ACI
ACI Semiconductor Limited
October 2026 Applications are open for the October 2026 VLSI design cohort Apply Now

ACI SEMICONDUCTOR LIMITED

ARTIS — Advanced Research & Training Institute for Semiconductor

 

 

Privacy Policy | গোপনীয়তা নীতি

 

 

PART A — ENGLISH TEXT

1. Who we are

ACI Semiconductor Limited is the data controller responsible for the personal data described in this Policy. ARTIS is the training institute operated by ACI Semiconductor Limited; it is a brand and operating unit and not a separate legal entity.

Registered office: Aristo Tower (Level 3), 239 Bir Uttam Mir Shawkat Sarak (Tejgaon–Gulshan Link Road), Dhaka 1208, Bangladesh

Contact for data protection matters: artis@aci-bd.com

2. Scope of this Policy

This Policy applies to personal data we handle when you visit the Website, submit an enquiry or expression of interest, apply for or enrol in a programme, attend our facility, use our laboratory systems, or communicate with us. It does not apply to third-party websites we link to, or to a partner organisation’s own handling of your data once you engage with them directly.

3. Legal framework

We handle personal data in accordance with the Personal Data Protection Act, 2026 (Act No. 63 of 2026), which repealed and replaced the Personal Data Protection Ordinance, 2025, and with other applicable law of Bangladesh, including the Cyber Protection Act, 2026 and the Consumer Rights Protection Act, 2009 where relevant.

4. Definitions

(a) “Personal data” means any information relating to an identified or identifiable individual.

(b) “Processing” means any operation performed on personal data, including collection, recording, storage, use, disclosure and erasure.

(c) “Data subject” means the individual to whom the personal data relates — in most cases, you.

(d) “We”, “us” and “our” mean ACI Semiconductor Limited.

5. The personal data we collect

Depending on how you interact with us, we may collect:

– Identity and contact data — name, date of birth, gender, photograph, email address, telephone number, postal address, emergency contact.

– Background data — educational history, institution, discipline, year of study, employment history, curriculum vitae, prior VLSI or tool experience.

– Application and enrolment data — programme applied for, batch, prerequisite assessment, admission decisions, correspondence with us.

– Academic data — attendance, assessment results, project work, instructor feedback, certification and credential records.

– Financial data — fee amounts, payment method, transaction and receipt references, bank or mobile financial service reference numbers. We do not collect or store full payment card numbers.

– Access and attendance data — RFID card identifier, entry and exit records, laboratory session logs.

– CCTV footage — images recorded in and around the facility, including laboratory areas.

– System and laboratory data — user account identifiers, login records, tool-licence usage logs, files stored on our systems in the course of your work.

– Technical data — IP address, device and browser type, pages visited, referral source, and similar information collected through cookies and analytics.

– Communications — emails, messages, call records, consultation bookings and support enquiries.

We do not seek sensitive personal data such as religious belief, political opinion or health information, except where you volunteer it for a specific purpose, for example an accessibility adjustment or a medical matter relevant to laboratory safety.

6. How we collect personal data

(a) Directly from you — through Website forms, consultation bookings, applications, enrolment documentation, correspondence and in-person interaction.

(b) Automatically — through cookies, server logs, the RFID access system, CCTV and laboratory system monitoring.

(c) From third parties — from a sponsoring employer, university or scholarship provider where they nominate you for a programme, and from payment providers confirming a transaction.

7. Why we process personal data, and on what basis

We process personal data for the purposes set out below. Where we rely on your consent, you may withdraw it at any time as described in section 18.

 

Purpose

Categories of data

Basis

Responding to enquiries and expressions of interest

Identity, contact, communications

Consent; steps taken at your request

Assessing applications and administering admission

Identity, background, application data

Steps taken prior to entering a contract

Delivering the programme, teaching and assessment

Academic, access, system data

Performance of our contract with you

Issuing certificates and verifying credentials

Identity, academic data

Performance of contract; legitimate interest in credential integrity

Enabling credentials issued by EDA vendors or other third parties

Identity, contact, academic data

Consent

Processing fees and maintaining financial records

Financial, identity data

Performance of contract; legal obligation

Facility security and asset protection

CCTV, access and attendance data

Legitimate interest in safety and security

Protecting licensed software, PDKs and confidential material

System and laboratory logs

Legitimate interest; contractual duty to vendors and clients

Sharing your profile with prospective employers or partners

Identity, background, academic data

Your prior consent, given for that purpose

Marketing about our programmes and events

Identity, contact data

Consent

Improving the Website and our services

Technical data

Legitimate interest; consent for non-essential cookies

Complying with law and responding to lawful requests

Any relevant category

Legal obligation

8. CCTV monitoring

(a) We operate CCTV in and around our facility, including laboratory areas, to protect the safety of people and to protect equipment, licensed software and confidential materials.

(b) Cameras are not installed in washrooms, prayer rooms or changing areas. Signage indicates where CCTV is in operation.

(c) Footage is retained for thirty (30) days and then overwritten, unless it has been preserved for the investigation of a specific incident, a complaint, an insurance claim or a legal proceeding.

(d) Access to footage is restricted to authorised personnel. Footage is disclosed outside the organisation only to law-enforcement or regulatory authorities acting under lawful authority, or where necessary to establish, exercise or defend a legal claim.

9. RFID access and attendance

(a) Each trainee is issued an RFID card. The system records the card identifier and the time of entry to and exit from the facility and, where applicable, to laboratory areas.

(b) We use these records to administer access, to compile attendance for assessment and certification eligibility, and to account for who is present in the event of an emergency or a security incident.

(c) The system does not collect biometric data. The card identifies the card, and the card is linked to your enrolment record.

(d) Attendance records are not used for any purpose unconnected with your programme, facility safety or security.

10. Cookies and website analytics

(a) The Website uses strictly necessary cookies to function, and may use analytics and preference cookies to understand how the site is used and to improve it.

(b) Non-essential cookies are set only with your consent, which you may give or withhold through the cookie notice and change later.

(c) You can also control cookies through your browser settings. Blocking strictly necessary cookies may affect how parts of the Website work.

11. Who we share personal data with

We do not sell or rent personal data. We share it only as follows:

– Companies within our group — for administration, technical support, internal reporting and, with your consent, recruitment.

– EDA vendors and other certifying bodies — limited identity and academic data, where you seek a credential they issue or recognise, and only with your consent.

– Payment service providers and banks — to process and reconcile fee payments. These providers handle your payment credentials under their own terms; we do not receive or store full card details.

– Technology and hosting providers — who process data on our instructions under written terms requiring confidentiality and security.

– Prospective employers and industry partners — only as described in section 12.

– Professional advisers, auditors and insurers — where necessary and subject to confidentiality.

– Regulators, law-enforcement agencies and courts — where we are required to disclose by law or lawful order, or where disclosure is necessary to establish, exercise or defend a legal claim.

– A successor entity — in connection with a merger, reorganisation or transfer of business, subject to equivalent protection.

12. Sharing with prospective employers and partners

(a) We will share your profile, curriculum vitae, project work or assessment results with a prospective employer, an OSAT or design-house partner, or another company within our group only where you have given prior, specific consent for that purpose.

(b) We will tell you who the recipient is and what will be shared before we share it.

(c) You may decline, and you may withdraw a consent already given at any time. Withdrawal does not affect sharing that has already occurred, and does not affect your programme, your assessment or your certificate.

(d) Once a recipient has received your data, that organisation handles it as its own controller under its own privacy policy.

13. Where your data is stored and transferred

(a) Our website and systems are currently hosted in Bangladesh, and we expect this to remain so for at least the next two years.

(b) We may in future use hosting or service providers located outside Bangladesh, in addition to local hosting. We will do so only in accordance with the cross-border transfer requirements of the Personal Data Protection Act, 2026, including the conditions applicable to the relevant category of data and, where required, your consent or the approval of the competent authority.

(c) Where you seek a credential issued by an EDA vendor or another organisation established outside Bangladesh, a limited set of identity and academic data will be transferred to that organisation for that purpose, with your consent.

(d) We will update this Policy before any material change in where personal data is stored.

14. How long we keep personal data

We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law. Our current retention periods are:

 

Category

Retention period

Enquiries and expressions of interest that do not lead to enrolment

24 months from last contact

Applications that are unsuccessful or withdrawn

24 months from the decision

Enrolment, academic, assessment and certification records

10 years from completion, so that credentials can be verified

Financial and payment records

6 years from the end of the relevant financial year, or longer where tax or company law requires

RFID access and attendance logs

3 years from the end of the programme

CCTV footage

30 days, unless preserved for a specific incident or claim

Laboratory system and tool-licence logs

3 years

Website analytics data

14 months

Marketing consent and preference records

Until consent is withdrawn, and 3 years thereafter as evidence of the position

Records of consent to share data with employers or partners

3 years from the date of consent

 

At the end of the applicable period we delete the data or anonymise it so that it can no longer be linked to you.

15. How we protect personal data

(a) We apply technical, administrative and physical safeguards appropriate to the sensitivity of the data, including access control on a need-to-know basis, authentication controls, network security measures, monitoring of laboratory systems, secure disposal, and staff confidentiality obligations.

(b) Our service providers are engaged under written terms requiring confidentiality and appropriate security.

(c) No system can be guaranteed to be entirely secure. You are responsible for keeping your account credentials and access card confidential and for reporting any suspected compromise to us promptly.

16. Your rights

Subject to the conditions and exemptions in the Personal Data Protection Act, 2026, you may:

– ask whether we hold personal data about you, and obtain a copy of it;

– ask us to correct data that is inaccurate, incomplete or out of date;

– ask us to delete data where we no longer have a lawful basis to keep it;

– ask us to restrict or object to particular processing;

– withdraw a consent you have given;

– ask us not to send you marketing communications;

– complain to the competent supervisory authority in Bangladesh.

Some rights are qualified. For example, we may need to retain academic, financial or security records for the periods stated in section 14 even after a deletion request, so that we can verify credentials, meet legal obligations or defend a claim. Where we cannot act on a request in full, we will explain why.

17. How to exercise your rights

(a) Write to us at artis@aci-bd.com with the words “Data request” in the subject line, describing what you want and the period concerned.

(b) We may ask for information to verify your identity before we act, so that we do not disclose data to the wrong person.

(c) We aim to respond within thirty (30) days of receiving a complete request. Where a request is complex, we will tell you and give a revised timeframe.

(d) We do not charge for a first request. A reasonable fee may apply to repeated or manifestly excessive requests.

18. Withdrawing consent

Where we rely on your consent — for marketing, for sharing your profile with an employer or partner, for a third-party credential, or for non-essential cookies — you may withdraw it at any time by writing to artis@aci-bd.com or by using the unsubscribe option in a marketing message. Withdrawal takes effect for the future and does not make earlier processing unlawful.

19. Children

Our programmes and services are for persons aged 18 or above. We do not knowingly collect personal data from anyone under 18. If we become aware that we have done so, we will delete it. If you believe a minor has given us personal data, please contact us.

20. Data breaches

We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to cause significant harm, we will notify the competent authority and affected individuals within the timeframe and in the manner required by the Personal Data Protection Act, 2026, and will explain what happened and what steps we and you can take.

21. Changes to this Policy

We may update this Policy. The current version is published on the Website with its effective date. Where a change materially affects how we use your personal data, we will give notice using the contact details on record and, where the law requires it, obtain fresh consent.

22. Language and equal authenticity

(a) This Policy is published in English and in Bangla. Both versions are official texts, both are equally binding, and the section numbering of the two versions is identical.

(b) The two versions are to be read together as a single instrument and, so far as possible, interpreted so as to be consistent with one another.

(c) If a difference cannot be reconciled by such interpretation, the meaning that prevails is the one that best gives effect to the purpose of the section concerned, read in the context of the Policy as a whole, and that is consistent with the mandatory law of Bangladesh.

(d) Neither version is subordinate to the other by reason of being a translation.

23. Contact and complaints

For any question, request or complaint about this Policy or about how we handle your personal data:

ACI Semiconductor Limited (ARTIS)

Aristo Tower (Level 3), 239 Bir Uttam Mir Shawkat Sarak (Tejgaon–Gulshan Link Road), Dhaka 1208, Bangladesh

Telephone: +880 1704 124089 (Sunday to Thursday, 9:00 am – 6:00 pm)

Email: artis@aci-bd.com

If you are not satisfied with our response, you may complain to the supervisory authority established under the Personal Data Protection Act, 2026.

 

 

খণ্ড খ — বাংলা পাঠ

১. আমরা কারা

এই নীতিতে বর্ণিত ব্যক্তিগত উপাত্তের জন্য দায়িত্বপ্রাপ্ত উপাত্ত নিয়ন্ত্রক হলো ACI Semiconductor Limited। ARTIS এই কোম্পানি পরিচালিত প্রশিক্ষণ প্রতিষ্ঠান; ইহা একটি ব্র্যান্ড ও পরিচালন ইউনিট, আলাদা আইনি সত্তা নয়।

ঠিকানা: অ্যারিস্টো টাওয়ার (লেভেল ৩), ২৩৯ বীর উত্তম মীর শওকত সরক (তেজগাঁও–গুলশান লিঙ্ক রোড), ঢাকা ১২০৮, বাংলাদেশ

উপাত্ত সুরক্ষাসংক্রান্ত যোগাযোগ: artis@aci-bd.com

২. নীতির পরিসর

আপনি ওয়েবসাইট ব্যবহার করলে, অনুসন্ধান বা আগ্রহ প্রকাশ জমা দিলে, প্রোগ্রামে আবেদন বা ভর্তি হলে, সুবিধাকেন্দ্রে উপস্থিত হলে, ল্যাব সিস্টেম ব্যবহার করলে বা আমাদের সঙ্গে যোগাযোগ করলে যে ব্যক্তিগত উপাত্ত আমরা প্রক্রিয়াকরণ করি, এই নীতি তার ক্ষেত্রে প্রযোজ্য। আমাদের লিঙ্ককৃত তৃতীয় পক্ষের ওয়েবসাইট, অথবা আপনি সরাসরি যুক্ত হলে কোনো অংশীদার প্রতিষ্ঠানের নিজস্ব প্রক্রিয়াকরণের ক্ষেত্রে এই নীতি প্রযোজ্য নয়।

৩. আইনি কাঠামো

আমরা ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (২০২৬ সনের ৬৩ নং আইন) — যাহা ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ রহিত করে প্রণীত হয়েছে — এবং প্রযোজ্য ক্ষেত্রে সাইবার সুরক্ষা আইন, ২০২৬ ও ভোক্তা-অধিকার সংরক্ষণ আইন, ২০০৯ সহ বাংলাদেশের অন্যান্য আইন অনুযায়ী উপাত্ত প্রক্রিয়াকরণ করি।

৪. সংজ্ঞা

(ক) “ব্যক্তিগত উপাত্ত” বলতে শনাক্তকৃত বা শনাক্তযোগ্য কোনো ব্যক্তিসংক্রান্ত তথ্য বুঝাবে।

(খ) “প্রক্রিয়াকরণ” বলতে সংগ্রহ, লিপিবদ্ধকরণ, সংরক্ষণ, ব্যবহার, প্রকাশ ও মুছে ফেলাসহ উপাত্তের উপর সম্পাদিত যেকোনো কার্যক্রম বুঝাবে।

(গ) “উপাত্ত বিষয়” বলতে যাঁর সঙ্গে উপাত্তটি সম্পর্কিত সেই ব্যক্তি—অধিকাংশ ক্ষেত্রে আপনি—কে বুঝাবে।

(ঘ) “আমরা” বা “আমাদের” বলতে ACI Semiconductor Limited বুঝাবে।

৫. আমরা যে ব্যক্তিগত উপাত্ত সংগ্রহ করি

আপনি কীভাবে আমাদের সঙ্গে যুক্ত হন তার উপর নির্ভর করে আমরা সংগ্রহ করতে পারি:

– পরিচয় ও যোগাযোগ — নাম, জন্মতারিখ, লিঙ্গ, ছবি, ইমেইল, ফোন নম্বর, ঠিকানা, জরুরি যোগাযোগ।

– পটভূমি — শিক্ষাগত যোগ্যতা, প্রতিষ্ঠান, বিষয়, শিক্ষাবর্ষ, কর্মঅভিজ্ঞতা, জীবনবৃত্তান্ত, পূর্ববর্তী ভিএলএসআই বা টুল অভিজ্ঞতা।

– আবেদন ও ভর্তি — আবেদিত প্রোগ্রাম, ব্যাচ, পূর্বশর্ত যাচাই, ভর্তিসংক্রান্ত সিদ্ধান্ত ও পত্রালাপ।

– একাডেমিক — উপস্থিতি, মূল্যায়নের ফলাফল, প্রজেক্ট কাজ, প্রশিক্ষকের মন্তব্য, সনদ ও ক্রেডেনশিয়ালের রেকর্ড।

– আর্থিক — ফির পরিমাণ, পরিশোধের মাধ্যম, লেনদেন ও রসিদের রেফারেন্স, ব্যাংক বা এমএফএস রেফারেন্স নম্বর। সম্পূর্ণ কার্ড নম্বর আমরা সংগ্রহ বা সংরক্ষণ করি না।

– প্রবেশ ও উপস্থিতি — RFID কার্ড শনাক্তকারী, প্রবেশ ও প্রস্থানের রেকর্ড, ল্যাব সেশন লগ।

– সিসিটিভি ফুটেজ — ল্যাবসহ সুবিধাকেন্দ্র ও তার আশপাশে ধারণকৃত চিত্র।

– সিস্টেম ও ল্যাব — অ্যাকাউন্ট শনাক্তকারী, লগইন রেকর্ড, টুল লাইসেন্স ব্যবহারের লগ, কাজের সময় সিস্টেমে সংরক্ষিত ফাইল।

– কারিগরি — আইপি ঠিকানা, ডিভাইস ও ব্রাউজারের ধরন, পরিদর্শিত পৃষ্ঠা ও কুকিসহ সমজাতীয় তথ্য।

– যোগাযোগ — ইমেইল, বার্তা, কল রেকর্ড, কনসালটেশন বুকিং ও সহায়তাসংক্রান্ত অনুসন্ধান।

ধর্মীয় বিশ্বাস, রাজনৈতিক মতামত বা স্বাস্থ্যসংক্রান্ত তথ্যের মতো সংবেদনশীল উপাত্ত আমরা চাই না; তবে কোনো নির্দিষ্ট প্রয়োজনে — যেমন প্রবেশগম্যতাসংক্রান্ত ব্যবস্থা বা ল্যাব নিরাপত্তাসংক্রান্ত স্বাস্থ্যতথ্য — আপনি স্বেচ্ছায় দিলে তা ব্যতিক্রম।

৬. কীভাবে সংগ্রহ করি

(ক) সরাসরি আপনার কাছ থেকে — ওয়েবসাইটের ফর্ম, কনসালটেশন বুকিং, আবেদন, ভর্তি-ডকুমেন্টেশন, পত্রালাপ এবং সরাসরি যোগাযোগের মাধ্যমে।

(খ) স্বয়ংক্রিয়ভাবে — কুকি, সার্ভার লগ, RFID প্রবেশ ব্যবস্থা, সিসিটিভি এবং ল্যাব সিস্টেম পর্যবেক্ষণের মাধ্যমে।

(গ) তৃতীয় পক্ষ থেকে — কোনো স্পন্সর প্রতিষ্ঠান, বিশ্ববিদ্যালয় বা বৃত্তিপ্রদানকারী আপনাকে মনোনীত করলে, এবং পেমেন্ট সার্ভিস প্রদানকারী লেনদেন নিশ্চিত করলে।

৭. কেন প্রক্রিয়াকরণ করি এবং কোন ভিত্তিতে

নিম্নলিখিত উদ্দেশ্যে আমরা উপাত্ত প্রক্রিয়াকরণ করি। যেখানে সম্মতির উপর নির্ভর করি, সেখানে ১৮ নং অনুচ্ছেদ অনুযায়ী যেকোনো সময় সম্মতি প্রত্যাহার করা যাবে।

 

উদ্দেশ্য

উপাত্তের ধরন

ভিত্তি

অনুসন্ধান ও আগ্রহ প্রকাশের জবাব দেওয়া

পরিচয়, যোগাযোগ, পত্রালাপ

সম্মতি; আপনার অনুরোধে গৃহীত পদক্ষেপ

আবেদন মূল্যায়ন ও ভর্তি পরিচালনা

পরিচয়, পটভূমি, আবেদন

চুক্তি সম্পাদনের পূর্ববর্তী পদক্ষেপ

প্রোগ্রাম পরিচালনা, পাঠদান ও মূল্যায়ন

একাডেমিক, প্রবেশ, সিস্টেম

চুক্তি পালন

সনদ প্রদান ও ক্রেডেনশিয়াল যাচাই

পরিচয়, একাডেমিক

চুক্তি পালন; সনদের নির্ভরযোগ্যতায় বৈধ স্বার্থ

ইডিএ ভেন্ডর বা তৃতীয় পক্ষের ক্রেডেনশিয়াল প্রাপ্তি

পরিচয়, যোগাযোগ, একাডেমিক

সম্মতি

ফি প্রক্রিয়াকরণ ও হিসাব সংরক্ষণ

আর্থিক, পরিচয়

চুক্তি পালন; আইনি বাধ্যবাধকতা

সুবিধাকেন্দ্রের নিরাপত্তা ও সম্পদ রক্ষা

সিসিটিভি, প্রবেশ ও উপস্থিতি

নিরাপত্তাসংক্রান্ত বৈধ স্বার্থ

লাইসেন্সকৃত সফটওয়্যার, PDK ও গোপনীয় সামগ্রী রক্ষা

সিস্টেম ও ল্যাব লগ

বৈধ স্বার্থ; ভেন্ডর ও ক্লায়েন্টের নিকট চুক্তিবদ্ধ দায়

সম্ভাব্য নিয়োগকর্তা বা অংশীদারের সঙ্গে প্রোফাইল শেয়ার

পরিচয়, পটভূমি, একাডেমিক

এই উদ্দেশ্যে দেওয়া আপনার পূর্বসম্মতি

প্রোগ্রাম ও ইভেন্টসংক্রান্ত প্রচারণা

পরিচয়, যোগাযোগ

সম্মতি

ওয়েবসাইট ও সেবার মানোন্নয়ন

কারিগরি উপাত্ত

বৈধ স্বার্থ; অপ্রয়োজনীয় কুকির ক্ষেত্রে সম্মতি

আইন পরিপালন ও বৈধ অনুরোধে সাড়া

প্রাসঙ্গিক যেকোনো ধরন

আইনি বাধ্যবাধকতা

৮. সিসিটিভি পর্যবেক্ষণ

(ক) মানুষের নিরাপত্তা এবং সরঞ্জাম, লাইসেন্সকৃত সফটওয়্যার ও গোপনীয় সামগ্রী রক্ষার উদ্দেশ্যে ল্যাবসহ সুবিধাকেন্দ্র ও তার আশপাশে সিসিটিভি পরিচালিত হয়।

(খ) ওয়াশরুম, নামাজঘর বা পোশাক পরিবর্তনের কক্ষে ক্যামেরা নেই। যেখানে সিসিটিভি সক্রিয়, সেখানে সাইনেজ দেওয়া থাকে।

(গ) ফুটেজ তিরিশ (৩০) দিন সংরক্ষিত রাখা হয় এবং তারপর মুছে ফেলা হয়, যদি না কোনো নির্দিষ্ট ঘটনা, অভিযোগ, বীমা দাবি বা আইনি কার্যক্রমের জন্য সংরক্ষণ করা হয়।

(ঘ) ফুটেজে প্রবেশাধিকার কেবল অনুমোদিত কর্মীদের। আইন প্রয়োগকারী বা নিয়ন্ত্রক সংস্থার বৈধ অনুরোধে, অথবা আইনি দাবি প্রতিষ্ঠা বা রক্ষার প্রয়োজনে ছাড়া ফুটেজ বাইরে প্রকাশ করা হয় না।

৯. RFID প্রবেশ ও উপস্থিতি

(ক) প্রতিজন প্রশিক্ষণার্থীকে একটি RFID কার্ড দেওয়া হয়। সিস্টেম কার্ডের শনাক্তকারী এবং সুবিধাকেন্দ্র ও প্রযোজ্য ক্ষেত্রে ল্যাবে প্রবেশ ও প্রস্থানের সময় লিপিবদ্ধ করে।

(খ) এই রেকর্ড প্রবেশ নিয়ন্ত্রণ, মূল্যায়ন ও সনদের যোগ্যতা নির্ধারণে উপস্থিতি হিসাব, এবং জরুরি অবস্থা বা নিরাপত্তাজনিত ঘটনায় কারা উপস্থিত তা নির্ণয়ে ব্যবহার করা হয়।

(গ) এই ব্যবস্থা কোনো বায়োমেট্রিক উপাত্ত সংগ্রহ করে না। কার্ডটি কার্ডকেই শনাক্ত করে, এবং কার্ডটি আপনার ভর্তি-রেকর্ডের সঙ্গে সংযুক্ত।

(ঘ) উপস্থিতির রেকর্ড আপনার প্রোগ্রাম, সুবিধাকেন্দ্রের নিরাপত্তা বা সুরক্ষা ব্যতীত অন্য কোনো উদ্দেশ্যে ব্যবহার করা হয় না।

১০. কুকি ও ওয়েবসাইট অ্যানালিটিক্স

(ক) ওয়েবসাইট পরিচালনার জন্য অপরিহার্য কুকি ব্যবহার করা হয়; সাইটের ব্যবহার বুঝতে ও মানোন্নয়নে অ্যানালিটিক্স ও পছন্দসংক্রান্ত কুকিও ব্যবহার করা হতে পারে।

(খ) অপ্রয়োজনীয় কুকি কেবল আপনার সম্মতিতে সেট করা হয়, যা আপনি কুকি নোটিশের মাধ্যমে দিতে, না দিতে বা পরে পরিবর্তন করতে পারেন।

(গ) ব্রাউজার সেটিংস থেকেও কুকি নিয়ন্ত্রণ করা যায়। অপরিহার্য কুকি ব্লক করলে ওয়েবসাইটের কিছু অংশ সঠিকভাবে কাজ না-ও করতে পারে।

১১. কাদের সঙ্গে উপাত্ত শেয়ার করি

আমরা ব্যক্তিগত উপাত্ত বিক্রি বা ভাড়া দেই না। কেবল নিম্নোক্ত ক্ষেত্রে শেয়ার করি:

– আমাদের গ্রুপভুক্ত কোম্পানি — প্রশাসন, কারিগরি সহায়তা, অভ্যন্তরীণ প্রতিবেদন এবং আপনার সম্মতিতে নিয়োগের প্রয়োজনে;

– ইডিএ ভেন্ডর ও অন্য সনদ প্রদানকারী সংস্থা — আপনি তাদের ক্রেডেনশিয়াল চাইলে, কেবল সম্মতিতে এবং সীমিত পরিচয় ও একাডেমিক উপাত্ত;

– পেমেন্ট সার্ভিস প্রদানকারী ও ব্যাংক — ফি প্রক্রিয়াকরণ ও মিলকরণের জন্য; তারা নিজস্ব শর্তে পরিচালিত;

– প্রযুক্তি ও হোস্টিং সার্ভিস প্রদানকারী — গোপনীয়তা ও নিরাপত্তার লিখিত শর্তে আমাদের নির্দেশনায়;

– সম্ভাব্য নিয়োগকর্তা ও অংশীদার — কেবল ১২ নং অনুচ্ছেদ অনুযায়ী;

– পেশাদার পরামর্শক, নিরীক্ষক ও বীমাকারী — প্রয়োজনে এবং গোপনীয়তার শর্তে;

– নিয়ন্ত্রক সংস্থা, আইন প্রয়োগকারী সংস্থা ও আদালত — আইন বা বৈধ আদেশে প্রয়োজন হলে;

– উত্তরাধিকারী প্রতিষ্ঠান — মার্জার, পুনর্গঠন বা ব্যবসা হস্তান্তরের ক্ষেত্রে, সমপর্যায়ের সুরক্ষা সাপেক্ষে।

১২. সম্ভাব্য নিয়োগকর্তা ও অংশীদারের সঙ্গে শেয়ার

(ক) আপনার প্রোফাইল, জীবনবৃত্তান্ত, প্রজেক্ট কাজ বা মূল্যায়নের ফলাফল কেবল তখনই সম্ভাব্য নিয়োগকর্তা, OSAT বা ডিজাইন-হাউস অংশীদার, অথবা গ্রুপভুক্ত অন্য কোম্পানির সঙ্গে শেয়ার করা হবে, যখন আপনি সেই উদ্দেশ্যে পূর্বাহ্নে সুনির্দিষ্ট সম্মতি দিয়েছেন।

(খ) শেয়ার করার আগে আমরা আপনাকে জানাব কার কাছে এবং কী শেয়ার করা হবে।

(গ) আপনি অসম্মতি জানাতে পারেন এবং যেকোনো সময় সম্মতি প্রত্যাহার করতে পারেন। প্রত্যাহারে পূর্বে সংঘটিত শেয়ারিং অবৈধ হয় না, এবং ইহাতে আপনার প্রোগ্রাম, মূল্যায়ন বা সনদ ক্ষতিগ্রস্ত হবে না।

(ঘ) উপাত্ত প্রাপ্তির পর সংশ্লিষ্ট প্রতিষ্ঠান তার নিজস্ব গোপনীয়তা নীতি অনুযায়ী স্বতন্ত্র নিয়ন্ত্রক হিসাবে তা প্রক্রিয়াকরণ করবে।

১৩. উপাত্ত কোথায় সংরক্ষিত হয় ও হস্তান্তর

(ক) আমাদের ওয়েবসাইট ও সিস্টেম বর্তমানে বাংলাদেশে হোস্ট করা, এবং আগামী অন্তত দুই বছর তা অব্যাহত থাকবে বলে আমরা প্রত্যাশা করি।

(খ) ভবিষ্যতে স্থানীয় হোস্টিংয়ের পাশাপাশি আমরা বাংলাদেশের বাইরে অবস্থিত সার্ভিস প্রদানকারী ব্যবহার করতে পারি। সেই ক্ষেত্রে ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর সীমান্তাতিক্রান্ত হস্তান্তরসংক্রান্ত বিধান, সংশ্লিষ্ট শ্রেণির উপাত্তের জন্য প্রযোজ্য শর্ত এবং প্রয়োজনে আপনার সম্মতি বা কর্তৃপক্ষের অনুমোদন মেনে তা করা হবে।

(গ) বাংলাদেশের বাইরে প্রতিষ্ঠিত কোনো ইডিএ ভেন্ডর বা সংস্থার ক্রেডেনশিয়াল নিতে চাইলে আপনার সম্মতিতে সীমিত পরিচয় ও একাডেমিক উপাত্ত সেই সংস্থার কাছে হস্তান্তর করা হবে।

(ঘ) উপাত্ত সংরক্ষণের স্থানে কোনো গুরুত্বপূর্ণ পরিবর্তনের আগে আমরা এই নীতি হালনাগাদ করব।

১৪. কতদিন সংরক্ষণ করি

যে উদ্দেশ্যে সংগ্রহ করা হয়েছে তার জন্য যতক্ষণ প্রয়োজন, অথবা আইন যতদিন দাবি করে — ততদিনই আমরা উপাত্ত সংরক্ষণ করি। বর্তমান মেয়াদসমূহ:

 

শ্রেণি

সংরক্ষণের মেয়াদ

ভর্তিতে পরিণত হয়নি এমন অনুসন্ধান ও আগ্রহ প্রকাশ

শেষ যোগাযোগের তারিখ হতে ২৪ মাস

অসফল বা প্রত্যাহারকৃত আবেদন

সিদ্ধান্তের তারিখ হতে ২৪ মাস

ভর্তি, একাডেমিক, মূল্যায়ন ও সনদের রেকর্ড

সমাপনের তারিখ হতে ১০ বছর, যাতে ক্রেডেনশিয়াল যাচাই করা যায়

আর্থিক ও পরিশোধের রেকর্ড

সংশ্লিষ্ট অর্থবছর শেষ হতে ৬ বছর, অথবা কর বা কোম্পানি আইনে দীর্ঘতর মেয়াদ প্রয়োজন হলে ততদিন

RFID প্রবেশ ও উপস্থিতির লগ

প্রোগ্রাম শেষ হওয়ার তারিখ হতে ৩ বছর

সিসিটিভি ফুটেজ

৩০ দিন; নির্দিষ্ট ঘটনা বা দাবির জন্য সংরক্ষিত হলে ব্যতিক্রম

ল্যাব সিস্টেম ও টুল লাইসেন্স লগ

৩ বছর

ওয়েবসাইট অ্যানালিটিক্স

১৪ মাস

প্রচারণাসংক্রান্ত সম্মতি ও পছন্দের রেকর্ড

সম্মতি প্রত্যাহার পর্যন্ত, এবং পরবর্তী ৩ বছর প্রমাণ হিসাবে

নিয়োগকর্তা/অংশীদারের সঙ্গে শেয়ারের সম্মতির রেকর্ড

সম্মতির তারিখ হতে ৩ বছর

 

মেয়াদ শেষে উপাত্ত মুছে ফেলা হয় অথবা এমনভাবে বেনামী করা হয় যাতে তা আর আপনার সঙ্গে সংযুক্ত করা না যায়।

১৫. উপাত্ত সুরক্ষায় আমাদের ব্যবস্থা

(ক) উপাত্তের সংবেদনশীলতা অনুযায়ী আমরা কারিগরি, প্রশাসনিক ও ভৌত সুরক্ষাব্যবস্থা প্রয়োগ করি — প্রয়োজন-ভিত্তিক প্রবেশাধিকার, পরিচয় যাচাই, নেটওয়ার্ক নিরাপত্তা, ল্যাব সিস্টেম পর্যবেক্ষণ, নিরাপদ বিনষ্টকরণ এবং কর্মীদের গোপনীয়তার দায়সহ।

(খ) আমাদের সার্ভিস প্রদানকারীদের সঙ্গে গোপনীয়তা ও যথাযথ নিরাপত্তার শর্তসহ লিখিত চুক্তি রয়েছে।

(গ) কোনো ব্যবস্থাই শতভাগ নিরাপদ নয়। আপনার অ্যাকাউন্টের তথ্য ও অ্যাক্সেস কার্ড গোপন রাখা এবং কোনো সম্ভাব্য সম্বেদনশীল ঘটনা দ্রুত জানানো আপনার দায়িত্ব।

১৬. আপনার অধিকার

ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর শর্ত ও ব্যতিক্রম সাপেক্ষে আপনি পারেন:

– আমরা আপনার ব্যক্তিগত উপাত্ত রাখি কিনা জানতে ও তার অনুলিপি পেতে;

– ভুল, অসম্পূর্ণ বা পুরাতন উপাত্ত সংশোধন করাতে;

– যে উপাত্ত রাখার আর বৈধ ভিত্তি নেই তা মুছে ফেলতে বলতে;

– নির্দিষ্ট প্রক্রিয়াকরণ সীমিত করতে বা আপত্তি জানাতে;

– প্রদত্ত সম্মতি প্রত্যাহার করতে;

– প্রচারণামূলক বার্তা বন্ধ করতে বলতে;

– বাংলাদেশের সংশ্লিষ্ট তত্ত্বাবধায়ক কর্তৃপক্ষের কাছে অভিযোগ করতে।

কিছু অধিকার শর্তসাপেক্ষ। যেমন, ক্রেডেনশিয়াল যাচাই, আইনি বাধ্যবাধকতা পালন বা কোনো দাবি মোকাবিলার প্রয়োজনে মুছে ফেলার অনুরোধের পরেও ১৪ নং অনুচ্ছেদে উল্লিখিত মেয়াদ পর্যন্ত একাডেমিক, আর্থিক বা নিরাপত্তাসংক্রান্ত রেকর্ড রাখতে হতে পারে। পূর্ণাঙ্গভাবে অনুরোধ রক্ষা করতে না পারলে আমরা কারণ জানাব।

১৭. অধিকার প্রয়োগের পদ্ধতি

(ক) ইমেইলের বিষয় লাইনে “Data request” লিখে artis@aci-bd.com ঠিকানায় আপনার অনুরোধ ও সংশ্লিষ্ট সময়কাল উল্লেখ করে লিখুন।

(খ) ভুল ব্যক্তির কাছে উপাত্ত প্রকাশ এড়াতে কার্যক্রম গ্রহণের আগে আমরা পরিচয় যাচাইয়ের তথ্য চাইতে পারি।

(গ) পূর্ণাঙ্গ অনুরোধ পাওয়ার তারিখ হতে তিরিশ (৩০) দিনের মধ্যে সাড়া দেওয়ার চেষ্টা করি। জটিল অনুরোধের ক্ষেত্রে তা জানিয়ে নতুন সময়সীমা দেওয়া হবে।

(ঘ) প্রথম অনুরোধের জন্য কোনো ফি নেই। বারবার বা স্পষ্টত অসম্ভব পরিমাণের অনুরোধে যুক্তিসঙ্গত ফি প্রযোজ্য হতে পারে।

১৮. সম্মতি প্রত্যাহার

প্রচারণা, নিয়োগকর্তা বা অংশীদারের সঙ্গে প্রোফাইল শেয়ার, তৃতীয় পক্ষের ক্রেডেনশিয়াল অথবা অপ্রয়োজনীয় কুকি — এসব ক্ষেত্রে আমরা আপনার সম্মতির উপর নির্ভর করি। artis@aci-bd.com ঠিকানায় লিখে অথবা প্রচারণামূলক বার্তার আনসাবস্ক্রাইব লিঙ্ক ব্যবহার করে যেকোনো সময় সম্মতি প্রত্যাহার করতে পারেন। প্রত্যাহার ভবিষ্যতের জন্য কার্যকর; ইহা পূর্ববর্তী প্রক্রিয়াকরণকে অবৈধ করে না।

১৯. অপ্রাপ্তবয়স্ক

আমাদের প্রোগ্রাম ও সেবা ১৮ বছর বা তদূর্ধ্ব বয়সীদের জন্য। আমরা জেনেশুনে ১৮ বছরের কম বয়সী কারো ব্যক্তিগত উপাত্ত সংগ্রহ করি না। এরূপ ঘটেছে জানতে পারলে আমরা তা মুছে ফেলব। কোনো অপ্রাপ্তবয়স্ক আমাদের উপাত্ত দিয়েছে বলে মনে হলে অনুগ্রহ করে যোগাযোগ করুন।

২০. উপাত্ত লঙ্ঘন

ব্যক্তিগত উপাত্ত লঙ্ঘন শনাক্ত, অনুসন্ধান ও প্রতিকারের প্রক্রিয়া আমাদের রয়েছে। কোনো লঙ্ঘনে উল্লেখযোগ্য ক্ষতির আশঙ্কা থাকলে ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এ নির্ধারিত সময় ও পদ্ধতিতে আমরা সংশ্লিষ্ট কর্তৃপক্ষ ও ক্ষতিগ্রস্ত ব্যক্তিদের অবহিত করব এবং কী ঘটেছে ও কী ব্যবস্থা নেওয়া যায় তা জানাব।

২১. নীতি পরিবর্তন

আমরা এই নীতি হালনাগাদ করতে পারি। হালনাগাদ সংস্করণ কার্যকর তারিখসহ ওয়েবসাইটে প্রকাশ করা হবে। কোনো পরিবর্তন আপনার উপাত্ত ব্যবহারে গুরুত্বপূর্ণ প্রভাব ফেললে সংরক্ষিত যোগাযোগের ঠিকানায় নোটিশ দেওয়া হবে এবং আইনে প্রয়োজন হলে নতুন করে সম্মতি নেওয়া হবে।

২২. ভাষা ও সমপ্রমাণিকতা

(ক) এই নীতি ইংরেজি ও বাংলা — উভয় ভাষায় প্রকাশিত। দুইটি সংস্করণই সরকারি পাঠ এবং সমানভাবে বাধ্যকর; উভয় সংস্করণে অনুচ্ছেদের ক্রমিক নম্বর অভিন্ন।

(খ) সংস্করণ দুটিকে একক দলিল হিসাবে পাঠ করতে হবে এবং যতদূর সম্ভব পরস্পরসঙ্গতিপূর্ণভাবে ব্যাখ্যা করতে হবে।

(গ) এরূপ ব্যাখ্যার পরেও বিরোধ নিরসন না হলে, সেই অর্থ প্রাধান্য পাবে যা নীতির সামগ্রিক পরিপ্রেক্ষিতে সংশ্লিষ্ট অনুচ্ছেদের উদ্দেশ্য সর্বোত্তমভাবে প্রতিফলিত করে এবং বাংলাদেশের বাধ্যতামূলক আইনের সঙ্গে সঙ্গতিপূর্ণ।

(ঘ) অনুবাদ হওয়ার কারণে কোনো সংস্করণকে অপরটির অধীন গণ্য করা যাবে না।

২৩. যোগাযোগ ও অভিযোগ

এই নীতি বা আপনার ব্যক্তিগত উপাত্ত পরিচালনাসংক্রান্ত যেকোনো প্রশ্ন, অনুরোধ বা অভিযোগের জন্য:

ACI Semiconductor Limited (ARTIS)

অ্যারিস্টো টাওয়ার (লেভেল ৩), ২৩৯ বীর উত্তম মীর শওকত সরক (তেজগাঁও–গুলশান লিঙ্ক রোড), ঢাকা ১২০৮, বাংলাদেশ

ফোন: +৮৮০ ১৭০৪ ১২৪০৮৯ (রবিবার–বৃহস্পতিবার, সকাল ৯টা – সন্ধ্যা ৬টা)

ইমেইল: artis@aci-bd.com

আমাদের জবাবে সন্তুষ্ট না হলে আপনি ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর অধীনে প্রতিষ্ঠিত তত্ত্বাবধায়ক কর্তৃপক্ষের কাছে অভিযোগ করতে পারেন।