Privacy Policy

Last update: 23 Feb 2026

Data We Collect & Process

ZiroOne (“the Company”, “we”, “our”, or “us”) collects and processes personal and organizational data in connection with the provision of its Enterprise Resource Planning (ERP) services. The data collected is limited to that which is necessary for lawful business operations, contractual obligations, system administration, regulatory compliance, and service improvement. In the course of providing our services, we may collect personal data including, but not limited to, names, employee identification numbers, job titles, departmental affiliations, contact information, company details, and other identification data supplied either directly by users or by authorized representatives of the subscribing organization. Such data is processed strictly for purposes related to account management, user authentication, internal administration, reporting, and operational functionality of the ERP platform. We also collect certain technical and system-generated information automatically when users access or interact with the platform. This may include IP addresses, device identifiers, browser and operating system details, access timestamps, activity logs, and audit records. This information is processed for legitimate interests including maintaining system security, preventing unauthorized access, monitoring performance, troubleshooting technical issues, and ensuring service integrity. Where applicable modules are utilized, the system may process financial, employment, attendance, payroll, provident fund, loan, asset management, and other operational data necessary for organizational administration. Such data is processed solely in accordance with the instructions of the subscribing organization and for legitimate business purposes consistent with applicable laws and regulations. ZiroOne may use cookies or similar technologies to facilitate secure session management, enhance user experience, and support system analytics. These technologies do not collect information beyond what is necessary to ensure proper system functionality and security. All data processing activities are conducted in accordance with applicable data protection laws and regulations. We implement appropriate technical and organizational measures to safeguard the confidentiality, integrity, and availability of all data processed through the platform. Data is collected and retained only to the extent necessary to fulfill the purposes described herein or as required by law.

Why We Use This Data

ZiroOne processes collected data solely for legitimate business purposes and in accordance with applicable laws and contractual obligations. The primary purpose of processing such data is to deliver, maintain, and improve the functionality of the ERP platform and its associated modules. Personal and organizational data are used to establish and manage user accounts, authenticate authorized users, facilitate secure access to system features, and enable the proper operation of modules such as human resource management, payroll processing, provident fund administration, asset management, financial reporting, and other organizational services. Data processing ensures that system outputs, reports, and transactions are accurate, reliable, and aligned with the operational requirements of the subscribing organization. Technical and system-generated data are used to maintain platform security, detect and prevent unauthorized access, investigate suspicious activities, monitor system performance, and ensure service continuity. Such processing is necessary to safeguard data integrity, protect against cyber threats, and maintain the stability of the platform. We may also use collected data to comply with applicable legal and regulatory obligations, respond to lawful requests from governmental or regulatory authorities, enforce contractual rights, and fulfill audit and reporting requirements. In certain circumstances, data may be processed for service improvement purposes, including system optimization, feature enhancement, performance analysis, and user experience refinement. Any such processing is conducted in a manner that respects data protection principles and maintains appropriate safeguards. Under no circumstances is data processed for purposes that are incompatible with the original intent of collection or beyond what is reasonably necessary for the provision of services, legal compliance, or legitimate business interests.

Data Sharing

ZiroOne does not sell, trade, or rent personal or organizational data to third parties. Data processed through the ERP platform is treated as confidential and is disclosed only in limited circumstances where such disclosure is necessary, lawful, and consistent with the purposes outlined in this Policy. Data may be shared with authorized personnel within the subscribing organization strictly for operational, administrative, and management purposes. Access to data is role-based and restricted to individuals who require such access to perform their professional duties. We may engage trusted third-party service providers to support the operation, maintenance, hosting, or security of the platform. In such cases, limited data may be processed by these service providers solely for the purpose of delivering contracted services on our behalf. All third-party processors are bound by contractual obligations requiring confidentiality, data protection safeguards, and compliance with applicable laws. Data may also be disclosed where required by applicable law, regulation, court order, or lawful request from governmental or regulatory authorities. In such circumstances, disclosure shall be limited to the extent legally required and, where permitted, the affected organization will be notified. In the event of a merger, acquisition, corporate restructuring, or sale of assets, data may be transferred as part of the business transition, subject to appropriate confidentiality protections and continued adherence to data protection obligations. We implement appropriate technical and organizational measures to ensure that any data shared with authorized parties is protected against unauthorized access, misuse, alteration, or disclosure. Under no circumstances shall data be disclosed for purposes that are inconsistent with this Policy or beyond what is necessary to provide the ERP services or comply with legal requirements.

Security Measures

ZiroOne is committed to protecting the confidentiality, integrity, and availability of all personal and organizational data processed through the ERP platform. We implement appropriate technical, administrative, and organizational safeguards designed to prevent unauthorized access, disclosure, alteration, loss, or destruction of data. Our security framework includes, but is not limited to, access control mechanisms, user authentication procedures, role-based authorization, encrypted data transmission, secure server infrastructure, firewall protection, and continuous system monitoring. Access to data is strictly limited to authorized users and personnel who require such access for legitimate business purposes. Authentication credentials are securely managed, and user activities may be logged for audit and accountability purposes. Data transmitted between users and the platform is protected using industry-standard encryption protocols. Additionally, we employ secure hosting environments and regularly update system components to mitigate vulnerabilities and protect against emerging security threats. Security patches, software updates, and risk assessments are conducted periodically to maintain system resilience. We also maintain internal policies and procedures governing data handling, incident response, and access management. Personnel with access to sensitive information are subject to confidentiality obligations and appropriate training to ensure compliance with data protection standards. In the event of a security incident or data breach, we will take prompt and appropriate remedial actions, including investigation, mitigation, and notification where required by applicable laws and regulations. While we implement reasonable and industry-standard security measures, no method of electronic storage or transmission is entirely secure. Accordingly, we cannot guarantee absolute security but remain committed to continuously improving our safeguards to protect data entrusted to us.

Retention & Deletion

ZiroOne retains personal and organizational data only for as long as necessary to fulfill the purposes for which such data was collected, including the provision of ERP services, compliance with contractual obligations, resolution of disputes, enforcement of legal agreements, and adherence to applicable legal and regulatory requirements. Data retention periods are determined based on the nature of the information, the operational necessity of the data, statutory or regulatory obligations, and legitimate business interests. Certain financial, payroll, taxation, employment, and audit-related records may be retained for extended periods where required by law or applicable compliance standards. Upon termination of the service agreement or upon written instruction from the subscribing organization, data may be securely archived, returned, or permanently deleted, subject to any applicable legal or regulatory retention requirements. Where deletion is requested and legally permissible, reasonable measures will be taken to securely erase or anonymize the data in a manner that prevents recovery or reconstruction. Backup copies of data may be retained for a limited duration as part of routine disaster recovery and business continuity processes. Such backup data remains protected under the same security controls and will be automatically overwritten or securely deleted in accordance with established retention schedules. ZiroOne reserves the right to retain anonymized or aggregated data that no longer identifies individuals or specific organizations for analytical, statistical, or system improvement purposes. All retention and deletion practices are conducted in accordance with applicable data protection laws and internal data governance policies to ensure responsible data lifecycle management.

User Rights & Requests

ZiroOne recognizes and respects the rights of users and data subjects in relation to their personal data, in accordance with applicable data protection laws and regulations. Individuals whose data is processed through the ERP platform may have certain rights regarding access, correction, restriction, objection, portability, or deletion of their personal information, subject to legal and contractual limitations. Users may request access to the personal data maintained about them, including information regarding the nature, purpose, and scope of processing activities. Where personal data is inaccurate, incomplete, or outdated, users may request correction or update of such information through authorized administrative channels or by submitting a formal request. Subject to applicable laws and operational requirements, users may also request the restriction of processing, object to certain forms of data processing, or request the deletion of their personal data. Such requests will be evaluated in light of contractual obligations, legal compliance requirements, audit obligations, and legitimate business interests. In cases where deletion is not legally permissible, ZiroOne will provide an explanation outlining the basis for continued retention. Where technically feasible and legally required, users may request the transfer of their personal data in a structured, commonly used, and machine-readable format. All requests relating to user rights must be submitted in writing through authorized communication channels. ZiroOne may take reasonable steps to verify the identity of the requesting party prior to processing any request to ensure the security and integrity of personal data. Requests will be addressed within a reasonable timeframe in accordance with applicable legal requirements. The exercise of user rights shall not adversely affect the rights and freedoms of other individuals or compromise the Company’s legal and regulatory obligations.

Governing Law

This Privacy Policy and all matters relating to the collection, processing, retention, and protection of data by ZiroOne shall be governed by and construed in accordance with the applicable laws and regulations of the jurisdiction in which ZiroOne operates, without regard to conflict of law principles. Any dispute, claim, or controversy arising out of or relating to this Policy, including the interpretation, enforcement, or alleged breach thereof, shall be subject to the exclusive jurisdiction of the competent courts within the applicable jurisdiction, unless otherwise agreed in writing between ZiroOne and the subscribing organization. Where applicable data protection or privacy laws impose mandatory requirements, such provisions shall prevail to the extent required by law.

Changes to This Policy

ZiroOne reserves the right to amend, modify, or update this Privacy Policy at any time to reflect changes in legal requirements, regulatory obligations, technological developments, operational practices, or service enhancements. Any material changes to this Policy will be communicated through appropriate channels, including publication on our official website or notification within the ERP platform. Continued use of the services following the effective date of any updates shall constitute acknowledgment and acceptance of the revised Policy. We encourage users and subscribing organizations to review this Policy periodically to remain informed about how data is collected, processed, and protected.

Contact Information

ZiroOne provides structured support services to ensure uninterrupted operations and timely issue resolution. Our support framework includes:

• Technical assistance during business hours
• Incident tracking and response management
• System updates and maintenance
• Guidance for feature usage and configuration

For inquiries, technical assistance, or partnership discussions, please contact:

ZiroOne
Email: support@ziroone.com
Phone: 09609-014-015
Address: 567/1, Lebel 4, Mirpur, Section-2, Dhaka-1216.

We are committed to responding promptly and professionally to all communications.