PART A — ENGLISH TEXT
ACI Semiconductor Limited is the data controller responsible for the personal data described in this Policy. ARTIS is the training institute operated by ACI Semiconductor Limited; it is a brand and operating unit and not a separate legal entity.
Registered office: Aristo Tower (Level 3), 239 Bir Uttam Mir Shawkat Sarak (Tejgaon–Gulshan Link Road), Dhaka 1208, Bangladesh
Contact for data protection matters: artis@aci-bd.com
This Policy applies to personal data we handle when you visit the Website, submit an enquiry or expression of interest, apply for or enrol in a programme, attend our facility, use our laboratory systems, or communicate with us. It does not apply to third-party websites we link to, or to a partner organisation’s own handling of your data once you engage with them directly.
We handle personal data in accordance with the Personal Data Protection Act, 2026 (Act No. 63 of 2026), which repealed and replaced the Personal Data Protection Ordinance, 2025, and with other applicable law of Bangladesh, including the Cyber Protection Act, 2026 and the Consumer Rights Protection Act, 2009 where relevant.
(a) “Personal data” means any information relating to an identified or identifiable individual.
(b) “Processing” means any operation performed on personal data, including collection, recording, storage, use, disclosure and erasure.
(c) “Data subject” means the individual to whom the personal data relates — in most cases, you.
(d) “We”, “us” and “our” mean ACI Semiconductor Limited.
Depending on how you interact with us, we may collect:
– Identity and contact data — name, date of birth, gender, photograph, email address, telephone number, postal address, emergency contact.
– Background data — educational history, institution, discipline, year of study, employment history, curriculum vitae, prior VLSI or tool experience.
– Application and enrolment data — programme applied for, batch, prerequisite assessment, admission decisions, correspondence with us.
– Academic data — attendance, assessment results, project work, instructor feedback, certification and credential records.
– Financial data — fee amounts, payment method, transaction and receipt references, bank or mobile financial service reference numbers. We do not collect or store full payment card numbers.
– Access and attendance data — RFID card identifier, entry and exit records, laboratory session logs.
– CCTV footage — images recorded in and around the facility, including laboratory areas.
– System and laboratory data — user account identifiers, login records, tool-licence usage logs, files stored on our systems in the course of your work.
– Technical data — IP address, device and browser type, pages visited, referral source, and similar information collected through cookies and analytics.
– Communications — emails, messages, call records, consultation bookings and support enquiries.
We do not seek sensitive personal data such as religious belief, political opinion or health information, except where you volunteer it for a specific purpose, for example an accessibility adjustment or a medical matter relevant to laboratory safety.
(a) Directly from you — through Website forms, consultation bookings, applications, enrolment documentation, correspondence and in-person interaction.
(b) Automatically — through cookies, server logs, the RFID access system, CCTV and laboratory system monitoring.
(c) From third parties — from a sponsoring employer, university or scholarship provider where they nominate you for a programme, and from payment providers confirming a transaction.
We process personal data for the purposes set out below. Where we rely on your consent, you may withdraw it at any time as described in section 18.
|
Purpose |
Categories of data |
Basis |
|
Responding to enquiries and expressions of interest |
Identity, contact, communications |
Consent; steps taken at your request |
|
Assessing applications and administering admission |
Identity, background, application data |
Steps taken prior to entering a contract |
|
Delivering the programme, teaching and assessment |
Academic, access, system data |
Performance of our contract with you |
|
Issuing certificates and verifying credentials |
Identity, academic data |
Performance of contract; legitimate interest in credential integrity |
|
Enabling credentials issued by EDA vendors or other third parties |
Identity, contact, academic data |
Consent |
|
Processing fees and maintaining financial records |
Financial, identity data |
Performance of contract; legal obligation |
|
Facility security and asset protection |
CCTV, access and attendance data |
Legitimate interest in safety and security |
|
Protecting licensed software, PDKs and confidential material |
System and laboratory logs |
Legitimate interest; contractual duty to vendors and clients |
|
Sharing your profile with prospective employers or partners |
Identity, background, academic data |
Your prior consent, given for that purpose |
|
Marketing about our programmes and events |
Identity, contact data |
Consent |
|
Improving the Website and our services |
Technical data |
Legitimate interest; consent for non-essential cookies |
|
Complying with law and responding to lawful requests |
Any relevant category |
Legal obligation |
(a) We operate CCTV in and around our facility, including laboratory areas, to protect the safety of people and to protect equipment, licensed software and confidential materials.
(b) Cameras are not installed in washrooms, prayer rooms or changing areas. Signage indicates where CCTV is in operation.
(c) Footage is retained for thirty (30) days and then overwritten, unless it has been preserved for the investigation of a specific incident, a complaint, an insurance claim or a legal proceeding.
(d) Access to footage is restricted to authorised personnel. Footage is disclosed outside the organisation only to law-enforcement or regulatory authorities acting under lawful authority, or where necessary to establish, exercise or defend a legal claim.
(a) Each trainee is issued an RFID card. The system records the card identifier and the time of entry to and exit from the facility and, where applicable, to laboratory areas.
(b) We use these records to administer access, to compile attendance for assessment and certification eligibility, and to account for who is present in the event of an emergency or a security incident.
(c) The system does not collect biometric data. The card identifies the card, and the card is linked to your enrolment record.
(d) Attendance records are not used for any purpose unconnected with your programme, facility safety or security.
(a) The Website uses strictly necessary cookies to function, and may use analytics and preference cookies to understand how the site is used and to improve it.
(b) Non-essential cookies are set only with your consent, which you may give or withhold through the cookie notice and change later.
(c) You can also control cookies through your browser settings. Blocking strictly necessary cookies may affect how parts of the Website work.
We do not sell or rent personal data. We share it only as follows:
– Companies within our group — for administration, technical support, internal reporting and, with your consent, recruitment.
– EDA vendors and other certifying bodies — limited identity and academic data, where you seek a credential they issue or recognise, and only with your consent.
– Payment service providers and banks — to process and reconcile fee payments. These providers handle your payment credentials under their own terms; we do not receive or store full card details.
– Technology and hosting providers — who process data on our instructions under written terms requiring confidentiality and security.
– Prospective employers and industry partners — only as described in section 12.
– Professional advisers, auditors and insurers — where necessary and subject to confidentiality.
– Regulators, law-enforcement agencies and courts — where we are required to disclose by law or lawful order, or where disclosure is necessary to establish, exercise or defend a legal claim.
– A successor entity — in connection with a merger, reorganisation or transfer of business, subject to equivalent protection.
(a) We will share your profile, curriculum vitae, project work or assessment results with a prospective employer, an OSAT or design-house partner, or another company within our group only where you have given prior, specific consent for that purpose.
(b) We will tell you who the recipient is and what will be shared before we share it.
(c) You may decline, and you may withdraw a consent already given at any time. Withdrawal does not affect sharing that has already occurred, and does not affect your programme, your assessment or your certificate.
(d) Once a recipient has received your data, that organisation handles it as its own controller under its own privacy policy.
(a) Our website and systems are currently hosted in Bangladesh, and we expect this to remain so for at least the next two years.
(b) We may in future use hosting or service providers located outside Bangladesh, in addition to local hosting. We will do so only in accordance with the cross-border transfer requirements of the Personal Data Protection Act, 2026, including the conditions applicable to the relevant category of data and, where required, your consent or the approval of the competent authority.
(c) Where you seek a credential issued by an EDA vendor or another organisation established outside Bangladesh, a limited set of identity and academic data will be transferred to that organisation for that purpose, with your consent.
(d) We will update this Policy before any material change in where personal data is stored.
We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law. Our current retention periods are:
|
Category |
Retention period |
|
Enquiries and expressions of interest that do not lead to enrolment |
24 months from last contact |
|
Applications that are unsuccessful or withdrawn |
24 months from the decision |
|
Enrolment, academic, assessment and certification records |
10 years from completion, so that credentials can be verified |
|
Financial and payment records |
6 years from the end of the relevant financial year, or longer where tax or company law requires |
|
RFID access and attendance logs |
3 years from the end of the programme |
|
CCTV footage |
30 days, unless preserved for a specific incident or claim |
|
Laboratory system and tool-licence logs |
3 years |
|
Website analytics data |
14 months |
|
Marketing consent and preference records |
Until consent is withdrawn, and 3 years thereafter as evidence of the position |
|
Records of consent to share data with employers or partners |
3 years from the date of consent |
At the end of the applicable period we delete the data or anonymise it so that it can no longer be linked to you.
(a) We apply technical, administrative and physical safeguards appropriate to the sensitivity of the data, including access control on a need-to-know basis, authentication controls, network security measures, monitoring of laboratory systems, secure disposal, and staff confidentiality obligations.
(b) Our service providers are engaged under written terms requiring confidentiality and appropriate security.
(c) No system can be guaranteed to be entirely secure. You are responsible for keeping your account credentials and access card confidential and for reporting any suspected compromise to us promptly.
Subject to the conditions and exemptions in the Personal Data Protection Act, 2026, you may:
– ask whether we hold personal data about you, and obtain a copy of it;
– ask us to correct data that is inaccurate, incomplete or out of date;
– ask us to delete data where we no longer have a lawful basis to keep it;
– ask us to restrict or object to particular processing;
– withdraw a consent you have given;
– ask us not to send you marketing communications;
– complain to the competent supervisory authority in Bangladesh.
Some rights are qualified. For example, we may need to retain academic, financial or security records for the periods stated in section 14 even after a deletion request, so that we can verify credentials, meet legal obligations or defend a claim. Where we cannot act on a request in full, we will explain why.
(a) Write to us at artis@aci-bd.com with the words “Data request” in the subject line, describing what you want and the period concerned.
(b) We may ask for information to verify your identity before we act, so that we do not disclose data to the wrong person.
(c) We aim to respond within thirty (30) days of receiving a complete request. Where a request is complex, we will tell you and give a revised timeframe.
(d) We do not charge for a first request. A reasonable fee may apply to repeated or manifestly excessive requests.
Where we rely on your consent — for marketing, for sharing your profile with an employer or partner, for a third-party credential, or for non-essential cookies — you may withdraw it at any time by writing to artis@aci-bd.com or by using the unsubscribe option in a marketing message. Withdrawal takes effect for the future and does not make earlier processing unlawful.
Our programmes and services are for persons aged 18 or above. We do not knowingly collect personal data from anyone under 18. If we become aware that we have done so, we will delete it. If you believe a minor has given us personal data, please contact us.
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to cause significant harm, we will notify the competent authority and affected individuals within the timeframe and in the manner required by the Personal Data Protection Act, 2026, and will explain what happened and what steps we and you can take.
We may update this Policy. The current version is published on the Website with its effective date. Where a change materially affects how we use your personal data, we will give notice using the contact details on record and, where the law requires it, obtain fresh consent.
(a) This Policy is published in English and in Bangla. Both versions are official texts, both are equally binding, and the section numbering of the two versions is identical.
(b) The two versions are to be read together as a single instrument and, so far as possible, interpreted so as to be consistent with one another.
(c) If a difference cannot be reconciled by such interpretation, the meaning that prevails is the one that best gives effect to the purpose of the section concerned, read in the context of the Policy as a whole, and that is consistent with the mandatory law of Bangladesh.
(d) Neither version is subordinate to the other by reason of being a translation.
For any question, request or complaint about this Policy or about how we handle your personal data:
ACI Semiconductor Limited (ARTIS)
Aristo Tower (Level 3), 239 Bir Uttam Mir Shawkat Sarak (Tejgaon–Gulshan Link Road), Dhaka 1208, Bangladesh
Telephone: +880 1704 124089 (Sunday to Thursday, 9:00 am – 6:00 pm)
Email: artis@aci-bd.com
If you are not satisfied with our response, you may complain to the supervisory authority established under the Personal Data Protection Act, 2026.
খণ্ড খ — বাংলা পাঠ
এই নীতিতে বর্ণিত ব্যক্তিগত উপাত্তের জন্য দায়িত্বপ্রাপ্ত উপাত্ত নিয়ন্ত্রক হলো ACI Semiconductor Limited। ARTIS এই কোম্পানি পরিচালিত প্রশিক্ষণ প্রতিষ্ঠান; ইহা একটি ব্র্যান্ড ও পরিচালন ইউনিট, আলাদা আইনি সত্তা নয়।
ঠিকানা: অ্যারিস্টো টাওয়ার (লেভেল ৩), ২৩৯ বীর উত্তম মীর শওকত সরক (তেজগাঁও–গুলশান লিঙ্ক রোড), ঢাকা ১২০৮, বাংলাদেশ
উপাত্ত সুরক্ষাসংক্রান্ত যোগাযোগ: artis@aci-bd.com
আপনি ওয়েবসাইট ব্যবহার করলে, অনুসন্ধান বা আগ্রহ প্রকাশ জমা দিলে, প্রোগ্রামে আবেদন বা ভর্তি হলে, সুবিধাকেন্দ্রে উপস্থিত হলে, ল্যাব সিস্টেম ব্যবহার করলে বা আমাদের সঙ্গে যোগাযোগ করলে যে ব্যক্তিগত উপাত্ত আমরা প্রক্রিয়াকরণ করি, এই নীতি তার ক্ষেত্রে প্রযোজ্য। আমাদের লিঙ্ককৃত তৃতীয় পক্ষের ওয়েবসাইট, অথবা আপনি সরাসরি যুক্ত হলে কোনো অংশীদার প্রতিষ্ঠানের নিজস্ব প্রক্রিয়াকরণের ক্ষেত্রে এই নীতি প্রযোজ্য নয়।
আমরা ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬ (২০২৬ সনের ৬৩ নং আইন) — যাহা ব্যক্তিগত উপাত্ত সুরক্ষা অধ্যাদেশ, ২০২৫ রহিত করে প্রণীত হয়েছে — এবং প্রযোজ্য ক্ষেত্রে সাইবার সুরক্ষা আইন, ২০২৬ ও ভোক্তা-অধিকার সংরক্ষণ আইন, ২০০৯ সহ বাংলাদেশের অন্যান্য আইন অনুযায়ী উপাত্ত প্রক্রিয়াকরণ করি।
(ক) “ব্যক্তিগত উপাত্ত” বলতে শনাক্তকৃত বা শনাক্তযোগ্য কোনো ব্যক্তিসংক্রান্ত তথ্য বুঝাবে।
(খ) “প্রক্রিয়াকরণ” বলতে সংগ্রহ, লিপিবদ্ধকরণ, সংরক্ষণ, ব্যবহার, প্রকাশ ও মুছে ফেলাসহ উপাত্তের উপর সম্পাদিত যেকোনো কার্যক্রম বুঝাবে।
(গ) “উপাত্ত বিষয়” বলতে যাঁর সঙ্গে উপাত্তটি সম্পর্কিত সেই ব্যক্তি—অধিকাংশ ক্ষেত্রে আপনি—কে বুঝাবে।
(ঘ) “আমরা” বা “আমাদের” বলতে ACI Semiconductor Limited বুঝাবে।
আপনি কীভাবে আমাদের সঙ্গে যুক্ত হন তার উপর নির্ভর করে আমরা সংগ্রহ করতে পারি:
– পরিচয় ও যোগাযোগ — নাম, জন্মতারিখ, লিঙ্গ, ছবি, ইমেইল, ফোন নম্বর, ঠিকানা, জরুরি যোগাযোগ।
– পটভূমি — শিক্ষাগত যোগ্যতা, প্রতিষ্ঠান, বিষয়, শিক্ষাবর্ষ, কর্মঅভিজ্ঞতা, জীবনবৃত্তান্ত, পূর্ববর্তী ভিএলএসআই বা টুল অভিজ্ঞতা।
– আবেদন ও ভর্তি — আবেদিত প্রোগ্রাম, ব্যাচ, পূর্বশর্ত যাচাই, ভর্তিসংক্রান্ত সিদ্ধান্ত ও পত্রালাপ।
– একাডেমিক — উপস্থিতি, মূল্যায়নের ফলাফল, প্রজেক্ট কাজ, প্রশিক্ষকের মন্তব্য, সনদ ও ক্রেডেনশিয়ালের রেকর্ড।
– আর্থিক — ফির পরিমাণ, পরিশোধের মাধ্যম, লেনদেন ও রসিদের রেফারেন্স, ব্যাংক বা এমএফএস রেফারেন্স নম্বর। সম্পূর্ণ কার্ড নম্বর আমরা সংগ্রহ বা সংরক্ষণ করি না।
– প্রবেশ ও উপস্থিতি — RFID কার্ড শনাক্তকারী, প্রবেশ ও প্রস্থানের রেকর্ড, ল্যাব সেশন লগ।
– সিসিটিভি ফুটেজ — ল্যাবসহ সুবিধাকেন্দ্র ও তার আশপাশে ধারণকৃত চিত্র।
– সিস্টেম ও ল্যাব — অ্যাকাউন্ট শনাক্তকারী, লগইন রেকর্ড, টুল লাইসেন্স ব্যবহারের লগ, কাজের সময় সিস্টেমে সংরক্ষিত ফাইল।
– কারিগরি — আইপি ঠিকানা, ডিভাইস ও ব্রাউজারের ধরন, পরিদর্শিত পৃষ্ঠা ও কুকিসহ সমজাতীয় তথ্য।
– যোগাযোগ — ইমেইল, বার্তা, কল রেকর্ড, কনসালটেশন বুকিং ও সহায়তাসংক্রান্ত অনুসন্ধান।
ধর্মীয় বিশ্বাস, রাজনৈতিক মতামত বা স্বাস্থ্যসংক্রান্ত তথ্যের মতো সংবেদনশীল উপাত্ত আমরা চাই না; তবে কোনো নির্দিষ্ট প্রয়োজনে — যেমন প্রবেশগম্যতাসংক্রান্ত ব্যবস্থা বা ল্যাব নিরাপত্তাসংক্রান্ত স্বাস্থ্যতথ্য — আপনি স্বেচ্ছায় দিলে তা ব্যতিক্রম।
(ক) সরাসরি আপনার কাছ থেকে — ওয়েবসাইটের ফর্ম, কনসালটেশন বুকিং, আবেদন, ভর্তি-ডকুমেন্টেশন, পত্রালাপ এবং সরাসরি যোগাযোগের মাধ্যমে।
(খ) স্বয়ংক্রিয়ভাবে — কুকি, সার্ভার লগ, RFID প্রবেশ ব্যবস্থা, সিসিটিভি এবং ল্যাব সিস্টেম পর্যবেক্ষণের মাধ্যমে।
(গ) তৃতীয় পক্ষ থেকে — কোনো স্পন্সর প্রতিষ্ঠান, বিশ্ববিদ্যালয় বা বৃত্তিপ্রদানকারী আপনাকে মনোনীত করলে, এবং পেমেন্ট সার্ভিস প্রদানকারী লেনদেন নিশ্চিত করলে।
নিম্নলিখিত উদ্দেশ্যে আমরা উপাত্ত প্রক্রিয়াকরণ করি। যেখানে সম্মতির উপর নির্ভর করি, সেখানে ১৮ নং অনুচ্ছেদ অনুযায়ী যেকোনো সময় সম্মতি প্রত্যাহার করা যাবে।
|
উদ্দেশ্য |
উপাত্তের ধরন |
ভিত্তি |
|
অনুসন্ধান ও আগ্রহ প্রকাশের জবাব দেওয়া |
পরিচয়, যোগাযোগ, পত্রালাপ |
সম্মতি; আপনার অনুরোধে গৃহীত পদক্ষেপ |
|
আবেদন মূল্যায়ন ও ভর্তি পরিচালনা |
পরিচয়, পটভূমি, আবেদন |
চুক্তি সম্পাদনের পূর্ববর্তী পদক্ষেপ |
|
প্রোগ্রাম পরিচালনা, পাঠদান ও মূল্যায়ন |
একাডেমিক, প্রবেশ, সিস্টেম |
চুক্তি পালন |
|
সনদ প্রদান ও ক্রেডেনশিয়াল যাচাই |
পরিচয়, একাডেমিক |
চুক্তি পালন; সনদের নির্ভরযোগ্যতায় বৈধ স্বার্থ |
|
ইডিএ ভেন্ডর বা তৃতীয় পক্ষের ক্রেডেনশিয়াল প্রাপ্তি |
পরিচয়, যোগাযোগ, একাডেমিক |
সম্মতি |
|
ফি প্রক্রিয়াকরণ ও হিসাব সংরক্ষণ |
আর্থিক, পরিচয় |
চুক্তি পালন; আইনি বাধ্যবাধকতা |
|
সুবিধাকেন্দ্রের নিরাপত্তা ও সম্পদ রক্ষা |
সিসিটিভি, প্রবেশ ও উপস্থিতি |
নিরাপত্তাসংক্রান্ত বৈধ স্বার্থ |
|
লাইসেন্সকৃত সফটওয়্যার, PDK ও গোপনীয় সামগ্রী রক্ষা |
সিস্টেম ও ল্যাব লগ |
বৈধ স্বার্থ; ভেন্ডর ও ক্লায়েন্টের নিকট চুক্তিবদ্ধ দায় |
|
সম্ভাব্য নিয়োগকর্তা বা অংশীদারের সঙ্গে প্রোফাইল শেয়ার |
পরিচয়, পটভূমি, একাডেমিক |
এই উদ্দেশ্যে দেওয়া আপনার পূর্বসম্মতি |
|
প্রোগ্রাম ও ইভেন্টসংক্রান্ত প্রচারণা |
পরিচয়, যোগাযোগ |
সম্মতি |
|
ওয়েবসাইট ও সেবার মানোন্নয়ন |
কারিগরি উপাত্ত |
বৈধ স্বার্থ; অপ্রয়োজনীয় কুকির ক্ষেত্রে সম্মতি |
|
আইন পরিপালন ও বৈধ অনুরোধে সাড়া |
প্রাসঙ্গিক যেকোনো ধরন |
আইনি বাধ্যবাধকতা |
(ক) মানুষের নিরাপত্তা এবং সরঞ্জাম, লাইসেন্সকৃত সফটওয়্যার ও গোপনীয় সামগ্রী রক্ষার উদ্দেশ্যে ল্যাবসহ সুবিধাকেন্দ্র ও তার আশপাশে সিসিটিভি পরিচালিত হয়।
(খ) ওয়াশরুম, নামাজঘর বা পোশাক পরিবর্তনের কক্ষে ক্যামেরা নেই। যেখানে সিসিটিভি সক্রিয়, সেখানে সাইনেজ দেওয়া থাকে।
(গ) ফুটেজ তিরিশ (৩০) দিন সংরক্ষিত রাখা হয় এবং তারপর মুছে ফেলা হয়, যদি না কোনো নির্দিষ্ট ঘটনা, অভিযোগ, বীমা দাবি বা আইনি কার্যক্রমের জন্য সংরক্ষণ করা হয়।
(ঘ) ফুটেজে প্রবেশাধিকার কেবল অনুমোদিত কর্মীদের। আইন প্রয়োগকারী বা নিয়ন্ত্রক সংস্থার বৈধ অনুরোধে, অথবা আইনি দাবি প্রতিষ্ঠা বা রক্ষার প্রয়োজনে ছাড়া ফুটেজ বাইরে প্রকাশ করা হয় না।
(ক) প্রতিজন প্রশিক্ষণার্থীকে একটি RFID কার্ড দেওয়া হয়। সিস্টেম কার্ডের শনাক্তকারী এবং সুবিধাকেন্দ্র ও প্রযোজ্য ক্ষেত্রে ল্যাবে প্রবেশ ও প্রস্থানের সময় লিপিবদ্ধ করে।
(খ) এই রেকর্ড প্রবেশ নিয়ন্ত্রণ, মূল্যায়ন ও সনদের যোগ্যতা নির্ধারণে উপস্থিতি হিসাব, এবং জরুরি অবস্থা বা নিরাপত্তাজনিত ঘটনায় কারা উপস্থিত তা নির্ণয়ে ব্যবহার করা হয়।
(গ) এই ব্যবস্থা কোনো বায়োমেট্রিক উপাত্ত সংগ্রহ করে না। কার্ডটি কার্ডকেই শনাক্ত করে, এবং কার্ডটি আপনার ভর্তি-রেকর্ডের সঙ্গে সংযুক্ত।
(ঘ) উপস্থিতির রেকর্ড আপনার প্রোগ্রাম, সুবিধাকেন্দ্রের নিরাপত্তা বা সুরক্ষা ব্যতীত অন্য কোনো উদ্দেশ্যে ব্যবহার করা হয় না।
(ক) ওয়েবসাইট পরিচালনার জন্য অপরিহার্য কুকি ব্যবহার করা হয়; সাইটের ব্যবহার বুঝতে ও মানোন্নয়নে অ্যানালিটিক্স ও পছন্দসংক্রান্ত কুকিও ব্যবহার করা হতে পারে।
(খ) অপ্রয়োজনীয় কুকি কেবল আপনার সম্মতিতে সেট করা হয়, যা আপনি কুকি নোটিশের মাধ্যমে দিতে, না দিতে বা পরে পরিবর্তন করতে পারেন।
(গ) ব্রাউজার সেটিংস থেকেও কুকি নিয়ন্ত্রণ করা যায়। অপরিহার্য কুকি ব্লক করলে ওয়েবসাইটের কিছু অংশ সঠিকভাবে কাজ না-ও করতে পারে।
আমরা ব্যক্তিগত উপাত্ত বিক্রি বা ভাড়া দেই না। কেবল নিম্নোক্ত ক্ষেত্রে শেয়ার করি:
– আমাদের গ্রুপভুক্ত কোম্পানি — প্রশাসন, কারিগরি সহায়তা, অভ্যন্তরীণ প্রতিবেদন এবং আপনার সম্মতিতে নিয়োগের প্রয়োজনে;
– ইডিএ ভেন্ডর ও অন্য সনদ প্রদানকারী সংস্থা — আপনি তাদের ক্রেডেনশিয়াল চাইলে, কেবল সম্মতিতে এবং সীমিত পরিচয় ও একাডেমিক উপাত্ত;
– পেমেন্ট সার্ভিস প্রদানকারী ও ব্যাংক — ফি প্রক্রিয়াকরণ ও মিলকরণের জন্য; তারা নিজস্ব শর্তে পরিচালিত;
– প্রযুক্তি ও হোস্টিং সার্ভিস প্রদানকারী — গোপনীয়তা ও নিরাপত্তার লিখিত শর্তে আমাদের নির্দেশনায়;
– সম্ভাব্য নিয়োগকর্তা ও অংশীদার — কেবল ১২ নং অনুচ্ছেদ অনুযায়ী;
– পেশাদার পরামর্শক, নিরীক্ষক ও বীমাকারী — প্রয়োজনে এবং গোপনীয়তার শর্তে;
– নিয়ন্ত্রক সংস্থা, আইন প্রয়োগকারী সংস্থা ও আদালত — আইন বা বৈধ আদেশে প্রয়োজন হলে;
– উত্তরাধিকারী প্রতিষ্ঠান — মার্জার, পুনর্গঠন বা ব্যবসা হস্তান্তরের ক্ষেত্রে, সমপর্যায়ের সুরক্ষা সাপেক্ষে।
(ক) আপনার প্রোফাইল, জীবনবৃত্তান্ত, প্রজেক্ট কাজ বা মূল্যায়নের ফলাফল কেবল তখনই সম্ভাব্য নিয়োগকর্তা, OSAT বা ডিজাইন-হাউস অংশীদার, অথবা গ্রুপভুক্ত অন্য কোম্পানির সঙ্গে শেয়ার করা হবে, যখন আপনি সেই উদ্দেশ্যে পূর্বাহ্নে সুনির্দিষ্ট সম্মতি দিয়েছেন।
(খ) শেয়ার করার আগে আমরা আপনাকে জানাব কার কাছে এবং কী শেয়ার করা হবে।
(গ) আপনি অসম্মতি জানাতে পারেন এবং যেকোনো সময় সম্মতি প্রত্যাহার করতে পারেন। প্রত্যাহারে পূর্বে সংঘটিত শেয়ারিং অবৈধ হয় না, এবং ইহাতে আপনার প্রোগ্রাম, মূল্যায়ন বা সনদ ক্ষতিগ্রস্ত হবে না।
(ঘ) উপাত্ত প্রাপ্তির পর সংশ্লিষ্ট প্রতিষ্ঠান তার নিজস্ব গোপনীয়তা নীতি অনুযায়ী স্বতন্ত্র নিয়ন্ত্রক হিসাবে তা প্রক্রিয়াকরণ করবে।
(ক) আমাদের ওয়েবসাইট ও সিস্টেম বর্তমানে বাংলাদেশে হোস্ট করা, এবং আগামী অন্তত দুই বছর তা অব্যাহত থাকবে বলে আমরা প্রত্যাশা করি।
(খ) ভবিষ্যতে স্থানীয় হোস্টিংয়ের পাশাপাশি আমরা বাংলাদেশের বাইরে অবস্থিত সার্ভিস প্রদানকারী ব্যবহার করতে পারি। সেই ক্ষেত্রে ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর সীমান্তাতিক্রান্ত হস্তান্তরসংক্রান্ত বিধান, সংশ্লিষ্ট শ্রেণির উপাত্তের জন্য প্রযোজ্য শর্ত এবং প্রয়োজনে আপনার সম্মতি বা কর্তৃপক্ষের অনুমোদন মেনে তা করা হবে।
(গ) বাংলাদেশের বাইরে প্রতিষ্ঠিত কোনো ইডিএ ভেন্ডর বা সংস্থার ক্রেডেনশিয়াল নিতে চাইলে আপনার সম্মতিতে সীমিত পরিচয় ও একাডেমিক উপাত্ত সেই সংস্থার কাছে হস্তান্তর করা হবে।
(ঘ) উপাত্ত সংরক্ষণের স্থানে কোনো গুরুত্বপূর্ণ পরিবর্তনের আগে আমরা এই নীতি হালনাগাদ করব।
যে উদ্দেশ্যে সংগ্রহ করা হয়েছে তার জন্য যতক্ষণ প্রয়োজন, অথবা আইন যতদিন দাবি করে — ততদিনই আমরা উপাত্ত সংরক্ষণ করি। বর্তমান মেয়াদসমূহ:
|
শ্রেণি |
সংরক্ষণের মেয়াদ |
|
ভর্তিতে পরিণত হয়নি এমন অনুসন্ধান ও আগ্রহ প্রকাশ |
শেষ যোগাযোগের তারিখ হতে ২৪ মাস |
|
অসফল বা প্রত্যাহারকৃত আবেদন |
সিদ্ধান্তের তারিখ হতে ২৪ মাস |
|
ভর্তি, একাডেমিক, মূল্যায়ন ও সনদের রেকর্ড |
সমাপনের তারিখ হতে ১০ বছর, যাতে ক্রেডেনশিয়াল যাচাই করা যায় |
|
আর্থিক ও পরিশোধের রেকর্ড |
সংশ্লিষ্ট অর্থবছর শেষ হতে ৬ বছর, অথবা কর বা কোম্পানি আইনে দীর্ঘতর মেয়াদ প্রয়োজন হলে ততদিন |
|
RFID প্রবেশ ও উপস্থিতির লগ |
প্রোগ্রাম শেষ হওয়ার তারিখ হতে ৩ বছর |
|
সিসিটিভি ফুটেজ |
৩০ দিন; নির্দিষ্ট ঘটনা বা দাবির জন্য সংরক্ষিত হলে ব্যতিক্রম |
|
ল্যাব সিস্টেম ও টুল লাইসেন্স লগ |
৩ বছর |
|
ওয়েবসাইট অ্যানালিটিক্স |
১৪ মাস |
|
প্রচারণাসংক্রান্ত সম্মতি ও পছন্দের রেকর্ড |
সম্মতি প্রত্যাহার পর্যন্ত, এবং পরবর্তী ৩ বছর প্রমাণ হিসাবে |
|
নিয়োগকর্তা/অংশীদারের সঙ্গে শেয়ারের সম্মতির রেকর্ড |
সম্মতির তারিখ হতে ৩ বছর |
মেয়াদ শেষে উপাত্ত মুছে ফেলা হয় অথবা এমনভাবে বেনামী করা হয় যাতে তা আর আপনার সঙ্গে সংযুক্ত করা না যায়।
(ক) উপাত্তের সংবেদনশীলতা অনুযায়ী আমরা কারিগরি, প্রশাসনিক ও ভৌত সুরক্ষাব্যবস্থা প্রয়োগ করি — প্রয়োজন-ভিত্তিক প্রবেশাধিকার, পরিচয় যাচাই, নেটওয়ার্ক নিরাপত্তা, ল্যাব সিস্টেম পর্যবেক্ষণ, নিরাপদ বিনষ্টকরণ এবং কর্মীদের গোপনীয়তার দায়সহ।
(খ) আমাদের সার্ভিস প্রদানকারীদের সঙ্গে গোপনীয়তা ও যথাযথ নিরাপত্তার শর্তসহ লিখিত চুক্তি রয়েছে।
(গ) কোনো ব্যবস্থাই শতভাগ নিরাপদ নয়। আপনার অ্যাকাউন্টের তথ্য ও অ্যাক্সেস কার্ড গোপন রাখা এবং কোনো সম্ভাব্য সম্বেদনশীল ঘটনা দ্রুত জানানো আপনার দায়িত্ব।
ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর শর্ত ও ব্যতিক্রম সাপেক্ষে আপনি পারেন:
– আমরা আপনার ব্যক্তিগত উপাত্ত রাখি কিনা জানতে ও তার অনুলিপি পেতে;
– ভুল, অসম্পূর্ণ বা পুরাতন উপাত্ত সংশোধন করাতে;
– যে উপাত্ত রাখার আর বৈধ ভিত্তি নেই তা মুছে ফেলতে বলতে;
– নির্দিষ্ট প্রক্রিয়াকরণ সীমিত করতে বা আপত্তি জানাতে;
– প্রদত্ত সম্মতি প্রত্যাহার করতে;
– প্রচারণামূলক বার্তা বন্ধ করতে বলতে;
– বাংলাদেশের সংশ্লিষ্ট তত্ত্বাবধায়ক কর্তৃপক্ষের কাছে অভিযোগ করতে।
কিছু অধিকার শর্তসাপেক্ষ। যেমন, ক্রেডেনশিয়াল যাচাই, আইনি বাধ্যবাধকতা পালন বা কোনো দাবি মোকাবিলার প্রয়োজনে মুছে ফেলার অনুরোধের পরেও ১৪ নং অনুচ্ছেদে উল্লিখিত মেয়াদ পর্যন্ত একাডেমিক, আর্থিক বা নিরাপত্তাসংক্রান্ত রেকর্ড রাখতে হতে পারে। পূর্ণাঙ্গভাবে অনুরোধ রক্ষা করতে না পারলে আমরা কারণ জানাব।
(ক) ইমেইলের বিষয় লাইনে “Data request” লিখে artis@aci-bd.com ঠিকানায় আপনার অনুরোধ ও সংশ্লিষ্ট সময়কাল উল্লেখ করে লিখুন।
(খ) ভুল ব্যক্তির কাছে উপাত্ত প্রকাশ এড়াতে কার্যক্রম গ্রহণের আগে আমরা পরিচয় যাচাইয়ের তথ্য চাইতে পারি।
(গ) পূর্ণাঙ্গ অনুরোধ পাওয়ার তারিখ হতে তিরিশ (৩০) দিনের মধ্যে সাড়া দেওয়ার চেষ্টা করি। জটিল অনুরোধের ক্ষেত্রে তা জানিয়ে নতুন সময়সীমা দেওয়া হবে।
(ঘ) প্রথম অনুরোধের জন্য কোনো ফি নেই। বারবার বা স্পষ্টত অসম্ভব পরিমাণের অনুরোধে যুক্তিসঙ্গত ফি প্রযোজ্য হতে পারে।
প্রচারণা, নিয়োগকর্তা বা অংশীদারের সঙ্গে প্রোফাইল শেয়ার, তৃতীয় পক্ষের ক্রেডেনশিয়াল অথবা অপ্রয়োজনীয় কুকি — এসব ক্ষেত্রে আমরা আপনার সম্মতির উপর নির্ভর করি। artis@aci-bd.com ঠিকানায় লিখে অথবা প্রচারণামূলক বার্তার আনসাবস্ক্রাইব লিঙ্ক ব্যবহার করে যেকোনো সময় সম্মতি প্রত্যাহার করতে পারেন। প্রত্যাহার ভবিষ্যতের জন্য কার্যকর; ইহা পূর্ববর্তী প্রক্রিয়াকরণকে অবৈধ করে না।
আমাদের প্রোগ্রাম ও সেবা ১৮ বছর বা তদূর্ধ্ব বয়সীদের জন্য। আমরা জেনেশুনে ১৮ বছরের কম বয়সী কারো ব্যক্তিগত উপাত্ত সংগ্রহ করি না। এরূপ ঘটেছে জানতে পারলে আমরা তা মুছে ফেলব। কোনো অপ্রাপ্তবয়স্ক আমাদের উপাত্ত দিয়েছে বলে মনে হলে অনুগ্রহ করে যোগাযোগ করুন।
ব্যক্তিগত উপাত্ত লঙ্ঘন শনাক্ত, অনুসন্ধান ও প্রতিকারের প্রক্রিয়া আমাদের রয়েছে। কোনো লঙ্ঘনে উল্লেখযোগ্য ক্ষতির আশঙ্কা থাকলে ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এ নির্ধারিত সময় ও পদ্ধতিতে আমরা সংশ্লিষ্ট কর্তৃপক্ষ ও ক্ষতিগ্রস্ত ব্যক্তিদের অবহিত করব এবং কী ঘটেছে ও কী ব্যবস্থা নেওয়া যায় তা জানাব।
আমরা এই নীতি হালনাগাদ করতে পারি। হালনাগাদ সংস্করণ কার্যকর তারিখসহ ওয়েবসাইটে প্রকাশ করা হবে। কোনো পরিবর্তন আপনার উপাত্ত ব্যবহারে গুরুত্বপূর্ণ প্রভাব ফেললে সংরক্ষিত যোগাযোগের ঠিকানায় নোটিশ দেওয়া হবে এবং আইনে প্রয়োজন হলে নতুন করে সম্মতি নেওয়া হবে।
(ক) এই নীতি ইংরেজি ও বাংলা — উভয় ভাষায় প্রকাশিত। দুইটি সংস্করণই সরকারি পাঠ এবং সমানভাবে বাধ্যকর; উভয় সংস্করণে অনুচ্ছেদের ক্রমিক নম্বর অভিন্ন।
(খ) সংস্করণ দুটিকে একক দলিল হিসাবে পাঠ করতে হবে এবং যতদূর সম্ভব পরস্পরসঙ্গতিপূর্ণভাবে ব্যাখ্যা করতে হবে।
(গ) এরূপ ব্যাখ্যার পরেও বিরোধ নিরসন না হলে, সেই অর্থ প্রাধান্য পাবে যা নীতির সামগ্রিক পরিপ্রেক্ষিতে সংশ্লিষ্ট অনুচ্ছেদের উদ্দেশ্য সর্বোত্তমভাবে প্রতিফলিত করে এবং বাংলাদেশের বাধ্যতামূলক আইনের সঙ্গে সঙ্গতিপূর্ণ।
(ঘ) অনুবাদ হওয়ার কারণে কোনো সংস্করণকে অপরটির অধীন গণ্য করা যাবে না।
এই নীতি বা আপনার ব্যক্তিগত উপাত্ত পরিচালনাসংক্রান্ত যেকোনো প্রশ্ন, অনুরোধ বা অভিযোগের জন্য:
ACI Semiconductor Limited (ARTIS)
অ্যারিস্টো টাওয়ার (লেভেল ৩), ২৩৯ বীর উত্তম মীর শওকত সরক (তেজগাঁও–গুলশান লিঙ্ক রোড), ঢাকা ১২০৮, বাংলাদেশ
ফোন: +৮৮০ ১৭০৪ ১২৪০৮৯ (রবিবার–বৃহস্পতিবার, সকাল ৯টা – সন্ধ্যা ৬টা)
ইমেইল: artis@aci-bd.com
আমাদের জবাবে সন্তুষ্ট না হলে আপনি ব্যক্তিগত উপাত্ত সুরক্ষা আইন, ২০২৬-এর অধীনে প্রতিষ্ঠিত তত্ত্বাবধায়ক কর্তৃপক্ষের কাছে অভিযোগ করতে পারেন।