Data is our work, so we take protecting it seriously. This Data Protection Policy explains how BigiByte handles the data we collect, process and deliver for clients, how we approach lawful data collection, and the safeguards we apply. For information we collect about website visitors and prospects, see our Privacy Policy.
1. Our principles
- Lawful and fair: we collect only publicly available data or data our client is authorised to access, for a purpose the client has confirmed is lawful.
- Purpose-limited and minimal: we collect only the fields a project needs and avoid personal data unless it is required.
- Accurate: we validate, clean and deduplicate data before delivery.
- Limited retention: we keep project data only as long as needed to deliver and support the work.
- Secure and confidential: access is restricted to the people working on the project.
- Accountable: we document how data is collected and can explain it to clients and regulators.
2. Our role
When we collect or process personal data on a client's behalf, the client is the controller (or "business") and BigiByte is the processor (or "service provider"). We process that data only on the client's documented instructions, for the purposes of the engagement, and never for our own purposes or to sell.
We offer a Data Processing Agreement (DPA) covering GDPR Article 28 terms, the EU Standard Contractual Clauses and the UK Addendum, and US state privacy law service-provider terms. Email info@bigibyte.com to request one.
3. Responsible data collection
- We review each project's sources, the data requested and the intended use before we start.
- We do not bypass paywalls, logins or technical access controls without authorisation, and we do not collect data the source clearly prohibits where doing so would be unlawful.
- We use polite crawling practices: sensible rate limits, caching, and avoiding load that could harm a website.
- We do not knowingly collect special-category or sensitive data (such as health, biometric, political or children's data) unless the client has a clear lawful basis and we have agreed safeguards in writing.
- For lead generation, we focus on business contact data and help clients meet applicable rules such as GDPR, CAN-SPAM, CASL and the ePrivacy rules, including honouring opt-outs.
- We may decline or stop work that we believe is unlawful or harmful. See our Acceptable Use Policy.
4. Security measures
- Encryption in transit (TLS) for all data transfers and deliveries, and encryption at rest on the storage services we use.
- Least-privilege access, unique accounts and multi-factor authentication on systems holding client data.
- Separate storage per client project, and credentials kept in secret managers rather than in code.
- Confidentiality commitments from every team member and subcontractor, and access removed promptly when someone leaves a project.
- Vetted infrastructure providers with recognised security certifications.
- Regular review of access and dependencies.
5. Subprocessors
We use a small number of infrastructure providers (for example cloud hosting, storage and email delivery) to perform the Services. We choose providers with strong security practices, bind them by written contracts, and will tell clients about new subprocessors that handle their personal data so they can object on reasonable grounds.
6. International transfers
Our team works from the United States and Bangladesh, and our providers may process data in other countries. Where personal data from the EEA, UK or Switzerland is transferred, we use appropriate safeguards such as the Standard Contractual Clauses and UK Addendum.
7. Retention and deletion
Unless the contract says otherwise, we delete or return client project data within 30 days after the end of the engagement or maintenance period, except where we must keep limited records by law. Clients can ask for earlier deletion at any time.
8. Incident response
If we become aware of a personal data breach affecting client data, we will notify the client without undue delay, and in any case within 72 hours, with the information they need to meet their own obligations, and we will take prompt steps to contain and fix it.
9. Requests from individuals
If someone contacts us to exercise their rights over data we hold for a client, we will pass the request to the client promptly and help them respond. If you believe your data is included in a dataset we produced, email info@bigibyte.com and we will help you reach the right controller.
10. Contact
Data protection questions, DPA requests or incident reports: info@bigibyte.com, BigiByte, Flat 10B, House 30/32, Road 10, Uttara Sector 15/B (beside Uttara Center Metro Station), Dhaka, Bangladesh.