Effective Date: 17 August 2026
Website: triloytech.com
1. Introduction
At TriloyTech (“we,” “our,” or “us”), we are committed to safeguarding your privacy and ensuring compliance with global data protection regulations, including the European Union’s General Data Protection Regulation (GDPR). This Privacy Policy explains how we collect, use, and protect your personal and business information when you engage with our custom software development services, use our SaaS products, or visit our website.
2. Our Role in Data Processing
Our responsibility regarding your data varies strictly based on the services provided:
- Custom Development Projects (Client Hosted): For custom software or application development, our standard practice is to develop the solution and deploy it directly onto the Client’s designated servers (often hosted in the EU or their preferred region). Post-deployment, TriloyTech retains no access to the Client’s servers, live databases, or end-user data. In this scenario, the Client acts as the sole Data Controller and Data Processor for their respective end-users. TriloyTech acts strictly as a technology vendor and does not process the Client’s end-user data.
- TriloyTech SaaS Products: When you use our proprietary SaaS products hosted on our infrastructure, TriloyTech acts as the Data Processor for any information you upload into the system, and you remain the Data Controller.
- B2B Client Information: For business operations, we act as the Data Controller for the business contact information (B2B data) of our direct clients.
3. Information We Collect
We limit data collection to what is strictly necessary to conduct business with you:
- Business Contact Information: Name, email address, phone number, company name, and billing information provided during proposals, invoicing, or SaaS registration.
- Usage Data: Standard website analytics, IP addresses, and browser data collected automatically when you visit triloytech.com.
4. Lawful Basis for Processing (GDPR Compliance)
Under the GDPR, we process your personal and business data under the following lawful bases:
- Contractual Necessity: Processing is necessary to fulfill our obligations under a Work Order, Proposal, or SaaS subscription agreement (e.g., to communicate with you and issue invoices).
- Legitimate Interest: To improve our services, maintain the security of our website, and provide customer support.
- Consent: Where you have explicitly opted-in to receive marketing communications.
5. Data Testing and Live Environments
For custom development projects, TriloyTech strictly utilizes “dummy” or synthetic data during the development and testing phases. We require that Clients do not share live database dumps containing personal data of EU citizens with our development team for local testing.
6. International Data Transfers
TriloyTech operates globally, with core development teams based in Bangladesh.
- For Custom Projects: Your end-user data remains securely on your chosen servers (e.g., in Europe) and is not transferred to Bangladesh.
- For Client Contact Data: Business contact information (B2B data) required for project management and billing is processed in Bangladesh. By engaging our services, you consent to this necessary transfer, which is safeguarded by strict internal confidentiality protocols.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your data. We only share data with trusted third-party service providers (such as payment processors or our own SaaS cloud hosting providers) strictly necessary to operate our business. All third parties are bound by strict confidentiality agreements.
8. Data Security and Breach Notification
We implement robust technical and organizational measures to secure your data against unauthorized access. In the unlikely event of a data breach involving your personal business data or our SaaS platforms, we will notify affected individuals and the relevant supervisory authorities within 72 hours of becoming aware of the breach, as mandated by the GDPR.
9. Data Retention
We retain your business contact and billing information only for as long as legally required for taxation and accounting purposes, or as long as you maintain an active SaaS subscription with us.
10. Your Data Protection Rights (Under GDPR)
If you are a resident of the European Economic Area (EEA), you have the following rights regarding your personal data held by TriloyTech:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): Request the deletion of your personal data, subject to legal constraints.
- Right to Restrict Processing: Request a temporary halt to data processing.
- Right to Data Portability: Request transfer of your data to another organization.
- Right to Object: Object to our processing of your data based on legitimate interest.
To exercise any of these rights, please contact us using the details below.
11. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes data protection laws, you have the legal right to lodge a complaint with a supervisory authority responsible for data protection in your country of residence within the EU.
12. Contact Information
For any privacy-related inquiries, requests to exercise your data rights, or GDPR compliance questions, please contact our Data Protection representative at:
- Email: contact@triloytech.com
- Phone: +(880) 1339870528
- Address: Level 5, Saleh Tower, House 1, Road 13, Garib-E-Newaz Avenue, Dhaka 1230.