) and do not want it in an automation unless it is expressly scoped, contracted and safeguarded first. If your source data contains it, tell us at scoping so it can be excluded or protected.

Why we use personal data, and on what basis

Every use below has a purpose and a lawful basis. Where GDPR or UK GDPR applies to you, the basis column is the one we rely on.

Purposes of processing and lawful bases
Purpose Data used Lawful basis
Answering your enquiry and preparing a quotation Enquiry and contact data Steps at your request before entering a contract
Delivering the agreed services Engagement data, client system data, AI logs Performance of a contract; for client system data, your written instruction under a DPA
Human review of AI output The specific record under review and the approval log Performance of a contract, and our legitimate interest in preventing errors reaching your customers
Invoicing, accounting and tax Engagement and billing data Legal obligation under Bangladeshi tax law
Employing and paying EOR staff Employment data Contract of employment and legal obligation under the Bangladesh Labour Act 2006 and tax rules
Security, incident handling and audit trails Technical data, access and action logs Legitimate interest in keeping systems and client data secure
Website measurement Technical data, aggregated Consent where cookie consent applies; otherwise legitimate interest in running the site

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not make decisions producing legal or similarly significant effects on a person by automated means without a human checkpoint.

AI systems and your data

The section most buyers actually want to read. This is what happens to data once it touches a model.

4.1Your data is never used to train models

Client data is used only to deliver the agreed services. It is never used to train, fine-tune, evaluate or improve any model for EICRA or for a third party. Where a model provider offers a setting that excludes customer data from provider training, we enable it and record that in the scope.

4.2Model providers

Delivery may use third-party AI model providers. The scope names them before work starts, so you know which company processes your data before you agree to anything. Where the architecture allows, the workflow runs on credentials in your own name, which means your contract with that provider governs the processing directly.

4.3Prompts, outputs and logs

  • Prompts and outputs are logged so a failure can be explained after the fact and an auditor can trace a decision.
  • Logs are kept for the period stated in the scope, normally ninety days, unless a longer audit period is agreed in writing.
  • Logs are access-controlled and visible only to the named delivery team and to you.
  • Where a workflow can run without personal data in the prompt, it is built that way — masking, tokenising or referencing a record ID instead of the record.

4.4Human oversight

Every production AI system we deliver includes a human checkpoint wherever a mistake would affect a person, a payment or a legal position, together with a confidence threshold, an exception queue and an alert to a named reviewer. If you instruct us in writing to remove that checkpoint, the instruction is recorded in the scope and responsibility for unreviewed output passes to you.

4.5What we will not build

  • Automated decisions with legal or similarly significant effect on a person without a human checkpoint and a route to human review.
  • Systems that profile individuals for advertising or scoring without a lawful basis and a documented assessment.
  • Scraping or enrichment of personal data from sources a person would not expect.
  • Anything processing special-category or children’s data without express scoping, contract and safeguards.

Who else can see the data

A short list, named in writing before work starts, with a right to object to any addition.

Categories of recipient and why they receive data
Recipient Why
AI model providers To process the prompts a delivered workflow sends, named in the scope before work starts
Automation and integration platforms To run the workflow itself, normally inside your own account
Hosting, storage and communication providers To operate the website, email and project channels
Professional advisers Accountants, auditors and lawyers, bound by professional confidentiality
Bangladeshi authorities Where law requires it — tax filings, EOR employment and work permit filings, or a lawful order
A successor business If the business or part of it is transferred, under equivalent protections

The sub-processor list is provided at signing. No new sub-processor is added without prior written notice and your right to object. We do not sell or rent personal data to anyone.

International data transfers

Work is performed in Bangladesh. If you are outside Bangladesh, that is a transfer, and these are the instruments that cover it.

Transfer mechanisms by client jurisdiction
Your jurisdiction Instrument we sign
United Kingdom ICO International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses
European Union and EEA EU Standard Contractual Clauses, with a transfer risk assessment where required
Singapore PDPA transfer-limitation clauses, or the ASEAN Model Contractual Clauses
United States and Canada Contractual data protection terms in the DPA, aligned to the state or provincial law that applies to you
Gulf states and elsewhere Terms agreed at scoping stage before any data moves
Bangladesh Processed locally under Bangladeshi law; no cross-border transfer

Bangladesh has not been granted an adequacy decision by the UK or the EU. That is precisely why we execute the instruments above rather than relying on adequacy, and it is a fair question to ask any offshore supplier.

How long we keep data, and how we protect it

Nothing is kept indefinitely except where Bangladeshi law requires it.

7.1Retention periods

Retention periods by data category
Data Kept for
Enquiry and contact data Up to 24 months from last contact, then deleted
Engagement and scope documents Life of the engagement plus the contractual limitation period
Client system data Life of the engagement; returned or deleted on request afterwards
AI prompt and output logs The period in the scope, normally 90 days
Invoices and accounting records The period Bangladeshi tax law requires
EOR employment records The period the Bangladesh Labour Act 2006 and tax rules require
Website technical logs Short-term, for security and troubleshooting

7.2Security measures

  • Least-privilege access through named accounts; no shared logins.
  • Credentials held in your own vaults and accounts wherever the architecture allows.
  • Our access removed at handover or on termination.
  • Encryption in transit, and at rest where the platform supports it.
  • Confidentiality obligations on every person who works on your engagement.
  • Breach notification to you without undue delay after we become aware, with the facts known at that time.

7.3Return and deletion

On termination, or on your written request at any time, client data held for delivery is returned or deleted, subject to retention required by law or by a legitimate legal hold. Backups are overwritten on their normal cycle rather than surgically edited, and remain protected until then.

Your rights, and how to use them

What you can ask for, how to ask, and how quickly we answer.

8.1What you can ask for

  • Access — a copy of the personal data we hold about you.
  • Correction — fix data that is wrong or incomplete.
  • Deletion — erase data we no longer have a basis to keep.
  • Restriction — pause processing while a dispute is resolved.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — where consent is the basis, withdraw it at any time without affecting past processing.
  • Complain — to your national data protection authority, or in Bangladesh to the competent authority.

Where we act as processor for a client, requests about that client’s data go to the client as controller. Tell us anyway and we will pass it on and support the response.

8.2How to make a request

Send the request through the contact page or by telephone on +880 1917 746550, stating what you want and enough detail for us to find your records. We reply within thirty days. If the request is complex we will say so and give a revised date rather than go quiet. There is no charge unless a request is manifestly excessive or repetitive.

Cookies, tracking and changes to this policy

What the website itself stores, and how you will know when this policy changes.

9.1Cookies

This site uses cookies that are necessary for it to work — session handling, security and remembering your preferences. Where enabled, it also uses analytics cookies to count visits and see which pages are read. Analytics data is aggregated and is not used to build advertising profiles or sold to anyone.

You can block or delete cookies in your browser settings. Blocking essential cookies will stop parts of the site from working. Where a consent banner is shown, your choice is stored and can be changed at any time.

9.2Links to other sites

Pages here may link to other websites, including model providers and platform documentation. We are not responsible for their privacy practices; read their policies before giving them data.

9.3Changes to this policy

We may update this policy and will publish the revised version on this page with a new effective date and version number. Material changes affecting an active engagement are notified to the client contact in writing rather than left to be discovered.

9.4Contact

Where to send privacy questions and requests
Detail Information
Legal name EICRA Soft Limited
Registered office JCX Business Tower, Plot 1136/A, Japan Street, Block I, Level 5, Suite G, Bashundhara R/A, Dhaka 1229, Bangladesh
Telephone +880 1917 746550
RJSC registration E67073(4565)/07
Privacy requests Through the contact page, answered within 30 days
Related documents Terms and Conditions · DPA, NDA and transfer clauses on request

FAQ

Privacy questions buyers ask first

Short, checkable answers to the questions a security or legal team sends before signing.

What personal data does EICRA collect?

For business enquiries we collect the contact details you send us: name, work email, phone, company and the content of your message. For delivery we access the client data inside the systems we automate, which may contain personal data about your staff or customers. For EOR and workforce services we collect employee records required by Bangladeshi employment and tax law.

Is EICRA a data controller or a data processor?

Both, depending on the activity. For our own website visitors and business contacts we are the controller. For client data processed inside an automation or an EOR engagement we act as processor on your written instructions under a Data Processing Agreement.

Do you use client data to train AI models?

No. Client data is used only to deliver the agreed services. It is never used to train, fine-tune or improve any model for EICRA or for a third party, and where a model provider offers a setting that excludes customer data from provider training, we enable it.

Which third parties can see our data?

Only named sub-processors required for delivery: the AI model provider used in your build, the automation platform your workflow runs on, hosting and communication tools, and statutory bodies for EOR filings. The list is provided at signing and no new sub-processor is added without prior written notice and your right to object.

How are international data transfers handled?

For UK clients we execute the ICO International Data Transfer Agreement or the UK Addendum. Where EU GDPR applies we use the EU Standard Contractual Clauses. For Singapore clients we contract to PDPA transfer-limitation obligations. Processing takes place in Bangladesh unless the scope says otherwise.

How long do you keep data?

Enquiry data is kept for up to twenty-four months. Client data is kept for the life of the engagement and returned or deleted on request afterwards. AI prompt and output logs are kept for the period stated in the scope, normally ninety days, unless a longer audit period is agreed. Employment and tax records are kept for the period Bangladeshi law requires.

What rights do I have over my data?

You can ask for access, correction, deletion, restriction, portability or objection, and you can withdraw consent at any time. Where we act as processor, requests go to the client who is the controller and we support them. Requests are answered within thirty days through the contact page.

Does this website use cookies or tracking?

The site uses cookies needed to run the site and, where enabled, analytics cookies to measure traffic. Analytics data is aggregated and is not used to build advertising profiles. You can block or delete cookies in your browser; essential cookies are required for the site to work.

Need our DPA, NDA or transfer clauses before you share data?Tell us which country you contract from and we will send the templates your legal team needs — before any scoping call, not after.