Enterprise Data Protection & Trust

Privacy & Data Governance Policy

Learn how BillMeBD collects, safeguards, and processes personal, technical, and billing data in compliance with global data protection standards (including GDPR) across all hosting, cloud infrastructure, domain registration, SSL, and managed sysadmin services.

Last Updated: September 2026 • Version: 3.2 (Production Ready)

1. Overview & Scope of Policy

This Privacy Policy applies to all services, products, APIs, client portals, and websites operated by BillMeBD ("we", "our", or "us"). We provide mission-critical cloud hosting, high-performance NVMe Virtual Private Servers (VPS), dedicated bare-metal servers, domain name registration, SSL certificates, software licenses, and systems administration assistance.

By creating an account, ordering services, or accessing our client portal, you acknowledge that your information will be handled strictly in accordance with this Policy.

2. Information We Collect

We collect only the essential data necessary to provision, secure, maintain, and bill your cloud infrastructure:

Account & Identity Information

Full name, registered email address, organization/company name, telephone number, physical billing address, tax identification (HSN/SAC/VAT/GST), and government KYC verification documents when mandated for fraud prevention.

Domain Registration & WHOIS Data

Registrant name, administrative/technical contacts, phone numbers, and nameservers required by ICANN and top-level domain (TLD) registry operators. ID Protection / WHOIS privacy is provided where supported by registry rules.

Billing & Payment Records

Transaction identifiers, payment gateway references (Stripe, PayPal, bKash, Nagad, Bank Transfers), credit card token snapshots, and billing ledger entries. We do not store raw full credit card numbers on local web servers.

Infrastructure & Security Logs

Source IP addresses, browser user-agents, active session tokens, cPanel SSO authentication nonces, CSF firewall triggers, and audit logs recorded to defend against unauthorized intrusion and brute-force attacks.

3. Purpose and Legal Basis for Processing

We process personal and technical data under the following lawful bases:

  • Contractual Performance: Automated provisioning of hosting packages, virtual machines, cPanel accounts, DNS records, automated backup archiving, and invoice dispatch.
  • Legal & Compliance Obligations: Tax reporting, ICANN WHOIS data escrow, fraud mitigation, anti-money laundering (AML) protocols, and response to valid court subpoenas.
  • Legitimate Interests: Securing server clusters, real-time DDoS mitigation, brute-force firewall blocking, automated renewal notices, and critical security advisories.

4. Security Standards & AES-256 Credential Vaulting

We implement industry-standard cryptographic protocols to protect client assets. Passwords are encrypted using irreversible multi-round Bcrypt/Argon2 hashing. Server root keys, provisioning API tokens, and confidential support credentials shared in support tickets are vaulted with AES-256-GCM authenticated encryption.

All web communications between your browser and our platform are encrypted via modern TLS 1.3 protocols with strict HSTS (HTTP Strict Transport Security) enforcement.

5. Upstream Service Providers & Data Transfers

To deliver global services, we interface with vetted upstream providers bound by strict confidentiality and data protection agreements:

  • Domain Registrars & Registries: (e.g., LogicBoxes, Enom, BTCL, ResellerClub) for domain provisioning.
  • Certificate Authorities: (e.g., Let's Encrypt, Sectigo, DigiCert) for SSL validation and cryptographic issuance.
  • Payment Gateways: Certified PCI-DSS compliant payment processing platforms.
  • Data Center Facilities: Tier-3/4 carrier-neutral colocation facilities with 24/7 biometric physical security.

6. Data Retention & Account Deletion Schedules

We retain data only as long as your account remains active or as required by applicable commercial accounting laws:

  • Active Service Data: Retained continuously throughout your active subscription.
  • Cancelled / Terminated Hosting Data: Backups and website file directories are permanently purged 30 days post-termination.
  • Financial & Invoice Inscriptions: Retained for 7 years in accordance with statutory accounting requirements.
  • Security & Audit Traces: Automatically rotated and purged after 90 to 180 days.

7. Your Rights & GDPR Privacy Controls

Under applicable data protection laws (including GDPR and regional privacy statutes), you possess full rights to:

Right to Access & Portability Request a full JSON export of your personal profile, services, and activity ledger anytime via the GDPR portal.
Right to Rectification Update contact emails, phone numbers, addresses, and authorized sub-account permissions instantly in client settings.
Right to Erasure (Anonymization) Submit a formal account closure and erasure request subject to zero outstanding debts and regulatory retention periods.

8. Contact Our Data Protection Officer

If you have questions regarding this Privacy Policy, data processing agreements (DPA), or wish to exercise your statutory rights, please submit a high-priority ticket via our client portal or contact our compliance desk:

BillMeBD Privacy & Compliance Office
Direct Compliance Desk: support{{ request()->getHost() }}
Open Compliance Ticket
0%