Executive Summary — At a Glance
Data Controller
Intactic Group Ltd.
Registered in Bangladesh
Response Window
Within 30 Days
For all data subject requests
Data Sales
None — Ever
We never sell personal data
Engagement Retention
5 Years
Post project completion
Intactic Group Ltd. ("Intactic", "we", "us") is committed to protecting your privacy. This combined Privacy & Cookies Notice explains what personal data we collect through intactic.net, how we use and safeguard it, who we share it with, and the rights available to you under applicable data protection law.
It also provides a complete inventory of the cookies this Site uses and the practical ways you can control them. Our approach is simple: collect the minimum required, protect it rigorously, and give you control without friction.
About This Notice
This Notice applies whenever you visit intactic.net or any of its subdomains, submit an inquiry or quotation request, subscribe to our insights, or engage our professional services. It does not apply to third-party platforms that we merely link to.
Where you become a client, additional data processing terms — including confidentiality and data processing schedules — are defined in your Engagement Agreement. Those agreements operate alongside this Notice and provide additional protections for client materials.
Data We Collect
We collect data through two channels — information you provide directly, and data gathered automatically.
Identity & Contact
Name, email address, phone number, job title, and company name — provided when you contact us, request a quote, or subscribe to updates.
Project & Business Data
Requirements briefs, budget ranges, timelines, and documents you choose to share during scoping or engagement discussions.
Technical Data
IP address (truncated where possible), browser type and version, operating system, device type, and time zone — collected automatically.
Usage Data
Pages visited, duration of visit, referral source, and interactions with site features — in aggregated or pseudonymous form.
Communication Records
Records of correspondence through email, contact forms, and scheduled calls with our team during office hours.
Preferences
Marketing preferences, communication consents, and cookie settings — retained so we can honor your choices.
We do not collect special-category data (such as health, biometric, or political data), and we do not knowingly collect data from children — see Section 14.
How We Use Your Data
We process personal data only for defined, legitimate purposes:
- Responding to your inquiries and delivering information you request — such as proposals, quotations, and technical guidance.
- Delivering and managing our professional services, including project communication, invoicing, and support.
- Improving our Site, services, and content through aggregated analytics and performance monitoring.
- Protecting the security and integrity of our systems — including fraud prevention and abuse detection.
- Sending insights and marketing communications — only where you have opted in, and with one-click unsubscribe in every message.
- Meeting legal, accounting, and regulatory obligations applicable to our operations.
Our promise: Intactic does not sell, rent, or trade your personal information to any third party for their marketing purposes. Ever.
Legal Bases for Processing
Where data protection law requires a legal basis, we rely on the following:
Contract
Processing necessary to respond to your inquiries and to perform obligations under an Engagement Agreement with you.
Legitimate Interests
Operating and securing our Site, improving service quality, and defending legal claims — assessed through balancing tests to respect your rights.
Consent
Sending optional marketing communications and setting non-essential cookies — you may withdraw consent at any time.
Legal Obligation
Retaining records for tax, accounting, and regulatory compliance as required by the laws of Bangladesh.
Data Sharing & Disclosure
We share personal data only with carefully selected categories of recipients:
- Service providers and sub-processors — cloud hosting, analytics, email delivery, and payment infrastructure — bound by contractual confidentiality and data protection commitments.
- Professional advisors — lawyers, accountants, and auditors — under confidentiality obligations, where necessary for legitimate business purposes.
- Law enforcement or regulators — only where disclosure is required by applicable law, regulation, or valid legal process.
- Business restructuring — in the event of a merger, acquisition, or asset sale, data may be transferred subject to this Notice and applicable law.
Every sub-processor we engage is assessed for security posture and contractual safeguards before receiving any data, and we maintain an internal register of processing activities.
International Data Transfers
Our infrastructure partners — including cloud hosting, database, and media delivery services — may process data in data centers located outside Bangladesh. Where personal data is transferred internationally, we apply appropriate safeguards such as contractual data protection clauses and, where applicable, standard contractual clauses.
We select providers whose infrastructure meets internationally recognized security certifications, and we minimize the scope of transferred data to what is strictly necessary for the service provided.
Data Retention & Deletion
We retain personal data only as long as necessary for the purposes described in this Notice, and in accordance with statutory retention obligations:
Project Data
5 Years
After project completion — supporting maintenance and warranty needs.
Inquiry Records
24 Months
From last interaction — for follow-up continuity and audit.
Marketing Consents
Until Withdrawn
Preferences retained so we can honor your choices.
When retention periods expire, data is securely deleted or irreversibly anonymized. You may request earlier deletion at any time — see Section 9 — subject to legal retention obligations which may require us to keep certain records (such as invoices) for the statutory period.
Data Security Measures
We implement layered, industry-standard controls aligned with enterprise practice to protect personal data against unauthorized access, alteration, disclosure, or destruction:
TLS 1.2+ / SSL encryption for all data transmitted between your browser and our servers.
Encryption at rest for stored data, including database-level protection.
Role-based access control following the principle of least privilege.
Audit logging and monitoring of administrative activities.
Regular dependency, vulnerability, and security posture reviews.
Team-wide security awareness training and incident response procedures.
No system is perfectly secure. In the unlikely event of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority without undue delay, consistent with our incident response procedures and applicable law.
Your Rights & Requests
Depending on your jurisdiction, you may exercise the following rights over your personal data at any time:
Right of Access
Request a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete personal data.
Erasure
Request deletion, subject to legal retention duties.
Restriction
Ask us to pause processing pending dispute or review.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests.
You may also withdraw consent for marketing or non-essential cookies at any time — withdrawal does not affect the lawfulness of earlier processing. To exercise any right, email [email protected]. We respond within thirty (30) days, may verify your identity before acting, and never charge a fee — except where requests are manifestly excessive or repetitive.
Understanding Cookies
Cookies are small text files placed on your device when you visit a website. They allow the site to remember your actions and preferences — enabling everything from keeping you signed in to understanding which articles resonate with readers.
Cookies are not programs: they cannot install malware, access your files, or transmit viruses. They simply store small amounts of data — set either by us (first-party) or by embedded third-party services (third-party) — that your browser returns on subsequent visits.
Session Cookies
Temporary cookies that expire automatically when you close your browser. Used for session integrity and security during a single visit.
Persistent Cookies
Remain on your device for a defined period — remembering preferences and enabling analytics continuity across visits.
Cookies We Use
The following table presents our complete cookie inventory, reviewed regularly by our engineering team:
We periodically audit this inventory and remove cookies that are no longer required. Changes are reflected in the "Last Updated" date on this page.
Managing Cookie Preferences
You have full control over non-essential cookies through your browser settings. Blocking any category is straightforward — note that blocking strictly necessary cookies may affect core site functionality:
Google Chrome
Settings → Privacy & Security → Third-party cookies
Mozilla Firefox
Settings → Privacy & Security → Cookies & Site Data
Apple Safari
Settings → Privacy → Manage Website Data
Microsoft Edge
Settings → Cookies & Site Permissions
You may also opt out of Google Analytics tracking entirely using the official Analytics opt-out browser add-on. Deleting cookies is equally effective — most browsers offer a clear-cookies action within the same settings panels shown above.
Third-Party Technologies
The Site embeds or relies upon a small number of established third-party technologies — including Google Analytics for aggregate traffic measurement, Cloudflare for security and performance, and select media or video embeds within our insights. These parties may set their own cookies under their own policies.
We apply a least-privilege approach to third-party integrations: each one must serve a defined purpose, and each is reviewed before deployment. We encourage you to consult the privacy policies of these providers through the links available when their content is presented.
Children’s Privacy
The Site is intended for business audiences and is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you are a parent or guardian who believes a child has provided us with personal data, please contact us at [email protected] and we will delete such data promptly upon verification.
Changes to This Notice
We may update this Notice to reflect changes in our data practices, technology stack, or legal requirements. Material changes will be signaled by an updated "Last Updated" date and, where appropriate, a revised version number and direct notice to affected individuals.
We recommend reviewing this page periodically. Your continued use of the Site following any update constitutes acknowledgment of the revised Notice, except where additional consent is required by law — in which case we will request it explicitly.
Official Correspondence
Contact Our Data Team
For privacy questions, data subject requests, cookie concerns, or to exercise any right described in this Notice — reach our data governance desk through any channel below. Every request receives a documented response.
Privacy & Data Requests
[email protected]
DSARs, privacy queries, concerns
Products & Platform Data
[email protected]
Product data handling
Companion Document
Terms & Policies
Review the contractual framework governing your use of intactic.net — intellectual property, acceptable use, payment terms, liability, and governing law.