Privacy Policy

Last updated: October 2026
DRAFT DOCUMENT: Subject to legal and regulatory review.
This Privacy Policy is a draft operational outline and must undergo formal review for compliance with relevant data protection legislation (e.g. Bangladesh Data Protection Act, GDPR where applicable).

1. Information Architecture & Tenant Isolation

ISPmix enforces cryptographic and architectural tenant isolation. Subscriber records, national identity document files, billing ledgers, and network credentials are strictly isolated per ISP tenant. Under no circumstances is cross-tenant data shared or aggregated without authorization.

2. Types of Data Processed

To provide broadband management services, the system processes subscriber contact details, installation addresses, national identification (NID/Passport) documents where required by telecom regulations, PPPoE credentials, IP addresses, invoice history, and support ticket transcripts.

3. Secret Encryption at Rest

Sensitive tenant integration secrets, including MikroTik router passwords, SMS gateway API credentials, and WhatsApp Business access tokens, are encrypted at rest using AES-256-GCM authenticated encryption and masked in administrative interfaces.

4. Access Controls & Audit Logging

All account access, permission changes, manual payment postings, and network override actions are permanently recorded in structured audit logs containing timestamps, IP addresses, and acting operator IDs.