1. Introduction
Extent Technologies Limited respects the privacy of customers, website visitors, business partners, facility visitors and users of our services.
This Privacy Policy explains how we collect, use, disclose, store and protect personal data. It applies to interactions with Extent Technologies Limited, including our website, sales, support, infrastructure services, data center operations, facility access and professional services.
This Privacy Policy should be read together with our Terms & Conditions, Cookie Preferences, and Acceptable Use Policy.
2. Data Protection Principles
We aim to process personal data lawfully, fairly and transparently. Personal data should be:
- collected for legitimate purposes;
- limited to information reasonably required for those purposes;
- accurate where reasonably necessary;
- protected against unauthorised access;
- retained only as long as reasonably required; and
- processed in accordance with applicable data-protection law.
3. Information We Collect
Depending on your relationship with us, we may collect:
Identity Information
Name, organisation, job title, authorised-contact details, government-issued identification where verification is reasonably required, and other identity-verification information.
Contact Information
Email address, telephone number, business address, billing address, and delivery address.
Account Information
Account identifiers, usernames, authentication records, account preferences, and authorised-user information. Passwords are stored only using appropriate security mechanisms and never in plain text.
Billing and Transaction Information
Invoices, orders, transaction references, payment status, billing records, and applicable tax information. Full card details are handled directly by authorised payment providers rather than Extent Technologies.
Technical and Network Information
IP addresses, network logs, server logs, authentication logs, routing information, device information, browser information, operating-system information, timestamps, security events, and abuse reports.
Communications
Emails, support tickets, quotation requests, project communications, incident communications, and other correspondence.
4. Data Center Facility Information
For physical security and controlled facility access, we may process information relating to data center visitors, customers, staff and authorised contractors.
This may include: name, organisation, contact details, visit date and time, authorised-access records, entry and exit records, CCTV footage, photographs where required, biometric access information, and security incident records.
Biometric information is treated with additional protection where required by applicable law. Biometric information is used strictly for facility access control and physical-security purposes and is never used for unrelated advertising or marketing.
5. CCTV
CCTV operates within and around controlled data center areas for physical security, access auditing, theft prevention, incident investigation, infrastructure protection, and safety.
CCTV footage is generally retained for up to 90 days, subject to operational configuration. Relevant footage may be retained for a longer period where reasonably necessary for an active security incident, investigation, dispute or legal obligation. Access to CCTV records is restricted strictly to authorised personnel.
6. How We Use Personal Data
We may process information to:
- provide products and services;
- prepare quotations and enter into contracts;
- provision infrastructure and administer customer accounts;
- process invoices and payments;
- provide technical support and remote hands;
- operate our data center and control facility access;
- maintain physical and network security;
- detect fraud, abuse, and investigate network incidents;
- operate email and communications services;
- deliver development projects;
- comply with legal obligations and maintain financial/tax records; and
- protect our rights, customers, and infrastructure.
7. Lawful Processing
Where required by applicable law, we process personal data using an appropriate lawful ground: your consent, performance of a contract, legal obligations, legitimate interests, security and fraud prevention, or protection of vital interests.
Where processing relies on consent, consent may be withdrawn subject to applicable law.
8. Bangladesh Personal Data Protection
Where applicable, personal data is processed in accordance with the Personal Data Protection Act, 2026 of Bangladesh and other applicable laws and regulations. We implement processes appropriate to our role as a data fiduciary, controller, processor or service provider.
9. Data Residency and Infrastructure
Extent Technologies operates infrastructure within Bangladesh.
Where a customer purchases a service expressly designated as a Bangladesh-hosted or Bangladesh data-residency service, customer service data will be hosted according to the residency commitments contained in the applicable service agreement.
This does not necessarily mean that every business system used by Extent Technologies is located exclusively in Bangladesh (for example, international telecommunications, payment processing, or global security feeds may involve service providers operating in other jurisdictions where legally permitted).
10. International Data Transfers
Where personal data must be transferred outside Bangladesh, we will take reasonable steps to comply with applicable restrictions and safeguards governing international data transfers, including contractual necessity and approved transfer protections.
11. Customer-Controlled Data
Enterprise customers may place their own applications and data on infrastructure provided by Extent Technologies. In such circumstances, the customer generally determines whose data is collected, why it is processed, and how long it is retained.
Extent Technologies may therefore act as a processor or infrastructure provider rather than the party determining the purpose of that processing.
13. HostOrient
Extent Technologies Limited is the parent company of HostOrient. Information may be shared between Extent Technologies and HostOrient where reasonably necessary to provide a requested service, operate shared infrastructure, administer billing, prevent abuse, or maintain security.
14. Legal Disclosure
We may disclose information where we reasonably believe disclosure is required or permitted by law, including in response to lawful court orders, regulatory requirements, law-enforcement requests, or urgent threats to systems or infrastructure.
15. Security
We use technical, physical and organisational measures designed to protect personal information: access controls, authentication, encryption where appropriate, network monitoring, CCTV, biometric access controls, backups, and incident-response procedures. No system can guarantee absolute security.
16. Personal Data Breaches
We maintain procedures for investigating suspected personal-data breaches. Where an incident triggers a notification requirement under applicable law, we will make the required notification to the appropriate authority or affected parties in the timeframe required by law.
17. Data Retention
Personal information is retained only as long as reasonably necessary for service delivery, contractual requirements, accounting, taxation, security, and dispute resolution. Once information is no longer reasonably required, it is deleted, anonymised, or securely archived.
18. Your Rights
Depending on applicable law, you may have rights to access personal data, request correction of inaccurate information, request deletion, request restriction of processing, object to eligible processing, or withdraw consent.
19. Privacy Requests and Contact
Existing customers should create a support ticket through the customer portal. Non-customers and website visitors should contact info@extentit.com or call +8809644-222444. Abuse issues should be sent to abuse@extentit.com.
20. Marketing
Where we send optional marketing communications, recipients may unsubscribe at any time. Essential operational communications regarding invoices, service status, security, or maintenance are not considered optional marketing.
22. Children's Data
Extent Technologies primarily provides business and enterprise technology services. Our services are not designed for children, and we do not knowingly create accounts for minors.
23. Third-Party Websites
Our website may link to third-party websites. We do not control independent websites and are not responsible for their privacy practices.
24. Changes to This Privacy Policy
We may update this Privacy Policy as our services, technologies or legal obligations change. The current version will always be published on our website with its latest revision date.
Assistance & Official Contacts
For questions regarding this policy, service level reviews, billing adjustments, or network abuse reports, please direct your communication through the designated channels:
Spam, phishing, malicious traffic, botnet activity, or copyright infringement originating from Extent Technologies IP allocations:
abuse@extentit.com