Enterprise HomeOmnibus Data Privacy Agreement (ODPA-NX-2026)
Privacy GovernanceDocument ID: NX-ODPA-2026.GLOBAL

Privacy
& Data Policy

This document serves as the authoritative Omnibus Data Privacy Agreement (“Agreement”) for M/S. Neuroxie, a Partnership IT Firm following The Partnership Act, 1932 and Commercial Law of Bangladesh.

This Agreement establishes the exhaustive legal and technical parameters for the collection, isolation, and protection of enterprise data. As a high-intensity engineering firm, we deploy military-grade encryption and zero-trust frameworks to safeguard the intellectual and personal assets of our global clientele. By engaging our personnel or accessing our systems, the Client acknowledges absolute and irrevocable acceptance of these terms.

Statutory Controller
M/S. Neuroxie
Legal Entity:M/S. Neuroxie
Jurisdiction:Brahmanbaria, BD
Registry:Chattogram RJSC, BD
RJSC Registration No:CHP-3867
Digital Business ID:503896191
Bangla Biz ID:RC2312909605
Global D-U-N-S®:73-223-4901
Effective Date:1 July, 2023
Article I

Binding Acceptance & Fiduciary Nexus

Digital Nexus of Privacy

1.1 Execution of Consent: Engagement with the Company via any digital channel—including but not limited to website interaction, client portal authentication, or repository integration—constitutes a formal, binding acceptance of this Omnibus Data Privacy Agreement (ODPA).

1.2 Supremacy of Privacy Terms: This ODPA establishes the foundational privacy framework for all technical engagements. In the event of a conflict between this document and any Client-side procurement boilerplate or generic purchase order terms, the standards of this Agreement shall take primacy.

“By utilizing M/S. Neuroxie resources, the Client acknowledges that data privacy is a shared fiduciary responsibility. This document represents the entire privacy agreement between the Parties.”

Article II

Data Taxonomy & Scope of Collection

Global Information Classification

The Company enforces a strictly tiered data classification model to ensure appropriate isolation and protection levels based on asset sensitivity.

Corporate Identity

KYC data, billing coordinates, and authorized signatory profiles used for fiduciary account management.

Technical Artifacts

Proprietary source code, database architectures, and architectural blueprints shared for engineering execution.

AI Inferences

Input prompt-chains and output telemetry processed through our secure, isolated machine learning pipelines.

Infrastructure Logs

Metadata, routing telemetry, and interaction timestamps collected solely for security forensic analysis.

Article III

Lawful Basis & Regulatory Compliance

Global Statutory Frameworks

The Company operates under the most rigorous international data protection frameworks, including GDPR (EU/UK), CCPA/CPRA (USA), and DPA 2018.

Contractual Necessity

Processing is essential for the evaluation of proposals and the delivery of technical deliverables defined in the SOW.

Legitimate Interests

Processing is required to maintain the security of our global engineering infrastructure and prevent commercial fraud.

Article IV

AI Privacy & LLM Zero-Retention

Algorithmic Isolation Mandate

As a leader in AI automation, the Company enforces absolute isolation between Client proprietary data and public foundation models.

“Proprietary business logic and training datasets processed through M/S. Neuroxie pipelines are NEVER utilized for public model training. All implementations utilize isolated enterprise API endpoints with Zero-Data-Retention (ZDR) protocols active.”

4.1 RAG Pipeline Security: Retrieval-Augmented Generation (RAG) indices are hosted in isolated, encrypted vector databases. Access is restricted via identity-aware proxies and hardware security keys.

Article V

Global Hubs & Cross-Border Governance

Dual-Continent Data Sovereignty

The Company's dual-hub model is governed by unified security protocols and binding Intra-Corporate Data Transfer Agreements.

Brahmanbaria Corporate HQ

Governance of master legal contracting and treasury data. Strict adherence to corporate privacy laws.

Dhaka Engineering

Isolated production lab for technical buildout. No permanent storage of PII on local Dhaka infrastructure.

Sovereign Regions

Cloud hosting is restricted to Client-specified sovereign regions (e.g., AWS US-East) with no cross-border mirroring.

Article VI

Sub-Processor Governance

Third-Party Ecosystem Integrity

The Company utilizes world-class infrastructure and service providers to deliver enterprise-grade performance.

Infrastructure Partners

AWS, Google Cloud, and Azure provide the foundational compute and storage layers, governed by their respective Enterprise Privacy Agreements.

Operational Tooling

Shurjopay, Aamarpay, bKash, Citibank, OpenAI (Enterprise), and Slack are utilized for secure transactional processing and corporate communication.

Article VII

Security Architecture & Encryption

Cryptographic Fiduciary Standards

We deploy military-grade security controls across our technical delivery pipeline.

  • TLS 1.3 Encryption In-Transit
  • AES-256-GCM Encryption At-Rest
  • FIDO2 Hardware-Level Auth
  • Zero-Trust Network Access (ZTNA)
Article VIII

Retention & Automatic Purge Protocols

Asset Lifecycle Governance

The Company adheres to a strict "Minimalist Retention" philosophy. Data is retained only for the duration required by law or contractual obligation.

Operational Data

Technical logs and metadata are purged automatically every 90 days to maintain lean security profiles.

Statutory Records

Financial and contractual records are retained for seven (7) years to comply with US IRS and international audit mandates.

Article IX

Statutory Rights & Data Portability

Client Control Mandates

Clients maintain absolute control over their enterprise data footprint. We provide streamlined protocols for exercising statutory rights.

Subject Access

Request full export of project metadata and audit trails.

Rectification

Correct outdated billing or directory identity data.

Erasure

Right to be forgotten following terminal account settlement.

Article X

Financial & Treasury Privacy

PCI-DSS Integrity Protocols

Payment data is isolated via industry-leading vaults. M/S. Neuroxie personnel never have access to full credit card numbers or raw bank credentials.

“All financial transactions are processed via Authorized Gateway Partners (Shurjopay/Aamarpay/bKash/Citibank). We utilize tokenization to ensure your financial identity is never stored on Neuroxie infrastructure.”
Article XI

Staff Augmentation Privacy

Embedded Resource Governance

For Staff Augmentation engagements, our personnel act as an extension of the Client's team, adhering to the Client's internal security and privacy policies.

"Augmented personnel access Client systems solely via Client-managed hardware or isolated VDI environments. No Client data is exfiltrated to M/S. Neuroxie corporate storage."

Article XII

Industrial IoT Telemetry

OT Privacy Governance

Hardware deployments utilize edge-processing to minimize data transmission. Operational Technology (OT) telemetry is anonymized prior to cloud synchronization.

Anonymized Stream

Sensor data is stripped of facility-identifying metadata at the edge before archival.

Isolated VLANs

IoT arrays operate on isolated VLAN segments with no route to the Client's corporate PII databases.

Article XIII

Cyber Security Audit Data

Forensic Privacy Governance

Vulnerability assessments and penetration testing generate high-sensitivity exploit data. This information is classified as "Level 5 - Maximum Security."

“Audit reports and exploit logs are stored in air-gapped encrypted volumes. Transmission to the Client is performed exclusively via multi-factor PGP-encrypted channels.”

Article XIV

Cookie & Tracking Policy

Telemetry Transparency Mandate

We utilize technical cookies strictly for session persistence and security verification. We do not utilize cross-site tracking or behavioral marketing pixels.

Essential Only

Only session and CSRF protection cookies are active. No third-party ad-network trackers are permitted.

Privacy Analytics

Web analytics are anonymized and self-hosted. We do not transmit visitor IP data to external advertising hubs.

Article XV

Law Enforcement Disclosure

Sovereign Compliance Protocols

The Company complies with valid legal process (subpoenas, warrants, court orders) from governmental authorities of competent jurisdiction.

“Unless prohibited by law, we will notify the Client of any data request from law enforcement. We vigorously contest broad or non-specific data requests that exceed statutory limits.”
Article XVI

Non-Monetization Warranty

Fee-for-Service Integrity

M/S. Neuroxie operates strictly as an engineering and advisory firm. Data monetization is fundamentally incompatible with our business model.

“We NEVER sell, rent, lease, or license client-identifiable data to third-party marketing brokers. Your project data is a technical asset, not a tradeable commodity.”

Article XVII

Children's Privacy (COPPA)

Age-Gated Compliance

Our services are directed exclusively to enterprise personnel and individuals over the age of 18. We do not knowingly collect data from children under the age of 13.

17.1 Automatic Deletion: If we identify that PII from a minor has been collected without parental consent, we will initiate immediate, irrevocable deletion protocols.

Article XVIII

Governance of Corporate Dissolution

Asset Transfer Protocols

In the event of a merger, acquisition, or total corporate dissolution, Client data will remain protected under the terms of this ODPA.

18.1 Opt-Out Right: In any event of asset transfer to an external entity, Clients will be notified via authorized channels and granted exactly 30 days to exercise their right to total data erasure prior to transfer.

Article XIX

Master Roadmap to
Resolution

Fiduciary Privacy Dispute Protocols

Protocol Phase 01

Privacy Affidavit

Client must submit a digitally signed PDF citing the exact ODPA clause breached, supported by technical logs or interaction timestamps.

Protocol Phase 02

Compliance Audit

Our internal Data Protection Officer (DPO) conducts a full forensic audit within 14 business days of submission.

Protocol Phase 03

Mandatory Cure Window

The Company retains an absolute right to remedy any verified technical breach within 30 days prior to further legal escalation.

Protocol Phase 04

Fiduciary Net-Settlement

Our treasury desk evaluates any required financial remediation, deducting all verified sunk infrastructure costs and labor hours.

Protocol Phase 05

Final Liability Release

Resolution is finalized only upon execution of a notarized 'Full Release' form, terminating all further liability and reverting data control.

Article XX

Governing Law & ICC Arbitration

Final Legal Venue

Jurisdictional Supremacy

All domestic transactions are governed by the statutory laws of Bangladesh. All international transactions are governed by the UN Convention on Contracts for the International Sale of Goods (CISG).

Final Arbitration Clause:

“Any dispute, controversy, or claim arising under this Policy shall be settled amicably or via final and binding arbitration under the Rules of Arbitration of the ICC or competent courts in Bangladesh. The language of arbitration shall be English.”

Corporate Compliance Desk

Global Data Protection & Legal Escalation

Authorized Global Corporate Governance Publication

M/S. Neuroxie. Brahmanbaria HQ & Dhaka R&D Center. Fiduciary Compliance Enforced.