PRIVACY & SECURITY

Privacy Policy & Data Security

How Akron Logic collects, uses, shares, secures and retains personal data across our website, client portal and services — and why we never see your card details.

Who we are and what this policy covers

Last updated: 31 August 2026

Akron Logic ("Akron Logic", "we", "us", "our") is the controller of the personal data described in this policy. We are an information technology company registered and operating in Bangladesh, providing custom software and application development, web and mobile engineering, hosting and domain services, IT infrastructure supply and support, cybersecurity and compliance services, technology talent sourcing, and professional training.

Our identity and registration details are:

  • Registered name: Akron Logic
  • Registered address: 267/17, Flat 7/E, Bankers Complex-01, New Town, Demra, Dhaka 1361, Bangladesh
  • Trade Licence number: TRAD/DSCC/007474/2026
  • Taxpayer Identification Number (TIN): (to be confirmed)
  • BIN / VAT registration: (to be confirmed)
  • Website: akronlogic.com

Questions, requests and complaints about personal data are handled by our Data Protection Lead:

  • Email: privacy@akronlogic.com
  • Telephone: +880 1721-496669
  • Hours: Sunday – Thursday, 10:00–19:00 (GMT+6), excluding Bangladesh government holidays
  • Post: Data Protection Lead, Akron Logic, 267/17, Flat 7/E, Bankers Complex-01, New Town, Demra, Dhaka 1361, Bangladesh

This policy applies to our public website at akronlogic.com, to our client portal and any account or project workspace we provide, and to the services delivered through them, including quotations, orders, invoices and online payments. It applies whether you are a prospective client, an active client, a supplier, a candidate, a training participant, or a visitor who only reads the site.

Akron Logic is the merchant for every order placed through akronlogic.com. Online card and mobile financial services payments are processed for us by Easy Payment System (EPS), operated by Optimum Solution and Services Limited (OSSL) (the "payment gateway"). The payment gateway is a separate organisation and processes payment credentials under its own terms and privacy notice. This policy explains what we do with your data; it does not, and cannot, describe the internal practices of the gateway, an issuing bank, a card scheme or a mobile wallet provider.

Read this policy together with our Terms of Service, Refund and Cancellation Policy, Delivery and Service Fulfilment Policy, Cookie Policy, Acceptable Use Policy and Payment Methods page.

What personal data we collect

We collect only what we need to quote for work, deliver it, take payment for it, support it, and meet our legal obligations. The categories below describe the data we hold; not every category applies to every person.

Identity data

  • Full name, and where relevant the name you are known by professionally.
  • Job title or designation, department, and the organisation you represent.
  • Business relationship role, such as authorised signatory, project contact or billing contact.
  • For suppliers, contractors and candidates: professional history, qualifications and references you choose to send us.

Contact data

  • Email address, including any additional address you nominate for invoices or notices.
  • Mobile and landline telephone numbers.
  • Billing address and, where hardware or physical deliverables are involved, the delivery address and the name and number of the person receiving them.
  • Preferred communication channel and language.

Account and authentication data

  • Username or login email for the client portal.
  • Your password, held only as a salted hash produced by a modern password hashing algorithm — we cannot read, recover or tell you your password.
  • One-time password (OTP) metadata: the fact that an OTP was requested, the channel used, the timestamp, and whether verification succeeded or failed. We do not retain the OTP value itself after verification.
  • Session identifiers, device and browser fingerprint attributes used for session security, and multi-factor authentication enrolment status.
  • Password reset, email verification and account recovery records.

Transaction and billing data

  • Order reference, quotation reference and invoice number.
  • Merchant transaction ID generated by our systems, and the gateway transaction ID returned to us by Easy Payment System (EPS).
  • Amount, currency (ordinarily BDT), tax and VAT components, and any discount applied.
  • Transaction status and status history, including authorised, successful, failed, cancelled, refunded or partially refunded.
  • Payment method category and non-sensitive descriptors only — for example "card", "mobile financial service" or "internet banking", the card scheme name, the issuing bank name where the gateway supplies it, and the masked last four digits where the gateway returns them.
  • Refund, cancellation and dispute records, including the reason given and the outcome.
  • Billing entity details needed for a valid tax invoice, such as company name, address, BIN and TIN.

Service delivery data

  • Project briefs, requirements, specifications, feedback and approvals you send us.
  • Support tickets, correspondence, call notes and meeting records.
  • Domain names, hosting plan details, DNS records and technical contact details where we provide hosting or domain services.
  • Access credentials or connection details you deliberately share with us to let us perform contracted work, which we handle under the security controls described below and delete or return at the end of the engagement.

Technical and usage data

  • IP address, approximate location derived from it, device type, operating system and browser version.
  • Pages requested, referring URL, timestamps, and error and performance diagnostics.
  • Server, application and security logs, including authentication attempts and administrative actions.
  • Cookie and consent records, as described in the cookies section below and in our Cookie Policy.

Compliance data

  • Records collected for anti-money-laundering and counter-terrorist-financing purposes where a transaction, client or engagement requires them, such as corporate registration documents, trade licence copies, or the identity documents of an authorised signatory.
  • Sanctions, fraud and transaction-monitoring flags and the notes recorded when a flag is reviewed.

We do not seek, and ask you not to send us, special category data such as health, religious, political or biometric information. If you send it to us unprompted, we will delete it unless we are required to keep it.

What we explicitly do not collect

We never receive, see or store full card numbers, CVV/CVC security codes, card expiry dates, card PINs, mobile financial services account PINs, or one-time passwords used to authorise a payment.

When you pay online, you are taken to the hosted checkout page operated by Easy Payment System (EPS) / Optimum Solution and Services Limited (OSSL). Your payment credentials are entered on that page, on the gateway's own systems, and are transmitted from your browser to the gateway. They are not routed through, logged by, or accessible to our servers, our staff or our contractors at any point.

What comes back to us is a result: a transaction identifier, an amount, a currency, a status, a payment method category and, where the gateway provides them, non-sensitive descriptors such as the scheme name or the masked last four digits of a card. That result is all we need to reconcile your order, issue your invoice and deliver your service.

Any security certification, authorisation or registration held by the payment gateway is a matter for the gateway and its own regulators. We make no representation about it in this policy, and you should rely on the gateway's own published information and terms.

Akron Logic does not hold and does not claim PCI DSS certification of its own, and we do not describe ourselves as PCI compliant. We do not need such certification for the model we operate, precisely because cardholder data never enters our environment. We are similarly not a bank, not a payment service provider or operator, and not licensed by Bangladesh Bank; we are a merchant that accepts payment through a third-party payment gateway.

We also never ask you for your password, your OTP or your PIN by email, telephone, SMS or chat. Any message that does is not from us — please report it to privacy@akronlogic.com immediately.

How we collect it

We collect personal data in three ways.

Directly from you. When you complete a contact, quotation or careers form; register for or use the client portal; place an order or complete checkout; email, call or message us; sign a proposal or contract; attend a training course; or send us documents in the course of an engagement.

Automatically, as you use the site. Through cookies and similar technologies, and through server and application logs generated whenever your browser requests a page or our systems process a request. This includes security telemetry such as failed login attempts and rate-limit events.

From the payment gateway and other third parties. After you complete or abandon a payment, Easy Payment System (EPS) returns the transaction result to us in two ways: by redirecting your browser back to our site with a result reference, and by a separate encrypted server-to-server callback (an Instant Payment Notification, or IPN) sent directly from the gateway to our servers. We treat the server-to-server callback, verified as described in the security section, as the authoritative record. We may also receive data from our bank in the course of settlement and reconciliation, from an accountant or auditor acting for us, from a recruitment partner where you were introduced to us as a candidate, and from public registries when we carry out due diligence on a corporate client.

Why we use your data

We use personal data for the following purposes, and for no incompatible purpose:

  1. 1.Contract performance and service delivery — preparing quotations, agreeing scope, provisioning accounts, domains, hosting and licences, executing the work, and providing the deliverables described in our Delivery Policy.
  2. 2.Payment processing and reconciliation — initiating a transaction with the gateway, verifying the result, matching payments to orders, issuing invoices and receipts, and maintaining the accounts of the business.
  3. 3.Refunds, cancellations and dispute handling — assessing and processing a request under our Refund and Cancellation Policy, and responding to a chargeback or bank query.
  4. 4.Customer support — answering questions, diagnosing faults, restoring service and keeping a history of what was asked and what was done.
  5. 5.Fraud prevention and transaction monitoring — detecting card testing, duplicated or manipulated orders, credential stuffing and other abuse, and protecting our systems and other clients.
  6. 6.Security and service integrity — operating access controls, logging, monitoring, backup and incident response.
  7. 7.Legal and regulatory compliance — issuing tax-compliant invoices, keeping accounting and transaction records, meeting anti-money-laundering and counter-terrorist-financing obligations where they apply to us, and responding to a lawful request from a competent authority.
  8. 8.Service improvement and analytics — understanding which pages and services are useful, measuring performance, and fixing what does not work, using aggregated or de-identified data wherever it will serve the purpose.
  9. 9.Marketing — sending service updates, offers and newsletters only where you have opted in, or where you are an existing client and the message concerns a service similar to one we already provide to you. Every marketing message carries a one-click unsubscribe, and unsubscribing never affects service delivery.
  10. 10.Recruitment and talent sourcing — assessing an application, and, where you consent, presenting your profile to a client engaging us for talent sourcing.

We do not sell personal data. We do not rent or trade contact lists. We do not use your data for automated decision-making that produces a legal or similarly significant effect on you; transaction-monitoring flags are always reviewed by a person before any action is taken on an account.

Cookies and tracking

Cookies are small files placed on your device by a website. We group ours into four categories.

  • Strictly necessary — required for the site and portal to work at all: session and authentication cookies, cross-site request forgery protection tokens, load-balancing, and the cookie that records your consent choice. These are set without consent because the service cannot be provided without them.
  • Preferences — remember choices you have made, such as interface layout, theme and language, so the site behaves consistently on your next visit.
  • Analytics — measure aggregate usage so we can improve the site. Set only after you accept analytics cookies in the consent banner.
  • Marketing — support advertising measurement and audience building. Set only after you accept marketing cookies in the consent banner.

What is actually deployed today. At the date of this policy, akronlogic.com runs on strictly necessary and preference cookies only. We have no third-party analytics, advertising or social tracking tags installed — no Google Analytics or Google Tag Manager, no Meta Pixel, no advertising remarketing tags. Session and authentication cookies expire when your session ends or, for a persistent login, after a limited period and in any event when you log out. The consent record and preference cookies persist for up to 12 months, after which you will be asked again. Server logs are separate from cookies and are covered in the retention section.

If we later deploy an analytics or marketing tool, we will name it in our Cookie Policy, add it to the consent banner as an opt-in category, and update the date at the top of this page before it is set on any visitor's device.

You can withdraw or change consent at any time through the consent banner control on the site, and you can block or delete cookies in your browser settings. Blocking strictly necessary cookies will prevent you from logging in or completing checkout. Note that the hosted checkout page sets its own cookies under the gateway's control and its own notice.

Who we share with

We share personal data only with the categories of recipient below, only to the extent needed, and only under contract or legal obligation.

  • The payment gateway — Easy Payment System (EPS), operated by Optimum Solution and Services Limited (OSSL), receives the order reference, amount, currency, and the customer name, email and mobile number needed to initiate and authenticate a payment and to send you a receipt.
  • Banks, card schemes and MFS providers — through the gateway, your transaction reaches an acquiring bank, the relevant card scheme or mobile financial services provider, and your own issuing bank or wallet provider. We do not choose these parties on your behalf beyond selecting a gateway, and each processes data under its own rules.
  • Our settlement bank — our Bangladeshi bank receives settlement and reconciliation information associated with your transaction reference.
  • Hosting and cloud infrastructure providers — our application and database are operated on managed cloud infrastructure, including a managed PostgreSQL, authentication and object-storage platform hosted in the Singapore region, together with a content delivery and DNS layer that terminates TLS at edge locations worldwide.
  • Email and messaging — our transactional and business email is delivered from our own mail servers, not a third-party bulk email service, which keeps message content within infrastructure we operate. Where an SMS or OTP message is sent, it is delivered through a Bangladeshi SMS aggregator, which receives only your mobile number and the message text.
  • Accountants, auditors and tax advisers — receive invoice and transaction records for statutory accounting, audit and tax filing.
  • Professional advisers — lawyers and insurers, where we need advice or must establish, exercise or defend a legal claim.
  • Subcontractors and specialist partners — where a project requires a named specialist, under a written confidentiality and data-protection agreement, and limited to the data that specialist needs.
  • Law enforcement, regulators, supervisory authorities and courts — where we are compelled by law or a valid legal process, or where disclosure is necessary to prevent or report a crime.
  • A successor entity — if the business or a relevant part of it is transferred, in which case you will be told before your data becomes subject to a different policy.

Every processor acting on our behalf is bound to process data only on our documented instructions, to keep it confidential, to apply appropriate security, and to delete or return it at the end of the engagement.

Cross-border transfer and currency

Some of the infrastructure and software we depend on is operated outside Bangladesh. In particular, our managed database, authentication and storage platform and our content-delivery and DNS layer store or route data on servers located outside Bangladesh, principally in Singapore and, for edge caching and TLS termination, at points of presence in multiple countries. Where personal data leaves Bangladesh, we apply the following safeguards: a written data-processing agreement with the provider, contractual confidentiality and security obligations, encryption in transit and at rest, restriction of access to named administrators, and selection of providers that publish an independently audited security programme. We keep the number of such providers deliberately small, and we do not transfer personal data to any party in a country where we cannot impose these safeguards.

Separately, and for the avoidance of doubt about your payment: the primary transaction currency for orders placed on akronlogic.com is BDT (Bangladeshi Taka), and such transactions are processed domestically through Easy Payment System (EPS), with settlement to a bank account held by Akron Logic in Bangladesh. An invoice may also be issued in USD and settled directly to us by international bank transfer or, for customers outside Bangladesh, in USDT stablecoin; those payments do not pass through Easy Payment System (EPS), and for a USDT payment we record the sending wallet address and the on-chain transaction hash in order to identify the payment and to return it if a refund becomes due. Where an invoice is quoted in another currency by agreement, the conversion basis is stated on the invoice, and your bank or wallet provider may apply its own conversion or cross-border fee that we neither set nor receive.

Data security

This section describes the technical and organisational controls we operate. They are the reason payment credentials never enter our environment.

Transport and network

  • Every page of akronlogic.com and the client portal is served exclusively over HTTPS with TLS 1.2 or higher; plaintext HTTP requests are permanently redirected to HTTPS.
  • HTTP Strict Transport Security (HSTS) is enabled, so a compliant browser refuses to connect to our domain over an insecure channel after its first visit.
  • Modern cipher suites only; legacy protocols and weak ciphers are disabled at the edge.
  • A security header baseline is applied, including a content security policy, X-Content-Type-Options, Referrer-Policy and frame-ancestor restrictions, to limit injection and clickjacking risk.
  • Rate limiting and abuse protection sit in front of authentication, checkout initiation and form endpoints.

Payment integration and secrets

  • All gateway credentials — merchant ID, store ID, gateway username and password, the hash or signature key, and the IPN decryption key — are held only in server-side environment variables on our infrastructure. They are never committed to the source repository, never embedded in client-side JavaScript, never placed in a cookie, localStorage or any other browser storage, and never sent to a browser.
  • Every request we make to the gateway API is signed, and every response and callback we receive is verified against that signature before it is acted upon. A callback that fails verification is rejected and logged as a security event.
  • The IPN callback is received on a dedicated server-side endpoint over TLS, is accepted only from the gateway, and is decrypted and validated server-side.
  • Before any order is marked paid or any service is released, we independently re-check the transaction with the gateway and confirm that the amount, currency, order reference and status match the order we created. A browser redirect alone is never treated as proof of payment, because a redirect can be replayed or manipulated by the client.
  • Transaction handling is idempotent: a repeated or duplicated callback cannot double-fulfil an order or trigger a second refund.
  • Credentials are rotated on a defined schedule and immediately on any suspicion of exposure, and on the departure of any person who had access to them.

Application and data

  • Passwords are stored only as salted hashes using a modern, deliberately slow password-hashing algorithm. Password reset uses single-use, time-limited tokens.
  • Multi-factor or OTP verification is available on portal accounts and is mandatory for every administrative account.
  • Access follows least privilege and is role-based: staff can reach only the data their role requires, and database row-level security enforces separation between client records at the data layer, not only in the application.
  • Administrative access is restricted to named individuals, is reviewed at least quarterly, and is revoked on the same working day that a person's role changes or their engagement ends.
  • Data is encrypted in transit and encrypted at rest on the managed database and storage platform.
  • Application, authentication and administrative actions are logged with timestamps and actor identity, and logs are protected against casual alteration.
  • Backups are taken on an automated schedule, encrypted, access-restricted, and restore-tested at least annually.

People and process

  • Every member of staff and every contractor is bound by a written confidentiality undertaking, and receives security and data-handling briefing on joining and refresher briefing at least annually.
  • Client credentials shared with us for a project are stored in a managed secret store, used only for the contracted purpose, and revoked or returned at the end of the engagement.
  • Changes reach production through reviewed, version-controlled deployment; dependencies are monitored for known vulnerabilities and patched on a risk-prioritised basis, with critical security patches applied as soon as practicable and normally within 7 working days.
  • We maintain an internal register of the personal data we hold, where it lives and who can reach it, and we review it at least annually.
  • Company devices used to access client data require full-disk encryption, screen lock and current endpoint protection.

No system is perfectly secure, and we make no claim that ours is. The controls described above are the controls we operate; the highest-risk data — your payment credentials — does not enter our environment at all; and we will tell you promptly if an incident affects your data.

Data retention

We keep personal data only as long as we have a purpose or an obligation for it. The periods below are the ones we apply. Where a Bangladeshi tax, accounting or financial-crime requirement prescribes a longer period, the statutory period prevails and our own schedule is aligned to it at the next review.

  • Transaction, invoice and payment records — 5 years from the end of the financial year in which the transaction occurred, in line with tax, VAT and accounting record-keeping requirements.
  • KYC and AML/CFT records, where collected — 5 years from the end of the business relationship or the date of the occasional transaction, consistent with the record-keeping expectations that apply to us as a merchant under the financial-crime framework referred to above.
  • Contracts, statements of work and signed approvals — 6 years from the end of the contract, to cover the limitation period for a contractual claim.
  • Client portal account data — for the life of the account, and then 12 months after closure, after which it is deleted or anonymised except where it forms part of a transaction record above.
  • Support tickets and correspondence — 24 months from the last message on the thread.
  • Server, application and security logs — 12 months, except where a log forms part of an open security or fraud investigation, in which case it is preserved until that matter closes.
  • Marketing consent and unsubscribe records — 3 years after consent is withdrawn, so we can prove we honoured your choice.
  • Recruitment and candidate data — 12 months after a decision, or longer if you consent to remain in our talent pool.
  • Backups — rolling encrypted backups retained for 35 days, after which they expire automatically.

When a record reaches the end of its period it is deleted, or irreversibly anonymised where we want to keep aggregate statistics. Data cannot always be erased instantly from a backup set; where you exercise a deletion right, we remove the record from live systems immediately and the backup copy expires on the cycle above, during which it is not used for any operational purpose.

Breach handling

We maintain an incident response procedure covering detection, escalation, containment, assessment, notification and post-incident review.

  1. 1.Detection and escalation. Any suspected incident — from a failed integrity check on a gateway callback to a lost device — is escalated to the Data Protection Lead immediately on discovery, and in any case within 24 hours.
  2. 2.Containment. We isolate the affected system, revoke or rotate exposed credentials and keys, force re-authentication where appropriate, and preserve evidence and logs before remediation.
  3. 3.Assessment. We establish what data was involved, how many people are affected, and the likely consequences for them.
  4. 4.Notification. Where an incident is likely to affect your rights, your funds or your account security, we will notify you directly and without undue delay, and in any event within 72 hours of confirming the breach, describing what happened, what data was involved, what we have done, and what you should do.
  5. 5.Gateway and partner notification. Where an incident touches payment flows in any way, we will notify Easy Payment System (EPS) / Optimum Solution and Services Limited (OSSL) without undue delay so that they and the acquiring institutions can take their own protective steps.
  6. 6.Authorities. We will report to a competent authority where the law requires it, and cooperate fully with any investigation.
  7. 7.Review. Every incident closes with a written root-cause review and a corrective action list with named owners and due dates.

We will not conceal an incident, and we will not delay telling you in order to complete our own investigation first.

Your rights and how to exercise them

Subject to applicable law and to the retention obligations described above, you may:

  • Access the personal data we hold about you and receive a copy of it.
  • Correct data that is inaccurate or incomplete.
  • Delete data where we no longer have a lawful reason to keep it. We cannot delete a transaction, tax or AML record before its statutory period expires, and we will tell you plainly when that is the reason.
  • Object to marketing at any time, by unsubscribing or by writing to us; this takes effect immediately and is unconditional.
  • Withdraw consent for anything we do on the basis of consent, including optional cookies, without affecting the lawfulness of what we did before withdrawal.
  • Restrict or object to a particular processing activity while a dispute about accuracy or legitimate interest is resolved.
  • Receive your data in a common, machine-readable format where it was provided by you and is processed by automated means.
  • Complain if you are unhappy with how we have handled your data.

To exercise any right, write to privacy@akronlogic.com with the subject line "Data request", telling us which right you are exercising and enough detail to find your records. You may also call +880 1721-496669 during Sunday – Thursday, 10:00–19:00 (GMT+6), excluding Bangladesh government holidays, but we will confirm the request in writing.

We will acknowledge your request within 3 working days and give a substantive response within 15 working days of verifying your identity. Working days are Sunday to Thursday, excluding Bangladesh government holidays. If a request is unusually complex we may extend the period once, and we will tell you why before the original deadline expires. We do not charge for a request unless it is manifestly unfounded or repetitive, in which case we will tell you the cost before doing the work.

We will verify your identity before releasing personal data, using details already on your account. We will never ask for your password or an OTP as part of that verification.

If you are not satisfied with our response, escalate in writing to the management of Akron Logic at 267/17, Flat 7/E, Bankers Complex-01, New Town, Demra, Dhaka 1361, Bangladesh, marked for the attention of the Data Protection Lead. We will review the matter afresh and reply. If you remain dissatisfied, you retain the right to seek a remedy from a competent authority or before the courts of Dhaka, Bangladesh under the laws of the People's Republic of Bangladesh. Nothing in this policy limits that right.

Requests about money rather than data — a refund, a cancellation or a duplicate charge — are handled under our Refund and Cancellation Policy. Where a refund is approved, funds are returned to the original payment method, on the issuing bank's or wallet provider's own processing schedule.

Children

Our website, client portal and services are directed at businesses and at adults acting in a professional capacity. They are not intended for, and we do not knowingly collect personal data from, any person under the age of 18. Where a training programme is offered to a participant under 18, enrolment and payment must be made by a parent, guardian or sponsoring organisation, and the contracting party is that adult or organisation.

If you believe a person under 18 has provided us with personal data, write to privacy@akronlogic.com and we will delete it promptly unless we are required by law to retain it.

Changes to this policy

We review this policy at least annually, and whenever we add a service, change a processor, or deploy a new tracking technology. Every revision is published on this page with a new Last updated date, which is the authoritative indication of the version in force.

Where a change is material — for example a new category of data, a new purpose, a new recipient, or a new international transfer — we will notify active clients by email to the address on their account, and will display a notice on the site, before or at the time the change takes effect. Continuing to use the site or our services after a change takes effect indicates acceptance of the revised policy; where the law requires fresh consent for a change, we will ask for it separately rather than infer it.

Contact us

For any question about this policy, about the personal data we hold, or about a data request or complaint:

  • Akron Logic
  • Registered address: 267/17, Flat 7/E, Bankers Complex-01, New Town, Demra, Dhaka 1361, Bangladesh
  • Privacy and data protection: privacy@akronlogic.com
  • Billing, refunds and support: support@akronlogic.com
  • General enquiries: contact@akronlogic.com
  • Telephone: +880 1721-496669
  • Hours: Sunday – Thursday, 10:00–19:00 (GMT+6), excluding Bangladesh government holidays (Asia/Dhaka (GMT+6))
  • Trade Licence: TRAD/DSCC/007474/2026 — TIN: (to be confirmed) — BIN/VAT: (to be confirmed)

You can also reach us through our Contact page, or read more about the company on our About page.

Questions about this document?

Write to contact@akronlogic.com or call +880 1721-496669WhatsApp. Akron Logic, 267/17, Flat 7/E, Bankers Complex-01, New Town, Demra, Dhaka 1361, Bangladesh. Office hours Sunday – Thursday, 10:00–19:00 (GMT+6), excluding Bangladesh government holidays.