1.1. "WinrySoft" ("Company", "we", "us", or "our") operates as a software development enterprise with registered offices at Kaunia, Barisal, Bangladesh.
1.2. "User" or "Data Subject" means any individual visiting the website, submitting an inquiry, requesting a commercial quotation, or interacting with our digital interfaces.
1.3. "Client Organization" refers to any commercial firm, hospital, educational institution, or retail enterprise procuring WinrySoft's bespoke development services or software solutions.
2.1. WinrySoft as Data Controller: WinrySoft acts as a Data Controller with respect to personal information collected directly through winrysoft.com, customer relationship databases, quotation submissions, employment applications, and billing records.
2.2. WinrySoft as Data Processor: For enterprise software deployments (including Hospital Pro, School ERP, Smart POS, and Accounting ERP), the licensing Client Organization remains the sole Data Controller of all internal data (e.g., patient clinical records, student academic files, employee payroll, customer transactional ledgers). WinrySoft processes such data strictly as a technical intermediary and software vendor pursuant to the Client's service agreement.
3.1. Voluntarily Submitted Identification Data: Full name, corporate email address, contact telephone numbers (including WhatsApp routing), company or institution name, job title, and physical address provided during inquiry or quote generation.
3.2. Project & Commercial Specifications: Functional requirements, architectural documents, technical briefs, and communication logs submitted to scope software development contracts.
3.3. Financial & Tax Compliance Data: Bank account transfer references, Mobile Financial Service transaction IDs (bKash/Nagad/Rocket), invoice records, and National Board of Revenue (NBR) TDS/VDS withholding tax deduction certificates.
3.4. Technical & Network Telemetry: Internet Protocol (IP) addresses, device hardware identifiers, browser specifications, access timestamps, and referring URLs logged automatically by standard web server protocols.
WinrySoft processes collected data under the following recognized legal bases:
5.1. Infrastructure & Hosting Providers: Data may be stored on secure cloud virtual private servers (VPS) and database infrastructure (e.g., AWS, DigitalOcean, or local BDIX data centers) governed by strict technical security standards.
5.2. Payment & Telecommunication Gateways: Commercial transactions and automated system notifications are processed through licensed Bangladesh payment gateways (SSLCommerz, bKash Merchant, Nagad) and authorized telecom SMS aggregators.
5.3. Absolute Prohibition on Data Commercialization: WINRYSOFT DOES NOT SELL, RENT, LEASE, TRADE, OR MONETIZE ANY PERSONAL OR BUSINESS DATA TO THIRD PARTIES, ADVERTISING NETWORKS, OR MARKETING AGGREGATORS UNDER ANY CIRCUMSTANCES.
6.1. Healthcare Records (Hospital Pro): Patient medical histories, diagnostic laboratory data, doctor prescriptions, and health records managed via WinrySoft software remain strictly confidential to the healthcare facility. WinrySoft personnel do not access, view, or duplicate patient clinical records except under explicit, written technical recovery instructions.
6.2. Academic Records (School ERP): Student academic grades, attendance, parental contacts, and tuition accounts are restricted exclusively to the authorized administrative staff of the licensing educational institution.
7.1. Encryption Standards: All external web communications are encrypted in transit using 256-bit Transport Layer Security (TLS/HTTPS).
7.2. Access Controls & NDAs: Access to customer databases and source code repositories is restricted via Role-Based Access Control (RBAC) to authorized engineers. All employees, developers, and subcontractors are bound by legally enforceable Non-Disclosure Agreements (NDAs).
7.3. Ephemeral Staging Retention: Development databases, staging servers, and test subdomains are maintained temporarily and permanently decommissioned after thirty (30) days of project dormancy or completion.
8.1. Inquiry & Proposal Data: Prospective client specifications and quote communications are preserved for up to twenty-four (24) months, after which they are securely purged from active CRM stores.
8.2. Commercial & Tax Records: Executed contracts, invoices, payment receipts, and TDS/VDS certificates are retained for seven (7) years to satisfy statutory fiscal audit requirements under Bangladesh tax law.
Users and Clients maintain the following rights regarding personal data held by WinrySoft as Data Controller:
Rights may be exercised by submitting a formal written request to info@winrysoft.com. Verified requests are addressed within ten (10) business days.
WinrySoft shall not disclose personal or enterprise data to external governmental agencies except where strictly mandated by a valid judicial warrant, summons, or statutory order issued by a competent court of the People's Republic of Bangladesh pursuant to the Cyber Security Act, 2023 or the Code of Criminal Procedure.
WinrySoft employs standard technical session cookies and anonymized telemetry solely to maintain website performance, secure user sessions, and evaluate server load. Users may configure web browser preferences to restrict cookie storage, which may impact certain interactive features.
12.1. Policy Updates: WinrySoft reserves the right to amend, revise, or update this Privacy Policy at any time to reflect operational modifications, technological advancements, or changes in statutory data protection laws in Bangladesh.
12.2. Effective Date & Notification: Any amendments shall become effective immediately upon posting to this website with an updated revision date. Continued engagement with our website or services following such revisions constitutes acknowledgment and acceptance of the modified Privacy Policy.