Privacy policy

How we handle merchant and customer data.

Last updated 5 May 2026. Effective immediately for all Nirbhor workspaces. Aligned with the GDPR / UK GDPR principles, the Meta Platform Terms, and Bangladeshi data-protection law.


This policy explains how Nirbhor - Md Forhad Hossain ("Nirbhor", "we") collects, uses, retains, shares, and protects personal data when a Bangladeshi merchant connects a Facebook Page, WhatsApp Business Account, or Instagram Professional account to the Nirbhor platform and our agent processes inbound and outbound conversations on the merchant's behalf. It applies to merchants and operators (our customers) and the end customers whose messages are handled by the agent.

For Meta's App Review and Platform Terms, this policy is the canonical statement of how we use Meta Platform data. For data subjects in Bangladesh, this policy is structured to align with the Digital Security Act 2018 and the Personal Data Protection ordinance pending before Parliament (collectively referred to here as "BD law"). For data subjects in the EU, EEA, and the United Kingdom, we voluntarily apply GDPR / UK GDPR principles — lawful basis, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability — as a baseline.

What we collect

We collect three categories of data, each only to the minimum extent needed to operate the service the merchant has enabled:

  • Workspace data — product catalog (titles, prices, stock, images), order records (SKU, quantity, payment method, shipping address, courier handoff), merchant policies (negotiation floors, escalation rules, persona settings), operator accounts (email, role, last sign-in), audit log entries.
  • Conversation data from connected platforms — for each Page / WABA / Instagram handle the merchant connects, the message threads exchanged with end customers, customer profile fields exposed by the platform (display name, locale, profile picture URL), media attachments, delivery and read receipts, and tool-call traces produced by our agent in service of those threads. Retrieved through Meta's official Graph APIs and Webhooks with the merchant's explicit page-owner consent.
  • Operational telemetry — model latency, tool-call latency, error rates, queue depth, billing usage. Aggregated at the merchant level; not tied to individual end customers in any reported metric.

We do not collect special categories of data (race, religion, health, biometrics, sexual orientation, political opinion) and we do not knowingly process data of children under 13. If the agent encounters such data in a customer message we do not treat it as a profile attribute; the message is processed for the immediate sales workflow and retained under the schedule below.

How we use it

We use the data above only for the purposes set out in this section. Each purpose has a defined lawful basis under GDPR Art. 6 (where applicable):

  • Service delivery — answering customer messages, looking up inventory, capturing orders, escalating to operators, briefing couriers. Lawful basis: contract performance with the merchant; legitimate interest of the merchant in operating their f-commerce shop, balanced against the customer's reasonable expectation that a shop will reply to their inquiry.
  • Service improvement on the merchant's own domain — refining guardrails, prompts, and routing for the specific merchant. Lawful basis: contract performance.
  • Cross-merchant model improvement — only with the merchant's explicit written opt-in, and with any opted-in conversation de-identified before it enters a training set. Default is off. Lawful basis: explicit consent (GDPR Art. 6(1)(a)).
  • Security, abuse prevention, and fraud detection — rate-limiting, anomaly detection, audit log, escalation when the agent detects probable abuse. Lawful basis: legitimate interest in protecting the platform and users.
  • Compliance with legal obligations — Bangladeshi tax record-keeping, responding to lawfully issued requests from regulators or law enforcement, defending legal claims. Lawful basis: legal obligation.

We do not sell personal data, we do not engage in cross-context behavioural advertising, and we do not allow advertisers to target users based on Meta Platform data we process.

Who we share with

We share personal data only with the categories of recipient below, each bound by a written data processing agreement that mirrors the obligations of this policy:

  • Meta Platforms Ireland Ltd. and Meta Platforms, Inc. — to deliver messages through Messenger, WhatsApp, and Instagram. Disclosure is limited to what is required to send a single message in response to a customer's inbound message, plus the management of the Page / WABA / IG handle association itself.
  • AI inference providers — Google Cloud Vertex AI for Gemini model calls. Inference contracts are zero-data-retention: prompts and outputs are not retained by the provider beyond the request itself, and are not used to train any provider-side model.
  • Infrastructure providers — managed hosting, observability, error reporting (sub-processor list available on request to [email protected]).
  • Courier and payment integrations — Pathao, Steadfast, RedX, eCourier, bKash, Nagad, Rocket, SSLCommerz. We share the minimum field set each integration requires to ship a parcel or settle a payment (typically: customer name, phone, shipping address, order amount, COD flag).
  • Professional advisers and auditors — counsel, accountants, compliance auditors, under confidentiality.
  • Regulators and law enforcement — only when compelled by lawfully issued orders, narrowed to the specific data the order requires.
  • Successor in interest — in the event of a merger, acquisition, or asset sale, we will transfer this data to the successor and notify affected merchants before the transfer takes effect.

Retention

We retain data only for as long as the workflow requires it, plus a short defensive window for support and audit:

  • Conversation messages and agent traces — 180 days by default; merchants may shorten in workspace settings.
  • Order records and invoices — 7 years, the period required by the Income Tax Ordinance 1984 (Bangladesh).
  • Operational telemetry — 13 months.
  • Operator accounts and audit logs — for the lifetime of the workspace plus 30 days after termination.
  • Backups — rolled forward and overwritten on a 30-day cycle.

A merchant may request earlier deletion at any time via /data-deletion. End customers can ask the merchant to delete a specific conversation, or contact Nirbhor directly at [email protected] if the merchant is unresponsive.

Your rights

Where applicable law grants the rights below — most notably the GDPR / UK GDPR for EU/UK data subjects and equivalent provisions of BD law for Bangladeshi data subjects — we honour them irrespective of the data subject's geographic location:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have data deleted, subject to retention obligations imposed on us by law (e.g. tax records).
  • Restriction and objection — pause certain processing activities.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — for processing based on consent, at any time, without affecting prior processing.
  • Lodge a complaint — with a competent supervisory authority. For BD: the Bangladesh Telecommunication Regulatory Commission. For EU: your national Data Protection Authority. For UK: the Information Commissioner's Office.

Email [email protected] from the address on the workspace, or use the self-serve deletion form. We acknowledge requests within 2 business days and complete them within 30 days; if the request is complex we may extend by an additional 30 days with notice. We do not charge for routine requests; we may charge a reasonable fee for manifestly unfounded or repetitive requests as permitted by GDPR Art. 12(5).

Meta platform data

Page access tokens, system user tokens, page metadata, message threads, and customer profile fields exposed by the Messenger Platform, WhatsApp Business Platform, and Instagram Graph API are Meta Platform data as defined by the Meta Platform Terms. We process Meta Platform data only to deliver the workflows the merchant has explicitly enabled — no advertising use, no resale, no enrichment of off-platform identity graphs.

We comply with the Meta Platform Terms, the Meta Developer Policies, and the WhatsApp Business Solution Terms. We complete Meta App Review prior to operating Standard Access in production. Where Meta's policies are stricter than this policy, Meta's policies prevail. A merchant may revoke our access at any time by removing the app from their Page Settings or WABA Business Manager; on revocation we cease processing and queue the associated data for deletion under the schedule above.

Contact

Data Protection Officer · [email protected] · Nirbhor is operated by Nirbhor - Md Forhad Hossain, a sole proprietorship (FIE) registered in Estonia, EU under Business Register code 17508470. Operations are based in Banani, Dhaka, Bangladesh. We respond in Bangla and English.

← Back to home

Connect your Facebook page. Watch the first reply ship.

Setup is fifteen minutes. The agent goes live in shadow mode first — drafting replies for your operator to approve — until you trust it enough to flip it to auto.

Start freeBook a 20-min walkthrough