This Privacy Policy applies to OBAYED (operated by MD. ABU OBAYEDA, "we", "us", or "our") and governs the collection, use, and protection of personal information obtained through our website at obayed.com and through our professional services. Please read this Policy carefully. By using our website or engaging our services, you agree to the practices described here.
About This Policy
This Policy describes how we handle personal data when you:
- Visit and interact with our website (obayed.com)
- Contact us via email, phone, or social media
- Engage us for any of our services including AI systems, GHL SaaS, web development, or related digital services
- Participate in our projects as a client or stakeholder
We process personal data only for the purposes described in this Policy and only to the extent necessary for those purposes.
Information We Collect
We collect two main categories of information: information you actively provide to us, and information collected automatically when you use our website or services.
Information Provided by You
When you contact us, request a proposal, or engage our services, you may provide us with:
- Contact details: Full name, email address, phone number, and business name.
- Project information: Details about your business, requirements, budget, and goals you share during consultations or project discussions.
- Account credentials: Login details for platforms we access on your behalf to deliver agreed services (e.g., your GHL account, hosting, domain registrar). We treat these with strict confidentiality and do not store them beyond operational necessity.
- Business data: Any content, data files, images, databases, or customer lists you share with us as part of a project. You are responsible for ensuring you have the right to share this data with us.
- Communications: Records of your correspondence with us via email, WhatsApp, or other channels.
- Payment information: Billing details necessary to process payments (see Section 8 on Payment Processors).
Automatically Collected Information
When you visit our website, we automatically collect certain technical information including:
- Usage data: Pages visited, time spent on pages, links clicked, and navigation patterns.
- Device and browser information: Browser type and version, operating system, screen resolution, and device type.
- IP address: Your approximate geographic location based on IP address (country/region level).
- Referrer data: The website or source that directed you to our site.
- Cookie data: Information stored in cookies as described in Section 9.
This information is collected via analytics tools and is primarily used in aggregate form to understand how visitors use our website.
How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: To provide, manage, and deliver the services you have engaged us for, including configuration, development, automation, and support.
- Communication: To respond to your enquiries, provide project updates, send invoices, and manage our business relationship.
- Project management: To understand your requirements, plan work, and coordinate with any subcontractors or third-party platforms necessary for your project.
- Billing and payments: To create and send invoices, process payments, and maintain financial records.
- Legal compliance: To comply with applicable laws, regulations, and contractual obligations.
- Website improvement: To understand how visitors use our website and to identify and fix issues or improve content.
- Security: To detect and prevent fraud, unauthorised access, or misuse of our services.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
AI Services & Data Processing
When we build or deploy AI systems, chatbots, or automation workflows for you, data handling has specific considerations:
- Data used to train or configure AI: Any data you provide for building AI workflows (e.g., example conversations, business knowledge bases, customer scripts) is used solely to configure your AI system. We do not use your proprietary data to train our own general models.
- AI API providers: AI systems we build may transmit prompts, user inputs, and context data to third-party AI APIs (such as OpenAI, Anthropic, or Google AI). These providers process data according to their own privacy policies. We will inform you of which AI providers are used in your project before commencement.
- Conversation logs: AI chatbot conversations may be logged for quality assurance, debugging, and system improvement purposes. The retention and access controls for these logs will be specified in your project agreement.
- Personal data in AI systems: If your AI system processes personal data about third parties (e.g., your end customers), you are the data controller for that data. You are responsible for ensuring your use of the AI system complies with applicable data protection laws, including obtaining any necessary consents from your users.
We strongly recommend reviewing the privacy policies of any third-party AI providers used in your project, as their data handling practices may differ from ours.
GoHighLevel (GHL) & Third-Party Integrations
For clients using GHL or other SaaS platforms as part of our services:
- Data stored within a GoHighLevel sub-account (contacts, pipelines, conversations, campaigns) is stored on GoHighLevel's infrastructure and is subject to GoHighLevel's own Privacy Policy.
- We access your GHL account solely to configure, set up, and support your sub-account as agreed. We do not access GHL accounts beyond the scope necessary to deliver services.
- Third-party integrations we configure on your behalf (e.g., Zapier, Twilio, Meta, Google) are governed by the respective platform's own privacy policy. You should review each platform's terms before use.
- Where we act as a reseller or manager of a white-label CRM platform, you (the reseller) are the primary data controller for your end clients' data within that platform. We act as a data processor on your behalf.
Payment Processors
We do not directly collect or store full payment card details. Payment transactions are processed through secure third-party payment processors. These processors collect and handle your payment information according to their own privacy policies and are responsible for maintaining PCI-DSS compliance.
We may receive limited transaction confirmation information (such as a payment reference number, amount, and timestamp) to reconcile our invoicing records.
We will inform you of the specific payment processor(s) used when invoicing. Always verify you are using a legitimate payment channel before submitting payment details.
Analytics & Cookies
Our website uses cookies and similar tracking technologies to operate correctly and to understand visitor behaviour. We use the following types:
- Essential cookies: Required for the website to function (e.g., session management, navigation). These cannot be disabled without impacting site functionality.
- Analytics cookies: We use Google Analytics to collect anonymised data about how visitors use our website (page views, session duration, traffic sources). This data is processed by Google in accordance with Google's Privacy Policy. IP addresses are anonymised.
- Marketing/tracking pixels: We may use tracking pixels (e.g., Meta Pixel) to measure the effectiveness of our own marketing campaigns. These tools may set cookies and transmit data to the respective platforms.
You can control or disable cookies through your browser settings. Disabling certain cookies may affect your experience on our website. Most modern browsers allow you to review and delete cookies via the browser's privacy or security settings.
Data Sharing & Service Providers
We do not sell your personal data. We may share your information only in the following limited circumstances:
- Service delivery partners: Trusted subcontractors or specialist contractors who assist us in delivering your project. These parties are bound by confidentiality obligations and may only process your data as instructed by us.
- Technology platforms: Third-party platforms and APIs used to deliver your project (e.g., cloud hosting providers, AI API services, automation platforms). These are governed by their own privacy policies.
- Payment processors: As described in Section 8, to facilitate payment transactions.
- Analytics providers: Anonymised, aggregated website usage data with analytics platforms such as Google Analytics.
- Legal obligations: If required to do so by law, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfer: In the unlikely event of a merger, acquisition, or sale of business assets, client data may be transferred to the relevant successor entity. We will notify you of any such change.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to meet legal, accounting, or reporting requirements:
- Client and project data: Retained for the duration of the client relationship and for a reasonable period thereafter (typically up to 3 years) for record-keeping, follow-up, and legal purposes.
- Financial records: Invoices and payment records are retained for at least as long as required by applicable tax laws in our jurisdiction.
- Communications: Email and message records are retained as long as reasonably necessary for business purposes, and then securely deleted.
- Website analytics: Aggregated, anonymised analytics data may be retained indefinitely. Individual session data is retained according to Google Analytics' default retention settings.
Upon the conclusion of a client relationship, you may request the deletion or return of any data you have provided, to the extent technically and legally practicable.
Data Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Use of encrypted communication channels (HTTPS) for all website interactions.
- Restricting access to sensitive client data to authorised personnel only, on a need-to-know basis.
- Securely handling and storing any credentials provided to us during a project engagement.
- Using reputable, security-audited cloud infrastructure and third-party platforms.
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you promptly in accordance with applicable law.
Your Rights & Privacy Requests
Depending on your location and applicable data protection laws, you may have certain rights regarding your personal data. These may include:
- Access: The right to request a copy of the personal data we hold about you.
- Correction: The right to request correction of inaccurate or incomplete personal data.
- Deletion: The right to request deletion of your personal data, subject to legal obligations to retain certain records.
- Restriction: The right to request that we restrict the processing of your data in certain circumstances.
- Portability: The right to receive your data in a structured, machine-readable format where applicable.
- Objection: The right to object to processing of your personal data for direct marketing purposes.
- Withdrawal of consent: Where we rely on your consent to process data, the right to withdraw that consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the details in Section 17. We will respond to requests within a reasonable timeframe and in accordance with applicable law. We may need to verify your identity before processing your request.
International Data Transfers
OBAYED operates from Bangladesh. Some of the third-party platforms and service providers we use (such as Google, OpenAI, GoHighLevel, and others) are based in other countries, including the United States. When you use our services or when we use these platforms to deliver your project, your data may be transferred to and processed in countries outside your home country.
We take steps to ensure that such transfers are conducted in compliance with applicable data protection laws, including relying on the providers' standard contractual clauses or equivalent safeguards where required.
By using our services, you acknowledge and consent to the potential transfer of your data to countries outside your jurisdiction, including countries that may have different data protection standards than your own.
Children's Privacy
Our website and services are intended for adults and business clients. We do not knowingly collect personal data from children under the age of 16 (or such other minimum age as applicable law requires in your jurisdiction).
If you believe that we have inadvertently collected information from a child under the applicable minimum age, please contact us immediately at abuobeyada574@gmail.com and we will take prompt steps to delete the information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, applicable laws, or our data practices. When we make material changes, we will update the "Last Updated" date at the top of this page.
We encourage you to review this Policy periodically. For active clients, we will notify you of material changes via email where reasonably practicable. Your continued use of our services following any changes constitutes your acceptance of the revised Policy.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please contact us:
- Email: abuobeyada574@gmail.com
- Phone: 01846360929
- Location: Dhaka, Bangladesh
We take privacy concerns seriously and will respond to your enquiry as promptly as possible.
Questions About Your Privacy?
Contact us directly – we'll respond promptly and transparently.