Privacy Policy
Compliant with: GDPR (EU) · UK GDPR · CCPA (California) · PDPA (Bangladesh) · ISO 27001 aligned
1. Overview and Scope
Betopia Group (registered office: Daisy Garden, House 14, Block A, Banasree, Dhaka-1219, Bangladesh; "Betopia," "we," "us," or "our") is the Data Controller for all personal data collected through the websites betopiagroup.com and betopialimited.com, and any associated digital properties operated by Betopia Group and its affiliated Strategic Business Units (collectively, "Betopia Group").
Betopia Group holds ISO 22301:2019 (Business Continuity Management) and ISO 9001:2015 (Quality Management System) certifications issued by QRO, reflecting our commitment to operational excellence and responsible data stewardship.
Applicable Legal Frameworks
| Framework | Jurisdiction | Key Obligation |
|---|---|---|
| GDPR (EU) 2016/679 | European Union | Lawful basis, data subject rights, DPA notification |
| UK GDPR / DPA 2018 | United Kingdom | Post-Brexit data protection regime |
| CCPA / CPRA | California, USA | Right to know, delete, opt-out of sale |
| PDPA Bangladesh (draft) | Bangladesh | National data sovereignty compliance |
| ISO 27001 aligned | Global | Information security management best practice |
2. Data Controller and Contact Information
| Legal Entity | Betopia Group |
| Registered Address | Daisy Garden, House 14, Block A, Banasree, Dhaka-1219, Bangladesh |
| General Contact | info@betopialimited.com |
| Privacy / DPO Contact | privacy@betopialimited.com |
| ISO Certifications | ISO 22301:2019 (QRO) | ISO 9001:2015 (QRO) |
For all privacy-related enquiries, data subject access requests, or complaints, contact us at privacy@betopialimited.com. We will acknowledge your request within 72 hours and respond substantively within 30 calendar days.
3. Personal Data We Collect
3.1 Data You Provide Directly
| Category | Examples | Collection Point |
|---|---|---|
| Identity data | Full name, job title, company name | Contact forms, RFQ forms, job applications |
| Contact data | Email address, phone number, LinkedIn URL | Lead capture forms, newsletter signup |
| Professional data | CV/resume, work history, skills, references | Career / talent application portal |
| Business enquiry data | Project scope, budget range, RFQ specifications | RFQ forms, partner enquiry forms |
3.2 Data Collected Automatically
| Category | Examples | Source |
|---|---|---|
| Technical data | IP address, browser type, OS, device ID | Server logs, GA4, Google Tag Manager |
| Usage data | Pages visited, session duration, click paths | Google Analytics 4, Hotjar |
| Cookie data | Session IDs, preference cookies, analytics cookies | See Cookie & Tracker Policy |
4. Lawful Basis for Processing
| Processing Activity | Lawful Basis | GDPR Article |
|---|---|---|
| Responding to business enquiries | Legitimate interests / Pre-contractual | Art. 6(1)(b)(f) |
| Processing job applications | Pre-contractual steps / Legitimate interests | Art. 6(1)(b)(f) |
| Sending newsletters | Consent | Art. 6(1)(a) |
| Website analytics | Consent (cookie banner) | Art. 6(1)(a) |
5. How We Use Your Personal Data
Business Operations
- Responding to business enquiries and RFQ forms
- Managing relationships across 22+ Strategic Business Units
- Providing information about our multi-sector services
Recruitment and Talent
- Processing job applications and recruitment pipeline
- Assessing candidate suitability for current/future roles
- Retaining data for talent pool (with consent)
8. Data Retention
| Data Category | Retention Period |
|---|---|
| Business enquiry data | 3 years from last contact |
| Client / partner contact data | Duration of relationship + 7 years |
| Job application data (unsuccessful) | 12 months from rejection |
9. Your Data Subject Rights
Right to be informed
Know what data we hold and how we use it
Right of access (DSAR)
Obtain a copy of your personal data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure
Request deletion of your personal data
Right to restrict
Limit how we use your data
Right to portability
Receive data in machine-readable format
To exercise your rights, email privacy@betopialimited.comwith subject line 'Data Subject Request'. We respond within 30 days.
11. Information Security
Betopia is aligned with ISO 27001 and holds ISO 9001:2015 and ISO 22301:2019 certifications. We implement TLS 1.2+ encryption in transit and AES-256 at rest, alongside role-based access control and regular vulnerability scanning.
14. Governing Law
This Policy is governed by the laws of Bangladesh, without prejudice to mandatory data protection rights under GDPR, UK GDPR, or CCPA. Disputes are subject to the jurisdiction of the courts of Dhaka, Bangladesh.
© 2026 Betopia Group. All rights reserved.