—1. Introduction
bZm Graphics Limited ("bZm," "we," "us," or "our") respects your privacy and is committed to protecting the personal data of everyone who interacts with our business, including website visitors, prospective clients, and active clients.
This Privacy Policy describes how we collect, use, store, and share your personal information when you visit our website at bzmgraphics.com or engage our creative post-production services.
bZm Graphics Limited is incorporated in Bangladesh with offices in Dhaka, Dubai, and Texas. We act as the data controller for personal information processed under this policy. Where we engage third parties to process data on our behalf, we ensure they do so under appropriate data protection agreements.
—2. Information We Collect
We collect personal information in the following categories, depending on how you interact with us:
Information you provide directly:
- Name, email address, phone number, and company name submitted via contact or enquiry forms
- Project briefs, creative assets, and files you upload or share with us for editing
- Billing information such as company address and payment details processed through our payment providers
- Communications including emails, messages, and meeting notes exchanged during a project
Information collected automatically:
- IP address, browser type, device type, and operating system
- Pages visited, time spent on site, and referring URLs collected via analytics tools
- Cookie identifiers and similar tracking technologies (see Section 8)
—3. How We Use Your Information
We use your personal data only for the purposes for which it was collected, or for compatible purposes as permitted by applicable law. Specifically:
- Service delivery: To process project briefs, communicate with you about your work, and deliver completed files.
- Billing and payments: To issue invoices, process payments, and maintain financial records as required by law.
- Client support: To respond to enquiries, resolve issues, and provide after-delivery support.
- Marketing: To send newsletters, service updates, or promotional content only where you have given consent or we have a legitimate interest, and always with an option to unsubscribe.
- Website improvement: To analyse site usage patterns and improve the user experience through aggregated, anonymised analytics.
- Legal compliance: To comply with applicable laws, regulations, and court orders.
—4. Legal Basis for Processing
Where applicable data protection legislation requires us to identify a legal basis for processing your personal data, we rely on the following:
- Contract performance: Processing necessary to deliver the services you have engaged us to provide.
- Legitimate interests: Processing necessary for our legitimate business interests, such as improving our services, maintaining security, and conducting direct marketing to existing clients, provided these interests are not overridden by your rights.
- Legal obligation: Processing required to comply with tax, accounting, or other legal requirements.
- Consent: Processing based on your explicit consent, such as subscribing to our newsletter. You may withdraw consent at any time without affecting the lawfulness of prior processing.
—6. Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention schedule is:
- Client assets (source files): Deleted within 90 days of project completion, unless a longer retention period is agreed in writing.
- Project correspondence and records: Retained for 5 years from the date of the last transaction, in line with standard commercial record-keeping requirements.
- Financial and billing records: Retained for 7 years as required by tax regulations.
- Marketing data: Retained until you withdraw consent or opt out of communications.
- Website analytics: Retained in anonymised, aggregated form with no fixed end date; identifiable session data is not retained beyond 26 months.
—7. Your Rights
Depending on your location, you may have the following rights with respect to your personal data. We will respond to verified requests within 30 days.
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data where we no longer have a lawful basis to retain it.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Request a structured, machine-readable copy of data you have provided to us.
- Objection: Object to processing based on our legitimate interests, including direct marketing.
- Withdrawal of consent: Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.
To exercise any of these rights, please contact us at privacy@bzmgraphics.com. We may need to verify your identity before processing a request.
—9. Security
bZm Graphics Limited takes data security seriously. We maintain administrative, technical, and physical safeguards designed to protect your personal information from unauthorised access, loss, misuse, or disclosure.
Our measures include ISO 27001-aligned practices, encrypted file storage, restricted staff access on a need-to-know basis, regular security audits, and secure file transfer protocols for all client asset exchanges.
While we implement these safeguards, no method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach that is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority without undue delay and within the timeframes required by applicable law.
—10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will notify active clients by email at least 14 days before the revised policy takes effect.
The most current version of this policy is always available at bzmgraphics.com/privacy-policy. The effective date at the top of this page indicates when it was last revised.
—11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please reach out to our privacy team: