Privacy Policy
Effective Date: 2026-01-01
Last Updated: 2026-05-27
1. Introduction
Penough Ltd. ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy outlines our practices concerning the collection, use, and safeguarding of your information when you interact with our cybersecurity services, website, Academy, and related applications.
2. Information We Collect
We may collect and process the following categories of data:
- Contact Data: Name, email address, phone number, and company details when you request a service or contact us.
- Technical Data: IP addresses, browser types, and log files generated when interacting with our digital infrastructure.
- Usage Data: Information about how you use our website or Academy platform for analytics and improvements.
- Service Execution Data: Client infrastructure details required conditionally for authorised penetration testing and security assessments, under strict non-disclosure agreements.
3. How We Use Your Information
Your data is strictly utilized for the following operational directives:
- To provide, maintain, and secure our cybersecurity services.
- To process transactions and deliver Penough Academy course materials.
- To answer inquiries, provide support, and communicate critical updates.
- To analyze and improve the performance and security of our own platforms.
4. Data Protection & Security
As a cybersecurity firm, we treat data security as our highest priority. We deploy state-of-the-art encryption (AES-256 for data at rest, TLS 1.3 for data in transit), regular internal audits, and stringent access controls to protect your information against unauthorized access, alteration, disclosure, or destruction. Our systems are subject to continuous Red Team testing.
5. Third-Party Disclosures
We do not sell, trade, or rent your personal identification information. We may securely share data with trusted third-party service providers (such as payment processors or cloud hosting environments) only when necessary to operate our business, provided those parties agree to equivalent strict confidentiality standards.
6. Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance user experience and gather analytical data. You may instruct your browser to refuse all cookies or to indicate when a cookie is being sent, though some platform features may not function properly without them.
7. Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, comply with our legal obligations in Bangladesh and internationally, resolve disputes, and enforce our agreements. Upon the expiration of the required retention period, or upon a valid user request for erasure, data is securely and permanently deleted from all active and backup systems.
8. Cross-Border Data Transfers
While Penough Ltd. operates globally, we prioritize local data processing where feasible. Any transfer of personal data outside of Bangladesh is conducted strictly in accordance with the adequate protection standards mandated by the Personal Data Protection Act (PDPA) of Bangladesh and international frameworks like the GDPR, utilizing approved mechanisms such as standard contractual clauses.
9. Data Breach Notification
In the unlikely event of a critical data breach that compromises personal data, Penough Ltd. is committed to notifying the relevant supervisory authorities and all affected individuals within 72 hours of discovery, in compliance with GDPR and PDPA mandates.
10. Your Rights (PDPA, GDPR, & CCPA)
Depending on your jurisdiction, you possess specific rights regarding your data:
- Right to Access & Portability: Request copies of your data in a structured, machine-readable format.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to Be Forgotten"): Request the deletion of your personal data.
- Right to Restrict or Object: Limit or object to how we process your data, including opting out of direct marketing.
- California Residents (CCPA): You have the right to direct us to "Do Not Sell or Share My Personal Information" and limit the use of sensitive data. Penough Ltd. does not sell personal information.
To exercise these rights, please contact our Data Protection Officer immediately.
11. Changes to This Policy
We reserve the right to update this Privacy Policy at any time to reflect evolving legal, technical, or business standards worldwide and within Bangladesh. Significant changes will be communicated via direct email or prominent notices on our platform.
12. Contact Us & Data Protection Officer (DPO)
If you have any questions, concerns, or requests to exercise your data rights, please contact our assigned Data Protection Officer (DPO) and compliance team:
Email: [email protected]
Phone: +8801986410710
HQ Address: 19/6, FDS Tower, Naddapara, Dakshin Khan, Dhaka -1230, Bangladesh