Privacy Policy
The short version
- We collect only what you type into our two forms (newsletter and project enquiry) plus basic technical data any web server receives.
- We use it to reply to you, to send the newsletter you asked for, and to keep this site secure. Nothing else.
- We do not sell or share your personal data for advertising, we do not profile you, and this site sets no cookies and uses no analytics or ad trackers.
- You can ask us to access, correct, export or delete your data, or stop emails, at any time: admin@techvigilant.com.
1. Who we are
This policy explains how TechVigilant (“TechVigilant”, “we”, “us”), based in Dhaka, Bangladesh, handles personal data collected through techvigilant.com and www.techvigilant.com (the “Site”).
For this Site we are the controller (the organisation that decides why and how personal data is used) under the EU General Data Protection Regulation (GDPR), the UK GDPR and equivalent laws, and the “business” under the California Consumer Privacy Act as amended by the CPRA (CCPA). All privacy questions and requests go to admin@techvigilant.com, which is read by the person responsible for data protection at TechVigilant.
2. What we collect, why, and for how long
We collect personal data only in the ways below. Retention periods are maximums; we delete or anonymise data sooner when we no longer need it.
| What | Data | Why we use it | Legal basis (EU/UK) | How long we keep it |
|---|---|---|---|---|
| Project enquiry form | Name, work email, company (optional), services you select, your message, date and time received. | To read your request, reply, and scope work with you. | Steps at your request before a contract (Art. 6(1)(b)); our legitimate interest in running our business and answering enquiries (Art. 6(1)(f)). | Up to 24 months after our last contact with you. If we start working together, the records we need move under the contract and are kept as the contract and applicable law require. |
| Newsletter (“The Dispatch”) | Name (optional), email, the topics you tick (blog posts, news, offers), date and time received. | To send you the emails you chose. | Your consent (Art. 6(1)(a)). You can withdraw it at any time. | Until you unsubscribe or withdraw consent. We then delete your details within 30 days, keeping only the minimum needed to remember not to email you again. |
| Technical and security data | IP address, browser and device type (user agent), requested page, time, response code. Collected automatically by our hosting provider when you visit. | To deliver the Site, keep it secure, prevent abuse and spam, and diagnose faults. | Our legitimate interest in a secure, working website (Art. 6(1)(f)). | Short-lived operational logs: typically a few days and never more than 30 days. |
| Emails you send us | Your email address, the content of your message and any attachments. | To respond and keep a record of the conversation. | Legitimate interest (Art. 6(1)(f)) or steps before a contract (Art. 6(1)(b)). | Up to 24 months after our last contact, unless a contract or the law requires longer. |
You are never required to give us personal data, but we cannot answer a request or send a newsletter without the fields marked as needed (name and email for an enquiry; email for the newsletter). We do not knowingly collect “special category” data (such as health or political opinions). Please do not include it in free-text boxes.
3. What we do not do
- We do not sell personal data and we do not “share” it for cross-context behavioural advertising (these terms are defined by the CCPA).
- We do not run advertising, retargeting or social-media tracking pixels.
- We do not use analytics or session-recording tools on the Site.
- We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not profile visitors.
- We do not buy or enrich contact lists with data about you.
6. International transfers
We are based in Bangladesh and our providers operate globally, so your data will be transferred outside the country where you live, including from the European Economic Area (EEA) or the UK. Where the GDPR or UK GDPR requires it, we rely on an appropriate transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses (with the UK Addendum or the UK International Data Transfer Agreement), or, in limited cases, your explicit consent or the necessity of the transfer to carry out your request. Cloudflare and Google each offer data-processing terms that include these safeguards. You can ask us for a copy of the safeguards we rely on at the address below.
7. Your rights
Depending on where you live, you have some or all of the rights below. We apply the same rights to everyone, wherever you are, to the extent we are able to.
- Access – get a copy of the personal data we hold about you and information about how we use it.
- Correction – have inaccurate or incomplete data fixed.
- Deletion (“right to be forgotten”) – have your data erased, unless we must keep it by law or to defend legal claims.
- Restriction – ask us to pause using your data while a dispute about it is resolved.
- Portability – receive the data you gave us in a structured, commonly used, machine-readable format (we use JSON or CSV) and have it sent to another controller where feasible.
- Objection – object to processing based on our legitimate interests, and to any direct marketing, at any time and free of charge.
- Withdraw consent – at any time, with no effect on processing that happened before. Every newsletter includes a way to unsubscribe, or just email us.
- Complain – to your data-protection authority (for example your national EU supervisory authority, the UK Information Commissioner’s Office, or your state attorney general). We would appreciate the chance to resolve it first.
How to use your rights
Email admin@techvigilant.com with the subject “Privacy request” and tell us what you would like. To protect you, we may ask you to confirm you control the email address involved, or to give details only you would know. We answer within one month (GDPR/UK GDPR) or 45 days (CCPA), and tell you if we need more time and why. There is no fee unless a request is clearly unfounded or excessive, in which case we will explain before doing anything. You may use an authorised agent; we will ask for proof of their authority. We will never penalise you or treat you differently for exercising a right.
8. Information for specific regions
European Economic Area and United Kingdom
The legal bases for each use of your data are listed in section 2. Where we rely on legitimate interests, we have weighed them against your rights and interests; you can ask us about that assessment.
California and other US states
In the last 12 months we have collected the following categories of personal information (CCPA categories): identifiers (name, email, IP address), customer-records information (company name), internet or network activity (basic request logs), and other information you choose to give us in messages. We collect these directly from you and automatically from your device, for the business purposes described in section 2, and disclose them only to the processors in section 5. We do not sell or share personal information, we do not knowingly sell or share the personal information of anyone under 16, and we do not collect “sensitive personal information” as defined by the CPRA. California residents, and residents of other US states with comparable laws (for example Virginia, Colorado, Connecticut, Texas), may request to know, access, correct, delete and port their data, and to appeal a refusal, as set out in section 7. Under California’s “Shine the Light” law, we do not disclose personal information to third parties for their own direct marketing.
Other countries
If you live somewhere with its own privacy law (for example Canada, Brazil, Australia, Singapore or India), you may have additional rights. Contact us and we will honour them as the law requires.
9. How we protect your data
We use industry-standard safeguards appropriate to the risk: all traffic to the Site is encrypted in transit (HTTPS/TLS); form submissions are stored in private object storage that is encrypted at rest and is not publicly accessible; access to submissions requires a secret credential and is limited to people at TechVigilant who need it; the Site applies strict input validation, a content-security policy and other browser security headers; and we keep our software dependencies minimal. No system is perfectly secure. If a personal-data breach is likely to put your rights at risk, we will notify the relevant authority within 72 hours where the law requires and will tell affected people without undue delay.
10. Children
The Site is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 (or the higher age set by local law). If you believe a child has given us personal data, contact us and we will delete it.
11. Changes to this policy
We will update this policy when our practices, providers or the law change. We always show the “Last updated” date at the top and record changes below. For material changes that affect how we use data you have already given us, we will tell you before the change takes effect (by email to subscribers, or a notice on the Site), and ask for your consent again if the law requires it.
| Date | Change |
|---|---|
| 5 October 2026 | First published version. |
12. Contact us
TechVigilant
Dhaka, Bangladesh
Email: admin@techvigilant.com
Phone: +880 1339-482000
You can also read our Terms of Use.
This policy is written in plain language on purpose. If anything here is unclear, ask us and we will explain it.