Privacy Policy & Data Protection
Transparent governance on how Qolek Technologies collects, processes, and safeguards telemetry, SMS payloads, voice call detail records (CDR), and enterprise client data across Bangladesh.
1. Scope & Legal Identity
This Privacy Policy applies to all digital platforms, APIs, SS7/SMPP gateways, Cloud IP-PBX clusters, custom enterprise software, and BDIX server infrastructure provided by Qolek Technologies (Trade License No: 000722, registered under the Laws of Bangladesh).
By provisioning an account, submitting an SMS dispatch request via REST/SMPP API, provisioning virtual SIP extensions, deploying custom ERP modules, or hosting workloads on our Dhaka datacenter clusters, you acknowledge that your enterprise data will be processed in accordance with this policy and Bangladesh Telecommunication Regulatory Commission (BTRC) operational guidelines.
2. Information We Collect
A. Corporate Account Information
Authorized administrative contact names, corporate email addresses, billing telephone numbers, trade license scans, and e-TIN/VAT certificates required for BTRC brand masking KYC.
B. Operational Telemetry & API Keys
Originating IP addresses, API secret credentials, webhook destination endpoints, transaction request timestamps, and system performance metrics.
3. SMS Payload & Cloud Telephony (CDR) Handling
Zero-Content Commercialization Guarantee
Qolek Technologies strictly does not inspect, sell, monetise, or distribute client SMS message bodies, OTP contents, or voice call recordings. Message payloads are strictly routed through telco interconnects for transmission purposes only.
- Bulk SMS Metadata: Includes recipient MSISDN (+8801...), timestamp, Sender ID (Masking/Non-Masking), Delivery Receipt (DLR) status code, and operator route ID (Grameenphone, Robi, Banglalink, Teletalk).
- IP-PBX Call Detail Records (CDR): Call start/end timestamps, caller ID, destination extension, call duration, and routing queue metrics. Call recordings (if enabled by customer) are stored in client-isolated encrypted S3 buckets with custom retention controls.
4. Data Retention & Regulatory Mandates
Pursuant to Bangladesh BTRC telecom regulations and the Cyber Security Act of Bangladesh:
| Data Category | Standard Retention | Storage Location |
|---|---|---|
| SMS DLR Logs & Delivery Telemetry | 90 Days (or custom corporate SLA) | Dhaka Tier-III Cluster |
| Cloud PBX CDR Logs | 180 Days (Extendable to 365 Days) | Encrypted PostgreSQL Cluster |
| Client Billing & Tax Records | 7 Years (National Board of Revenue) | Cold Encrypted Vault |
5. Cryptographic Security & Storage
Our platform architecture enforces ISO/IEC 27001:2022 compliant controls:
All API endpoints, Webhook triggers, and Admin portal sessions require mandatory HTTPS with SHA-256 ECC cipher suites.
Database storage volumes, backups, and customer uploaded assets are encrypted using Hardware Security Module (HSM) managed keys.
6. Telco Carrier Interconnects
To deliver SMS across Bangladesh, telemetry is securely routed through licensed Mobile Network Operators (Grameenphone Ltd, Robi Axiata Ltd, Banglalink Digital Communications Ltd, and Teletalk Bangladesh Ltd) via private SS7 / SMPP 3.4 VPN tunnels. No overseas transit hops are utilized for domestic A2P traffic.
7. Client Rights & Data Erasure
Corporate customers retain full control over their account data. Administrators may:
- Request export of contact address books, CDR logs, or ERP transaction ledgers.
- Rotate API secret keys instantly from the web console.
- Request complete data erasure upon contract termination, subject to statutory tax compliance hold periods.
8. Contact Data Protection Officer (DPO)
Corporate Data Governance Team
Qolek Technologies, Corporate Data Protection & Legal Division