Data Protection & Privacy

Privacy Policy

Effective Date: 21 August 2026 • Last Updated: 21 August 2026

Legal Directory 8 Policies
Our Core Privacy Commitment ZENOR BD collects personal data exclusively to provision, secure, verify, and maintain hosting and domain infrastructure. We do not sell, rent, or trade your personal data to third parties.

1 Scope

This Privacy Policy explains what information ZENOR BD collects, why it is used, how it may be shared with vetted infrastructure and payment providers, and how it is safeguarded under modern security standards.


2 Information We Collect

Identity & Account Details

Name, email, mobile phone number, physical address, company details, and client portal login credentials.

Verification Documents

National ID (NID), Trade License, and corporate verification documents when required for BTCL domains and BDIX compliance.

Billing & Transactions

Invoice history, payment references, transaction IDs, and bKash/Nagad/Gateway transaction hashes. Full card numbers are handled directly by PCI-compliant gateways.

Technical & Security Telemetry

IP address, browser and device metadata, authentication logs, security events, and Cloudflare firewall audit logs.


3 How We Use Information

  • To create, manage, configure, and authenticate client accounts and purchased services.
  • To register, transfer, renew, verify, and manage domain names with upstream registrars and BTCL.
  • To provision, secure, maintain, troubleshoot, and support hosting servers, VPS, and cloud systems.
  • To process invoices, detect duplicate or fraudulent payments, and resolve billing inquiries.
  • To prevent spam, malware distribution, phishing, credential theft, DDoS attacks, and abuse.
  • To deliver critical transactional notifications (invoices, renewals, maintenance, security alerts).

4 Marketing & Transactional Communications

ZENOR BD does not conduct unsolicited SMS marketing or general bulk email marketing campaigns. If marketing communications are introduced in the future, explicit consent and clear opt-out mechanisms will be provided.

Note: Essential transactional messages (invoice reminders, renewal alerts, security notices, password resets) will continue to be sent as they are required for ongoing service operation.


5 Third-Party Service Providers

We disclose necessary data to verified third-party partners strictly as required to deliver our services:

Cloudflare (Security & CDN) Payment Gateways & Banks ICANN Registrars & BTCL Data Center & Upstream Hosts WHMCS Billing System Google Analytics & Meta Pixel

6 Cookies, Telemetry & Data Security

We use session cookies, analytics tags (Google Tag Manager, Google Analytics), and security tokens (Cloudflare) to maintain active user sessions, measure site performance, and prevent automated bot abuse.

We implement modern administrative, SSL/TLS encrypted, and network security safeguards. However, no internet transmission can be guaranteed completely immune from external vulnerabilities.


7 Data Retention & Your Privacy Rights

Account and transactional records are retained as required for accounting, tax, domain registry compliance, fraud prevention, and dispute resolution. Hosting storage data is retained and deleted strictly in accordance with our Backup & Data Retention Policy.

Customers may request review, update, or correction of their personal data by submitting a ticket through the Client Portal with appropriate identity verification.